T1SP: Episode 24

T1SP: Episode 24



[ Subscribe to the Podcast: iTunes | Android | RSS ]

News


* [ ] Norse lays of 20 people; not clear what percentage that is; threat intel not going so well?
* [ ] OPM declines to release details on its big breach
* [ ] Juniper says it’s going to remove the code that it thinks was developed by the NSA to eavesdrop on traffic
* [ ] CVE details lists (OS X, iOS, Flash, Air, IE, Chrome, Firefox) as the software with the most issues
* [ ] GM is going to do a bug bounty
* [ ] The Hacker Manifesto turned 30 (My crime is that of curiosity)
* [ ] Sophos Home free for Windows and Mac users
* [ ] SF Yellowcab filling for bankruptcy
* [ ] Hackers shut down Ukraine power grid; evidently a malicious word doc sent via email; supposedly the Sandworm Team
* [ ] Bicycle Attack on TLS: https://guidovranken.files.wordpress.com/2015/12/https-bicycle-attack.pdf
* [ ] North Korea evidently detonated a hydrogen bomb
* [ ] Time warner customers lose email passwords (320K)
* [ ] Microsoft killing off IE 8, 9, and 10 on January 12th
* [ ] VTech launching new product line after it got hacked and leaked data on 6 million kids
* [ ] Big Flash player update, 0-day and 18 other issues


Ideas, updates, and discussion


* [ ] Back to Ubuntu from CentOS
* [ ] Sick for five weeks
* [ ] Ikigai (what you love, what the world needs, what you can be paid for, what you are good at)
* [ ] Giving books as gifts


Tools, talks, and projects


* [ ] TOWER-SEC protecting ECUs and Telematics on cars
* [ ] AppSensor project; Detection points: https://www.owasp.org/index.php/AppSensor_DetectionPoints
* [ ] Where the Science is Taking Us in Cybersecurity, Dan Geer
* [ ] Rapid7 Hackazon app (modern)
* [ ] DVNA (Damn vulnerable Node Application)
* [ ] Argon2 password hashing algorithm
* [ ] Dradis
* [ ] Kippo SSH honeypot


[ Subscribe to the Podcast: iTunes | Android | RSS ]

Notes


* The intro track is from one of my favorite EDM artists: Zomby. The song is ‘Orion’, and it’s from the ‘With Love’ album. Highly recommended if you like chill EDM.
* It’s better to listen via iTunes or with the player embedded above, but you can also download the sound file directly.

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Jaksot(532)

NO. 376 | AI transforms security, existential risk, and how to stay in front…

NO. 376 | AI transforms security, existential risk, and how to stay in front…

NO. 376 | AI transforms security, existential risk, and how to stay in front…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

3 Huhti 202320min

NO. 375 — 6 Post-GPT Phases, Github's Private Key, New Assistant Interfaces

NO. 375 — 6 Post-GPT Phases, Github's Private Key, New Assistant Interfaces

6 Post-GPT Phases, Github's Private Key, New Assistant InterfacesBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

27 Maalis 202317min

NO. 374 — AI Response Shaping, SpaceX Blueprints, GPT-4 Innovation Explosion…

NO. 374 — AI Response Shaping, SpaceX Blueprints, GPT-4 Innovation Explosion…

NO. 374 — AI Response Shaping, SpaceX Blueprints, GPT-4 Innovation Explosion…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

21 Maalis 202312min

NO. 373 — SPQA Architecture, LLaMA on M1 Mac, Loved Ones Voice Scams…

NO. 373 — SPQA Architecture, LLaMA on M1 Mac, Loved Ones Voice Scams…

NO. 373 — SPQA Architecture, LLaMA on M1 Mac, Loved Ones Voice Scams… Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

13 Maalis 202317min

Sponsored Interview — Kolide

Sponsored Interview — Kolide

Today I’m doing a Sponsored Interview with Kolide — a company I’ve heard a lot about recently and have been looking forward to chatting with. I’m talking to Jason Meller, the founder and CEO of Kolide and we talk about: The problems in the BOYD space Kolide’s approach to solving the problem A user-centric approach to policy compliance His view of what stops other players from being successful And other topics So with that, here’s Jason Meller… https://kolide.com/unsupervisedlearning  Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

13 Maalis 202337min

NO. 372 — LastPass Employee Hack, State AI Propaganda, Crowdstrike Report Analysis…

NO. 372 — LastPass Employee Hack, State AI Propaganda, Crowdstrike Report Analysis…

NO. 372 — LastPass Employee Hack, State AI Propaganda, Crowdstrike Report Analysis…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

7 Maalis 202329min

NO. 371 | Covid Lab Leak, Military Server Exposed, OAI Foundry…

NO. 371 | Covid Lab Leak, Military Server Exposed, OAI Foundry…

NO. 371 | Covid Lab Leak, Military Server Exposed, OAI Foundry…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

27 Helmi 202322min

NO. 370 | GoDaddy Hack, EU Chinese APTs, Hacking with ChatGPT

NO. 370 | GoDaddy Hack, EU Chinese APTs, Hacking with ChatGPT

NO. 370 | GoDaddy Hack, EU Chinese APTs, Hacking with ChatGPTBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

21 Helmi 202314min