Take 1 Security Podcast: Episode 11

Take 1 Security Podcast: Episode 11



Play Podcast

START CONTENT


* Twitch, a game streaming service owned by Amazon, was hacked last week


* Passwords, emails, usernames, addresses, phone numbers, dates of birth
* Amazon bought them last year for almost 1 billion dollars

* Bar Mitzvah attack on TLS


* Requires that you can sniff traffic
* Basically an RC4 problem
* Solution is to remove it from your supported algorithms

* GitHub Has been hit by a massive DDoS attack


* Apparently from China

* CSRF vulnerability found in a wind turbine


* Allowed you to pull usernames and passwords
* Also allowed the password to be changed for the default user, which had admin access

* CSRF vulnerability exposes Hilton customer accounts


* There was an account rotation issue where you could gain access to their account as long as you could guess their 9-digit username

* Snowden says IT workers now the targets of spies


* They’re not going after their information, but to use them for access to networks

* Premera hacked on same day as Blue Cross (January 29th)


* Same story: encryption, know your network, etc.
* Also same story: health data is harder to clean up from because it involves PII that cannot easily be changed
* More speculation around these attacks is that they’re data gathering for larger attacks on government networks

* Apple Acquires FoundationDB


* Fast NoSQL database probably to be used for its increasing entry into the services market

* Researchers use heat to breach air-gapped systems


* Everyone knows that an airgap is the best defense
* Ben-Gurion University came out with BitWhisper
* Now bidirectional using malware on both systems that controlled heat creation and detection
* Only 8-bits per hour

* BioCatch, Zumigo, Alibaba release tools to identify users


* I used to work with a technology called BioPass
* Uses what you do with your mouse, scrolling, how you smile via selfie, compares habits, your current location, etc. Similar to existing fraud detection just with more data points
* Really cool tech, needs to be used with the right authentication level

* Korea investing 5B in IoT and Smart Cars
* Bring Your Own IoT


* Recording audio and video are getting increasingly easy
* Sensitive meetings might become dead zones soon, and perhaps even sensitive work areas
* Some people will say that we already have this risk, but they key is the ease with which it can be done



END CONTENT

Play Podcast

Notes


* I skipped a week due to travel in Asia.

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Episoder(531)

Don’t Judge Yourself Based On What Companies Think of Your Skills

Don’t Judge Yourself Based On What Companies Think of Your Skills

I watched a number of videos last night about people losing their jobs, starting a YouTube channel, and just generally struggling. People are hurting because they’re feeling the ground shifting under their feet and it’s not clear if it’s their fault, what’s going on, or what to do about it. Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

29 Aug 20244min

Microsoft Fires DEI Team & The Correct Approach To Diversity

Microsoft Fires DEI Team & The Correct Approach To Diversity

Microsoft Lays Off DEI Team — Microsoft laid off its diversity, equity, and inclusion team, saying DEI is "no longer business critical." MORE Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

27 Aug 20242min

UL NO. 446: AI Ecosystem Components, MS 0-Days, Iranian Campaign Hacks…

UL NO. 446: AI Ecosystem Components, MS 0-Days, Iranian Campaign Hacks…

Political deepfakes are here, Grok2 is insane, weakness vs. evil, and more…  Check out ThreatLocker to secure your data: threatlocker.com/ul Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!   Discussed in this episode: Intro (00:00:00)Migration to Go (00:01:45)Aphorisms and AI Models (00:03:09)Peter Thiel and Joe Rogan Discussion (00:04:12)Thiel's Intellectual Approach (00:05:15)Thiel's Complexity (00:07:25)Community Libraries (00:11:13)AI Model Ecosystems (00:12:12)Microsoft Security Flaws (00:13:15)Russian Cyber Campaign (00:13:45)Taiwan Strait Drone Strategy (00:14:24)Offensive AI Research (00:14:45)Cyber Attacks on Iranian Banks (00:15:21)Trump's Fake Image Controversy (00:15:21)Deepfakes and Misinformation (00:16:16)Potential for Crisis from Misinformation (00:18:24)Iranian Hacking Campaigns (00:19:31)China's Cyber Spies (00:20:22)AI Image Generation Chaos (00:20:22)AI in Comedy (00:21:28)Deepfake Comedy Integration (00:22:40)Future of Deepfake Comedy (00:23:28)San Francisco's Software Ban (00:23:28)China's Manufacturing Crisis (00:24:25)Venture Capital Trends (00:25:30)Gen Z Unemployment Trends (00:28:24)Impact of Technology on Childhood (00:29:28)Dopamine Levels and Boredom (00:32:22)Privilege of Stable Households (00:34:23)Market for Content Authenticity (00:35:24)Weakness vs. Evil (00:35:24)Fabric Integration with Raycast (00:36:25)Eric Schmidt's Honest Interview (00:37:59)AI as Augmentation Technology (00:38:63)Live Coding Demonstration (00:39:57)The Importance of AI Awareness (00:41:08)Aphorism of the Week (00:41:29)Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

22 Aug 202442min

Introducing Substrate—An Open-source Framework for Human Understanding, Meaning, and Progress

Introducing Substrate—An Open-source Framework for Human Understanding, Meaning, and Progress

This episode introduces Substrate—An Open-source Framework for Human Understanding, Meaning, and Progress.  Substrate is a crowdsourced project designed to enhance understanding, communication, and action in order to move humanity forward. Read the Article:📃 https://danielmiessler.com/p/introducing-substrate TOPICS:Introduction to Substrate (00:00:00)Components of Substrate (00:01:18)GitHub Repository Overview (00:02:33)Purpose of Substrate (00:04:36)Argument Visualization Example (00:05:32)Graphical Representation of Arguments (00:07:55)Trust in Sources (00:09:56)Strengthening Discussions (00:10:57)Real-World Use Cases (00:11:54)Describing Yourself with Substrate (00:12:55)Learning About Others (00:14:54)Visualizing Arguments and Claims (00:15:51)Transparency in Evaluating Claims (00:17:59)The Tiny Teapot Claim (00:18:54)Substrate Plus AI (00:20:04)Automating Science Workflows (00:21:16)Monitoring Crime and Corruption (00:24:21)Leadership Accountability (00:29:49)Companies as Graphs of Algorithms (00:31:56)Future State Optimization (00:35:47)Understanding Security Assessment (00:36:41)Optimizing Processes with AI (00:37:46)The Purpose of Substrate (00:38:49)AI's Role in Substrate (00:39:56)Want to Be Involved? (00:39:56) REFERENCED RESOURCES: My 9,000-word Illustrated Essay on Where I Think AI is Heading🔥 https://danielmiessler.com/p/ai-predictable-path-7-components-2024 The Substrate Project:⚙️ https://github.com/human-substrate Follow on X:🆇 https://x.com/danielmiessler Subscribe to the newsletter at: ✉️ https://danielmiessler.com/subscribe Join the UL community at:🤝🏻https://danielmiessler.com/upgradeBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

9 Aug 202441min

UL NO. 444: Pizza Meter Intelligence, China Bypasses Bans, Securing AWS Secrets…

UL NO. 444: Pizza Meter Intelligence, China Bypasses Bans, Securing AWS Secrets…

What to expect at Blackhat/DEFCON, Identifying Explosives, OpenAI's new models, Llama 4 Timeline, and more…  ➡ Check out Vanta and get $1000 off:vanta.com/unsupervised Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!Discussed in this episode:Intro (00:00:00)OSINT and the Pizza Index (00:01:08)Agent Framework Development (00:02:12)State of Cybersecurity (00:04:08)Critical Security Vulnerabilities (00:05:27)Ransomware Trends (00:06:25)Data Breach Costs (00:07:29)AI Developments (00:08:40)California AI Regulation (00:09:42)OpenAI's GPT-4 Launch (00:11:01)Tech Company Updates (00:12:03)Shifts in Workforce Dynamics (00:13:07)Prisoner Swap News (00:17:06)Shark AI Model (00:18:03)Dementia Prevention Insights (00:19:03)Genetics of Self-Control (00:20:12)Name and Appearance Study (00:20:12)Alzheimer's Disease Research (00:20:12)Dungeons and Dragons Rulebooks (00:20:12)Novelists Writing Bug Reports (00:21:22)Recent UBI Study Analysis (00:21:22)Free-Range Kids Initiative (00:21:22)Discovery Farm Bot (00:22:13)Super Memory AI (00:22:13)Avi Shipman's AI Pendant (00:22:13)Installing Fabric (00:22:13)Fleet Open Source Tool (00:22:13)SOC2 Policy Templates (00:22:13)Clutch Security Platform (00:22:13)Black Hat Reminder (00:23:48)Aphorism of the Week (00:23:48)Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

9 Aug 202424min

Scaling Misinformation With AI

Scaling Misinformation With AI

Daniel Miessler discusses how AI can grow the number of elite propagandists and hackers employed by foreign intelligence agencies. Discussed in this video: AI-Enhanced Software and Disinformation (00:00:00)Russia utilizes AI software, Millio Radar, to create sophisticated fake personas for disinformation. Concerns About AI Sophistication (00:01:12)The increasing capabilities of AI could enable enemies to manipulate information on a massive scale. Shift from Block List to Allow List (00:02:30)The internet may need to transition to an allow list system to combat overwhelming disinformation. Risks for Ordinary Individuals (00:03:44)Regular users, especially the less tech-savvy, are at high risk of falling victim to manipulation online. Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

7 Aug 20245min

UL NO. 443: North Korean Co-workers, UBI Failure?, AI-Groupthink, GPS Spoofing…

UL NO. 443: North Korean Co-workers, UBI Failure?, AI-Groupthink, GPS Spoofing…

Switzerland goes open source, Google keeps cookies, DJI not cancelled, Alzheimer's spray, and more… ➡ Check out Vanta and get $1000 off:vanta.com/unsupervised Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!Discussed in this episode: Intro (00:00:00)Job Loss and Career Change (00:01:42)Self-Worth in the Job Market (00:02:55)The Need for Kindness (00:03:54)North Korean Cybersecurity Threat (00:04:57)GPS Spoofing Risks (00:07:11)Malicious Acts Disrupting Transportation (00:08:10)Google's Cookie Policy Change (00:09:19)AI's Impact on the Job Market (00:10:30)Generative AI and Creativity (00:11:32)Concerns Over AI Influence (00:12:50)Switzerland's Open Source Law (00:15:08)Waymo vs. Tesla in Self-Driving (00:16:07)Hiring Practices in Tech Companies (00:17:07)Declining U.S. Birthrate (00:18:11)Universal Basic Income (00:18:11)Building a Star Team (00:19:48)Overcoming Disadvantages (00:23:06)Distribution of Talent (00:24:07)Southwest Airlines Policy Change (00:25:16)Economic Stress in America (00:26:32)Breakthroughs in Medicine (00:27:45)Conspiracy Theories in Politics (00:28:32)Humanizing Political Differences (00:30:00)Lessons from "The Righteous Mind" (00:31:16)The Importance of Empathy (00:32:17)  Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

5 Aug 202433min

A Conversation with Christine Gadsby from BlackBerry

A Conversation with Christine Gadsby from BlackBerry

In this conversation, I speak with Christine Gadsby, Head of Product Security Operations Team at BlackBerry. We talk about: The Role of AI in Cybersecurity:  AI's real advancements, practical applications, and associated challenges, moving beyond the hype.  Enhancing Incident Response and Threat Hunting Christine highlights AI's significant impact on enhancing incident response and threat hunting, how AI quickly analyzes vast data to identify Indicators of Compromise (IoCs), automates routine tasks, and improves decision-making with actionable insights.  The Evolution of Blackberry in Cybersecurity Christine discusses Blackberry's shift from mobile devices to cybersecurity, emphasizing their focus on highly regulated environment and how the acquisition of Silence brought advanced AI capabilities, enhancing their security solutions.  Among other topics.  Intro (00:00:00)AI in Cybersecurity: Hype or Reality? (00:00:06)Incident Response and Threat Hunting (00:01:12)Automation in Security Programs (00:02:08)Industry-Specific AI Needs (00:03:20)AI's Role in Regulated Environments (00:04:23)Blackberry's AI Integration (00:04:50)Perceptions of Blackberry's Evolution (00:06:51)Trust in Vendor Relationships (00:09:11)AI's Potential in Monitoring (00:11:12)Challenges of Staffing in Cybersecurity (00:13:18)Staff Turnover in Cybersecurity (00:13:54)Burnout and Job Satisfaction (00:14:18)Hiring Challenges in Security (00:15:17)Confusion in Cyber Job Market (00:16:10)Job Changes Among Cyber Leaders (00:17:10)Outsourcing Security Functions (00:18:09)Pressure from Boards (00:18:57)Evolving Security Needs (00:19:40)Human Element in Cybersecurity (00:20:46)Talent Pipeline Issues (00:21:40)Challenges of Smaller Companies (00:22:32)Job Satisfaction and Workload (00:24:03)Pressure Cooker Environment (00:24:43)Crypto Attacks Resurgence (00:26:16)Crypto Mining Discussion (00:26:33)APT 32 Insights (00:27:22)Employee Training Importance (00:28:41)Indicators of Crypto Mining (00:29:45)Detection Challenges (00:30:30)Normal System Behavior (00:32:13)Looking Ahead to 2025 (00:32:44)*Supply Chain Pressures (00:35:08)Arms Race in Security (00:35:27)Liability Hot Potato (00:36:27)Managed Services Growth (00:36:44)Cyber Insurance Trends (00:37:52)CISO Evolution (00:39:10)The Importance of Trust in Supply Chain (00:39:56)Predictions for Cybersecurity Roles (00:40:46)Following Blackberry's Work (00:41:00)Networking and Future Conversations (00:41:05)Conclusion (00:41:37)Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

5 Aug 202441min

Populært innen Teknologi

romkapsel
rss-avskiltet
teknisk-sett
tomprat-med-gunnar-tjomlid
energi-og-klima
rss-impressions-2
shifter
nasjonal-sikkerhetsmyndighet-nsm
elektropodden
fornybaren
rss-alt-vi-kan
rss-alt-som-gar-pa-strom
smart-forklart
rss-snakk-om-sikkerhet
teknologi-og-mennesker
kunstig-intelligens-med-morten-goodwin
rss-bouvet-bobler
i-loopen
pedagogisk-intelligens
rss-digitaliseringspadden