Take 1 Security Podcast: Episode 11

Take 1 Security Podcast: Episode 11



Play Podcast

START CONTENT


* Twitch, a game streaming service owned by Amazon, was hacked last week


* Passwords, emails, usernames, addresses, phone numbers, dates of birth
* Amazon bought them last year for almost 1 billion dollars

* Bar Mitzvah attack on TLS


* Requires that you can sniff traffic
* Basically an RC4 problem
* Solution is to remove it from your supported algorithms

* GitHub Has been hit by a massive DDoS attack


* Apparently from China

* CSRF vulnerability found in a wind turbine


* Allowed you to pull usernames and passwords
* Also allowed the password to be changed for the default user, which had admin access

* CSRF vulnerability exposes Hilton customer accounts


* There was an account rotation issue where you could gain access to their account as long as you could guess their 9-digit username

* Snowden says IT workers now the targets of spies


* They’re not going after their information, but to use them for access to networks

* Premera hacked on same day as Blue Cross (January 29th)


* Same story: encryption, know your network, etc.
* Also same story: health data is harder to clean up from because it involves PII that cannot easily be changed
* More speculation around these attacks is that they’re data gathering for larger attacks on government networks

* Apple Acquires FoundationDB


* Fast NoSQL database probably to be used for its increasing entry into the services market

* Researchers use heat to breach air-gapped systems


* Everyone knows that an airgap is the best defense
* Ben-Gurion University came out with BitWhisper
* Now bidirectional using malware on both systems that controlled heat creation and detection
* Only 8-bits per hour

* BioCatch, Zumigo, Alibaba release tools to identify users


* I used to work with a technology called BioPass
* Uses what you do with your mouse, scrolling, how you smile via selfie, compares habits, your current location, etc. Similar to existing fraud detection just with more data points
* Really cool tech, needs to be used with the right authentication level

* Korea investing 5B in IoT and Smart Cars
* Bring Your Own IoT


* Recording audio and video are getting increasingly easy
* Sensitive meetings might become dead zones soon, and perhaps even sensitive work areas
* Some people will say that we already have this risk, but they key is the ease with which it can be done



END CONTENT

Play Podcast

Notes


* I skipped a week due to travel in Asia.

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Episoder(532)

The Experience of Free Will is Not Free Will

The Experience of Free Will is Not Free Will

A short essay on how it's possible to experience free will without it being real.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

1 Feb 20175min

Unsupervised Learning: No. 63

Unsupervised Learning: No. 63

Peak Prevention at AppSec Cali, Austrian Hotel Ransomware, Russian FSB Drama, WordPress Issues, AV Conflicts, Uber Pays Another Company's Bounty, Data Science, Rules for Rulers…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

30 Jan 201746min

Unsupervised Learning: No. 62

Unsupervised Learning: No. 62

An OWASP Gaming Security Framework, infosec news, OPSEC is obscurity, AMP is a horrible idea, the End of Twitter, the Sound of Silence, chaning your Echo wake word, RAWGraphs, Ask Lesley, and more…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

22 Jan 201728min

Unsupervised Learning: No. 61

Unsupervised Learning: No. 61

Nasty new GMail phishing bug, Microsoft kills security bulletins, ShadowBrokers go dark, Cellebrite hacked, Combining sensor data with machine learning, the tradeoff between privacy and IoT functionality, and more…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

16 Jan 201739min

Gratitude is the Epicenter of Happiness

Gratitude is the Epicenter of Happiness

The elusive center of happiness is gratitude, and the reason seems to be evolution.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

14 Jan 20174min

If You Believe Nothing You Can Be Convinced of Anything

If You Believe Nothing You Can Be Convinced of Anything

An essay about the Russian hacking attribution issue, and how people who cannot differentiate the credibility of information sources are ultimately set to believe anything rather than nothing.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

13 Jan 201712min

Unsupervised Learning: No. 60

Unsupervised Learning: No. 60

How we know Russia did it, the FBI using Best Buy, an IBM study on ransomware, MongoDB hacks, and more…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

11 Jan 201731min

4 Things To Do in the First Week of Every January

4 Things To Do in the First Week of Every January

A short piece on why I don't like New Years resolutions, and the four things I prefer to do instead. Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

27 Des 20162min

Populært innen Teknologi

romkapsel
rss-avskiltet
teknisk-sett
tomprat-med-gunnar-tjomlid
energi-og-klima
shifter
rss-impressions-2
elektropodden
fornybaren
smart-forklart
nasjonal-sikkerhetsmyndighet-nsm
rss-alt-som-gar-pa-strom
rss-alt-vi-kan
teknologi-og-mennesker
kunstig-intelligens-med-morten-goodwin
rss-snakk-om-sikkerhet
rss-bouvet-bobler
rss-digitaliseringspadden
rss-teams-cast-away
rss-bits-and-bytes-for-advokater