Take 1 Security Podcast: Episode 3

Take 1 Security Podcast: Episode 3



START CONTENT


* There was an issue with the Marriott website that exposed reservations and payment information. It’s now been fixed
* Police are now using a new radar to see into peoples’ homes without a warrant
* Security budgets are reportedly going up due to the mega-breaches in 2014


* Also leading to higher pay for CIOs
* Anecdotally, I’d say it’s a pretty good time to be in infosec

* A new security startup, PFP Cybersecurity, uses power consumption to detect malware


* Meant initially to be used for SCADA type systems

* The US hacked North Korean computers back in 2010


* This is reportedly the reasons we were so sure they hacked Sony
* Recently leaked documents from Snowden show heavy offense

* Snowden recently talked to Schneier at Harvard about a number of things


* The NSA is becoming increasingly offensively oriented vs. defensive
* The NSA supposedly uses compromised systems as jump points
* Snowden said most NSA hackers are junior enlisted with limited skills

* Russia reportedly hacking for geopolitical gain, not just money
* Millions of gas stations could be at risk of shutdown


* The Automated Tank Gauges can be remotely accessed by attackers
* Could be manipulated to cause alerts
* Potentially could be used to stop the flow of fuel

* Microsoft gave Charlie Hebdo data to FBI in 45 minutes
* Starwood hack based on bad passwords


* Bad passwords, password re-use, and a brute forcing tool
* Account harvesting is rough: user enumeration, weak passwords, and lack of account lockout

* Flash has another major exploit. Update your stuff.
* People continue to be worried that the President’s crackdown on hackers could hurt security professionals


* Congress is meeting on the 27th of January to discuss breach notification

* The wireless in around 2 million cars is highly vulnerable to attack
* A polish company has created Mouse-Box, which is an entire computer inside of a mouse enclosure


END CONTENT

Play Podcast

Notes


* Sorry about the noise part way through. My girl walked in and started unpacking groceries. But when I say one take, I mean one take.

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Avsnitt(532)

News & Analysis | No. 277

News & Analysis | No. 277

CISA FBI and NSA Release Five APT29 Targeted Vulnerabilities, FBI Benign Hacking, The US Sanctioned Russia and Expelled Diplomats, Google's Cookie Replacement Not Going Well, NERC Says 1/4 Customers Downloaded Solarwinds, Technology News, Human News, Content Curation & Analysis, Discovery, Recommendation, and the Aphorism of the Week…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

19 Apr 202127min

News & Analysis | No. 276

News & Analysis | No. 276

Social Media Scraping Outbreak, Microsoft AI Security Tool, FBI/CISA FortiOS Warning, Zoom Vuln at Pwn2Own, AWS Bombing, 485% Ransomware Increase, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

12 Apr 202126min

News & Analysis | No. 275

News & Analysis | No. 275

University Accellion Breaches, 533 million Facebook Users' Data, Solarwinds Hackers Got Top DHS Emails, Github Secrets Scanning, Ubiquiti's Breach, Seoul's IoT Towers, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

5 Apr 202125min

Interview: Amir Majidimehr, Audiophile Industry Disruptor

Interview: Amir Majidimehr, Audiophile Industry Disruptor

In this standalone episode I’m speaking with Amir Majidimehr. Amir is an audiophile, but he has a unique approach to the hobby that’s literally disrupting the industry. He’s basically introduced measurement, and what he calls Objectivism, into this very sensitive audiophile world that prizes itself on everything being a matter of preference, or up to the listener. Amir calls these types the Subjectivists. So what Amir does is use his decades of experience, and his professional training, to actual test this equipment—much of which costs tens of thousands of dollars—to find out if their outrageous claims have any merit. It’s truly refreshing to see in the hobby, and I’m excited to talk to him. Amir has a degree in electrical engineering, he used to run the digital media group at Microsoft in the 1980s, and he’s the founder of Audio Science Forums. And here’s our conversation…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

2 Apr 20211h 12min

News & Analysis | No. 274

News & Analysis | No. 274

Securing the Grid, PHP hacked, Russia/China Wargames, China v. Tesla, Top 10 American Threats, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

29 Mars 202120min

The Consumer Authentication Strength Maturity Model (CASMM)

The Consumer Authentication Strength Maturity Model (CASMM)

A maturity model for seeing where a user's internet hygiene currently is, and how to improve it.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

25 Mars 202113min

News & Analysis | No. 273

News & Analysis | No. 273

US Intelligence Says Putin and Russia Tampered in 2020 Election, Finland Says APT31 Hacked Parliament, Google Releases Chrome Data Gathering Report, Ulysses Tracks Cars Worldwide, Twitter Steganography, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

22 Mars 202121min

News & Analysis | No. 272

News & Analysis | No. 272

Russian/Chinese Deepfakes, Hafnium Fallout, Chinese AI and Cyber, Microsoft Flack, Patch Tuesday Updates, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

16 Mars 202122min

Populärt inom Teknik

uppgang-och-fall
market-makers
elbilsveckan
rss-badfluence
rss-racevecka
rss-laddstationen-med-elbilen-i-sverige
natets-morka-sida
rss-technokratin
skogsforum-podcast
rss-elektrikerpodden
hej-bruksbil
rss-uppgang-och-fall
bilar-med-sladd
garagehang
developers-mer-an-bara-kod
solcellskollens-podcast
rss-digitala-influencer-podden
rss-veckans-ai
har-vi-akt-till-mars-an
rss-snacka-om-ai