Take 1 Security Podcast: Episode 3

Take 1 Security Podcast: Episode 3



START CONTENT


* There was an issue with the Marriott website that exposed reservations and payment information. It’s now been fixed
* Police are now using a new radar to see into peoples’ homes without a warrant
* Security budgets are reportedly going up due to the mega-breaches in 2014


* Also leading to higher pay for CIOs
* Anecdotally, I’d say it’s a pretty good time to be in infosec

* A new security startup, PFP Cybersecurity, uses power consumption to detect malware


* Meant initially to be used for SCADA type systems

* The US hacked North Korean computers back in 2010


* This is reportedly the reasons we were so sure they hacked Sony
* Recently leaked documents from Snowden show heavy offense

* Snowden recently talked to Schneier at Harvard about a number of things


* The NSA is becoming increasingly offensively oriented vs. defensive
* The NSA supposedly uses compromised systems as jump points
* Snowden said most NSA hackers are junior enlisted with limited skills

* Russia reportedly hacking for geopolitical gain, not just money
* Millions of gas stations could be at risk of shutdown


* The Automated Tank Gauges can be remotely accessed by attackers
* Could be manipulated to cause alerts
* Potentially could be used to stop the flow of fuel

* Microsoft gave Charlie Hebdo data to FBI in 45 minutes
* Starwood hack based on bad passwords


* Bad passwords, password re-use, and a brute forcing tool
* Account harvesting is rough: user enumeration, weak passwords, and lack of account lockout

* Flash has another major exploit. Update your stuff.
* People continue to be worried that the President’s crackdown on hackers could hurt security professionals


* Congress is meeting on the 27th of January to discuss breach notification

* The wireless in around 2 million cars is highly vulnerable to attack
* A polish company has created Mouse-Box, which is an entire computer inside of a mouse enclosure


END CONTENT

Play Podcast

Notes


* Sorry about the noise part way through. My girl walked in and started unpacking groceries. But when I say one take, I mean one take.

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Avsnitt(532)

News & Analysis | No. 271

News & Analysis | No. 271

Hafnium Fallout and Response, Software Supply Chain Naming Attacks, SITA Airline Attack, REvil, China vs. India in Cyberspace, Russian Cybercrime Forum Hacks, Russians Underming American Vaccines, US Not Ready For AI Competition, CPU Side-channel Attacks, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

8 Mars 202129min

News & Analysis | No. 270

News & Analysis | No. 270

SolarWinds Malware Tool, SolarWinds Blaming the Intern, Amazon Whistleblowers, Google Linux Devs, NYC Black Mirror Dog, Portswigger Top 10, API Security Top 10, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

1 Mars 202124min

News & Analysis: No. 269

News & Analysis: No. 269

US charges North Korean hackers, Egregor users arrested, Let’s Encrypt Upgraded, Very Few Vulnerabilities Are Dangerous, North Korea Pursued COVID Vaccine Data, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

22 Feb 202143min

News & Analysis | No. 268

News & Analysis | No. 268

Florida water hack, ESET Reports 768% More UDP Attacks, 223 Vulns Being Used in Ransomware, Microsoft Will Report State Hack Attempts, Cops Using Copyright Weapons, TikTok Russian Battles, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

15 Feb 202127min

News & Analysis | No. 267

News & Analysis | No. 267

Supercookies, Mobile App Tracking, 80% PII, Moody's Cyber Rates, Facial Recognition California, Chinese Men Feminine, Google Bounty Payouts, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

8 Feb 202135min

News & Analysis | No. 266

News & Analysis | No. 266

China has 80% of US Adult PII, Chris DeRusha now US CISO, New Version of NAT Slipstreaming, Exposing.AI Looks For Your Face, Birdwatch Misinformation, Pentagon Vaccination Program, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

1 Feb 202122min

News & Analysis | No. 265

News & Analysis | No. 265

FireEye Solar Details, Cyberinsurace Supporting Crime, FBI Tracking Cell Pings, RDP DDoS Amplification, Palantir Stock, Fake Job Offers, DDoS Ransomware, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

25 Jan 202127min

What They Don’t Tell You About Being a Bounty Hunter or Content Creator

What They Don’t Tell You About Being a Bounty Hunter or Content Creator

How the dopamine hits of bugs and praise can become a trap.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

22 Jan 20215min

Populärt inom Teknik

uppgang-och-fall
market-makers
elbilsveckan
rss-badfluence
rss-racevecka
rss-laddstationen-med-elbilen-i-sverige
natets-morka-sida
rss-technokratin
skogsforum-podcast
rss-elektrikerpodden
hej-bruksbil
rss-uppgang-och-fall
bilar-med-sladd
garagehang
developers-mer-an-bara-kod
solcellskollens-podcast
rss-digitala-influencer-podden
rss-veckans-ai
har-vi-akt-till-mars-an
rss-snacka-om-ai