Take 1 Security Podcast: Episode 3

Take 1 Security Podcast: Episode 3



START CONTENT


* There was an issue with the Marriott website that exposed reservations and payment information. It’s now been fixed
* Police are now using a new radar to see into peoples’ homes without a warrant
* Security budgets are reportedly going up due to the mega-breaches in 2014


* Also leading to higher pay for CIOs
* Anecdotally, I’d say it’s a pretty good time to be in infosec

* A new security startup, PFP Cybersecurity, uses power consumption to detect malware


* Meant initially to be used for SCADA type systems

* The US hacked North Korean computers back in 2010


* This is reportedly the reasons we were so sure they hacked Sony
* Recently leaked documents from Snowden show heavy offense

* Snowden recently talked to Schneier at Harvard about a number of things


* The NSA is becoming increasingly offensively oriented vs. defensive
* The NSA supposedly uses compromised systems as jump points
* Snowden said most NSA hackers are junior enlisted with limited skills

* Russia reportedly hacking for geopolitical gain, not just money
* Millions of gas stations could be at risk of shutdown


* The Automated Tank Gauges can be remotely accessed by attackers
* Could be manipulated to cause alerts
* Potentially could be used to stop the flow of fuel

* Microsoft gave Charlie Hebdo data to FBI in 45 minutes
* Starwood hack based on bad passwords


* Bad passwords, password re-use, and a brute forcing tool
* Account harvesting is rough: user enumeration, weak passwords, and lack of account lockout

* Flash has another major exploit. Update your stuff.
* People continue to be worried that the President’s crackdown on hackers could hurt security professionals


* Congress is meeting on the 27th of January to discuss breach notification

* The wireless in around 2 million cars is highly vulnerable to attack
* A polish company has created Mouse-Box, which is an entire computer inside of a mouse enclosure


END CONTENT

Play Podcast

Notes


* Sorry about the noise part way through. My girl walked in and started unpacking groceries. But when I say one take, I mean one take.

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Avsnitt(532)

The Relationship Between Hardship, Struggle, and Meaning

The Relationship Between Hardship, Struggle, and Meaning

My essay on how struggle could be necessary for meaning, and how this could be the underlying cause of much of America's mental health problem.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

15 Okt 202013min

News & Analysis | No. 250

News & Analysis | No. 250

CrowdSec, Nudge, Trickbot Trickery, CISA Ransomware Guide, Twitter and Facebook anti-Disinformation, QAnon Takedowns, Putin Turning on Trump, Azure Vulnerabilities, PC shipments up, Virtual Sales Call AI, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

12 Okt 202026min

News & Analysis | No. 249

News & Analysis | No. 249

Operation Fortify, Cyber Pearl Harbor, Github Code Scanning, E-6B Flights, Blackbaud++, Grinder Password Reset, Cloudflare API Security, QNAP Drama, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

5 Okt 202021min

News & Analysis | No. 248

News & Analysis | No. 248

Everyday Threat Modeling, Why I Like TikTok So Much, Windows XP Leak, SSH 8.4, Renée DiResta's Latest, Student Visas Changes, Cisco IOS Vulns, QAonon Gamification, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

28 Sep 202016min

Why Creators Should Move to Direct Support Monetization

Why Creators Should Move to Direct Support Monetization

My essay about why I think creators—especially in InfoSec—should be setting up their own domains and moving to a direct model for monetization.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

24 Sep 202011min

No, Changing Your SSH Port Isn't Security by Obscurity

No, Changing Your SSH Port Isn't Security by Obscurity

My latest essay on the timeless debate on SSH ports and Security by Obscurity. I talk about why changing your port is not usually obscurity, and give what I believe to be an airtight method of how you can tell the difference between regular security and Security by Obscurity.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

23 Sep 202013min

News & Analysis | No. 247

News & Analysis | No. 247

SSH Port Obscurity, The TikTok Deal, Ransomware Death, Chinese Espionage CRM, Amazon Bribery, Instant Domain Admin, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

21 Sep 202020min

Book Summary | Naked Statistics, by Charles Wheelen

Book Summary | Naked Statistics, by Charles Wheelen

In this episode, I review the book Naked Statistics, by Charles Wheelen. I cover: My one-sentence summary of the text The table of contents, which is super helpful to see the structure of the argument My capture of the main points My takeaways, questions, and ideas that came from reading it My final summarization And then my rating of the book and whether I recommend you read the full text Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

16 Sep 202022min

Populärt inom Teknik

uppgang-och-fall
rss-racevecka
elbilsveckan
bilar-med-sladd
market-makers
rss-badfluence
skogsforum-podcast
rss-uppgang-och-fall
rss-technokratin
natets-morka-sida
rss-elektrikerpodden
developers-mer-an-bara-kod
hej-bruksbil
rss-digitala-influencer-podden
rss-veckans-ai
har-vi-akt-till-mars-an
garagehang
solcellskollens-podcast
rss-laddstationen-med-elbilen-i-sverige
rss-snacka-om-ai