Take 1 Security Podcast: Episode 8

Take 1 Security Podcast: Episode 8



START CONTENT


* New SSL attack called FREAK


* Has to do with falling RSA back to a deprecated and weak level
* Requires the client and server are both vulnerable
* The solution is to patch
* Many orgs will also want to note which servers were vulnerable
* The lesson is that you don’t reduce security to increase it
* Backdoors x time = regret

* Using Ruby’s Open-URI could be dangerous


* open-uri monkeypatches kernel.open
* open(params[:url]) can execute |ls

* Hilary Clinton used a personal email address and did not store correspondence on government servers for her entire 4 years as Secretary of Defense


* This seems highly suspect
* First you’re putting that data at risk in a personal system
* Second you’re obviously trying to hide your conversations

* Facebook can access your account without your password
* Google no longer encrypting Lollipop by default


* Was one of the main selling points for 5, and now it’s gone
* They said it was simply a driver issue

* DLink routers have a remote command injection bug


* Could allow DNS hijacking and other attacks

* ISIS has threatened some members of the Twitter team for disabling their accounts


* This really puts a point on public presence for me
* I’m a strong proponent of the belief that the way to avoid attack is to avoid being a target, not to be hard to attack once people want to
* This works for personal attacks, not for countries obviously

* There has been some major fraud happening with people connecting stolen cards to ApplePay


* The issue isn’t a security problem with ApplePay, but rather with standard bank / card security issue

* Up to 18.8 non-Anthem customers exposed in the Anthem breach


* This is in addition to the 80 million actual anthem customers

* GoPro vulnerability on its website exposes customer Wi-fi passwords


* Expect more of this

* Uber took over 5 months to issue a breach notification


* There was a breach of driver names and license numbers that they just now disclosed

* Seagate NAS vulnerability allows unauthorized root access


* This raises the cloud storage issue I blogged about last week



END CONTENT

Play Podcast

Notes


* Sorry about my voice on this one. I’m a bit sick. :(

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Avsnitt(532)

NO. 387 — Modern Parenting and Narcissism?, New Russian Hacking Unit, McKinsey AI Predictions, and more…

NO. 387 — Modern Parenting and Narcissism?, New Russian Hacking Unit, McKinsey AI Predictions, and more…

In this episode: 🧠 Is modern parenting creating narcissists?🔒 Top cybersecurity official warns of Chinese hackers🇷🇺 New Russian hacking unit identified🚀 NVIDIA's AI red team philosophy📈 McKinsey says AI will massively boost productivity💊 MDMA helps white supremacist move away from hate🔎 Google further soils the bedBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

20 Juni 202324min

NO. 386 — DBIR 2023, Vision, Smol-Developer, and more…

NO. 386 — DBIR 2023, Vision, Smol-Developer, and more…

In this episode: 🔥 Human Immortality Using LLMs🤖 Generative AI Reshaping Enterprises🔒 Verizon DBIR 2023 Analysis🪳 Chrome Zero-Day Patched💰 Lazarus Atomic Wallet Link🚀 Tame Your Compliance Beast🪳 MOVEit Vulnerability Exploitation📰 North Korean Hackers Impersonate Journalists📱 Apple ID-sharing🌐 Apple Vision Announced🔑 Password Crackdown Success📈 AI-Driven Stock Surge📱 iOS17 Features Summary🔐 Apple Passkey SharingBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

12 Juni 202326min

NO. 384 — World AI Coin, Russian Power Attacks, Guidance AI Workflow…

NO. 384 — World AI Coin, Russian Power Attacks, Guidance AI Workflow…

In this episode:👁️ Worldcoin, OpenAI, and eye scanning: A global ID and currency?⚡ Grid Threat: Russia-linked malware targets power grids🧠 Neuralink gets FDA approval for clinical trials🤖 Bing integrated into ChatGPT for enhanced AI chatbot experience🚗 Tesla Model Y becomes world's best-selling car🌈 LGBTQ searches soar 1,300% since 2004Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

3 Juni 202321min

NO. 382 — AI Attack Surface Map, Digital Assistants, Dragos Nope, Rogue AI Girlfriend…

NO. 382 — AI Attack Surface Map, Digital Assistants, Dragos Nope, Rogue AI Girlfriend…

In this episode:🛡️ Support DEFCON's AI Village event🧠 Dive into AI attack surfaces🤖 Uncover digital assistants' future🔒 Investigate Dragos Incident & Snake takedown🎵 Experience Google's MusicLM magic🚀 Secure the cloud with a free guide👩‍💻 Witness an AI girlfriend gone rogueBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

16 Maj 202317min

The Right Amount of Trauma

The Right Amount of Trauma

In this standalone episode I read my essay titled "The Right Amount of Trauma". https://danielmiessler.com/blog/the-right-amount-of-trauma/   Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

11 Maj 20237min

NO: 381 — Reviving Conference Strategies, Nurturing High-Performers, AI Business Takeover, Cyber Threats, and Diversifying Production 🧠🏢🦈📱🚗

NO: 381 — Reviving Conference Strategies, Nurturing High-Performers, AI Business Takeover, Cyber Threats, and Diversifying Production 🧠🏢🦈📱🚗

🧠 The Right Amount of Trauma: Nurturing high-performers🏢 Universal Business Components: AI's business takeover🦈 North Korean ReconShark: New global cyber threat📱 Apple's Brazil production: Diversifying from China🚗 NYPD's AirTag advice: Protect your car💵 US dollar losing reserve currency status🤖 IBM's hiring pause: AI and automation's impact🌐 World Economic Forum: Job disruption predictions 📺 YouTube views: Half on TV📞 GenZ's dumbphone trend: Reducing distractions🌿 A Post AI Future for Humans: Local community model💡 The Self-checkout Tipping Anti-Pattern: Dark pattern or generosity?Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

9 Maj 202311min

NO. 380 — LLM-Mind-Reading, Automated War, Rusty Sudo, Eliezer Bitterness Theory...

NO. 380 — LLM-Mind-Reading, Automated War, Rusty Sudo, Eliezer Bitterness Theory...

📚 Pre and Post-LLM Software: Adapt or be replaced🎙️ RSnake Show Appearance: AI-focused conversation🔐 RSA Live Podcast: Industry insights and advice🔮 Palantir AI: Automated war and terror🍏 New Apple Update Mechanism: Rapid Security Response🧠 LLM Mind-reading: Extracting text from brain activity🚫 Chatbanning: Samsung's response to data leak🔧 VMware & Zyxel Patches: Addressing vulnerabilities🔒 Google Security AI: Cloud Security AI Workbench🦀 Sudo Rust: Safer sudo and su in Rust🎥 Palo Alto Cameras: License plate tracking🏃‍♂️ Apple Coach: AI-powered health app🏦 First Republic Falls: FDIC intervention💡 Eliezer Bitterness Theory: AI doomsday predictions🤖🔥 Prompting Superpower: Advanced AI prompting techniques🛠️ ShadowClone & FigmaChain: Useful tools🐍 Recommendation: Learn Python and Langchain💬 Aphorism: Carl Jung on creativityBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

2 Maj 202318min

NO. 378 — AI Resilience Scale, Moloch The Demon, Ukraine Data Leak, and more...

NO. 378 — AI Resilience Scale, Moloch The Demon, Ukraine Data Leak, and more...

NO. 378—AI Resilience Scale, Moloch The Demon, Ukraine Data Leak, and more...Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

17 Apr 202325min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
rss-racevecka
bilar-med-sladd
market-makers
skogsforum-podcast
rss-laddstationen-med-elbilen-i-sverige
rss-technokratin
natets-morka-sida
rss-elektrikerpodden
developers-mer-an-bara-kod
mediepodden
ai-sweden-podcast
rss-uppgang-och-fall
solcellskollens-podcast
hej-bruksbil
bli-saker-podden
rss-it-sakerhetspodden
rss-veckans-ai
rss-fabriken-2