Firewalls Don't Stop Dragons Podcast

Blocking .zip Domains


Listen Later

Two weeks ago, I told you about the availability of two new top-level domains that also happen to be popular file name extensions: .zip and .mov. The ambiguity will undoubtedly be exploited by ne’er-do-wells to trick people into doing something they shouldn’t do. There are clever ways to manipulate website addresses that would trick even tech-savvy people into clicking malicious links. Today I’ll tell you how these tricks work and explain you can avoid all of these issues by simply blocking these new domains.

In other news: iTunes for Windows patches a nasty bug; Android malware downloaded over 420 million times; Android phones vulnerable to fingerprint brute-force attacks; Luxottica exposes 300 million customer records; free VPN service SuperVPN exposes 360 million user records; Amazon gets slap on the wrist for Ring video doorbell private data access; KeePass “master password crack” not as bad as it sounds; Twitter adding Content Notes ‘fact checks’ to images; Microsoft now scanning inside password-protected zip files; drone pilot is NOT killed by drone; AI is NOT likely to cause human extinction; and Brave introduces new Off The Record browsing mode. Plus my Dear Carey question: recommended cheat sheet for computer safety.

Article Links
  1. [MacRumors] PSA: If You Run Windows, Make Sure to Update iTunes to Fix Security Vulnerability https://www.macrumors.com/2023/06/01/itunes-windows-vulnerability/
  2. [Lifehacker] This Android Malware Was Downloaded Over 420 Million Times https://lifehacker.com/this-android-malware-was-downloaded-over-420-million-ti-1850492306
  3. [BleepingComputer] Android phones are vulnerable to fingerprint brute-force attacks https://www.bleepingcomputer.com/news/security/android-phones-are-vulnerable-to-fingerprint-brute-force-attacks/
  4. [bitdefender.com] Luxottica 2021 breach: 300 million customer records up for grabs online https://www.bitdefender.com/blog/hotforsecurity/luxottica-2021-breach-300-million-customer-records-up-for-grabs-online/
  5. [hackread.com] Free VPN Service SuperVPN Exposes 360 Million User Records https://www.hackread.com/free-vpn-service-supervpn-leaks-user-records/
  6. [AppleInsider] Amazon gets slap on the wrist over privacy violations with Ring cameras https://appleinsider.com/articles/23/05/31/amazon-gets-slap-on-the-wrist-over-privacy-violations-with-ring-cameras
  7. [Naked Security] Serious Security: That KeePass “master password crack”, and what we can learn from it https://nakedsecurity.sophos.com/2023/05/31/serious-security-that-keepass-master-password-crack-and-what-we-can-learn-from-it/
  8. [Mashable] Twitter will now put Community Notes ‘fact checks’ on images https://mashable.com/article/twitter-notes-on-media-images
  9. [Ars Technica] Microsoft is scanning the inside of password-protected zip files for malware https://arstechnica.com/information-technology/2023/05/microsoft-is-scanning-the-inside-of-password-protected-zip-files-for-malware/
  10. [VICE] USAF Official Says He ‘Misspoke’ About AI Drone Killing Human Operator in Simulated Test https://www.vice.com/en/article/4a33gj/ai-controlled-drone-goes-rogue-kills-human-operator-in-usaf-simulated-test
  11. [Schneier Blog] On the Catastrophic Risk of AI https://www.schneier.com/blog/archives/2023/06/on-the-catastrophic-risk-of-ai.html
  12. [brave.com] Request “Off the Record” https://brave.com/privacy-updates/26-request-off-the-record/
  13. Tip of the Week: Blocking .zip Domains: https://firewallsdontstopdragons.com/how-to-block-the-new-zip-domain/
  14. Further Info
    • How to send files securely: https://firewallsdontstopdragons.com/how-to-send-files-securely-like-tax-info/ 
    • Checklist of Tips for my book: https://firewallsdontstopdragons.com/wp-content/uploads/2023/02/FDSDv5-workbook-v1.pdf
    • 10 Years After Snowden: https://www.eff.org/deeplinks/2023/05/10-years-after-snowden-some-things-are-better-some-were-still-fighting 
    • The Wayback Machine: https://web.archive.org/ 
    • Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 
    • Give the gift of privacy and security: https://fdsd.me/coupons 
    • Send me your questions! https://fdsd.me/qna 
    • Support our mission! https://fdsd.me/support 
    • Subscribe to the newsletter: https://fdsd.me/newsletter 
    • Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book 
    • Generate secure passphrases! https://d20key.com/#/
    • Table of Contents

      Use these timestamps to jump to a particular section of the show.

      • 0:01:27: DEF CON update
      • 0:02:40: News preview
      • 0:04:59: If you use iTunes on Windows, update your app soon
      • 0:06:25: Android malware was downloaded over 420M times
      • 0:10:29: Android phones vulnerable to fingerpint brute force attacks
      • 0:16:59: Luxottica breach exposes 300 million records
      • 0:20:00: Free VPN service SuperVPN exposes 360 million user records
      • 0:24:21: Amazon gets slap on the wrist over Ring privacy violations
      • 0:26:10: KeePass “master password crack”
      • 0:29:59: Twitter to put Community Notes on images
      • 0:32:48: Microsoft is scanning contents of password-protection zip files
      • 0:37:47: AI drone did NOT kill its human operator
      • 0:43:19: About that AI article leading to human extinction
      • 0:50:54: Brave browser’s new Off The Record feature
      • 0:56:14: Dear Carey: cheatsheet for computer cleanup?
      • 0:58:01: Tip of the Week: Blocking .zip domains
      • 1:03:36: Wrap up and look ahead
      • ...more
        View all episodesView all episodes
        Download on the App Store

        Firewalls Don't Stop Dragons PodcastBy Carey Parker

        • 4.9
        • 4.9
        • 4.9
        • 4.9
        • 4.9

        4.9

        64 ratings


        More shows like Firewalls Don't Stop Dragons Podcast

        View all
        Hacked by Hacked

        Hacked

        189 Listeners

        Security Now (Audio) by TWiT

        Security Now (Audio)

        2,010 Listeners

        Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

        Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

        373 Listeners

        Risky Business by Patrick Gray

        Risky Business

        373 Listeners

        SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

        SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

        653 Listeners

        CyberWire Daily by N2K Networks

        CyberWire Daily

        1,022 Listeners

        Smashing Security by Graham Cluley

        Smashing Security

        318 Listeners

        Click Here by Recorded Future News

        Click Here

        418 Listeners

        Darknet Diaries by Jack Rhysider

        Darknet Diaries

        8,035 Listeners

        Hacking Humans by N2K Networks

        Hacking Humans

        315 Listeners

        Techlore Surveillance Report by Techlore

        Techlore Surveillance Report

        105 Listeners

        Cyber Security Headlines by CISO Series

        Cyber Security Headlines

        139 Listeners

        Risky Bulletin by risky.biz

        Risky Bulletin

        44 Listeners

        Hacker And The Fed by Chris Tarbell & Hector Monsegur

        Hacker And The Fed

        169 Listeners

        The AI Fix by Graham Cluley and Mark Stockley

        The AI Fix

        34 Listeners