DevelopSec: Developing Security Awareness

DevelopSec: Developing Security Awareness

By Jardine Software Inc.NewsTechnologyEducationTech News
Download on the App Store

DevelopSec: Developing Security Awareness episodes

  • Newscast - Oct. 20, 2015

    Hi and welcome to the DevelopSec newscast for October 20th, 2015.  I am James Jardine and I wanted to take a few moments to talk about some recent news stories over the past week.

    • Apple removes several apps that could spy on encrypted traffic - http://arstechnica.com/security/2015/10/apple-removes-several-apps-that-could-spy-on-encrypted-traffic/ , http://www.theregister.co.uk/2015/10/09/apple_borks_adblocking_app_over_privacy_concerns/

     

    • Apps installed a root certificate on device.
    • Could allow monitoring of data, even SSL/TLS traffic.
    • Recommended to uninstall the apps, unfortunately it was not made clear which ones they are.
    • com CSRF bug pays security tester $25,000 - http://www.theregister.co.uk/2015/10/09/hotmail_hijack_hole_earns_boffin_25k_double_bug_bounty_trouble/
      • Wesley Wineberg found a Cross-Site Request Forgery flaw in the Microsoft Outlook.com website.
      • Could hijack user sessions.
      • Responsible/Coordinated disclosure allowed flaw to be resolved before publicly disclosed.
    • Medicaid Data Breach, Security Issue at NC and CA Facilities - http://healthitsecurity.com/news/medicaid-data-breach-security-issue-at-nc-and-ca-facilities
      • Spreadsheet sent via email unencrypted.
        • Highlights importance of attention to detail. Sometimes the simplest mistakes create a potential risk.
        • Difficult to prove if data was accessed by unauthorized users.
        • What options could be used instead of emailing the attachment?
      • Thumb drive stolen from employees home
        • Data should be encrypted.
        • Ensure policies exist that cover acceptable use of portal storage.
        • Ensure that employees are trained on the policies.

     

    Join the conversation on google+ (https://www.google.com/+Developsec) and Twitter (@DevelopSec)

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    27 min
  • Newscast - Sept. 30, 2015

    James breaks down a few news stories from the previous week.  The following stories were discussed, including some brief points.

     

    • Microsoft Accidentally pushes test patch http://www.zdnet.com/article/microsoft-accidentally-issued-a-test-windows-update-patch/
      • Of course the community assumes hack.
      • Oversight that allowed a test patch to be released.
      • They are working to remove it.
    • Credit Card Liability Shift Is here
      • Starting October 1, 2015 if your a vendor and use the magnetic stripe on a chip enabled card, certain fraudulent transactions will fall to you, instead of the bank.
      • This doesn’t change the liability for consumers.
      • James' interview on Channel 4 News in Jacksonville http://www.news4jax.com/news/new-credit-card-technology/35391900
    • WinRAR exploit – Is it just hype? http://www.theregister.co.uk/2015/09/30/500m_winrar_users_open_to_remote_code_execution_zero_day/
      • Requires you to execute an exe, which is something we are taught not to do from untrusted sources.
      • Estimates say this effects 500 million users, but let’s be realistic on the risk here. It requires you to execute an executable.
      • Remember not to run attachments or files unless they are from a trusted source and you are expecting the item.
    • Huge iOS 9 Security Flaw (or maybe not?) https://www.yahoo.com/tech/s/huge-ios-9-security-flaw-lets-anyone-see-134547688.html
      • Can bypass the lock screen to see photos and contacts.
      • Uses Siri (so it has to be enabled on the lock screen).
      • Requires physical access to the device.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    24 min
  • Newscast - Sept. 23, 2015

    James breaks down a few news stories from the previous week.  The following stories were discussed, including some brief points.

    • $1 million bounty for iOS 9 hack http://www.wired.com/2015/09/spy-agency-contractor-puts-1m-bounty-iphone-hack/
      • Zerodium announced 1 million dollar bounty for hack that can take over an iOS device remotely, via web page, vulnerable app or text message
      • Terms of offer demand that bug not be reported to Apple or publicly disclosed
      • Not uncommon for iOS bugs to fetch big money
    • Rare malware outbreak hits some Apple apps http://www.usatoday.com/story/tech/2015/09/21/apple-china-hack-app-store-malware--xcode-ghost/72572190/
      • Some developers used fake versions of XCode to create applications
      • Designed to steal user passwords
      • Reportedly little danger to US iphone users unless using Chinese social media apps.
      • Important to use software from trusted sources.
    • Comcast to Pay $33 million over Privacy Breach http://www.huffingtonpost.com/entry/comcast-to-pay-over-privacy-breach_55fb30d7e4b0fde8b0cd9fe4
      • 75,000 names, phone numbers and addresses published
      • People paid $1.50 / month more for privacy
      • Each customer will get $100
      • Some law enforcement, judges and domestic violence abuse victims will get more due to facing increased safety concerns.

    Follow us on Twitter (@developsec).  If you want to be alerted when new items are available you can subscribe on our website at https://www.developsec.com

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    16 min
  • Ep. 30: HTTP Strict Transport Security (HSTS): Intro

    James talks about HTTP Strict Transport Security (HSTS) and what it is for.  For more information, check out the corresponding post https://www.developsec.com/2015/09/17/http-strict-transport-security-hsts-overview/ that has links to other references.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    15 min
  • Ep. 29: FTC Start with Security Guidelines

    Just recently, the FTC released "Start with Security: A Guide for Busines" which is a set of 10 items businesses can do to help secure their assetts.  The full guide can be found at https://www.ftc.gov/tips-advice/business-center/guidance/start-security-guide-business. 

     

    James Jardine breaks gives an overview of the 10 items provided in the document. If you are a business, these are some good things to think about when it comes to security.  The interesting twist is that it is not highly technical, rather uses real companies as examples for the different items.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    25 min
  • Ep. 28: What is Penetration Testing

    In this episode, James Jardine talks about what penetration testing, "pen testing", is and how it really has a lot of meanings to different people.  A pen test isn't something that should be considered negative, rather it is a positive approach to helping identify security risks to your organization. 

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    21 min
  • Ep. 27: Importance of Security for BA and PM

    In this episode James covers some thoughts on how business analysts and project managers are crucial to the security role for applications.  It doesn't take a huge change in the way work is done and the domino affect carries all the way through to QA. 

    Accompanying Blog Post: https://www.developsec.com/2015/06/01/business-analysts-and-product-managers-security-roles/

     

    Follow us on Twitter: @developsec

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    16 min
  • Ep. 26: The Importance of Security for QA

    QA plays a crucial role in testing for security flaws within applications.  They have the Proximity, Knowledge of the Application and it is an extension to the role they currently fill.  James Jardine discusses why security testing is critical to the QA role. 

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    23 min
  • Ep. 25: Static Analysis: Analyzing the Options

    Static analysis is an important part of the secure development lifecycle.  There are some things to think about when you are considering a static analysis option.  James discusses the questions in this episode.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    18 min
  • Ep. 24: The Importance of Baselines

    Understanding baselines of our networks, applications, traffice, etc is important to identifying security issues.  James Jardine shares some thoughts on the need for these baselines and why they are important.  There is a quick write up on this topic at https://www.developsec.com.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    15 min

About DevelopSec: Developing Security Awareness

From the publisher's feed

Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of…