Discussed Articles
1) Osman’s Shmoocon 2016 Recap
Hear about the awesome talks and things learned from Osman’s trip to DC
* https://archive.org/details/Where_Do_The_Phishers_Live
* https://archive.org/details/Containing_An_Attack_With_Linux_Containers
* https://archive.org/details/Penetration_Testing_Custom_Tls_Stacks
* https://archive.org/details/Keynote_Address
* https://archive.org/details/Hiding_From_The_Investigator
* https://archive.org/details/Gatekeeper_Exposed
2) President Obama to appoint CISO
President Obama opens up a position for a new Federal CISO position for the US Government. Thanks Obama!
* https://www.usajobs.gov/GetJob/ViewDetails/428904900
* http://www.federaltimes.com/story/government/cybersecurity/2016/02/09/obama-federal-ciso/80032796/
3) Where Should Information Security Teams Report
CISOs can report to a variety of different positions besides directly to a CEO. We explore various different articles on the topic and provide our own take.
* http://krebsonsecurity.com/2015/04/whats-your-security-maturity-level/
* http://www.computerworld.com/article/2490736/cybercrime-hacking/target-top-security-officer-reporting-to-cio-seen-as-a-mistake.html
* http://resources.idgenterprise.com/original/AST-0135469_ESG-Brief-HP-Maturity-Model-Oct-2014.pdf
4) Hacked Toy Company VTech’s TOS Now Says It’s Not Liable for Hacks
A company decides that liability can be waived away through a strongly worded clickthrough agreement. A duo of podcasters disagree with their limited legal knowledge.
* https://motherboard.vice.com/read/hacked-toy-company-vtech-tos-now-says-its-not-liable-for-hacks
* http://www.troyhunt.com/2016/02/no-vtech-cannot-simply-absolve-itself.html