The Host Unknown Podcast

Episode 213 - The So Many Technical Issues Episode


Listen Later

This week in InfoSec  (10:26)

With content liberated from the “today in infosec” twitter account and further afield

1st April 1998: Hackers changed the MIT home page to read "Disney to Acquire MIT for $6.9 Billion".

https://x.com/todayininfosec/status/1907094503552336134     

1st April 2004: The now ubiquitous Gmail service is launched as an invitation-only beta service. At first met with skepticism due to it being launched on April Fool’s Day, the ease of use and speed that Gmail offered for a web-based e-mail service quickly won converts. The fact that Gmail was invitiation-only for a long time helped fueled a mystique that those who had a Gmail address were hip and uber-cool. Those of us who are actually hip and uber-cool didn’t mind, of course, as those types of things don’t bother hip and uber-cool people. 

https://thisdayintechhistory.com/04/01/gmail-launched/  

 

Rant of the Week (14:07)

Kink and LGBT dating apps exposed 1.5m private user images online

https://www.bbc.co.uk/news/articles/c05m5m5v327o

Researchers have discovered nearly 1.5 million pictures from specialist dating apps – many of which are explicit – being stored online without password protection, leaving them vulnerable to hackers and extortionists.

Anyone with the link was able to view the private photos from five platforms developed by M.A.D Mobile: kink sites BDSM People and Chica, and LGBT apps Pink, Brish and Translove.

These services are used by an estimated 800,000 to 900,000 people.

M.A.D Mobile was first warned about the security flaw on 20 January but didn't take action until the BBC emailed on Friday.

They have since fixed it but not said how it happened or why they failed to protect the sensitive images.

 

Billy Big Balls of the Week (24:00)

Oracle's masterclass in breach comms: Deny, deflect, repeat

There have been some disclosure stinkers in the past. Back in 2016, The Reg discovered that Yahoo! had taken a few years to disclose security snafus that occured in 2013 and 2014, for example. These days we often see organizations simply choose not to publicly address their issues. A quick self-referral to the regulators and some letters sent directly to those affected pass as the bare minimum, and while these organizations won't get any Brownie points for transparency, the approach doesn't tend to invite too much in the way of long-lasting criticism either.

When Oracle issued its flat-out denial of the first breach allegations that surfaced from cybercrime forums, it seemed like it was yet another wannabe big-time scriptkiddie making false claims for clout.

To make matters worse, Oracle seemingly tried to swerve any flak with some careful semantics. Its original denial stated: "There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data."

Infosec experts Kevin Beaumont and Jake Williams later both claimed that Oracle appears to have used the Internet Wayback Machine's archive exclusion process to remove evidence about the intrusion.

 

Industry News (33:25)

Google to Switch on E2EE for All Gmail Users

ICO Apologizes After Data Protection Response Snafu

North Korea's Fake IT Worker Scheme Sets Sights on Europe

Royal Mail Investigates Data Breach Affecting Supplier

Stripe API Skimming Campaign Unveils New Techniques for Theft

Over Half of Attacks on Electricity and Water Firms Are Destructive

Amateur Hacker Leverages Russian Bulletproof Hosting Server to Spread Malware

CrushFTP Vulnerability Exploited Following Disclosure Issues

Major Online Platform for Child Exploitation Dismantled

 

Tweet of the Week (41:25)

https://x.com/MalwareJake/status/1907416667052786110

Come on! Like and bloody well subscribe!

...more
View all episodesView all episodes
Download on the App Store

The Host Unknown PodcastBy Host Unknown, Thom Langford, Andrew Agnes, Javvad Malik

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

5 ratings


More shows like The Host Unknown Podcast

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,963 Listeners

Risky Business by Patrick Gray

Risky Business

361 Listeners

No Such Thing As A Fish by No Such Thing As A Fish

No Such Thing As A Fish

4,843 Listeners

Page 94: The Private Eye Podcast by Page 94: The Private Eye Podcast

Page 94: The Private Eye Podcast

280 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

313 Listeners

Click Here by Recorded Future News

Click Here

387 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,816 Listeners

Hard Fork by The New York Times

Hard Fork

5,356 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners

The Rest Is Entertainment by Goalhanger

The Rest Is Entertainment

795 Listeners

The AI Fix by Graham Cluley and Mark Stockley

The AI Fix

25 Listeners

16 Sunsets by Antica & Telltale Studios

16 Sunsets

35 Listeners