
Sign up to save your podcasts
Or


In the adage "people, process, technology" the technology comes last in the list for a reason as it is only as good as the people and processes that surround and support it. In this week's Great Security Debate we cover a range of topics all focused on the importance (and impacts) of the people and the process as key to the success of security technology. Said differently we can throw all the tech in the world out there, and it does no good without the other two.
Tune in to this week's episde to learn all about these and more. Show links below have the details of articles, items we cover in the episode.
We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.
Support The Great Security Debate
Links:
Over the past 18 months, the way we work has changed including within the security field. On this episode of The Great Security Debate, Dan, Brian and Erik dig into some of the long-term implications of working today and beyond.
This episode is available in both audio and video formats. The video edition is on our YouTube channel along with a growing collection of video from previous episodes. https://youtu.be/p099pC4dh3A
Get notified via email when each new episode is published, and find out about exciting new projects from The Great Security Debate team. Sign up here: https://newsletter.greatsecuritydebate.net
Thanks for listening! Tell your friends and let us know your comments, feedback and ideas for future Great Security Debates.
Support The Great Security Debate
Links:
A recent visit by US companies to the White House sparked a debate between Dan, Brian and Erik about how to improve security. Was the result useful to the cause, or useful to the marketing goals of the attendees? The risks are high, but are the responses going to move the needle? We discuss on this week's Great Security Debate.
Leave some feedback, give a thumbs up, a star or whatever your favourite podcast app prefers, and tell your friends about the podcast. Thanks for being a listener!
Support The Great Security Debate
Links:
If you want to check out the new video edition of the podcast, please go to:
https://youtu.be/FBBmA9YDNfQ
where you can subscribe, give thumbs up and ring bells like YouTubers have been asking you to do for years. You know the drill.
Also, our apologies for the hum in the audio throughout the entire episode. The problem has been identified and the source (Dan) has been taken out back and schooled on the difference between mic-level and line-level audio feeds. He promises it won't happen again... often.
Now, on to the show.
This week, Dan, Brian and Erik tackle the recent changes announced by Apple regarding moves to protect children from online predators and from the passing of illegal material about children. The project has three parts, each with its own benefits and concerns. We cover them each individually:
First, the scanning of messages inbound to minors (Under 18s) on a Apple Family Sharing account in which images are tested for inappropriateness, blurred and the child alerted that they may be about to look at something that they may want to reconsider. If they are under 13 and decide to view the image the parents are notified. This is an opt-in programme and parents decide whether or not to join for the family.
Next comes the proactive scanning of iCloud Photo Library stored at Apple. For a long time many have wondered why end-to-end encryption had not been put into iCloud, and this is a likely factor. The photos are tested against the hashes of a set of known images containing child pornography and issues are raised to the authorities. This is and has been happening on other cloud photo services including Microsoft and Flickr for some time.
Finally, and most controvertially from a privacy perspective, Apple is implementing a proactive test of the hashes ofphotos stored on customers' Apple devices against this same set of known images. In the US there is no law that prevents this but runs counter to the marketing emphasis Apple has placed on the privacy of data within their devices. The method is rather intricate and strives to prevent Apple from seeing anything unless it suspects there are systemic child pornography issues at bay.
These technology approaches change the game for prosecutors and law enforcement, and they expose issues earlier. But what happens when this capability gets expanded, or brought into law as mandatory for use against its citizens who speak out politically, or is taken over by bad actors? Look at the link in the show notes regarding the keys the TSA made for physical locks at the airport - every hole is a potential future vulnerability. Does the end justify the means? We discuss in depth on this week's Great Security Debate!
If you want to support the efforts of The Great Security Debate, please feel free to become a patron and get some cool benefits of supporting this independent show - https://www.patreon.com/securitydebate
Support The Great Security Debate
Links:
Get notified in an email every time a new episode of The Great Security Debate drops, or when we announce in-person episode recordings (coming soon)! Sign up for our newsletter: https://newsletter.greatsecuritydebate.net
Dan, Brian, and Erik find themselves debating whether or not the new up-to-$10M reward for information regarding ransomware and other attacks will make a material difference in the upward trend in technology as a weapon.
Tune in and enjoy this episode of The Great Security Debate. Please let us know your thoughts by leaving rating feedback in your podcast app, and/or sending us an email to [email protected]. Thanks for listening!
Support The Great Security Debate
Links:
Recently a lot of newsworthy security incidents have taken place. A common thread through many is not that they were sophisticated or required lots of time to plan and execute, or even that the victim had not invested in a lot of whizbang security technology which led to them not noticing the attack. The common thread much more simple: that fundamental security measures were not being taken by the organisation. Things like turning off accounts when people left the organisation, removing disused technology from the network, and the reuse of passwords by staff amongst public-facing and internal systems.
The fundamentals make it easy for attackers to get into networks and systems, both enterprise and personal, and are all things that we can each work on individually and within our organisations to improve and make the attacks that much harder for the bad actors to execute. This week's episode discusses those fundamentals and how to approach them.
The "slide" that is often referenced in the episode comes from a talk that Dan gave to the National Information Standards Organisation (NISO) last week on why it was so important to maintain the security of their systems. The whole presentation deck is available at http://slideshare.net/secratic/security-is-an-enabler-not-securing-is-an-inhibitor-249421889 and the specific slide is on Slide 8.
Thanks for listening. You can subscribe to the podcast on your favourite podcast application or by visiting our website https://www.greatsecuritydebate.net/subscribe. Please let us know what you think by leaving a comment in the podcast application's rating section or emailing us [email protected]
Support The Great Security Debate
Links:
A wide range of cause and effect discussion in this week's episode.
Join Erik, Brian and Dan as they count their pieces of flair and determine if we are the right fit to keep working at Flingers.
Support The Great Security Debate
Links:
The news of the week includes discussion about some changes to Amazon's home devices including Echo and Ring with the activation of their Sidewalk Network on all those devices by default and the potential for both ubiquitous connectivity for IoT devices, and the possibiity of abuse of the data that is seen . Brian, Erik and Dan also talk about the impact that the launch of the new Apple Application Tracking Transparency (ATT) program which asks users if they want to be tracked (spoiler alert: they very much do not). This will impact ads and apps that depends on ads pretty heartily, and we debate the pros and cons. Enter the data lakes (troves of data just waiting to be mined by companies to find "interesting things" (or targets for attackers).
We really appreciate your feedback, both through subscribing and rating on your favourite podcast application, and by email to us at [email protected]
Thanks for listening!
Support The Great Security Debate
Links:
We got asked by a listener to help answer the question, "Why Does My CISO Hate Me?" While we may not be privy to the exact situation in play there, we are pretty sure that no one's CISO truly hates them (but they may not be fond of all the things that everyone does all the time). In the debate today, we talk about some of the things that challenge CISOs including:
We also highlight a number of the things that CISOs and security teams can improve on to build better and stronger relationships across the organisation, too, such as:
We are all heading toward a common goal, so let's work together to accomplish it!
Thanks for listening. Until next time...
Support The Great Security Debate
Links:
We open season 2 with a new format: guests! Our first guest, Jessica Burn, has been working closely with CISOs and the security industry at Forrester where she is a Senior Analyst covering the role of the CISO, Incident Response, Zero Trust Strategy and Continuous Controls Monitoring.
Dan, Erik, Brian and Jess use a new Forrester report about recommendations for security programs in 2021 as the basis for the discussion (and debate), including a few major themes:
We still debate, we still discuss, we still shift the discussion to automotive and manufacturing from time to time, but now we have some additional voices to add to the debate, too. Thanks so much, Jess!
Special Guest: Jessica Burn.
Support The Great Security Debate
Links:
From the publisher's feed