Episode 0x14-- Happy Birthday Mr. Gattaca... we'll vote for you too.
There's interesting things afoot. Y'all should pay attention.
This is the 21st episode for those of you that don't have 16 fingers. Not sure we should be revealing this yet, but it's going to be a wild winter solstice celebration this year. The southern folk at Southern Fried Security and this gang of teenage malcontents are up to no good. Well, actually extra special good. Let me sum up - it's Security Charity... Gangnam Style.
Stay tuned for the carnage.
Upcoming over the next hour...
Lots of NewsBreachesSCADAsDERPs!!!and then our discussion topic--Disaster RecoveryAnd if you've got commentary, please sent it [email protected] for us to check out.
DISCLAIMER: It's not that explicit, but you may want to use headphones if you're at work.
ADDITIONAL DISCLAIMER: In case it is unclear, this is the story of 4 opinionated infosec pros who have sufficient opinions of their own they don't need to speak for anyone except themselves. Ok? Good.
NewsService Sells Access to Fortune 500 FirmsU.S. looks to replace human surveillance with computersHow a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole CSO Online has an opinion too.Broadcom DoS on BCM4325 and BCM4329 devices Auditor General Report: Canada is sucking at the "cyber"The Kiwi .gov makes their internal network kiosk accessibleChina Unicom replaces Cisco devices over security concerns Huawei gives Australia peeks at its network hardware and code to regain trustHire great infosec people (and keep them) !Breaches - The never ending never ending story...Billabong Hacked Again (yes, again), Hackers Claim to Have Obtained 37,000 Account DetailsPeru Domains Registrar hacked and 207116 Domain panel credentials leakedSouth Carolina Suffers Massive Data BreachAttacker grabs data for 3.6 million South Carolina taxpayers; governor wants to see culprit "brutalized"Hackers crack Texan bank, Experian credit records come flooding outVermont credit union discards unencrypted data of 85,000Anonymous owns a police forumThe SCADAsCritical flaw found in software used by many industrial control systemsCybergeddon now? Industrial control systems targetedErrata / DERP of the week awardMy name is Jakub Walczak, and I work for Hakin9 – the magazine that reaches over 60 000 readers mainly in the USA, India, and Australia.
I have seen your website and I was wondering if you would like to cooperate with us. Please let me know.
I am looking forward to hearing from you.
Sorry Jakub, perhaps you should listen to the show or read about our opinions of Hackin9 before you send email like this again. Just sayin.Commentary
Yeah, so we ran a little long... the commentary segment has been pulled out into a separate recording. It'll show up on the RSS feed tomorrow, but if you want it right now, you can grab it here.
Foot In The Door - Disaster Recoveryc, i and A <-- that="" one="" counts="" li="">RTO, RPOpractice, practice, practice
Hardcore - Recovering from the Disaster you didn't plan forDo the post-mortem. Netflix's AWS outage post-mortemdo security olde style- use the opportunties provided by the red-print report to get the thing fixed right.Make sure you've prepared yourselfIncluding a "get home" bag at the officeDon't make plans that require employees to run on infrastructure that might not be thereMailbag / Bizarro LandThe quick & dirty: Stroz Friedberg evaluated the technical watchdog (MarkMonitor) for the so-called ISP "Six Strikes", and gave it a thumbs-up. However, SF was also actively lobbying for the RIAA between 2004 and 2009.
I want to like this company - they're doing it less wrong than many other folks - and thus I find myself experiencing another bout of Infosec Depression.
Original article, albeit from a non-impartial source here
In ClosingMatt's Movie Review Argo was so good - That Ben Affleck is DELICIOUSWe do research too - Ben's running a survey and will publish results. Check it out!The Security Conference Library If you're interested in helping out with openCERT.ca, drop a line to [email protected]Contribute to the Strategic Defense Execution Standard (#SDES) and you'll be Doing Infosec Right in no time.Upcoming Appearances: Ben and Dave at HackFest in Quebec City, James at SecurityZone in Cali, ColombiaBSidesDave - held immediately after Hackfest, Dave will not be sleeping before his flight home, so keep him companySigning up for a SANS course? Be sure to use the code "Liquidmatrix_150" and save $150 off the course fee!Seacrest Says: "Why are my pants wet?" Hope everyone makes it through #Sandy safelyCreative Commons license: BY-NC-SA