Episode E -- Just a bunch of hosers
Teh Podcast Warz Haz Begun!
It's another week in infosec. I can't get excited about it either. Too many news stories of note, breaches and a new section - the SCADAs. In the same way that we had too many breach stories so we broke them out, we're doing the same with SCADA. Expect a lot of derision from Dave and I -- there's a lot of bullshit and we're calling it.
We'd also like to wave hello to the team at Riskhose. We're sorry that you misinterpreted young Matt's question - we'll straighten you out when we do our Risk-tacular episode this fall. Also, we're starting to suspect that the Riskhose Utahian may be a closet Canadian - he knows too much about Canadian musicians and he does know all of the words to Romantic Traffic (and yes Alex, when you come to Toronto, we'll go visit all of the subway stations so that you can produce your fan version of the video.)
Interestingly, between the Riskhose podcast and some threats from the Southern Fried Security bunch, it's on - the Podcast Wars are here - expect that the next few months are going to be epic in the world of infosec podcasting. We may even take a swipe at NetSec!
SyriaSSL Certificate HijinksCyberHackersOSXCanadianismsThe WIFIsGoogle-ized…and then our discussion topic - Dumb StoriesAnd if you've got commentary, please sent it to [email protected] for us to check out.
DISCLAIMER: It's not that explicit, but you may want to use headphones if you're at work.
ADDITIONAL DISCLAIMER: In case it is unclear, this is the story of 4 opinionated infosec pros who have sufficient opinions of their own they don't need to speak for anyone except themselves. Ok? Good.
NewsJava.com SSL cert expiredAl-Jazeera websites hacked by Assad loyalist groupCyber attacks grow increasingly "reckless", official says3 years later, hackers who hit Google continue string of potent attacks …and no one is looking out for the stuff that really matters.New utility nabs OS X keychain passwordsGlobal virus downs N.S. computer system for a monthSniffing open WiFi networks is not wiretapping, judge says:VirusTotal acquired by GoogleNo shooting at protest? Police may block mobile devices via AppleBreachesGuild Wars 2 officials say ongoing password attack affects 11,000 accountsAntisec Leaks 1,000,001 UDIDs From A Trove Of 12 Million Allegedly Stolen From An FBI Laptop Or was it 12 million? ...or not? and some apps use IMEI as password!NullCrew pillages Sony servers?The SCADAsSecret account in mission-critical router opens power plants to tamperingAnonymous Hack Lukoil Bulgaria SiteErrataVendor Cybercrime StatsCommentaryFoot In The Door - Your Dumbest Story EVAH!!!!Dave - VIEW SOURCE HACKERZJamie - our developer broke SSL -- that’s why we use proprietary encryption. But we’re not telling anyone what/how he did.Matt - SQL injected a DB to /dev/nullBen - I didn’t feel 3DES was secure because the source is available online, so I invented my own variantHardcoreSkipping the hardcore because we've got a great Mailbag question.Mailbag / Bizarro LandLove your podcast, even if you try to count in Hex :-) It would be great if you were able to dive deep into what modern defenders need to do to get ahead of attackers. Right now, attackers need to only make simple changes to their attacks and defenders are left on their kiesters. How do we change that pattern?
Besides deploying antivirus :-)
Matt suggests a cool slide deck from Zane over at EtsyBen suggests you read Liquidmatrix ;)… and thanks to Thomas Preissler for his comments about the show!In ClosingWe do research too - Ben's running a survey and will publish results. Check it out!The Security Conference Library -- is a copy of the conferences amassed by @helpmerob and we’re adding more. If you’ve got pix/pdfs/slides/code/video of a security conference and you want to add to an attempt at the largest/bestest/least dickish security conference library -- send us a note (mailbag) and we’ll take your bits and file them. (NOTE: much is stored at http://myrcurial.com/conferences but you can totally trust that guy)If you're interested in helping out with openCERT.ca, drop a line to [email protected]Three Quarters of Liquidmatrix (with some Securosis added in) are doing a panel at SecTor If you're thinking of attending SecTor 2012, grab 10% off with discount code "liquidmatrix-2012" or if you can only make it to the expo floor, grab a free expo pass with code "liquidmatrix-Expo2012"Vote Dave for ISC2 Board Ballot!The Seacrest says “I miss Gilmore Girls" and "Skerple"