DevelopSec: Developing Security Awareness

Newscast - Sept. 30, 2015


Listen Later

James breaks down a few news stories from the previous week.  The following stories were discussed, including some brief points.

 

  • Microsoft Accidentally pushes test patch http://www.zdnet.com/article/microsoft-accidentally-issued-a-test-windows-update-patch/
    • Of course the community assumes hack.
    • Oversight that allowed a test patch to be released.
    • They are working to remove it.
  • Credit Card Liability Shift Is here
    • Starting October 1, 2015 if your a vendor and use the magnetic stripe on a chip enabled card, certain fraudulent transactions will fall to you, instead of the bank.
    • This doesn’t change the liability for consumers.
    • James' interview on Channel 4 News in Jacksonville http://www.news4jax.com/news/new-credit-card-technology/35391900
  • WinRAR exploit – Is it just hype? http://www.theregister.co.uk/2015/09/30/500m_winrar_users_open_to_remote_code_execution_zero_day/
    • Requires you to execute an exe, which is something we are taught not to do from untrusted sources.
    • Estimates say this effects 500 million users, but let’s be realistic on the risk here. It requires you to execute an executable.
    • Remember not to run attachments or files unless they are from a trusted source and you are expecting the item.
  • Huge iOS 9 Security Flaw (or maybe not?) https://www.yahoo.com/tech/s/huge-ios-9-security-flaw-lets-anyone-see-134547688.html
    • Can bypass the lock screen to see photos and contacts.
    • Uses Siri (so it has to be enabled on the lock screen).
    • Requires physical access to the device.

Send us a text

For more info go to https://www.developsec.com or follow us on X (@developsec).

The DevelopSec podcast is brought to you by Jardine Software Inc.

...more
View all episodesView all episodes
Download on the App Store

DevelopSec: Developing Security AwarenessBy Jardine Software Inc.

  • 4
  • 4
  • 4
  • 4
  • 4

4

3 ratings