Risky Business

Risky Business #696 -- Why Twitter had to kill SMS 2FA


Listen Later

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Why Twitter had to kill SMS 2FA
  • A look at Meta’s new verification service
  • How a ransomware attack disrupted the semiconductor supply chain
  • Why Anonymous Sudan is probably a Russian info op
  • Microsoft mixes up public and private keys in Azure B2C (for real)
  • Much, much more
  • This week’s show is brought to you by Proofpoint. Its Executive Vice President of Cybersecurity Strategy Ryan Kalember joins the show in the sponsor slot.

    Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

    Show notes
    • " rel="noopener noreferrer">How to Protect Yourself From Twitter’s 2FA Crackdown | WIRED
    • " rel="noopener noreferrer">Elon Musk Says Twitter Lost $60mn a Year Because 390 Telcos Used Bot Accounts to Pump A2P SMS | Commsrisk
    • " rel="noopener noreferrer">Twitter’s Two-Factor Authentication Change ‘Doesn't Make Sense’ | WIRED
    • " rel="noopener noreferrer">Elon Musk on Twitter: "@MKBHD Twitter is getting scammed by phone companies for $60M/year of fake 2FA SMS messages" / Twitter
    • " rel="noopener noreferrer">rat king 🐀 on Twitter: "as twitter goes through diff versions of what it’s subscription service looks like, meta rolls out its own verified program… https://t.co/BPNILEFGZ0" / Twitter
    • " rel="noopener noreferrer">WA wedding photographer’s fury as Instagram account deactivated | news.com.au — Australia’s leading news site
    • " rel="noopener noreferrer">Semiconductor industry giant says ransomware attack on supplier will cost it $250 million - The Record from Recorded Future News
    • " rel="noopener noreferrer">State of emergency as City of Oakland grapples with ransomware attack - The Record from Recorded Future News
    • " rel="noopener noreferrer">Irish TV broadcaster says attempted hack will affect programming - The Record from Recorded Future News
    • " rel="noopener noreferrer">Revealed: the US adviser who tried to swing Nigeria’s 2015 election | Cambridge Analytica | The Guardian
    • " rel="noopener noreferrer">Political aides hacked by ‘Team Jorge’ in run-up to Kenyan election | World news | The Guardian
    • " rel="noopener noreferrer">Fox News stars and staffers privately blasted election fraud claims as bogus, court filing shows
    • " rel="noopener noreferrer">google_fog_of_war_research_report.pdf
    • " rel="noopener noreferrer">Hacks, leaks and wipers: Google analyzes a year of Russian cyberattacks on Ukraine | CyberScoop
    • " rel="noopener noreferrer">Scandinavian Airlines hit by cyberattack, 'Anonymous Sudan' claims responsibility - The Record from Recorded Future News
    • " rel="noopener noreferrer">Azure B2C Crypto Misuse and Account Compromise - Praetorian
    • " rel="noopener noreferrer">GoDaddy: Hackers stole source code, installed malware in multi-year breach
    • " rel="noopener noreferrer">WIP26 Espionage | Threat Actors Abuse Cloud Infrastructure in Targeted Telco Attacks - SentinelOne
    • " rel="noopener noreferrer">Hyundai, Kia to provide anti-theft software updates following viral TikTok challenge - The Record from Recorded Future News
    • " rel="noopener noreferrer">Health info for 1 million patients stolen using critical GoAnywhere vulnerability | Ars Technica
    • " rel="noopener noreferrer">Latest attack on PyPI users shows crooks are only getting better | Ars Technica
    • " rel="noopener noreferrer">Belgium launches nationwide safe harbor for ethical hackers | The Daily Swig
    • " rel="noopener noreferrer">Tor Project Moves Away from Infrastructure Ran by Internet Monitoring Firm
    • Bank accounts overdrawn, missing and suspended without warning, bank won't talk to me : LegalAdviceUK
    • ...more
      View all episodesView all episodes
      Download on the App Store

      Risky BusinessBy Patrick Gray

      • 4.6
      • 4.6
      • 4.6
      • 4.6
      • 4.6

      4.6

      352 ratings


      More shows like Risky Business

      View all
      Security Now (Audio) by TWiT

      Security Now (Audio)

      1,961 Listeners

      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

      634 Listeners

      Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

      Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

      368 Listeners

      Hacked by Hacked

      Hacked

      176 Listeners

      CyberWire Daily by N2K Networks

      CyberWire Daily

      1,008 Listeners

      Smashing Security by Graham Cluley & Carole Theriault

      Smashing Security

      312 Listeners

      Click Here by Recorded Future News

      Click Here

      386 Listeners

      Malicious Life by Malicious Life

      Malicious Life

      923 Listeners

      Darknet Diaries by Jack Rhysider

      Darknet Diaries

      7,840 Listeners

      Cybersecurity Today by Jim Love

      Cybersecurity Today

      141 Listeners

      CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

      CISO Series Podcast

      182 Listeners

      Hacking Humans by N2K Networks

      Hacking Humans

      309 Listeners

      Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

      Defense in Depth

      71 Listeners

      Cyber Security Headlines by CISO Series

      Cyber Security Headlines

      120 Listeners

      Risky Bulletin by risky.biz

      Risky Bulletin

      33 Listeners