Security Now - 16k MP3

Security Now - 16k MP3

Download on the App Store

Security Now - 16k MP3 episodes

  • SN749: Win 7 - R. I. P.
    This week's Security Now! podcast is titled "Windows 7 - R.I.P.," not because there's much that we haven't already said about the fact, but that it happens TODAY; and that, given the still massive install base of Windows 7, it's significant that all of those machines will now be going without any clearly needed security updates. So the big news for this week WAS to be the event of the first successful preimage attack on the SHA-1 hash. But that news was preempted at the last minute by the much more immediately significant news of the remotely exploitable "Cable Haunt" vulnerability that's present in most of the world's cable modems right now! So we'll be talking about that after we look at the FBI's recent request to have Apple unlock another terrorist's iPhone; update on the Checkrain jailbreak solution; examine the challenge of checking for illegal images while preserving privacy; look at some deeply worrying research into just how easy it is for bad guys to get SIMs swapped; examine the consequences of not patching a bad VPN flaw; deal with a bit of miscellany; and then, finally, look at the new "Cable Haunt" vulnerability.
    1 hr 58 min
  • SN748: A Malware Lexicon
    This first podcast of 2020 we look at a proposed standard for creating machine-readable warrant canaries. We also take a precautionary lesson from a big Xiaomi blunder, examine Microsoft's research into brute-forcing RDP, look at the continuing problem at the Point Of Sale, follow-up on Russia's plan to disconnect from the Internet, consider the end of life of Python 2.7, review the top 20 HackerOne bounty payers, warn of some bad new SQLite security vulnerabilities and cover a bit of Sci-Fi, SQRL and SpinRite miscellany. Then we group all malware into a seven-member Lexicon and quickly run through each one.
    1 hr 59 min
  • SN747: The Best of 2019
    For Security Now!'s annual holiday podcast, Leo takes us back to reexamine several significant events covered by this podcast during the past year.
    1 hr 48 min
  • SN746: A Decade of Hacks
    This week we stumble into Microsoft's own confusion about whether or not Microsoft's Security Essentials will continue receiving updates after January 14th. We look briefly at the year when Ransomware happened, we revisit the Avast and AVG Mozilla extensions to see how they're doing, we look at the just-announced big news for Apple's and Google's bug bounty programs for 2020, and also at Mozilla's addition of another very appealing DoH provider (which Leo apparently likes). We provide a nudge to Drupal site masters to update their Drupal Cores RIGHT NOW... And then we conclude by revisiting this past decade -- spanning 2010 to 2019 -- and the many hacks we've explored during these previous ten years.
    1 hr 43 min
  • SN745: PlunderVolt
    This week we start with a reminder about Google's still operating SensorVault, we look inside Google's new "Verified SMS" Messages feature, examine another salvo in the end-to-end encryption war, a nice authentication feature added to iOS v13.3, some patch Tuesday news, a startling discovery about the weaknesses of RSA at scale, a collection of quick bits about last Friday the 13th, Mozilla 2FA for add-on developers, the surprising hard out for Microsoft's Security Essentials, and two bits about Chrome 79. Then we have a clarification about last week's VPN-geddon Denied discussion, a significant announcement about my new focus, some SQRL news... and then we conclude with a look at yet another interesting new way of compromising Intel processors known as "PlunderVolt".
    1 hr 49 min
  • SN744: VPN-geddon Denied
    This week we look at Microsoft's force-feeding of Windows 10 feature updates, the creation of a tool to keep Win7 and 8 updates freely flowing for free, the continuing evolution of a new highly secure programming language, an update to Microsoft's RDP client for iOS, Avast and AVG in the doghouse, some VERY severe authentication bypasses in OpenBSD, and a note about the WireGuard VPN. Then we take a look at the report which every security website breathlessly covered - and got wrong.
    1 hr 37 min
  • SN743: Android "StandHogg"
    This week we revisit free upgrades from Win7 or 8 to 10 (which can still be done, a alert for users of HP SSDs, the complications which arise with international privacy treaties when end-to-end encryption might be threatened, the US government's formal permission to hack, a quick look at a particularly devastating Ransomware attack, more anti-tracking privacy happiness coming soon, by default, to Firefox, the never-ending headaches caused by Windows DLLs, an update on my "Joy of Sync" determinations, and a look at the way some Android multitasking features can and are being actively abused -- with Google's knowledge.
    1 hr 49 min
  • SN742: Pushing DoH
    This week we look at some interesting changes coming to Android and some inherent challenges presented by the nature of the Android ecosystem. We examine some newly revealed troubles with the venerable VNC clients and servers. We note a welcome change to Twitter and update on law enforcement's "foregone conclusion" strategy to force password divulgence. We then look at a surprising pre-announcement from Microsoft about DNS, then dig more deeply into the details of the emerging DoH protocol and reveal a VERY interesting and surprising and unsuspected capability.
    1 hr 41 min
  • SN741: TPM-FAIL
    This week we look back at November's Patch Tuesday while we count down to the impending end of patches for Windows 7 and Server 2008. We check in with CheckM8 and Checkra.in as the iOS bootrom exploit continues to mature. We look at GitHub's announcement launch of "GitHub Security Lab" to bring bounties and much stronger security focus to the open source community. We discuss a recent court ruling regarding U.S. border entry device searches. We cover yet another bad WhatsApp remote code execution vulnerability. We examine the impact of version 2 of ZombieLoad, the formation of the Bytecode Alliance, and a bit of media miscellany. Then we examine the impact of two Trusted Platform Module (TPM) failings, one which allows local key extraction, and a second that can be exploited remotely over a network.
    1 hr 55 min
  • SN740: Credential Delegation
    This week we check in on the developments of the long-term, now working, full consumer jailbreak of iOS devices from the iPhone 4S through the iPhone X. We examine the strange case of the misbehaving transducer, catch up on the rapidly evolving exploitation of the BlueKeep vulnerability, check out Mozilla's rebuttal to Comcast's attack on DoH, examine the surprising state of web browser support for DoH, and remind Linux and BSD users to refresh their distros after an important flaw was disclosed in a widely used archive library. Then we take a deep dive into the operation of a newly announced forthcoming solution and standard for significantly improving TLS website certificate security known as "TLS Credential Delegation."
    1 hr 58 min

About Security Now - 16k MP3

From the publisher's feed

Steve Gibson, the man who coined the term spyware and created the first anti-spyware program,