Total Leo (Audio)

Security Now 937: The Man in the Middle


Listen Later

  • Picture of the Week: Steve shares a funny "what we say vs what we mean" image about tech support conversations.
  • WinRAR v6.23 fixes: Steve explains that updating to the latest WinRAR is more important than initially thought, with two critical vulnerabilities being actively exploited by hackers since April to install malware.
  • HTTPS for local networks: Responding to listener email, Steve agrees HTTP is fine for local network devices like routers but notes risks in larger corporate networks.
  • Portable domains for email: Steve endorses a listener suggestion to purchase your own domain and use third-party services, retaining control if a provider shuts down.
  • Google Topics and monopolies: Steve and Leo debate whether Topics favors large advertisers with greater reach to get user targeting data.
  • Voyager 2 antenna analysis: A listener calculates the antenna beam width mathematically, showing 2 degrees off-axis may not be as remarkable as it sounded.
  • Windows time settings: Steve clarifies the STS issue does not impact end users changing Windows clock settings, it's enterprise server-side.
  • Unix time in TLS handshakes: The hosts discuss why Unix time stamps are sent but not required for TLS, tracing back to early nonce generation.
  • Fake flash drives: Steve warns of a slew of fake high-capacity thumb drives flooding the market, explaining how SpinRite tests detected the flaw.
  • Man-in-the-middle attacks: While agreeing HTTPS helps prevent malicious injection, Steve examines MITM attack practicality, arguing they are difficult for hackers to pull off.
  • Show Notes - https://www.grc.com/sn/SN-937-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:

    • kolide.com/securitynow
    • canary.tools/twit - use code: TWIT
    • Building Cyber Resilience Podcast
    • ...more
      View all episodesView all episodes
      Download on the App Store

      Total Leo (Audio)By TWiT

      • 4.3
      • 4.3
      • 4.3
      • 4.3
      • 4.3

      4.3

      200 ratings


      More shows like Total Leo (Audio)

      View all
      Talking Cars (MP3) by Consumer Reports

      Talking Cars (MP3)

      416 Listeners

      TechStuff by iHeartPodcasts

      TechStuff

      1,754 Listeners

      This Week in Tech (Audio) by TWiT

      This Week in Tech (Audio)

      3,064 Listeners

      MacBreak Weekly (Audio) by TWiT

      MacBreak Weekly (Audio)

      2,015 Listeners

      The Vergecast by The Verge

      The Vergecast

      3,714 Listeners

      Accidental Tech Podcast by Marco Arment, Casey Liss, John Siracusa

      Accidental Tech Podcast

      2,143 Listeners

      Daily Tech News Show by Tom Merritt

      Daily Tech News Show

      1,396 Listeners

      TWiT News (Audio) by TWiT

      TWiT News (Audio)

      78 Listeners

      All TWiT.tv Shows (Audio) by TWiT

      All TWiT.tv Shows (Audio)

      356 Listeners

      9to5Mac Happy Hour by 9to5Mac

      9to5Mac Happy Hour

      731 Listeners

      Upgrade by Relay

      Upgrade

      1,219 Listeners

      The Clark Howard Podcast by Clark Howard

      The Clark Howard Podcast

      5,468 Listeners

      9to5Mac Daily by 9to5Mac

      9to5Mac Daily

      530 Listeners

      TWiT Throwback (Audio) by TWiT

      TWiT Throwback (Audio)

      4 Listeners

      Waveform: The MKBHD Podcast by Vox Media Podcast Network

      Waveform: The MKBHD Podcast

      42 Listeners

      TWiT Events (Audio) by TWiT

      TWiT Events (Audio)

      8 Listeners

      Total Mikah (Audio) by TWiT

      Total Mikah (Audio)

      3 Listeners

      This Day in AI Podcast by Michael Sharkey, Chris Sharkey

      This Day in AI Podcast

      227 Listeners

      Untitled Linux Show (Audio) by TWiT

      Untitled Linux Show (Audio)

      7 Listeners

      The Kim Komando Show by Kim Komando

      The Kim Komando Show

      167 Listeners