Security Now (Audio)

SN 948: What if a Bit Flipped? - Privacy Badger, Downfall, OpenVPN, Windshield Barnacle, Article 45


Listen Later

  • Privacy Badger blocks trackers on news sites and prevents browser exposure to unwanted domains like TikTok and Datadog.
  • No major updates on EU's controversial Article 45 in eIDAS 2.0. Industry pushback continues as implementation would threaten encryption.
  • Cryptocurrency exchange Poloniex lost $130M in a hot wallet hack, the 14th largest crypto theft.
  • Decentralized finance platform Raft lost $3.3M due to an exploit.
  • Crook operated website iotaseed.io to generate wallet seed phrases, then recorded and stole them.
  • New Intel processor vulnerability called Downfall leaks encryption keys and sensitive data between users on shared systems.
  • Russia moves to formally ban all VPN use in the country.
  • Two new flaws found in OpenVPN software, one allowing memory access.
  • SpinRite development paused as DOS and Windows versions are complete.
  • Understanding assembly language helps malware analysis and exploit development, but high-level decompilers also useful.
  • Quantum-safe symmetric cryptography is limited compared to asymmetric crypto.
  • EU's Article 45 allows transparent decryption and traffic interception, supposedly for security purposes.
  • "Windshield Barnacle" parking enforcement device uses suction cups and 1000 lbs of force to immobilize vehicles until parking tickets are paid.
  • Sci-fi book series Aeon 14 by M.D. Cooper offers fun military space opera adventure.
  • 27-year-old theoretical crypto attack now shown practical. Passive network observers can steal SSH RSA keys if faulty signature generated, allowing impersonation.
  • Show Notes - https://www.grc.com/sn/SN-948-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:

    • kolide.com/securitynow
    • bitwarden.com/twit
    • GO.ACILEARNING.COM/TWIT
    • ...more
      View all episodesView all episodes
      Download on the App Store

      Security Now (Audio)By TWiT

      • 5
      • 5
      • 5
      • 5
      • 5

      5

      2 ratings


      More shows like Security Now (Audio)

      View all
      This Week in Tech (Audio) by TWiT

      This Week in Tech (Audio)

      3,002 Listeners

      Hands-On Tech (Audio) by TWiT

      Hands-On Tech (Audio)

      1,965 Listeners

      WSJ Tech News Briefing by The Wall Street Journal

      WSJ Tech News Briefing

      1,633 Listeners

      Security Now (Audio) by TWiT

      Security Now (Audio)

      1,963 Listeners

      MacBreak Weekly (Audio) by TWiT

      MacBreak Weekly (Audio)

      2,013 Listeners

      Windows Weekly (Audio) by TWiT

      Windows Weekly (Audio)

      854 Listeners

      Risky Business by Patrick Gray

      Risky Business

      362 Listeners

      No Agenda Show by Adam Curry & John C. Dvorak

      No Agenda Show

      5,924 Listeners

      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

      633 Listeners

      Tech News Weekly (Audio) by TWiT

      Tech News Weekly (Audio)

      1,064 Listeners

      Accidental Tech Podcast by Marco Arment, Casey Liss, John Siracusa

      Accidental Tech Podcast

      2,092 Listeners

      Windows Weekly (Audio) by TWiT

      Windows Weekly (Audio)

      2 Listeners

      Cyber Security Headlines by CISO Series

      Cyber Security Headlines

      120 Listeners

      Human Events Daily with Jack Posobiec by Human Events with Jack Posobiec

      Human Events Daily with Jack Posobiec

      5,886 Listeners