
Sign up to save your podcasts
Or


Ransomware uses software to extort people. A piece of ransomware might arrive in your inbox looking like a PDF, or a link to a website with a redirect. Ransomware is often distributed using social engineering. The email address might resemble someone you know, or a transactional email from a company like Uber or Amazon.
Tim Gallo and Allan Liska are authors of the O’Reilly book Ransomware: Defending Against Digital Distortion. They join me to describe the 5 stages of ransomware: deployment, installation, command and control, destruction, and extortion. Tim and Allan describe conditions under which it might make sense to pay the extortion, and some frightening recent cases of ransomware impacting the real world.
We would love to get your feedback on Software Engineering Daily. Please fill out the listener survey, available on softwareengineeringdaily.com/survey. Also–Software Engineering Daily is having our third Meetup, Wednesday May 3rd at Galvanize in San Francisco. The theme of this Meetup is Fraud and Risk in Software. We will have great food, engaging speakers, and a friendly, intellectual atmosphere. To find out more, go to softwareengineeringdaily.com/meetup.
The post Ransomware with Tim Gallo and Allan Liska appeared first on Software Engineering Daily.
The online advertising industry is a giant casino. Giant technology companies are the casino owners, online publishers are the casino employees, the brand advertisers are the victims who keep returning to the casino to lose their money, and the small adtech companies are the sharks who make lots of money exploiting the inefficiencies of the system.
One of these smaller adtech companies is called eZanga. eZanga sells “pre-filtered traffic.” Pre-filtered traffic means traffic that will pass through bot detection filters. A publisher can purchase traffic to their website so that the ads on that website get viewed.
eZanga describes this technology as “marketing,” and has won a giant contract with United States government to handle advertising for the GSA. Advertising fraud does not just promote misinformation–it is now taking our tax dollars and spending it on paid traffic.
If any of this is confusing to you, don’t worry. We explain it all in today’s episode with Shailin Dhar, the advertising fraud expert who wrote a detailed report about eZanga and its contract with the US Government. Shailin was previously on the show to give an overview of ad fraud, and what his work as an ad fraud investigator entails.
Also, Shailin will be a speaker at our third Meetup, Wednesday May 3rd at Galvanize in San Francisco. The theme of this Meetup is Fraud and Risk in Software. We will have great food, engaging speakers, and a friendly, intellectual atmosphere. To find out more, go to softwareengineeringdaily.com/meetup.
Ad Fraud in Our Own Backyard: The Dhar Method
The post Ad Fraud In Our Own Backyard with Shailin Dhar appeared first on Software Engineering Daily.
The Internet is decreasing in privacy and increasing in utility. Under some conditions, this tradeoff makes sense. We publicize our profile photo so that people know what we look like. Under other conditions, this tradeoff does not make sense. We do not want a television that costs less to purchase because it is silently recording all of the conversations that take place in the room and selling them to the highest bidder.
The example of the TV that records everything you say (which is a real thing) illustrates a tradeoff of the Internet. The advertising industry pushes us towards lower marginal costs for products and services in exchange for less privacy.
Someday we will live in a world where it will be easy for consumers to control the dial on the tradeoff between privacy and the price of their services. Until then, we have almost zero control over what information the advertising surveillance industrial complex knows about us.
Bill Budington is a security engineer with the Electronic Frontier Foundation. In today’s episode, Bill describes some of the current techniques used by the advertising industry to track your activity through the web. Bill works on encryption tools as well as Panopticlick, a project that allows users to see what trackers they are vulnerable to.
Software Engineering Daily is having our third Meetup, Wednesday May 3rd at Galvanize in San Francisco. The theme of this Meetup is Fraud and Risk in Software. We will have great food, engaging speakers, and a friendly, intellectual atmosphere. To find out more, go to softwareengineeringdaily.com/meetup.
The post Web Tracking with Bill Budington appeared first on Software Engineering Daily.
Thursday February 23rd was a big day in security news: details were published about the Cloudbleed bug, which leaked tons of plaintext requests from across the Internet into plain view. On the same day, the first collision attack against SHA-1 was demonstrated by researchers at Google, foretelling the demise of SHA-1 as a safe hashing function.
What does this mean for the average engineer? What are the implications for regular internet users? Haseeb Qureshi interviews Max Burkhardt, a security researcher at Airbnb, to get to the bottom of what exactly happened, what it means, and how it affects the security of web applications.
The post Cloudbleed and SHA-1 Collision with Max Burkhardt appeared first on Software Engineering Daily.
Security vulnerabilities are an important concern in systems. When we specify that we want certain information hidden, for example our phone number or our date of birth, we expect the system to hide the information. However, this doesn’t always happen due to human error in the code because programmers have to write checks and filters across the program.
In this episode, Edaena Salinas interviews Jean Yang, Assistant Professor at the Computer Science Department at Carnegie Mellon, who presents Jeeves, a language that allows programmers to specify security policies more intuitively, making it harder to leak information that is meant to be protected. Jean explained how Jeeves was implemented and how it can be used. We also talked about what it takes to bring research concepts from academia to the industry and at the end we had a very interesting conversation on how to educate a broader audience on the importance of security. Jean was also named one of the 35 innovators under 35 by MIT Technology Review.
The post Security Language with Jean Yang appeared first on Software Engineering Daily.
Vulnerabilities exist in every computer system. As a system gets bigger, the number of vulnerabilities magnifies. The web is the biggest, most complex computer system we have–but fortunately, the steps we can take to secure our web applications are often quite simple.
Jared Smith is a cyber security research scientist with Oak Ridge National Laboratory. He joined me on the show to discuss web application security, but I really wanted to know his position on some of the more grandiose topics–Stuxnet, our power grid, Russian hacking, and corporate backdoors.
This was a wide ranging discussion and I enjoyed it a lot. For a presentation Jared gave at Nodevember about Web Security, check out this YouTube video.
The post Cyber Warfare with Jared Smith appeared first on Software Engineering Daily.
Every digital system has vulnerabilities. Cars can be hacked, locked computers can be exploited, and credit cards can be spoofed. Security researchers make a career out of finding these types of vulnerabilities.
Samy Kamkar’s approach to security research is not just about dissection–it’s also about creativity. For many of the technologies he hacks on, Samy open-sources code that summarily describes the vulnerability he has been working on. For example, in his project PoisonTap, Samy open-sourced code that you can run on a $5 Raspberry Pi, and plug into a locked computer to exploit it.
Our conversation covered the art of deconstructing technologies for vulnerabilities and Samy’s goals as a security researcher. We also touched on some of the broader issues of modern security.
The post Security Research with Samy Kamkar appeared first on Software Engineering Daily.
A huge percentage of online advertisements are never seen by humans. They are viewed by bots–automated scripts that are opening web pages in a browser and pretending to be a human. Advertising scammers set up web pages, embed advertisements on those pages, and then pay for bot traffic to come and view those advertisements.
This aspect of the internet is bizarre and alarming. Think about it–how much of the Internet economy depends on online advertising? A lot! How many of those advertisements are consumed by robots? Some estimates say as much as 80%.
The more time I spend looking at the online advertising industry, the more perplexed and curious I become. Augustine Fou also has this curiosity. He got a PhD at MIT in material science and engineering–but today he spends his time researching advertising fraud and working as an independent consultant.
The post Ad Fraud Research with Augustine Fou appeared first on Software Engineering Daily.
Advertising fraud is easy, legal, and extremely profitable. A fraudster can set up a website, scrape content from the internet, and run programmatic advertisements against that website. The fraudster can then purchase bot traffic. Those bots will visit the page, consume advertisements, and return profit to the owner of the page.
In a past life, Shailin Dhar worked for a company that set up these types of advertising fraud schemes. He was fascinated by the industry in the same way that plenty of people get fascinated with the fast-moving market dynamics that are enabled by modern software. But over time, the novelty wore off and Shailin realized how big the fraud problem is and how much it was hurting people.
In today’s episode Shailin and I discuss how bots and poorly aligned incentives lead to systemic failures and significant financial loss for brands who purchase advertising.
The post Ad Fraud Everywhere with Shailin Dhar appeared first on Software Engineering Daily.
Botnets have a massive influence on the Internet. As we have seen recently with the Mirai Botnet, IOT bots can take down companies as big as Netflix. In our recent episodes about advertising fraud, we’ve talked about how bots are being used to take billions of dollars of revenue from advertisers.
Derek Muller is one of those advertisers who has spent money on ads and gotten nothing but fake traffic in return. Two years ago, he posted a video on YouTube about his experience purchasing advertising traffic on Facebook and getting Likes from accounts that were clearly fake accounts.
Derek is the host of Veritasium, an awesome YouTube channel about science, truth, and technology–so we also talked some about how he built a successful YouTube business.
The post Botnet Facebook Likes with Derek Muller appeared first on Software Engineering Daily.
From the publisher's feed