TechSNAP

TechSNAP

By Jupiter BroadcastingNewsTech News
Download on the App Store

TechSNAP episodes

  • Episode 374: Quantum Resistant Encryption

    Good progress is being made on post-quantum resilient computing. We’ll explain how they’re achieving it, the risks facing traditional cryptography.

    Plus how bad defaults led to the theft of military Drone docs, new attacks against LTE networks, more!

    Sponsored By:

    • Digital Ocean: Apply our promo snapocean after you create your account, and get a $10 credit.
    Promo Code: snapocean
  • iXSystems: Get a system purpose built for you.
  • Promo Code: Tell them we sent you!
  • Ting: Save $25 off a device, or get $25 in service credits!
  • Promo Code: Visit techsnap.ting.com

    Links:

    • Hacker Steals Military Docs Because Someone Didn’t Change a Default FTP Password
  • Year-Old Critical Vulnerabilities Patched in ISP Broadband Gear | The first stop for security news
  • Timehop admits that additional personal data was compromised in breach
  • Researchers Uncover New Attacks Against LTE Network Protocol
  • Breaking LTE on Layer Two
  • Nintendo reportedly rolling out new, more hack-resistant Switch hardware
  • Wire and post-quantum resistance
  • What is quantum computing?
  • Quantum Computing and its Impact on Cryptography
  • Why Quantum Computers Might Not Break Cryptography
  • Remote Manage Linux Boxes?
  • Learning OpenStack?
  • 48 min
  • Episode 373: FreeBSD Already Does That

    Allan Jude and Wes sit-down for a special live edition of the TechSNAP program.

    Joined by Jed and Jeff they have a wide ranging organic conversation.

    Special Guest: Allan Jude.

    Sponsored By:

    • Digital Ocean: Apply our promo snapocean after you create your account, and get a $10 credit.
    Promo Code: snapocean
  • iXSystems: Get a system purpose built for you.
  • Promo Code: Tell them we sent you!
  • Ting: Save $25 off a device, or get $25 in service credits!
  • Promo Code: Visit techsnap.ting.com
    1 hr 36 min
  • Episode 372: Logs and Metrics and Traces, Oh My!

    Netflix has learned the hard way how to utilize all the logs, we cover their lessons in their journey to build a fully observable system.

    Plus the Lazy State FPU bug that cropped up this week, backdoored Docker images, your questions, and more!

    Sponsored By:

    • Digital Ocean: Apply our promo snapocean after you create your account, and get a $10 credit.
    Promo Code: snapocean
  • iXSystems: Get a system purpose built for you.
  • Promo Code: Tell them we sent you!
  • Ting: Save $25 off a device, or get $25 in service credits!
  • Promo Code: Visit techsnap.ting.com

    Links:

    • INTEL-SA-00145
  • Colin Percival on Twitter
  • NetBSD Documentation: How lazy FPU context switch works
  • Lazy FPU Save/Restore (CVE-2018-3665)
  • 17 Backdoored Docker Images Removed From Docker Hub
  • Lessons from Building Observability Tools at Netflix
  • Jobs at Linux Academy
  • 37 min
  • Episode 371: They Never Learn

    Microsoft puts a data center under the ocean, and they might be onto something. The Zip Slip vulnerability sneaks into your software, and VPNFilter turns out to be more complicated than first known.

    Plus the mass exploit of Drupalgeddon2 continues, we break down why, a batch of questions, and more.

    Sponsored By:

    • Digital Ocean: Apply our promo snapocean after you create your account, and get a $10 credit.
    Promo Code: snapocean
  • Ting: Save $25 off a device, or get $25 in service credits!
  • Promo Code: Visit techsnap.ting.com
  • iXSystems: Get a system purpose built for you.
  • Promo Code: Tell them we sent you!

    Links:

    • Microsoft sinks data centre off Orkney
  • How to protect yourself from megabreaches like the one that hit Ticketfly
  • Three months later, a mass exploit of powerful Web servers continues
  • Breach detection with Linux filesystem forensics
  • Zip Slip Vulnerability
  • VPNFilter Update
  • RouterSploit: Exploitation Framework for Embedded Devices
  • 45 min
  • Episode 370: Hidden in Plain Sight

    We explain how the much hyped VPNFilter malware actually works, and its rather surprising sophistication.

    Plus a clear break down of the recent Kubernetes news, how a 40 year old tel-co protocol is being abused today, and a Git vulnerability you should know about.

    Sponsored By:

    • Digital Ocean: Apply our promo snapocean after you create your account, and get a $10 credit.
    Promo Code: snapocean
  • iXSystems: Get a system purpose built for you.
  • Promo Code: Tell them we sent you!
  • Ting: Save $25 off a device, or get $25 in service credits!
  • Promo Code: Visit techsnap.ting.com

    Links:

    • Hiding Information in Plain Text - IEEE Spectrum
  • Remediating the May 2018 Git Security Vulnerability – Microsoft DevOps Blog
  • When to use git subtree? - Stack Overflow
  • Ghostery Email Incident Update - Ghostery
  • Surprise! Student receives $36,000 Google bug bounty for RCE flaw – Naked Security
  • SS7 routing-protocol breach of US cellular carrier exposed customer data | Ars Technica
  • SnoopSnitch - Apps on Google Play
  • Kubernetes Containerd Integration Goes GA - Kubernetes
  • Hackers infect 500,000 consumer routers all over the world with malware | Ars Technica
  • FBI seizes domain Russia allegedly used to infect 500,000 consumer routers | Ars Technica
  • Singapore ISP Leaves 1,000 Routers Open to Attack | Threatpost | The first stop for security news
  • Don't let Frank near the server
  • Dave decides to move some plugs...
  • 52 min
  • Episode 369: Another Pass at Bypass

    We’ll explain how Speculative Store Bypass works, and the new mitigation techniques that are inbound.

    Plus this week’s security news has a bit of a theme, and we share some great war stories sent into the show.

    Sponsored By:

    • Digital Ocean: Apply our promo snapocean after you create your account, and get a $10 credit.
    Promo Code: snapocean
  • iXSystems: Get a system purpose built for you.
  • Promo Code: Tell them we sent you!
  • Ting: Save $25 off a device, or get $25 in service credits!
  • Promo Code: Visit techsnap.ting.com

    Links:

    • Security Flaw Impacts Electron-Based Apps
  • Attackers Use UPnP to Sidestep DDoS Defenses | Threatpost | The first stop for security news
  • Another severe flaw in Signal desktop app lets hackers steal your chats in plaintext
  • Critical Linux Flaw Opens the Door to Full Root Access | Threatpost | The first stop for security news
  • Microsoft, Google: We've found a fourth data-leaking Meltdown-Spectre CPU hole • The Register
  • Speculative Store Bypass explained: what it is, how it works
  • TechSNAP Episode 351: Performance Meltdown
  • Dave's Users flip the switch!
  • Dave's War Story is really Screwy!
  • Egon's Adventures in misslabled VMs
  • 45 min
  • Episode 368: EFail Explained

    The EFail hype-train has hit hypersonic speed, we’ll tap the breaks and explain who disclosed it, what it is, what it’s not, our recommendations, and early reactions.

    Plus things to consider when deciding on-premises vs a cloud deployment, and the all business gadget from 1971 that kicked off the consumer electronics revolution.

    Links:

    • The HP-35
    — Consumer Electronics, an Origin Story
  • The people cost of building out a Kubernetes cluster on-prem | Operos
  • EFAIL
  • — EFAIL describes vulnerabilities in the end-to-end encryption technologies OpenPGP and S/MIME that leak the plaintext of encrypted emails.
  • efail-attack-paper.pdf
  • GnuPG Efail press release Response
  • No, PGP is not broken, not even with the Efail vulnerabilities - ProtonMail Blog
  • — Recently, news broke about potential vulnerabilities in PGP, dubbed Efail. However, despite reports to the contrary, PGP is not actually broken, as we will explain in this post.
  • Eric's War Story is VERY Familiar
  • When it rains it pours for Steve
  • Critical Cisco WebEx Bug Allows Remote Code Execution
  • Cisco WebEx and 3rd Party Support Utilities
  • 37 min
  • Episode 367: FreeNAS Uber Build

    Our FreeNAS build is complete and Allan’s back to cover the final details. Plus the new GPU attack against Android phones, and a perfect example of poor IoT security.

    Sponsored By:

    • Digital Ocean: Apply our promo snapocean after you create your account, and get a $10 credit.
    Promo Code: snapocean
  • iXSystems: Get a system purpose built for you.
  • Promo Code: Tell them we sent you!
  • Ting: Save $25 off a device, or get $25 in service credits!
  • Promo Code: Visit techsnap.ting.com

    Links:

    • Drive-by Rowhammer attack uses GPU to compromise an Android phone | Ars Technica
    — JavaScript based GLitch pwns browsers by flipping bits inside memory chips.
  • Rooting a Logitech Harmony Hub
  • — Exploitation of these vulnerabilities from the local network could allow an attacker to control the devices linked to the Hub as well as use the Hub as an execution space to attack other devices on the local network
  • A Complete Guide to FreeNAS Hardware Design, Part I: Purpose and Best Practices
  • — If it’s imperative that your ZFS based system must always be available, ECC RAM is a requirement. If it’s only some level of annoying (slightly, moderately…) that you need to restore your ZFS system from backups, non-ECC RAM will fit the bill.
  • FreeNAS: A Worst Practices Guide
  • Jason likes Hubble
  • Bryan Nuked an email server once...
  • Humble Book Bundle: DevOps by Packt (pay what you want and help charity)
  • — This software engineering bundle is Packt with information! Streamline your processes with ebooks like Automate it!, DevOps for Networking, Mastering Ansible, and Continuous Delivery with Docker and Jenkins. You'll also get helpful videos including Mastering DevOps, Mastering Windows PowerShell 5 Administration, Learning Kubernetes, and more.
    38 min
  • Episode 366: Catching up with Allan

    We catch up with Allan Jude and he shares stories of hunting network bottlenecks, memories of old firewalls, and some classic ZFS updates.

    Plus the vulnerabilities found in Volkswagen cars, and the lengths a security research went to create the ultimate honeypot laptop.

    Special Guest: Allan Jude.

    Sponsored By:

    • Digital Ocean: Apply our promo snapocean after you create your account, and get a $10 credit.
    Promo Code: snapocean
  • Ting: Save $25 off a device, or get $25 in service credits!
  • Promo Code: Visit techsnap.ting.com
  • iXSystems: Get a system purpose built for you.
  • Promo Code: Tell them we sent you!

    Links:

    • Volkswagen and Audi Cars Vulnerable to Remote Hacking
    — esearchers also gained access to the IVI system's root account, which they say allowed them access to other car data.
  • It’s Impossible to Prove Your Laptop Hasn’t Been Hacked. I Spent Two Years Finding Out.
  • — For the last two years, I have carried a “honeypot” laptop with me every time I’ve traveled; this computer was intended to attract (and then detect) tampering.
  • chipsec
  • — Platform Security Assessment Framework
  • UEFITool
  • — UEFI firmware image viewer and editor
  • Haven Project
  • — Haven is for people who need a way to protect their personal spaces and possessions without compromising their own privacy, through an Android app and on-device sensors
  • Mr S. Delivers on his DO FreeNAS Guide
  • OZ Shares a War Story
  • Dave's REALLY Close Call...
  • Karl Gives us the CTO View on new Hires
  • Our Approach to Employee Security Training | PagerDuty
  • — These are both training courses that we developed in-house and delivered ourselves.
    49 min
  • Episode 365: The Unfixable Exploit

    Hardware flaws that can’t be solved, human errors at the physical layer, and spoofing cellular networks with a $5 dongle.

    Sponsored By:

    • iXSystems: Get a system purpose built for you.
    Promo Code: Tell them we sent you!
  • Digital Ocean: Apply our promo snapocean after you create your account, and get a $10 credit.
  • Promo Code: snapocean
  • Ting: Save $25 off a device, or get $25 in service credits!
  • Promo Code: Visit techsnap.ting.com

    Links:

    • Sysadmin unplugged wrong server, ran away, hoped nobody noticed • The Register
    — ‘I was a snot-nosed kid fresh out of college and thought I knew everything!’
  • Spoofing Cell Networks with a USB to VGA Adapter | Hackaday
  • — Available through the usual overseas suppliers for as little has $5 USD, these devices can be used unmodified to transmit low-power FM, DAB, DVB-T, GSM, UMTS and GPS signals.
  • ShofEL2, a Tegra X1 and Nintendo Switch exploit
  • — The Tegra X1 (also known as Tegra210) SoC inside the Nintendo Switch contains an exploitable bug that allow taking control over early execution, bypassing all signature checks.
  • Atlanta spends more than $2 million to recover from ransomware attack
  • — . It appears that firms Secureworks and Ernst & Young were paid $650,000 and $600,000, respectively, for emergency services while Edelman was paid $50,000 for crisis communication services. Overall, the funds seemingly applied to the ransomware attack response add up to approximately $2.7 million.
  • Google Chrome 66 Released Today Focuses on Security
  • — The biggest change is that Google Chrome will start showing SSL certificate errors for all Symantec certs issued before June 1, 2016. This is "stage two" of Google's long-term plan on distrusting Symantec certificates altogether.
  • Where to get started with monitoring?
  • defunkt uses a fool tools for his network
  • Brian shares some love for Zabbix
  • VMware Patches Pwn2Own VM Escape Vulnerabilities
  • — VMware on Tuesday patched a series of vulnerabilities uncovered earlier this month at Pwn2Own. The flaws enabled an attacker to execute code on a workstation and carry out a virtual machine escape to attack a host server.
  • balena - A Moby-based container engine for IoT
  • — A Moby-based container engine for IoT
    39 min

About TechSNAP

From the publisher's feed

Systems, Network, and Administration Podcast. Every two weeks TechSNAP covers the stories that impact those of us in the tech industry, and all of us that follow it. Every episode we dedicate a…

More shows like TechSNAP

Packet Protector by Packet Pushers

Packet Protector

7 Listeners