Security News

S3 Ep148: Remembering crypto heroes
2023-08-17 19:43

ATMs always take your card right in, don't they? So the idea of these ATM skimming crooks is they're not just interested in your card details, like a web phisher would be.

S3 Ep147: What if you type in your password during a meeting?
2023-08-10 19:34

DUCK. So we did get the Mark I, and I guess it was the last mainstream digital computer that had a driveshaft, Doug, operated by an electrical motor. DUCK. I think they intended that as a slightly humorous note, but they did note that previous research, not their own, has discovered that touch-typers tend to be much more regular about the way that they type.

#S3
S3 Ep146: Tell us about that breach! (If you want to.)
2023-08-03 17:56

The root of the problem is that shared CPU components, like the internal memory system, combine attacker data and data from any other application, resulting in a combined leakage signal in the power consumption. Whether just suffering a ransomware attack is inevitably enough to be a material data breach.

S3 Ep145: Bugs With Impressive Names!
2023-07-27 18:47

The problem is there was no data authentication or verification stage. The moral of the story is: Don't rely on data you can't verify.

#S3
S3 Ep144: When threat hunting goes down a rabbit hole
2023-07-20 20:58

Listeners will probably know that Virus Total is a very popular service where, if you've got a file that either you know it's malware and you want to know what lots of different products call it, or if you think, "Maybe I want to get the sample securely to as many vendors as possible, as quickly as possible". The file is meant to be made available to dozens of cybersecurity companies almost immediately.

S3 Ep143: Supercookie surveillance shenanigans
2023-07-13 18:48

DUCK. Yes, the usual large number of bugs fixed. Although Elevation of Privilege usually gets looked down on as lesser than Remote Code Execution, where crooks use the bug to break in in the first place, the problem with EoP has to do with crooks who are already "Loitering with intent" in your network.

S3 Ep142: Putting the X in X-Ops
2023-07-06 19:58

MATT. Yes, the idea of Bring Your Own Device [BYOD] wouldn't fly back in the day, would it? MATT. One of the things that's changed so much since then, Paul, is that, back in the day, you had an infected machine, and everyone was desperate to get the machine disinfected.

#S3
S3 Ep141: What was Steve Jobs’s first job?
2023-06-29 18:58

DOUG. Emergency Apple patches, justice for the 2020 Twitter hack, and "Turn off your phones, please!". DOUG. As luck would have it, we have a long list of things you can do other than just turning off your phone for five minutes.

#S3
S3 Ep140: So you think you know ransomware?
2023-06-22 20:48

DUCK. I don't know whether that's true, but I like to think it is. Before we get to stuff that's in the news, we are pleased, nay thrilled, to announce the first of three episodes of Think You Know Ransomware?

S3 Ep139: Are password rules like running through rain?
2023-06-15 18:43

As long as they don't choose password or secret or one of the Top Ten Cats' Names in the world, maybe it's OK if we force them to change it to another not-very-good password before the crooks would be able to crack it? The simple observation is that changing a bad password regularly doesn't make it a better password.

#S3