Security News

S3 Ep127: When you chop someone out of a photo, but there they are anyway…
2023-03-23 19:59

They found this bug in the app on Google Pixel Phones that lets you take a screenshot, or a photo you've captured, and crop it, or blank out bits of it. Google Pixel phones had a serious data leakage bug - here's what to do!

#S3
S3 Ep 126: The price of fast fashion (and feature creep) [Audio + Text]
2023-03-16 19:56

No audio player below? Listen directly on Soundcloud. You can listen to us on Soundcloud, Apple Podcasts, Google Podcasts, Spotify, Stitcher and anywhere that good podcasts are found.

#S3
S3 Ep125: When security hardware has security holes [Audio + Text]
2023-03-09 20:58

Ransomware bust, ransomware warning, and anti-ransomware advice. DOUG. Ransomware, more ransomware, and TPM vulnerabilities.

S3 Ep124: When so-called security apps go rogue [Audio + Text]
2023-03-02 19:40

DOUG. Scambaiting, rogue 2FA apps, and we haven't heard the last of LastPass. Alright, let's stay on the subject of 2FA. We are seeing a spike in rogue 2FA apps in both app stores.

S3 Ep123: Crypto company compromise kerfuffle [Audio + Text]
2023-02-23 19:58

DOUG. Crypto company code captured, Twitter's pay-for-2FA play, and GoDaddy breached. DOUG. Well, let's bring things into the modern, and talk about GoDaddy.

S3 Ep122: Stop calling every breach “sophisticated”! [Audio + Text]
2023-02-16 19:46

DOUG. Patching bugs, hacking Reddit, and the early days of computing. Like in the LastPass breach and the recent GitHub breach, source code got stolen, along with a bit of other stuff.

S3 Ep121: Can you get hacked and then prosecuted for it? [Audio + Text]
2023-02-09 19:41

Exactly the same when you try and use a password you say, "I want to copy that password and use it." You have to put in a master password to get access to your passwords, but you don't have to put in the master password to get access to the configuration file to get access to the passwords.

Amazon S3 to apply security best practices for all new buckets
2023-02-07 09:45

Starting in April 2023, Amazon S3 will change the default security configuration for all new S3 buckets.For new buckets created after this date, S3 Block Public Access will be enabled, and S3 access control lists will be disabled.

S3 Ep120: When dud crypto simply won’t let go [Audio + Text]
2023-02-02 19:50

This is not a breach of the GitHub systems or the GitHub infrastructure or how GitHub stores files - it's just that GitHub's code on GitHub some of the stuff that was supposed to be private got downloaded. In the end, GitHub found, I think, that there are only three stolen certificates that were actually still valid, in other words, that crooks could actually use for signing anything.

S3 Ep119: Breaches, patches, leaks and tweaks! [Audio + Text]
2023-01-26 19:57

DOUG. OK, we've got some tips if you are affected by this, starting with: Don't click "Helpful" links in emails or other messages. Apple patches are out - old iPhones get an old zero-day fix at last!