Risky Business show

Risky Business

Summary: Risky Business primary podcast.

Podcasts:

 Risky Business #394 -- Matthew Green talks "crypto bans" | File Type: audio/mpeg | Duration: Unknown

On this week's show we're chatting with Johns Hopkins University cryptographer Matthew Green about rumblings emanating out of DC with regard to "stopping encryption", whatever the hell that means. In this week's sponsor interview we're chatting with Oliver Fay from Context about a paper they did in conjunction with UK's CERT about exploit kits. How much do they cost? Are there any that stick out as being particularly good? Or bad, depending on your point of view... Links to everything are in this week's show notes . read more [1] [1] http://risky.biz/RB394

 Risky Business #393 -- So who's Satoshi this week? | File Type: audio/mpeg | Duration: Unknown

On this week's show -- in addition to covering the latest claims about the true identity of Satoshi Nakamoto -- we're taking a look at a recent deal between a very large bank in Australia and Sydney's University of New South Wales. read more [1] [1] http://risky.biz/RB393

 Risky Business #392 -- A look at Silverpush with Kevin Finisterre | File Type: audio/mpeg | Duration: Unknown

On this week's show we're chatting with Kevin Finisterre about Silverpush -- the creepy ultrasonic audio-beaconing technology used by advertising companies that was in the press a couple of weeks ago. Kevin was all over it and he joins me to discuss the growing overlap between the techniques used by marketers and blackhats. read more [1] [1] http://risky.biz/RB392

 Risky Business #391 -- Dell fails hard | File Type: audio/mpeg | Duration: Unknown

On this week's show we're chatting with Darren Kemp of Duo Security. He's one of the authors of a post about the latest example of computer manufacturer shitware introducing catastrophic vulnerabilities into shipped systems. This time it's Dell's turn. If you haven't heard what they actually did you'll hardly even believe it. That's this week's feature interview. read more [1] [1] http://risky.biz/RB391

 Risky Business #390 -- Crypto derpery abounds in wake of Paris attacks | File Type: audio/mpeg | Duration: Unknown

In this week's feature interview we're checking in with FireEye's Jonathan Wrolstad. He's a threat intelligence guy at FireEye and they've just published a really interesting report about what a threat group is doing in terms of target recon. They're using marketing company tricks to recon all sorts of high value targets. It's very interesting stuff, and it's likely tied to the Russian state. read more [1] [1] http://risky.biz/RB390

 Risky Business #389 -- US law: CFAA isn't a bug, it's a feature! | File Type: audio/mpeg | Duration: Unknown

On this week's show we're chatting with computer crime lawyer extraordinaire Tor Ekeland! He's worked on a number of high profile CFAA cases. Most recently he's been defending former Reuters and LA Times journalist Matthew Keys on some pretty hefty CFAA charges. He's also the guy who got Andrew Aurenheimer out of jail so he could go and live a free life as a Nazi troll. (Is that really a win?) He also defended Lauri Love... basically if you're a hacker who's fallen foul of the CFAA, this is the guy you want on your team. read more [1] [1] http://risky.biz/RB389

 Risky Business #388 -- Cyber shrinkery, IoT shenanigans and guest Troy Hunt | File Type: audio/mpeg | Duration: Unknown

This week's feature interview is with Troy Hunt of HaveIBeenPwned.com. And he's noticing something pretty weird. It's common for people to deface websites for bragging rights, and yeah, it's not new that data dumps are the new bragging fodder. But it seems like these days attackers are seeing Troy's site as the definitive place to get cred. Now they'll steal a bunch of data and Troy is their first stop. Life is strange on the internets. That's this week's feature interview. read more [1] [1] http://risky.biz/RB388

 Risky Business #387 -- Hack people to death! | File Type: audio/mpeg | Duration: Unknown

In this week's feature interview we're chatting with Chris Rock from Kustodian. Chris did a great presentation at Ruxcon last week about how easy it is to hack people to death! He's found out just how easy it is to register births and deaths in the united states and Australia via online systems. He says it's a problem that could result in a virtual baby harvest for fraudsters who plan ahead. It's really fun stuff, that's this week's feature. read more [1] [1] http://risky.biz/RB387

 Risky Business #386 -- Katie Moussouris on the (groan) disclosure debate | File Type: audio/mpeg | Duration: Unknown

On this week's show we're checking in with Katie Moussouris of HackerOne. She's an ex Microsoftie who's spent something like a decade working on vulnerability disclosure policies. She even helped get a vuln disclosure ISO standard ratified! And she'll be joining us this week to discuss disclosure politics, I guess you'd call it... for those of us who've been around infosec for a while, most of us would rather stick our face in a blender than talk about it, but Katie will be along to point out why people should fight their "disclosure debate fatigue" and get involved. read more [1] [1] http://risky.biz/RB386

 Risky Business #385 -- Richard Bejtlich talks USA/China espionage agreement | File Type: audio/mpeg | Duration: Unknown

******LANGUAGE WARNING: The f-bomb features, unbleeped, once in this week's show. Just a note for those of you with the kids in the car. On this week's show we're chatting with FireEye's chief security strategist Richard Bejtlich about this new agreement between China and the USA. The two countries have apparently agreed that they won't hack each other with the aim of stealing IP anymore. Questions to Richard include: Are they kidding? And: How did they announce this with a straight face? read more [1] [1] http://risky.biz/RB385

 Risky Business #384 -- Mark Dowd talks AirDrop pwnage, XCode iOS scandal | File Type: audio/mpeg | Duration: Unknown

We've got a great show for you this week. Mark Dowd drops by to talk about the recent spate of Trojaned iOS apps that made it into Apple's China App Store. We also talk to him about his awesome AirDrop bug. How did it work? This week's sponsor segment is actually a real cracker. Context IS consultant David Klein tells us how he owned an entire cloud platform by enumerating some shitty 90s-style bugs in some third party libraries they were using. It's comedy gold. This cloud platform that uses security at a selling point. It's bad. read more [1] [1] http://risky.biz/RB384

 Risky Business #383 -- Inside FireEye's research gag | File Type: audio/mpeg | Duration: Unknown

On this week's show we take a look at what the hell it happening in Germany, where FireEye sought and obtained an ex parte injunction against a bunch of security researchers over a presentation they were about to do at 44Con. We speak with infosec lawyer Alex Urbelis -- he was at 44Con when all this came to light and he shares his insights. read more [1] [1] http://risky.biz/RB383

 Risky Business #382 -- Charlie Miller talks car hax, Uber | File Type: audio/mpeg | Duration: Unknown

On this week's show we're checking in with Charlie Miller. We chat car hacking and we also (kind of) find out what he's up to now he's working at Uber. This week's show is brought to you by HackLabs, an Australian security consultancy. They're a key sponsor of Australia's Cyber Security Challenge, which is basically a CTF for Australian CS students. What makes this one a bit different is it's being run by the Prime Minister's Office, which is, yeah, unexpected. Chris joins us later to discuss the challenge, that's this week's sponsor interview. read more [1] [1] http://risky.biz/RB382

 Risky Business #381 -- Samy Kamkar on his outlaw days | File Type: audio/mpeg | Duration: Unknown

On this week's show we're chatting with hacker superstar and YouTube phenomenon Samy Kamkar. Samy is a security researcher of note -- his recent hardware hacks have been coming thick and fast. This week I spoke to him about his brush with the law following his unleashing of the Samy worm on MySpace a decade ago, some of his recent research and his plans for the future. read more [1] [1] http://risky.biz/RB381

 Risky Business #380 -- AshMad fallout: Attackers doxed, suicides and mayhem | File Type: audio/mpeg | Duration: Unknown

On this week's show we look at the fallout from the Ashley Madison attack. Did Brian Krebs just dox the Impact Team ringleader? Is he Australian? Adam Boileau and I talk about all the AshMad fallout and other infosec news. read more [1] [1] http://risky.biz/RB380

Comments

Login or signup comment.