Episode 356: The Concern with Containers




TechSNAP show

Summary: <p>The problems containers can’t solve, nasty security flaws in Skype and Telegram, and Cisco discovers they have a bigger issue on their hands then first realized. </p> <p>And the latest jaw-dropping techniques to extract data from air-gapped systems.</p><p>Sponsored By:</p><ul> <li> <a rel="nofollow" href="http://techsnap.ting.com">Ting</a>: <a rel="nofollow" href="http://techsnap.ting.com">Save $25 off a device, or get $25 in service credits!</a> Promo Code: Visit techsnap.ting.com</li> <li> <a rel="nofollow" href="https://do.co/snap">Digital Ocean</a>: <a rel="nofollow" href="https://do.co/snap">Apply our promo snapocean after you create your account, and get a $10 credit.</a> Promo Code: snapocean</li> <li> <a rel="nofollow" href="http://ixsystems.com/techsnap">iXSystems</a>: <a rel="nofollow" href="http://ixsystems.com/techsnap">Get a system purpose built for you.</a> Promo Code: Tell them we sent you!</li> </ul><p>Links:</p><ul> <li> <a title="Skype can't fix a nasty security bug without a massive code rewrite" rel="nofollow" href="http://www.zdnet.com/article/skype-cannot-fix-security-bug-without-a-massive-code-rewrite/">Skype can't fix a nasty security bug without a massive code rewrite</a> — The bug grants a low-level user access to every corner of the operating system.</li> <li> <a title="Zero-day vulnerability in Telegram" rel="nofollow" href="https://securelist.com/zero-day-vulnerability-in-telegram/83800/">Zero-day vulnerability in Telegram</a> — The special nonprinting right-to-left override (RLO) character is used to reverse the order of the characters that come after that character in the string. In the Unicode character table, it is represented as ‘U+202E’; one area of legitimate use is when typing Arabic text. In an attack, this character can be used to mislead the victim. It is usually used when displaying the name and extension of an executable file: a piece of software vulnerable to this sort of attack will display the filename incompletely or in reverse.</li> <li> <a title="Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability" rel="nofollow" href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1?source=infected.io-telegram">Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability</a> — After further investigation, Cisco has identified additional attack vectors and features that are affected by this vulnerability. In addition, it was also found that the original fix was incomplete so new fixed code versions are now available. </li> <li> <a title="Microsoft To Embrace Decentralized Identity Systems Built On Bitcoin And Other Blockchains" rel="nofollow" href="https://www.forbes.com/sites/ktorpey/2018/02/12/microsoft-to-embrace-decentralized-identity-systems-built-on-bitcoin-and-other-blockchains/#76af78a45ada">Microsoft To Embrace Decentralized Identity Systems Built On Bitcoin And Other Blockchains</a> — In a new post today, Microsoft announced their embrace of public blockchains, such as Bitcoin and Ethereum, for use in decentralized identity systems.</li> <li> <a title="XRballer comments on The Stolen XRB has already been Redistributed/Sold Off" rel="nofollow" href="https://www.reddit.com/r/CryptoCurrency/comments/7wonkf/the_stolen_xrb_has_already_been_redistributedsold/du215tr/">XRballer comments on The Stolen XRB has already been Redistributed/Sold Off</a> — But this check was only on java-script client side, you find the js which is sending the request, then you inspect element - console, and run the java-script manually, to send a request for withdrawal of a higher amount than in your balance.</li> <li> <a title="Containers Will Not Fix Your Broken Culture" rel="nofollow" href="https://queue.acm.org/detail.cfm?id=3185224">Containers Will Not Fix Your Broken Culture</a> — Spoiler alert: the solutions to many difficulties that seem technical can be found by examining our interactions with others. Let's talk about five things you'll want to know when working with those pesky creatures known as humans.</li> <li> <a title="Escaping Sensitive Data from Faraday-Caged, Air-Gapped Computers via Magnetic Fields" rel="nofollow" href="https://arxiv.org/abs/1802.02700">Escaping Sensitive Data from Faraday-Caged, Air-Gapped Computers via Magnetic Fields</a> — In this paper, we show how attackers can bypass Faraday cages and air-gaps in order to leak data from highly secure computers. </li> <li><a title="Feedback: BeyondCorp" rel="nofollow" href="http://pastedown.ctrl-c.us/#RP5t3LFg3gLPAoBi70ua6IyQJGo.markdown">Feedback: BeyondCorp</a></li> <li><a title="Feedback: Mgmt" rel="nofollow" href="http://pastedown.ctrl-c.us/#2jhTp3-geBThElev10Bg9oFRHm4.markdown">Feedback: Mgmt</a></li> <li><a title="Feedback: SuperMicro Mobo?" rel="nofollow" href="http://pastedown.ctrl-c.us/#U4lx-Ttdf1fcuRyMeWoF6JKsNVo.markdown">Feedback: SuperMicro Mobo?</a></li> <li><a title="Super Micro Computer X8DTN+" rel="nofollow" href="https://www.supermicro.com/products/motherboard/QPI/5500/X8DTN_.cfm?IPMI=O">Super Micro Computer X8DTN+</a></li> </ul>