Artwork

Sisällön tarjoaa Host Unknown, Thom Langford, Andrew Agnes, and Javvad Malik. Host Unknown, Thom Langford, Andrew Agnes, and Javvad Malik tai sen podcast-alustan kumppani lataa ja toimittaa kaiken podcast-sisällön, mukaan lukien jaksot, grafiikat ja podcast-kuvaukset. Jos uskot jonkun käyttävän tekijänoikeudella suojattua teostasi ilman lupaasi, voit seurata tässä https://fi.player.fm/legal kuvattua prosessia.
Player FM - Podcast-sovellus
Siirry offline-tilaan Player FM avulla!

Episode 109 - The Helium Breather

55:24
 
Jaa
 

Manage episode 332509139 series 2706360
Sisällön tarjoaa Host Unknown, Thom Langford, Andrew Agnes, and Javvad Malik. Host Unknown, Thom Langford, Andrew Agnes, and Javvad Malik tai sen podcast-alustan kumppani lataa ja toimittaa kaiken podcast-sisällön, mukaan lukien jaksot, grafiikat ja podcast-kuvaukset. Jos uskot jonkun käyttävän tekijänoikeudella suojattua teostasi ilman lupaasi, voit seurata tässä https://fi.player.fm/legal kuvattua prosessia.

This week in InfoSec (12:04)

With content liberated from the “today in infosec” twitter account and further afield

24th June 1998: The NSA published the Skipjack encryption algorithm used by the Clipper chip, after the algorithm was declassified.

Clipper Chip

https://twitter.com/todayininfosec/status/1275882063753699328

24th June 2012: In the wake of the Flashback botnet which targeted Macs, Apple removed a statement from its website bragging that OS X isn't susceptible to viruses.

Apple removes claim that ‘Macs don’t get PC viruses’

https://twitter.com/todayininfosec/status/1275969494330949632

Rant of the Week (19:12)

Government employees banned from using VPNs in India

In the latest chapter of India's ongoing battle against online privacy software, government employees are now barred from using third-party VPN services.

The new directive came following the decision of some of the best VPNs to shut down their Indian servers amid privacy concerns over new data law. So far, ExpressVPN, Surfshark and NordVPN have all announced they will physically leave the country before CERT-in directives come into force on June 27.

All this was discovered because:

Indian government issues confidential infosec guidance to staff – who leak it

India's government last week issued confidential information security guidelines that calls on the 30 million plus workers it employs to adopt better work practices – and as if to prove a point, the document quickly leaked on a government website.

The document, and the measures it contains, suggest infosec could be somewhat loose across India's government sector.

"The increasing adoption and use of ICT has increased the attack surface and threat perception to government, due to lack of proper cyber security practices followed on the ground," the document opens.

Billy Big Balls of the Week (28:13)

Amazon can't channel the dead, but its deepfake voices take a close second

In the latest episode of Black Mirror, a vast megacorp sells AI software that learns to mimic the voice of a deceased woman whose husband sits weeping over a smart speaker, listening to her dulcet tones.

Only joking – it's Amazon, and this is real life. The experimental feature of the company's virtual assistant, Alexa, was announced at an Amazon conference in Las Vegas on Wednesday.

Rohit Prasad, head scientist for Alexa AI, described the tech as a means to build trust between human and machine, enabling Alexa to "make the memories last" when "so many of us have lost someone we love" during the pandemic.

In an explanatory video, Amazon showed a child asking: "Alexa, can Grandma finish reading me The Wizard of Oz?" at which point the assistant's normally artificial voice shifted gears into a softer, more natural timbre. The point being that it's supposed to convincingly sound like the kid's grandma.

Industry News (36:07)

BRATA Android Malware Group Now Classified As Advanced Persistent Threat

Former Amazon Worker Convicted of Capital One Data Breach

Google Chrome Extensions Could Be Used to Track Users Online

New DFSCoerce NTLM Relay Attack Enables Hackers to Perform Windows Domain Takeover

Cloudflare Outage Knocks Hundreds of Websites Offline

US Bank Data Breach Impacts Over 1.5 Million Customers

Euro Cops Dismantle Multimillion-Dollar Phishing Gang

Yodel Cyber Incident Disrupts UK Deliveries

Less Than Half of Organizations Have Open Source Security Policy

Cloudflare lava lamps:

https://www.cloudflare.com/en-gb/learning/ssl/lava-lamp-encryption/

Michael Reeves goldfish trading

https://youtu.be/USKD3vPD6ZA

Tweet of the Week (44:01)

https://twitter.com/InfosecEditor/status/1539992708617568261

https://twitter.com/mattjay/status/1539776073180893189

Come on! Like and bloody well subscribe!

  continue reading

192 jaksoa

Artwork
iconJaa
 
Manage episode 332509139 series 2706360
Sisällön tarjoaa Host Unknown, Thom Langford, Andrew Agnes, and Javvad Malik. Host Unknown, Thom Langford, Andrew Agnes, and Javvad Malik tai sen podcast-alustan kumppani lataa ja toimittaa kaiken podcast-sisällön, mukaan lukien jaksot, grafiikat ja podcast-kuvaukset. Jos uskot jonkun käyttävän tekijänoikeudella suojattua teostasi ilman lupaasi, voit seurata tässä https://fi.player.fm/legal kuvattua prosessia.

This week in InfoSec (12:04)

With content liberated from the “today in infosec” twitter account and further afield

24th June 1998: The NSA published the Skipjack encryption algorithm used by the Clipper chip, after the algorithm was declassified.

Clipper Chip

https://twitter.com/todayininfosec/status/1275882063753699328

24th June 2012: In the wake of the Flashback botnet which targeted Macs, Apple removed a statement from its website bragging that OS X isn't susceptible to viruses.

Apple removes claim that ‘Macs don’t get PC viruses’

https://twitter.com/todayininfosec/status/1275969494330949632

Rant of the Week (19:12)

Government employees banned from using VPNs in India

In the latest chapter of India's ongoing battle against online privacy software, government employees are now barred from using third-party VPN services.

The new directive came following the decision of some of the best VPNs to shut down their Indian servers amid privacy concerns over new data law. So far, ExpressVPN, Surfshark and NordVPN have all announced they will physically leave the country before CERT-in directives come into force on June 27.

All this was discovered because:

Indian government issues confidential infosec guidance to staff – who leak it

India's government last week issued confidential information security guidelines that calls on the 30 million plus workers it employs to adopt better work practices – and as if to prove a point, the document quickly leaked on a government website.

The document, and the measures it contains, suggest infosec could be somewhat loose across India's government sector.

"The increasing adoption and use of ICT has increased the attack surface and threat perception to government, due to lack of proper cyber security practices followed on the ground," the document opens.

Billy Big Balls of the Week (28:13)

Amazon can't channel the dead, but its deepfake voices take a close second

In the latest episode of Black Mirror, a vast megacorp sells AI software that learns to mimic the voice of a deceased woman whose husband sits weeping over a smart speaker, listening to her dulcet tones.

Only joking – it's Amazon, and this is real life. The experimental feature of the company's virtual assistant, Alexa, was announced at an Amazon conference in Las Vegas on Wednesday.

Rohit Prasad, head scientist for Alexa AI, described the tech as a means to build trust between human and machine, enabling Alexa to "make the memories last" when "so many of us have lost someone we love" during the pandemic.

In an explanatory video, Amazon showed a child asking: "Alexa, can Grandma finish reading me The Wizard of Oz?" at which point the assistant's normally artificial voice shifted gears into a softer, more natural timbre. The point being that it's supposed to convincingly sound like the kid's grandma.

Industry News (36:07)

BRATA Android Malware Group Now Classified As Advanced Persistent Threat

Former Amazon Worker Convicted of Capital One Data Breach

Google Chrome Extensions Could Be Used to Track Users Online

New DFSCoerce NTLM Relay Attack Enables Hackers to Perform Windows Domain Takeover

Cloudflare Outage Knocks Hundreds of Websites Offline

US Bank Data Breach Impacts Over 1.5 Million Customers

Euro Cops Dismantle Multimillion-Dollar Phishing Gang

Yodel Cyber Incident Disrupts UK Deliveries

Less Than Half of Organizations Have Open Source Security Policy

Cloudflare lava lamps:

https://www.cloudflare.com/en-gb/learning/ssl/lava-lamp-encryption/

Michael Reeves goldfish trading

https://youtu.be/USKD3vPD6ZA

Tweet of the Week (44:01)

https://twitter.com/InfosecEditor/status/1539992708617568261

https://twitter.com/mattjay/status/1539776073180893189

Come on! Like and bloody well subscribe!

  continue reading

192 jaksoa

Alle episoder

×
 
Loading …

Tervetuloa Player FM:n!

Player FM skannaa verkkoa löytääkseen korkealaatuisia podcasteja, joista voit nauttia juuri nyt. Se on paras podcast-sovellus ja toimii Androidilla, iPhonela, ja verkossa. Rekisteröidy sykronoidaksesi tilaukset laitteiden välillä.

 

Pikakäyttöopas