Serious About Security Podcast

The Serious about Security Podcast is brought to you by the Greater Lafayette Security Professionals (GLSP) group, Secure Purdue, and the Center for Education and Research in Information Assurance and Security (CERIAS) at Purdue University.

The views and opinions expressed in this podcast are those of the participants and do not reflect the views and opinions of Purdue University and The Center for Education and Research in Information Assurance and Security (CERIAS).

Subscribe: XML Feed Apple iTunes Podcast Page

Episodes

Episode 68: Disabling Webcam Lights and a Presidential Panel Recommends Changes for the NSA

Researchers discover a method to disable the webcam indicator light on some Apple MacBook models to surreptitiously spy on users. The President’s panel recommends some changes for the NSA.

( More... )

Episode 67: Dial 00000000 for Launch and French Government Attempts to be Google

The launch code for the US nuclear arsenal was set to 00000000 for almost 20 years. A French government ministry used an intermediate certificate authority to create a man-in-the-middle attack to pretend to be Google.

( More... )

Episode 66: Forward Secrecy and Botnet Gathered Passwords

Twitter enables Forward Secrecy for users. The Pony botnet captures a lot of passwords.

( More... )

Episode 65: Yahoo! Encrypts and Healthcare.gov Has Some Security Issues

Following the lead of Google, Yahoo! begins encrypting its fiber connections between data centers. The website for the Affordable Care Act, Healthcare,gov, has some security issues.

( More... )

Episode 64: Facebook Warns Adobe Users and IE 0-day Injects Payload into Memory

Facebook determines which users have the same password as on the compromised Adobe site and warns them. A watering hole attack uses an IE 0-day vulnerability to inject a malicious payload directly into memory.

( More... )

Episode 63: The badBIOS Controversy and the NSA taps Google and Yahoo!

BadBIOS? Is it real, imagined, or a hoax? The NSA is tapping the fiber connecting the data centers of Google and Yahoo!

( More... )

Episode 62: Steps to Avoid Internet Surveillance and Big Corp Social Engineering Fails

The EFF provides ten steps to avoid Internet surveillance. Several major corporations are owned in the DEFCON Social Engineering Capture the Flag contest.

( More... )

Episode 61: iCloud Insecurity and Avoid the Hacker Title

Apple’s iCloud and Two-Factor Authentication have some issues discovered. A dispute leads to court-ordered seizures due to use of the term “hacker”.

( More... )

Episode 60: Let’s Audit Truecrypt and Beware of Ransomware

Matthew Green looks to fund a project to audit Truecrypt in light of recent NSA revelations. Cryptolocker is some nasty ransomware.

( More... )

Episode 59: Tor Stinks According to the NSA and Microsoft Follows Yahoo!

A leaked presentation from Edward Snowden reveals that the NSA thinks that Tor stinks. Microsoft is recycling old email addresses just like Yahoo!

( More... )

Episode 58: Kids Crack iPad Security and Circle Security Avoids NIST Crytpo

Kids in the LA Unified School District break the security on school-issued iPads. Circle Security, a privacy software company, is moving away from government-approved crypto algorithms.

( More... )

Episode 57: Follow-ups on Java, Yahoo! recycling email addresses, and iPhone 5s fingerprint sensor

We review some previous subjects to see what has happened lately. We look at Oracle’s Java security issues, Yahoo! recycling email addresses, and the iPhone 5s fingerprint sensor.

( More... )

Episode 56: Apple’s iPhone 5S has a fingerprint reader

Apple’s iPhone 5S includes a fingerprint reader in the home button.

( More... )

Episode 55: The NSA allegedly weakens and attacks cryptography

Through revelations from Edward Snowden, the National Security Agency (NSA) has intentionally weakened cryptography products, acquired private keys, and built systems to brute force attack encrypted data.

( More... )

Episode 54: Password Complexity and Apple Products Have Trouble with Six Arabic Characters

We have a discussion on password complexity, length, and the applications that use passwords. Apple Mac OS X and iOS have a bug in CoreText that causes crashes with a specific Arabic text string of six characters.

( More... )

Episode 53: US Email Providers Close and Facebook Founder’s TImeline Hacked

Two US-based email providers close their doors or shut their email services due to issues with the NSA and the PATRIOT Act. A security researcher convinces Facebook’s security team that he found a bug by publicly exploiting the problem on Mark Zuckerberg’s TImeline.

( More... )

Episode 52: Blackhat and DEFCON Review

We look at some interesting revelations from Blackhat and DEFCON.

( More... )

Episode 51: The Feds Hate Criminals using Tor and The Twitter Two-Step (Auth)

The FBI may used malware to attack Tor to find criminals. Twitter has overhauled its two-factor authentication system.

( More... )

Episode 50: Data Breaches Galore!

We take a look at a variety of security breaches in the news lately.

( More... )

Episode 49: Apple Developer Site Hacked and Tumblr iOS Shared Their Passwords!

The Apple Developer web site was hacked by one of its own developers. Tumblr for iOS had a security issue that exposed user passwords.

( More... )

Episode 48: Android App Packaging has a Hole and There’s Big Business in Exploits

A vulnerability is discovered in the Android package contents verification. Trading in 0-day exploits is big business.

( More... )

Episode 47: Club Nintendo has Hacked Accounts and the Emergency Alert System has a flaw

Club Nintendo has more than 15m password guessing attempts and almost 24k account compromised. One type of system in the Emergency Alert System has known SSH private key for root.

( More... )

Episode 46: Privacy Tools!

We talked about a variety of privacy tools available to avoid NSA monitoring.

( More... )

Episode 45: Facebook leaks and Microsoft pays out!

Facebook reports on a bug that leaked private information on 6 million users. Microsoft starts a bug bounty program with some sizable payouts.

( More... )

Episode 44: Yahoo! to kick out deadbeat users and the FDA offers medical device guidance

Yahoo! has decided to clean up and release old, unused accounts. The Food and Drug Administration is providing security guidance for medical devices.

( More... )