Our weekly audio security column
& podcast by Steve Gibson and Leo Laporte
TechTV's Leo Laporte and I take 30 to 90 minutes near the end of each week to discuss important issues of personal computer security. Sometimes we'll discuss something that just happened. Sometimes we'll talk about long-standing problems, concerns, or solutions. Either way, every week we endeavor to produce something interesting and important for every personal computer user.

 You may download and listen to selected episodes from this page (see below), or subscribe to the ongoing series as an RSS "podcast" to have them automatically downloaded to you as they are produced. To subscribe, use whichever service you prefer . . .

 Receive an automatic eMail reminder whenever a new episode is posted here (from ChangeDetection.com). See the section at the bottom of this page.

 Send us your feedback: Use the form at the bottom of the page to share your opinions, thoughts, ideas, and suggestions for future episodes.

 Leo also produces "This Week in Tech" (TWiT) and a number of other very popular podcasts (TWiT is America's most listened to podcast!) So if you are looking for more informed technology talk, be sure to check out Leo's other podcasts and mp3 files.

 And a huge thanks to AOL Radio for hosting the high-quality MP3 files and providing the bandwidth to make this series possible. We use "local links" to count downloads, but all of the high-quality full-size MP3 files are being served by AOL Radio.

Episode Archive

Each episode has SIX resources:

High quality 64 kbps mp3 audio file
Quarter size, bandwidth-conserving,
16 kbps (lower quality) mp3 audio file
A web page with any supplementary notes
A web page text transcript of the episode
A simple text transcript of the episode
Ready-to-print PDF (Acrobat) transcript  

(Note that the text transcripts will appear a few hours later
than the audio files since they are created afterwards.)

For best results: RIGHT-CLICK on one of the two audio icons & below then choose "Save Target As..." to download the audio file to your computer before starting to listen. For the other resources you can either LEFT-CLICK to open in your browser or RIGHT-CLICK to save the resource to your computer.

Episode #642 | 19 Dec 2017 | 120 min.

This week we examine how Estonia handled the Infineon crypto bug; two additional consequences of the pressure to maliciously mine cryptocurrency; zero-day exploits in the popular vBulletin forum system; Mozilla in the doghouse over “Mr. Robot”; Win10’s insecure password manager mistake; when legacy protocol come back to bite us; how to bulk-steal any Chrome user’s entire stored password vault; and we finally know where and why the uber-potent Mirai botnet was created, and by whom.  We also have a bit of errata and some fun miscellany. Then we’re going to take a look at BGP, another creaky yet crucial – and vulnerable – protocol that glues the global Internet together.
58 MB 14 MB  186 KB   <-- Show Notes 124 KB 85 KB 154 KB

Episode #641 | 12 Dec 2017 | 125 min.
The iOS 11 Security Tradeoff

This week we discuss the details behind the “USB/JTAG takeover” of Intel’s Management Engine, a rare Project Zero discovery, Microsoft’s well-meaning but ill-tested IoT security project, troubles with EV certs, various cryptocurrency woes, a clever DNS spoofing detection system, a terrific guide to setting up the EdgeRouter X for network segmentation, last week’s emergency out-of-cycle patch from Microsoft, a mitigated vulnerability in Apple’s HomeKit, Valve’s ending of Bitcoin for Steam purchases, finally some REALLY GOOD news in the elusive quest for encrypted email, a bit of miscellany, some closing-the-loop feedback with our listeners, and a look at the security sacrifice Apple made in the name of convenience and what it means.
59 MB 15 MB  196 KB   <-- Show Notes 134 KB 93 KB 166 KB

Episode #640 | 05 Dec 2017 | 104 min.
More News & Feedback

This week we discuss the long-awaited end of StartCom & StartSSL, inside last week’s macOS passwordless root account access and problems with Apple’s patches, the question of Apple allowing 3D facial data access to apps, Facebook’s new and controversial use of camera images, in-the-wild exploitation of one of last month’s patched Windows vulnerabilities, an annoying evolution in browser-based cryptocurrency mining, exploitation of Unicode in email headers, Google’s advancing protection for Android users, a terrific list of authentication dongle-supporting sites and services, Mirai finds another 100,000 exposed ZyXEL routers, Google moves to reduce system crashes, a bit of miscellany including another security-related Humble Bundle offering, and some closing-the-loop feedback from our terrific listeners.
50 MB 12 MB  304 KB   <-- Show Notes 129 KB 78 KB 147 KB

Episode #639 | 28 Nov 2017 | 129 min.
News & Feedback

This week we discuss a new bad bug found in the majority of SMTP mailing agents, 54 high-end HP printers found to be remotely exploitable, more than 3/4ths of 433,000 websites are using vulnerable JavaScript libraries, horrible free security software, some additional welcome Firefox news, a bit of errata, some fun miscellany, and a BUNCH of feedback from our listeners including reactions to last week's Quad 9 recommendation.
62 MB 15 MB  459 KB   <-- Show Notes 134 KB 102 KB 178 KB

Episode #638 | 21 Nov 2017 | 93 min.
Quad Nine

This week we discuss Windows having a birthday, Net Neutrality about to succumb to big business despite a valiant battle, Intel's response to the horrifying JTAG over USB discovery, another surprising AWS public bucket discovery, Android phones caught sending position data when all permissions are denied, many websites found to be watching their visitors' actions, more Infineon ID card upset, the return of BlueBorne, a new arrival to our "Well, THAT didn't take long" department, speedy news for Firefox 57, some miscellany, listener feedback, and a look at the very appealing and speedy new "Quad 9" alternative DNS service.
44 MB 11 MB  360 KB   <-- Show Notes 107 KB 70 KB 130 KB

Episode #637 | 14 Nov 2017 | 131 min.
Schneier on Equifax

This week we discuss why Steve won’t be relying upon Face ID for security, a clever new hack of longstanding NTFS and Windows behavior, the Vault 8 WikiLeaks news, the predictable resurgence of the consumer device encryption battle, a new and clever data exfiltration technique, new antimalware features coming to Chrome, an unbelievable discovery about access to the IME in Skylake and subsequent Intel chipsets, a look at who’s doing the unauthorized crypto mining, WebAssembly is ready for primetime, a bit of miscellany, some closing-the-loop feedback with our listeners – and then we share Bruce Schneier’s congressional testimony about the Equifax breach.
62 MB 16 MB  389 KB   <-- Show Notes 144 KB 97 KB 174 KB

Episode #636 | 07 Nov 2017 | 97 min.

This week we discuss the inevitable dilution in the value of code signing, a new worrisome cross-site privacy leakage, is Unix embedded in all our motherboards?, the ongoing application spoofing problem, a critical IP address leakage vulnerability in TOR and the pending major v3 upgrade to TOR, a Signal app for ALL our desktops, an embarrassing and revealing glitch in Google Docs, bad behavior by an audio driver installer, a pending RFC for IoT updating, two reactions to Win10 Controlled Folder Access, a bit of miscellany, some closing the loop with our listeners, and, three weeks after the initial ROCA disclosure I'm reminded of two lines from the movie "Serenity" -- Assassin:"It's worse than you know." Mal:"It usually is."
46 MB 12 MB  294 KB   <-- Show Notes 126 KB 75 KB 140 KB

Episode #635 | 31 Oct 2017 | 127 min.
Reaper Redux

This week we examine the source of WannaCry, a new privacy feature for Firefox, Google's planned removal of HPKP, the idea of visual objects as a second factor, an iOS camera privacy concern, the CAPTCHA wars, a horrifying glimpse into a non-Net Neutrality world, the Coinhive DNS hijack, the new Bad Rabbit cryptomalware, a Win10 anti-cryptomalware security tip, spying vacuum cleaners, a new Amazon service, some loopback Q&A with our listeners, and another look at the Reaper botnet.
61 MB 15 MB  477 KB   <-- Show Notes 148 KB 95 KB 172 KB

Episode #634 | 24 Oct 2017 | 123 min.
IoT Flash Botnets

This week we discuss some ROCA fallout specifics, an example of PRNG misuse, the Kaspersky Lab controversy, a DNS security initiative for Android, another compromised download occurrence, a browser-based cryptocurrency miner for us to play with... and Google considering blocking them natively, other new protections coming to Chrome, an update on Marcus Hutchins, Microsoft's "TruePlay" being added to the Win10 fall creators update, some interesting "Loopback" from our terrific listeners... and then we take a closer look at the rapidly growing threat of IoT-based "Flash Botnets."
59 MB 15 MB  317 KB   <-- Show Notes 147 KB 92 KB 168 KB

Episode #633 | 17 Oct 2017 | 120 min.

This week we examine ROCA's easily factorable public keys, the surprising prevalence of web-based cryptocurrency mining, some interesting work in iOS dialog password dialog spoofing, Google's Advanced Protection Program, some good "Loopback" comments from our listeners... and then we take a close look at KRACK - the Key Reinstallation AttaCK against ALL unpatched WiFi systems.
57 MB 14 MB  577 KB   <-- Show Notes 166 KB 93 KB 171 KB

Episode #632 | 10 Oct 2017 | 109 min.
The DNSSEC Challenge

This week we take a look at a well-handled breach-response at Discus, a rather horrifying mistake Apple made in the implementation of their APFS encryption (and the difficulty to the user of fully cleaning up after it), the famous "robots.txt" file gets a brilliant new companion, somewhat shocking news about Windows XP... or is it?, Firefox EOL for Windows XP support coming next summer, the sage security thought for the day, an update on "The Orville", some closing the loop comments, including a recommendation of the best Security Now series we did in the past... and finally, a look at the challenge of DNSSEC.
52 MB 13 MB  340 KB   <-- Show Notes 129 KB 81 KB 151 KB

Episode #631 | 03 Oct 2017 | 120 min.
Private Contact Discovery

This week we discuss some aspects of iOS v11, the emergence of browser hijack cryptocurrency mining, new information about the Equifax hack, Google security research and Gmail improvements, breaking DKIM without breaking it, concerns over many servers in small routers and aging unpatched motherboard EFI firmware, a new privacy leakage bug in IE, a bit of miscellany, some long-awaited closing-the-loop feedback from our listeners, and a close look into a beautiful piece of work by Moxie & Co. on Signal.
59 MB 14 MB  269 KB   <-- Show Notes 135 KB 89 KB 161 KB

Episode #630 | 25 Sep 2017 | ??? min.
The Great DOM Fuzz-Off

This week, Father Robert and I follow more Equifax breach fallout, look at encryption standards blowback from the Edward Snowden revelations, examine more worrisome news of the CCleaner breach, see that ISPs may be deliberately infecting their own customers, warn that turning off iOS radios doesn't, look at the first news of the FTC's suit against D-Link's poor security, examine a forthcoming Broadcom GPS chip features, warn of the hidden dangers of high-density barcodes, discuss Adobe's disclosure of their own private key, close the loop with our listeners, and examine the results of DOM fuzzing at Google's Project Zero.
57 MB 14 MB  267 KB   <-- Show Notes 123 KB 98 KB 169 KB

Episode #629 | 19 Sep 2017 | 120 min.
Apple Bakes Cookies

This week Padre and I discuss what was up with SN's recent audio troubles, more on the Equifax fiasco, the EFF and Cory Doctorow weigh in on forthcoming browser-encrypted media extensions (EME), an emerging browser-based payment standard, when two-factor is not two-factor, the CCleaner breach and what it means, a new Bluetooth-based attack, an incredibly welcome and brilliant cookie privacy feature in iOS 11, and a heads-up caution about the volatility of Google's Android smartphone cloud backups.
57 MB 14 MB  249 KB   <-- Show Notes 126 KB 101 KB 172 KB

Episode #628 | 12 Sep 2017 | 108 min.
The Equifax Fiasco

This week we discuss last Friday's passing of our dear friend and colleague Jerry Pournelle, when AI is turned to evil purpose, whether and when Google's Chrome browser will warn of man in the middle attacks, why Google is apparently attempting to patent pieces of a compression technology they did not invent, another horrifying router vulnerability disclosure -- including ten 0-day vulnerabilities, an update on the sunsetting of Symantec's CA business unit, another worrying failure at Comodo, a few quick bits, an update on my one commercial product SpinRite, answering a closing the loop question from a listener, and a look at the Equifax fiasco.
52 MB 13 MB  326 KB   <-- Show Notes 114 KB 83 KB 148 KB

Episode #627 | 05 Sep 2017 | 119 min.

Although there are an unbelievable FIVE “Sharknado” movies, this will be the first and last time we use that title for a podcast! This week we have another update on Marcus Hutchins. We discuss the validity of WikiLeaks documents, the feasibility of rigorously proving software correctness, and the fact that nearly half a million people need to get their bodies' firmware updated. Another controversial CIA project is exposed by WikiLeaks. A careful analysis is done of the FCC's Title II Net Neutrality public comments. We talk about a neat two-factor auth tracking site, the Stupid Patent of the Month, an example of a vanity top-level domain, a bit of errata, and finish up with the utterly unconscionable security mistakes made by AT&T in their line of U-Verse routers.
56 MB 14 MB  359 KB   <-- Show Notes 143 KB 95 KB 172 KB

Episode #626 | 29 Aug 2017 | 120 min.
Shattering Trust

This week we cover a bit of the ongoing drama surrounding Marcus Hutchins, examine a reported instance of interagency hacking, follow the evolving market for 0-day exploits, examine trouble arising from the continued use of a deprecated Apple security API, discover that Intel's controversial platform management engine CAN, after all be disabled, look into another SMS attack, bring note to a nice looking TOTP authenticator, recommend an alternative to the shutting-down CrashPlan, deal with a bit of errata and miscellany, then we look into an interesting bit of research which invokes "The Wrath of Kahn".
58 MB 14 MB  327 KB   <-- Show Notes 136 KB 93 KB 167 KB

Episode #625 | 22 Aug 2017 | 129 min.
Security Politics

This week we discuss the continuing Marcus Hutchins drama, the disclosure of a potentially important Apple secret, a super-cool website and browser extension our listeners are going to appreciate, trouble with extension developers being targeted, a problem with the communication bus standard in every car, an important correction from Elcomsoft, two 0-days in Foxit's PDF products, Lavalamps for entropy, the forthcoming iOS 11 TouchID killswitch, very welcome Libsodium audit results, a mistake in AWS permissions, a refreshingly forthright security statement, a bit of errata, miscellany, and a few closing the loop bits from our terrific listeners!
61 MB 15 MB  475 KB   <-- Show Notes 156 KB 99 KB 180 KB

Episode #624 | 15 Aug 2017 | 123 min.
Twelve and Counting

This week we have a Marcus Hutchins update, the backstory on the NIST's rewrite of their 15 year old password guidance, can DNA be used to hack a computer?, can stop sign graffiti be used to misdirect autonomous vehicles?, the final nail in the WoSign/StartCom coffin, why we need global Internet policy treaties, this week in "researchers need protection", a VPN provider who is doing everything right, Elcomsoft's password manager cracker, a bit of errata and miscellany... and some closing the loop feedback from this podcast's terrific listeners.
58 MB 15 MB  219 KB   <-- Show Notes 121 KB 89 KB 157 KB

Episode #623 | 08 Aug 2017 | 125 min.
Inching Forward

This week we discuss and look into DigiCert's acquisition of Symantec's certificate authority business unit, LogMeIn's LastPass Premium price hike, the troubling case of Marcus Hutchins' post-Defcon arrest, another instance of WannaCry-style SMBv1 propagation, this week's horrific IoT example, some hopeful IoT legislation, the consequences of rooting early Amazon Echoes, the drip drip drip of Wikileaks Vault 7 drips again, Mozilla's VERY interesting easy-to-use secure large file encrypted store and forward service, the need to know what your VPN service is really up to, a bit of errata, miscellany, and some closing-the-loop feedback from our always-attentive terrific listeners.
59 MB 15 MB  219 KB   <-- Show Notes 139 KB 91 KB 163 KB

Episode #622 | 01 Aug 2017 | 102 min.
Hack the Vote

This week we look at the expected DEF CON fallout including the hacking of U.S. election voting machines, Microsoft’s enhanced Bug Bounty Program, the wormification of the Broadcom WiFi firmware flaw, the worries when autonomous AI agents begin speaking in their own language which we cannot understand, Apple’s pulling VPN clients from its Chinese App Store, a follow-up on iRobot’s floor plan mapping intentions, some news on the Chrome browser front, the 18th Vault 7 WikiLeaks dump, and some closing-the-loop feedback from our terrific podcast followers.
48 MB 12 MB  177 KB   <-- Show Notes 119 KB 76 KB 144 KB

Episode #621 | 25 Jul 2017 | 123 min.
Crypto Tension

We start off this week with a fabulous Picture of the Week and, for the first time in this podcast’s 12-year history, our first Quote of the Week. Then we’ll be discussing the chilling effects of arresting ethical hackers, the upcoming neutrality debate congressional hearing, something troubling I encountered at McAfee.com, an entirely new IoT nightmare you couldn’t have seen coming and just won’t believe, the long-awaited Adobe Flash end-of-life schedule, welcome performance news for Firefox users, the FCC allocates new sensor spectrum for self-driving cars, three bits of follow-up errata, a bit of miscellany, and then Crypto Tension – a careful look at the presently ongoing controversy surrounding the deliberate provisioning of passive eavesdropping decryption being seriously considered for inclusion in the forthcoming TLS v1.3 standard.
59 MB 15 MB  263 KB   <-- Show Notes 166 KB 98 KB 179 KB

Episode #620 | 18 Jul 2017 | 104 min.
Calm Before the Storm

This week, while waiting for news from the upcoming BlackHat & DefCon conventions, we discuss another terrific security eBook bundle offer, a Net Neutrality follow-up, a MySpace account recovery surprise, another new feature coming to Win10, the wrong-headedness of paste-blocking web forms, Australia versus the laws of math, does an implanted pacemaker meet the self-incrimination exemption?, an updated worse-case crypto-future model, it's surprising what you can find at a flea market, another example of the consumer as the product, a SQRL technology update, and some closing-the-loop feedback from our terrific listeners.
49 MB 12 MB  250 KB   <-- Show Notes 119 KB 80 KB 149 KB

Episode #619 | 11 Jul 2017 | 113 min.
All the Usual Suspects

This week we have all the usual suspects: governments regulating their citizenry, evolving Internet standards, some brilliant new attack mitigations and some new side-channel attacks, browsers responding to negligent certificate authorities, specious tracking lawsuits, flying device jailbreaking, more IoT tomfoolery, this week’s horrifying Android vulnerability, more Vault 7 CIA WikiLeaks, a great tip about controlling the Internet through DNS – and even more! In other words, all of the usual suspects! (And two weeks until our annual Black Hat exploit extravaganza!)
54 MB 14 MB  292 KB   <-- Show Notes 116 KB 78 KB 143 KB

Episode #618 | 27 Jun 2017 | 113 min.
Research: Useful & Otherwise

This week we discuss another terrific NIST initiative, RSA crypto in a quantum computing world, Cisco's specious malware detection claims, the meaning of post-audit OpenVPN bug findings, worrisome bugs revealed in Intel's recent Skylake and Kaby Lake processors, the commercialization of a malware technique, WannaCry keeps resurfacing, Linksys responds to the CIA's Vault 7 CherryBomb firmware, another government reacts to encryption, the NSA's amazing GitHub repository, more news about HP printer auto-updating, a piece of errata, some miscellany, and some closing-the-loop feedback from our listeners.
54 MB 14 MB  257 KB   <-- Show Notes 122 KB 86 KB 154 KB

Episode #617 | 20 Jun 2017 | 113 min.
When Governments React

This week we discuss France, Britain, Japan, Germany & Russia each veering around in their Crypto Crash Cars, Wikileaks' Vault7 reveals widespread CIA WiFi router penetration, why we can no longer travel with laptops, HP printer security insanity, how long are typical passwords?, Microsoft to kill off SMBv1, the all-time mega ransomware pay out, Google to get into the whole-system backup business, hacking PCs with "Vape Pens", a bit of miscellany, and a bunch of Closing the Loop feedback with our terrific listeners.
54 MB 14 MB  365 KB   <-- Show Notes 153 KB 88 KB 165 KB

Episode #616 | 13 Jun 2017 | 124 min.
Things Are Getting Worse

This week we discuss clever malware hiding its social media communications. The NSA documents the Russian election hacking two-factor authentication bypass; meanwhile, other Russian attackers leverage Google’s own infrastructure to hide their spoofing. Tavis finds more problems in Microsoft’s anti-malware protection; a cryptocurrency stealing malware; more concerns over widespread Internet-connected camera design; malware found to be exploiting Intel’s AMT motherboard features; the new danger of mouse-cursor hovering; Apple’s iCloud sync security claims; Azure changes their CA; a bunch of catch-up miscellany; and a bit of “closing the loop” feedback from our listeners.
60 MB 15 MB 484 KB   <-- Show Notes 125 KB 97 KB 169 KB

Episode #615 | 06 Jun 2017 | 119 min.
Legacy’s Long Tail

This week we discuss an embarrassing high-profile breach of an online identity company, an overhyped problem found in Linux’s sudo command, the frightening software used by the U.K.’s Trident nuclear missile submarine launch platforms, how emerging nations prevent high school test cheating, another lesson about the danger of SMS authentication codes, another worrisome Shodan search result, high-penetration dangerous adware from a Chinese marketer, another “that’s not a bug” bug in Chrome allowing websites to surreptitiously record audio and video without the user’s knowledge, the foreseeable evolution of hybrid cryptomalware, the limp return of Google Contributor, Google continues to work on end-to-end email encryption, a follow-up on straight-to-voicemail policy, “homomorphic encryption” (what the heck is that?), and “closing the loop” follow-up from recent discussions.
57 MB 14 MB 251 KB   <-- Show Notes 115 KB 93 KB 161 KB

Episode #614 | 30 May 2017 | 123 min.
Vulnerabilities Galore!

This week we discuss a new non-email medium for spearphishing, Chipotle can’t catch a break, social engineering WannaCry exploits on Android, video subtitling now able to takeover our machines, a serious Android UI design flaw that Google appears to be stubbornly refusing to address, Linux gets its own version of WannaCry, another dangerous NSA exploit remains unpatched and publicly exploitable on WinXP and Server 2003 machines, a look at 1Password’s brilliant and perfect new Travel Mode, Google extends its ad tracking into the offline world, some follow-ups, miscellany, and closing-the-loop feedback from our terrific listeners – concluding with my possibly useful analogy to explain the somewhat confusing value of open versus closed source.
58 MB 15 MB 212 KB   <-- Show Notes 137 KB 93 KB 168 KB

Episode #613 | 23 May 2017 | 129 min.
WannaCry Aftermath

This week we examine a bunch of WannaCry follow-ups, including some new background, reports of abilities to decrypt drives, attacks on the kill switch, and more. We also look at what the large Stack Overflow site had to do to do HTTPS, the WiFi security of various properties owned by the U.S. President, more worrisome news coming from the U.K.'s Theresa May, the still sorry state of certificate revocation, are SSDs also subject to Rowhammer-like attacks, some miscellany, and closing the loop with our listeners.
62 MB 16 MB 453 KB   <-- Show Notes 128 KB 92 KB 159 KB

Episode #612 | 16 May 2017 | 116 min.
Makes You WannaCry

This week Steve and Leo discuss an update on the FCC's Net Neutrality comments, the discovery of an active keystroke logger on dozens of HP computer models, the continuing loss of web browser platform heterogeneity, the OSTIF's just-completed OpenVPN security and practices audit, more on the dangers of using smartphones as authentication tokens, some extremely welcome news on the Android security front, long-awaited updated password recommendations from NIST, some follow-up errata, a bit of tech humor and miscellany, closing the loop with some listener feedback, and then a look at last week's global explosion of the WannaCry worm.
55 MB 14 MB 185 KB   <-- Show Notes 135 KB 88 KB 158 KB

Episode #611 | 09 May 2017 | 131 min.
Go FCC Yourself

This week Steve and Leo discuss much more about the Intel AMT nightmare, Tavis and Natalie discover a serious problem in Microsoft's built-in malware scanning technology, Patch Tuesday, Google's Android patches, SMS two-factor authentication breached, Google goes phishing, the emergence of ultrasonic device tracking, lots of additional privacy news, some errata and miscellany, actions U.S. citizens can take to express their dismay over recent Net Neutrality legislation, and some quick closing-the-loop feedback from our terrific listeners.
62 MB 16 MB 574 KB   <-- Show Notes 145 KB 95 KB 170 KB

Episode #610 | 02 May 2017 | 137 min.
Intel's Mismanagement Engine

This week Steve and Leo discuss the long-expected remote vulnerability in Intel's super-secret motherboard Management Engine technology, exploitable open ports in Android apps, another IoT blows a suspect's timeline, newly discovered problems in the Ghostscript interpreter, yet another way for ISPs and others to see where we go, a new bad problem in the Edge browser, Chrome changes its certificate policy, an interesting new "vigilante botnet" is growing fast, a proposed solution to smartphone-distracted driving, ransomware as a service, Net Neutrality heads back to the chopping block (again), an intriguing new service from Cloudflare, and the ongoing Symantec certificate issuance controversy. Then some fun errata, miscellany, and some "closing the loop" feedback from our terrific listeners.
66 MB 16 MB 208 KB   <-- Show Notes 147 KB 100 KB 173 KB

Episode #609 | 25 Apr 2017 | 107 min.
The Double Pulsar

This week Steve and Leo discuss how one of the NSA's Vault7 vulnerabilities has gotten loose, a clever hacker removes Microsoft deliberate (and apparently unnecessary) block on Win7/8.1 updates for newer processors, Microsoft refactors multifactor authentication, Google to add native ad-blocking to Chrome… and what exactly *are* abusive ads?, Mastercard to build a questionable fingerprint sensor into their cards, are Bose headphones spying on their listeners?, 10 worrisome security holes discovered in Linksys routers, MIT cashes out half of its IPv4 space, and the return of two meaner BrickerBots. Then some Errata, a bit of Miscellany, and, time permitting, some "Closing the Loop" feedback from our podcast's terrific listeners.
51 MB 13 MB 270 KB   <-- Show Notes 129 KB 82 KB 151 KB

Episode #608 | 18 Apr 2017 | 127 min.
News & Feedback Potpourri

This week Steve and Leo discuss another new side-channel attack on smartphone PIN entry (and much more), Smartphone fingerprint readers turn out to be far more spoofable that we had hoped. All Linux kernels prior to v4.5 are vulnerable to a serious remote network attack over UDP, a way to prevent Google from tracking the search links we click (and to allow us to copy the links from the search results), the latest NSA Vault7 data dump nightmare, the problem with punycode domains, four years after the public UPnP router exposure, looking closely at the mixed blessing of hiding WiFi access point SSID broadcasts, some miscellany, and then a collection of quick "Closing The Loop" follow-ups from last week's "Proactive Privacy" podcast.
61 MB 15 MB 265 KB   <-- Show Notes 122 KB 90 KB 155 KB

Episode #607 | 11 Apr 2017 | 139 min.
Proactive Privacy  (Really, this time!)

This week Steve and Leo discuss Symantec finding 40 past attacks explained by the Vault 7 document leaks, an incremental improvement coming to CA certificate issuance, and Microsoft’s patching of a zero-day Office vulnerability that was being exploited in the wild. They ask, “What’s a Brickerbot?” They cover why you need a secure DNS registrar, This Week in IoT Tantrums, a headshaker from our “You really can’t make this stuff up” department, the present danger of fake VPN services, and an older edition of Windows reaching end of patch life. They continue with some “closing the loop” feedback from their listeners and a bit of miscellany, then close with a comprehensive survey of privacy-encroaching technologies and what can be done to limit their grasp.
67 MB 17 MB 225 KB   <-- Show Notes 150 KB 102 KB 178 KB

Episode #606 | 04 Apr 2017 | 115 min.
Proactive Privacy

This week Steve and Leo discuss another iOS update update, more bad news and some good news on the IoT front, the readout on Tavis Ormandy's shower revelation, more worrisome anti-encryption saber rattling from the EU, a look at a recent Edward Snowden tweet, Samsung's S8 mistake, an questionable approach to online privacy, celebrating the 40th anniversary of Alice and Bob, some quickie feedback loops from our listeners, an update on my projects, and a comprehensive examination of proactive steps users can take to enhance their online privacy.
54 MB 14 MB 210 KB   <-- Show Notes 148 KB 87 KB 160 KB

Episode #605 | 28 Mar 2017 | 142 min.
Google -vs- Symantec

This week Jason and I discuss Google’s Tavis Ormandy taking an inspiration shower, iOS gets a massive feature and security update, a new target for ‘Bot money harvesting appears, Microsoft suffers a rather significant user-privacy fail, the UK increases its communications decryption rhetoric, a worrisome vote in the US senate, NEST fails to respond to a researcher's report, this week in IoT nonsense, a fun quote of the week, a bit of miscellany, some quickie questions from our listeners, and a close look at the developing drama surrounding Google's enforcement of the Certificate Authority Baseline rules with Symantec.
68 MB 17 MB 416 KB   <-- Show Notes 123 KB 106 KB 175 KB

Episode #604 | 21 Mar 2017 | 117 min.
Taming Web Ads

This week Leo and I discuss developments in the New Windows on Old Hardware front, Cisco finds a surprise in the Vault 7 docs, Ubiquiti was caught with their PHPs down, Check Point discovered problems in WhatsApp and Telegram, some interesting details about the long-running Yahoo breaches, the death of the “eBay Football,” the latest amazing IoT insanity, the incredible results of the CanSecWest Pwn2Own competition, a classic “you’re doing it wrong” example, Tavis pokes LastPass again, some miscellany, and an interesting proposal about controlling web advertising abuse.
56 MB 14 MB 248 KB   <-- Show Notes 126 KB 85 KB 153 KB

Episode #603 | 14 Mar 2017 | 108 min.
Vault 7

This week Leo and I discuss March's long-awaited patch Tuesday, the release deployment of Google Invisible reCaptcha, getting more than you bargained for with a new Android smartphone, the new "Find my iPhone" phishing campaign, the failure of WiFi anti-tracking, a nasty and significant new hard-to-fix web server 0-day vulnerability, what if your ISP decides to unilaterally block a service you depend upon?, shining some much-needed light onto a poorly conceived end-to-end messaging application, two quick takes, a bit of errata and miscellany... and a look into what Wikileaks revealed about the CIA's data collection capabilities and practices.
51 MB 13 MB 176 KB   <-- Show Notes 131 KB 83 KB 153 KB

Episode #602 | 07 Mar 2017 | 138 min.
Let's Spoof

This week, Leo and I discuss the countdown to March’s Patch Tuesday. What was behind Amazon’s S3 outage? Why don’t I have a cellular connectivity backup? We share some additional Cloudflare perspective. Amazon will fight another day over their Voice Assistant’s privacy. An examination of the top nine Android password managers uncovers problems. We’ll cover another fileless malware campaign found in the wild; security improvements in Chrome and Firefox; a proof of concept for BIOS ransomware; a how-to walk-through for return-oriented programming; a nifty new site-scanning service.
66 MB 17 MB 360 KB   <-- Show Notes 140 KB 103 KB 177 KB

Episode #601 | 28 Feb 2017 | 101 min.
The First SHA-1 Collision

This week, Leo and I discuss the “CloudBleed” incident; another project zero 90-day timer expires for Microsoft; this week's IoT head-shaker; a New York airport exposes critical server data for a year; another danger created by inline third party TLS-intercepting "middleboxes"; more judicial thrashing over fingerprint warrants; Amazon says no to Echo data warrant; a fun drone-enabled proof on concept is widely misunderstood; another example of A/V attack surface expansion; some additional Crypto education pointers and miscellany... and, finally, what does Google's deliberate creation of two SHA-1-colliding files actually mean?
48 MB 12 MB 220 KB   <-- Show Notes 133 KB 80 KB 148 KB

Episode #600 | 21 Feb 2017 | 124 min.
The MMU Side-Channel Attack

This week, Leo and I discuss the completely cancelled February patch Tuesday amid a flurry of serious problems; it's not only laptop webcams that we need to worry about; the perils of purchasing a previously-owned Internet connected auto; Chrome changes its UI making certificate inspection trickier; the future of Firefox Add-Ons; Win10's lock screen is leaking the system’s clipboard; a collection of new problems for Windows; a amazing free Crypto book online from Stanford and New York University; pfSense and Ubiquity follows-ups; a bit of geek humor and miscellany… And a deep dive into yet another sublime hack from our ever-clever friends, led by professor Herbert Bos at the University of Amsterdam.
59 MB 15 MB 206 KB   <-- Show Notes 127 KB 89 KB 155 KB

Episode #599 | 14 Feb 2017 | 102 min.
TLS Interception INsecurity

This week, Leo and I discuss the delay in this month's Patch Tuesday (we may know why!), our favorite ad-blocker embraces the last major browser, a university gets attacked by its own vending machines, PHP leaps into the future, a slick high-end Linux hack, the rise of fileless malware, some good advice for tax time, it's not only Android's pattern lock that's vulnerable to visual eavesdropping, what happens with you store a huge pile of Samsung Note 7's in one place?, some fun miscellany, a MUST NOT MISS science fiction TV series, a look at the growing worrisome security implications of uncontrolled TLS interception.
48 MB 12 MB 260 KB   <-- Show Notes 110 KB 72 KB 133 KB

Episode #598 | 07 Feb 2017 | 115 min.
Two Armed Bandits

This week, Leo and I discuss printers around the world getting hacked!, Vizio's TVs really were watching their watchers, Windows has a new 0-day problem, Android's easy-to-hack pattern lock, an arsonist's pacemaker rats him out, a survey finds that many iOS apps are not checking TLS certificates, the courts create continuing confusion over eMail search warrants, a blast from the past: SQL Slammer appears to return, Cellebrite's stolen cell phone cracking data begins to surface, some worrisome events in the Encrypted Web Extensions debate, Non-Windows 10 users are not alone, a couple of questions answered, my report of a terrific Sci-Fi series, a bit of other miscellany... and a fun story about one armed bandits being hacked by two armed bandits..
54 MB 14 MB 257 KB   <-- Show Notes 116 KB 85 KB 150 KB

Episode #597 | 31 Jan 2017 | 107 min.
Traitors in our Midst

This week, Leo and I discuss the best “I'm not a Robot” video ever; Cisco's WebEx problem being far more pervasive than first believed; More bad news (and maybe some good news) for Netgear; Gmail adds .js to the no-no list; a hotel finally decides to abandon electronic room keying; more arguments against the use of modern AV; another clever exploitable CSS browser hack; some (hopefully final) password complexity follow-ups; a bit of errata and miscellany; a SQRL status update; a “Luke... trust the SpinRite” story; and a very nice analysis of a little-suspected threat hiding among us.
51 MB 13 MB 322 KB   <-- Show Notes 115 KB 80 KB 143 KB

Episode #596 | 24 Jan 2017 | 119 min.
Password Complexity Calculations

This week, Leo and I discuss how, while still on probation Symantec issues additional invalid certificates, Tavis Ormandy finds a very troubling problem in Cisco's Web conferencing extension for Chrome, yesterday's more-important-than-usual update to iOS, renewed concerns about LastPass metadata leakage, the SEC looks askance at what's left of Yahoo, a troubling browser form auto-fill information leakage, Tor further hides its hidden services, China orbits a source of entangles photons?, Heartbleed three years later, a new take on compelling fingerprints, approaching the biggest Pwn2Own ever, some miscellany... and some tricks for computing password digit and bit complexity equivalence.
56 MB 14 MB 207 KB   <-- Show Notes 112 KB 84 KB 146 KB

Episode #595 | 17 Jan 2017 | 113 min.
Whats up with WhatsApp?

This week, Leo and I discuss a classic bug at GoDaddy which bypassed domain validation for 8850 issued certificates; could flashing a peace sign compromise your biometric data?; it's not only new IoT devices that may tattle on you: many autos have been able to for the past 15 years; McDonalds gets caught in a web security bypass; more famous hackers have been hacked; Google uses AI to increase image resolution; more on the value or danger of password tricks; and... does WhatsApp incorporate a deliberate crypto backdoor?
54 MB 14 MB 234 KB   <-- Show Notes 120 KB 85 KB 150 KB

Episode #594 | 10 Jan 2017 | 112 min.
A look into PHP malware

This week, Leo and I discuss the US Federal Trade Commission's step into the IoT and home networking malpractice world, a radio station learning a lesson about what words NOT to repeat, Google's plan to even eliminate the "checkbox", a crucial caveat to the "passwords are long enough" argument, more cause to be wary of third-party software downloads, a few follow-ups to last week's topics, a bit of miscellany and a close look at the government's Russian hacking disclosure and a well-known piece of (related?) PHP malware.
53 MB 13 MB 224 KB 126 KB 86 KB 152 KB

Episode #593 | 03 Jan 2017 | 107 min.
I'm NOT a Robot! (Really)

This week, Leo and I discuss law enforcement and the Internet of Tattling things, a very worrisome new and widespread PHP eMail vulnerability, Paul and MaryJo score a big concession from Microsoft, a six year old "hacker" makes the news, Apple discovers how difficult it is to make developers change, hyperventilation over Russian malware found on a power utility's laptop, the required length of high entropy passwords, more pain for Netgear, an update on the just finalized v1.3 of TLS, the EFF's growing "Secure" messaging scorecard, a bunch of fun miscellany... and how does that "I'm not a Robot" non-CAPTCHA checkbox CAPTCHA work?
50 MB 13 MB 379 KB 137 KB 83 KB 153 KB

• Current Podcast Page
• Security Now 2023
• Security Now 2022
• Security Now 2021
• Security Now 2020
• Security Now 2019
• Security Now 2018
• Security Now 2017
• Security Now 2016
• Security Now 2015
• Security Now 2014
• Security Now 2013
• Security Now 2012
• Security Now 2011
• Security Now 2010
• Security Now 2009
• Security Now 2008
• Security Now 2007
• Security Now 2006
• Security Now 2005

You can receive an eMail reminder whenever this page is updated with a new Security Now! episode. Click the "Monitor Changes" button to have the highly-regarded "Change Detection" web site monitor this page and send you a note when it changes.

Monitor this page for changes: (it's private by ChangeDetection)
Security Now!, SpinRite Testimonials, and other Feedback:
Please use GRC's Visitor & Listener FEEDBACK Page where you may easily submit any feedback for Security Now, SpinRite testimonials, suggestions for future Security Now topics or questions & comments for future Listener Feedback episodes. Thank you!

Jump to top of page
Gibson Research Corporation is owned and operated by Steve Gibson.  The contents
of this page are Copyright (c) 2024 Gibson Research Corporation. SpinRite, ShieldsUP,
NanoProbe, and any other indicated trademarks are registered trademarks of Gibson
Research Corporation, Laguna Hills, CA, USA. GRC's web and customer privacy policy.
Jump to top of page

Last Edit: Jan 09, 2019 at 15:17 (1,925.13 days ago)Viewed 30 times per day