Risky Business #377 -- Wassenaar back to drawing board, latest from BlackHat

You're drunk, Wassenaar. Go home.
06 Aug 2015 » Risky Business

On this week's show we discuss the BIS decision to ditch its car-a-zay plans for Wassenaar regulation, the latest car hacking news and more.

We also check in with Trey Ford in this week's feature slot. Trey was the General Manager of the BlackHat conference, these days he works at Rapid7, and he joins us to talk about the vibe in Vegas at this year's conference.

This week's show is brought to you by RSA Security! Big thanks to RSA for making this week's show possible. RSA's very own Chris Thomas will be joining us in this week's sponsor interview to talk about the role industry should be playing in education. RSA is helping a few universities set up "learning SOCs", but where to from there?

Don't forget you can now support the Risky Business page via our Patreon campaign.

Oh, and do add Patrick and Adam on Twitter if that's your thing.

Show notes

Government Takes Second Look at US Wassenaar Rules | Threatpost | The first stop for security news
https://threatpost.com/unusual-re-do-of-us-wassenaar-rules-applauded/114096

Chrysler and Harman Hit With a Class Action Complaint After Jeep Hack | WIRED
http://www.wired.com/2015/08/chrysler-harman-hit-class-action-complaint-...

Patch Your OnStar iOS App to Avoid Getting Your Car Hacked | WIRED
http://www.wired.com/2015/07/patch-gm-onstar-ios-app-avoid-wireless-car-...

This Gadget Hacks GM Cars to Locate, Unlock, and Start Them (UPDATED) | WIRED
http://www.wired.com/2015/07/gadget-hacks-gm-cars-locate-unlock-start/

Hackers Could Heist Semis by Exploiting This Satellite Flaw | WIRED
http://www.wired.com/2015/07/hackers-heist-semis-exploiting-satellite-flaw/

Hackers Can Seize Control of Electric Skateboards and Toss Riders | WIRED
http://www.wired.com/2015/08/hackers-can-seize-control-of-electric-skate...

DRAM "Bitflipping" exploit for attacking PCs: Just add JavaScript | Ars Technica
http://arstechnica.com/security/2015/08/dram-bitflipping-exploit-for-att...

"Thunderstrike 2" rootkit uses Thunderbolt accessories to infect Mac firmware [Updated] | Ars Technica
http://arstechnica.com/apple/2015/08/thunderstrike-2-rootkit-uses-thunde...

0-day bug in fully patched OS X comes under active exploit to bypass password protection | Ars Technica
http://arstechnica.com/security/2015/08/0-day-bug-in-fully-patched-os-x-...

Inside the $100M 'Business Club' Crime Gang - Krebs on Security
http://krebsonsecurity.com/2015/08/inside-the-100m-business-club-crime-g...

Chinese VPN Service as Attack Platform? - Krebs on Security
http://krebsonsecurity.com/2015/08/chinese-vpn-service-as-attack-platform/

Newly discovered Chinese hacking group hacked 100+ websites to use as "watering holes" | Ars Technica
http://arstechnica.com/security/2015/08/newly-discovered-chinese-hacking...

China-Tied Hackers That Hit U.S. Said to Breach United Airlines - Bloomberg Business
http://www.bloomberg.com/news/articles/2015-07-29/china-tied-hackers-tha...

Russian hacker targets CommSec, E*TRADE retail accounts
http://www.theage.com.au/business/markets/russian-hacker-targets-commsec...

New attack on Tor can deanonymize hidden services with surprising accuracy | Ars Technica
http://arstechnica.com/security/2015/07/new-attack-on-tor-can-deanonymiz...

Bound to happen: BIND bug exploits now in the wild \u2022 The Register
http://www.theregister.co.uk/2015/08/04/bind_bug_exploits_now_in_the_wild/

Windows 10 Upgrade Spam Carries CTB-Locker Ransomware | Threatpost | The first stop for security news
https://threatpost.com/windows-10-upgrade-spam-carries-ctb-locker-ransom...

drspringfield / cabletables - Bitbucket
https://bitbucket.org/drspringfield/cabletables

John McAfee cuffed by Tennessee cops, faces drug-driving, gun rap \u2022 The Register
http://www.theregister.co.uk/2015/08/05/tennessee_cops_stops_john_mcafee...

McAfee tells El Reg: 'My shootout with the police was highly exaggerated' \u2022 The Register
http://www.theregister.co.uk/2015/08/05/john_mcafee_says_police_shootout...

Office Lip Dub - Everything's Under Control by Peregrine - YouTube
https://www.youtube.com/watch?v=o8DQKieBPNU