Risky Business #408 -- Advertising ecosystem security with Dan Kaminsky, news with Grugq

Deja WHOAH...
21 Apr 2016 » Risky Business

On this week's show, as promised, we'll be checking in with Dan Kaminsky of WhiteOps to discuss their bread and butter -- click fraud prevention. We also get his thoughts on what the ad industry could do to stamp out malvertising. As you'll hear, he thinks the only way forward is to actually fix browsers. Seems sensible to us!

Adam Boileau is taking a well-deserved week off, so The Grugq pops in to fill in. We'll chat to him about all the infosec news of the last week.

Oh, and do add Patrick and Grugq on Twitter if that's your thing.

Show notes

How Hacking Team got hacked | Ars Technica
http://arstechnica.com/security/2016/04/how-hacking-team-got-hacked-phin...

How hackers eavesdropped on a US Congressman using only his phone number | Ars Technica
http://arstechnica.com/security/2016/04/how-hackers-eavesdropped-on-a-us...

Apple stops patching QuickTime for Windows despite 2 active vulnerabilities | Ars Technica
http://arstechnica.com/security/2016/04/apple-stops-patching-quicktime-f...

Adobe warns that uninstalling vulnerable QuickTime for Windows can break Creative Cloud | ZDNet
http://www.zdnet.com/article/adobe-warns-that-uninstalling-vulnerable-qu...

Microsoft Wins Widespread Support in Privacy Clash With Govt. | Threatpost | The first stop for security news
https://threatpost.com/microsoft-wins-widespread-support-in-privacy-clas...

Apple and FBI Faceoff at House Encryption Hearing | Threatpost | The first stop for security news
https://threatpost.com/apple-and-fbi-faceoff-at-house-encryption-hearing...

BlackBerry CEO Defends Lawful Access Principles, Supports Phone Hack | Threatpost | The first stop for security news
https://threatpost.com/blackberry-ceo-defends-lawful-access-principles-s...

2015 Google Android Security Report | Threatpost | The first stop for security news
https://threatpost.com/android-security-report-29-percent-of-active-devi...

Cisco Talos Blog: Widespread JBoss Backdoors a Major Threat
http://blog.talosintel.com/2016/04/jboss-backdoor.html

IRS Chief: Agency Faces Loss of Key InfoSec Personnel
http://www.govinfosecurity.com/irs-chief-agency-faces-loss-key-infosec-p...

Matthew Keys Sentenced to Two Years for Aiding Anonymous | WIRED
http://www.wired.com/2016/04/journalist-matthew-keys-sentenced-two-years...

A Scheme to Encrypt the Entire Web Is Actually Working | WIRED
http://www.wired.com/2016/04/scheme-encrypt-entire-web-actually-working/

Researchers Crack Microsoft and Google's Shortened URLs to Spy on People | WIRED
http://www.wired.com/2016/04/researchers-cracked-microsoft-googles-short...

Flashback: Declassified 1970 DOD cybersecurity document still relevant | Ars Technica
http://arstechnica.com/security/2016/04/flashback-declassified-1970-dod-...

Underwriters Labs refuses to share new IoT cybersecurity standard | Ars Technica
http://arstechnica.com/security/2016/04/underwriters-labs-refuses-to-sha...

New MIT Scanner Finds Web App Flaws in a Minute | Threatpost | The first stop for security news
https://threatpost.com/new-mit-scanner-finds-web-app-flaws-in-a-minute/1...

VMware Patches Critical Session Handling Vulnerability | Threatpost | The first stop for security news
https://threatpost.com/vmware-patches-critical-session-handling-vulnerab...

'Blackhole' Exploit Kit Author Gets 7 Years - Krebs on Security
http://krebsonsecurity.com/2016/04/blackhole-exploit-kit-author-gets-8-y...