Plus news, Haroon Meer and MORE!
March 24th, 2016 --
On this week's show we're chatting with myNetWatchman's Donald McCarthy about some research he's done into these crews shaking down US companies for W2 forms. He and his colleagues have identified at least 40 crews involved in this stuff. We'll get the skinny on that in this week's feature interview. We're also chatting with Haroon Meer this week in the sponsor interview. Haroon is the head honcho over at Thinkst Applied Research and we'll be talking to him some more about the fantastic honeypot product they've released: Canary.Tools.
All the news that's fit to... put in CMS?
March 24th, 2016 --
Links to everything discussed in episode 405 of the Risky Business podcast...
Counterterrorism researcher and ex GCHQ-er David Wells joins the show...
March 17th, 2016 --
On this week's show we're chatting with David Wells. He's ex GCHQ and ASD but these days he's a counterterrorism boffin with the Lowy Institute. He's joining us to discuss the IS document leak. Depending on which story you read its either the death of the organisation or it won't do anything at all to disrupt it. We get David's thoughts on what this leak will actually for the so-called Caliphate. In this week's sponsor interview we're doing something a bit different.. following on from last week's interview with Re/Code's Arik Hesseldahl we're chatting with Tenable's CFO, Steve Vintz.
Are we sick of #FBiOS yet?
March 17th, 2016 --
Links to everything discussed in episode 403 of the Risky Business information security podcast.
PLUS news with Adam and BugCrowd's Casey Ellis in the sponsor chair...
March 10th, 2016 --
On this week's show we're chatting with re/code's senior editor and "enterprise dude" Arik Hesseldahl about the business of infosec. Information security related stocks and shares are tanking on indexes all over the world... why? How can this be happening in a $75bn sector that is tipped to grow into a $175bn sector in the next four years? Arik will join us with the skinny on that. But don't panic, tanking infosec share prices might be a good thing for the discipline. We'll find out why a bit later on. In this week's sponsor interview we chat with BugCrowd CEO Casey Ellis.
Not the craziest week in infosec, but still plenty to talk about...
March 10th, 2016 --
Links to everything discussed in episode 402 of the Risky Business infosec podcast.
YSoSerial makes deserialisation attacks serious...
March 3rd, 2016 --
On this week's show we get into a serious technical discussion about deserialisation attacks with with one of Adam Boileau's colleagues, Brendan Jamieson about the biggest issue in infosec that no one is talking about -- deserialisation vulnerabilities and their exploitation. This attack class is a serious problem in enterprise environments thanks to the release of the YSoSerial tool about a year ago. Pen-testers who are across this bug class are finding issues everywhere they look, and hardly anyone is talking about it. But we do, this week.
Lots of policy news this week!
March 3rd, 2016 --
Links to items discussed in this week's episode of the Risky Business podcast.
Apple and FBI are both silly sausages...
February 25th, 2016 --
On this week's podcast we'll hear from Daniel Hodson of Elttam Security here in Australia. Daniel and his business partner Matt Jones have been looking into the security of messaging software that has recommended by the EFF. Does a bunch of ticks from the EFF actually say much about app security? Well, not really, as it turns out.
Apple, FBI still dominate agenda...
February 25th, 2016 --
A list of security items making the agenda this week.
Oops. This is going to get... tricky...
February 18th, 2016 --
On this week's show we chat with Dan Guido from Trail of Bits about the stoush between Apple and the US department of justice. In this week's sponsor interview we speak with Cris Thomas, a.k.a. Space Rogue. Cris works for Tenable Network Security, this week's sponsor, and he joins us in this week's podcast to talk about NIST's cyber security framework. Adam Boileau joins the show to discuss the week's security news. Links to everything are in this week's show notes.
The glibc bug is this week's other show-stopper...
February 18th, 2016 --
Links to everything discussed in episode 399 of the Risky Business information security podcast.
Bonus lulz courtesy of Cisco...
February 11th, 2016 --
This week's show is one for the CSOs! It's the economics edition, I guess you'd call it. We'll be chatting with Professor Lawrence Gordon, co-creator of the Gordon Loeb model for Cyber Security investment. We speak to him about contemporary infosec budgets and how spending of $500m a year by some financial institutions in the USA is actually sensible.
Lots of malware news this week...
February 11th, 2016 --
Links to items discussed in episode 398 of the Risky Business podcast.
You're a diverse bunch...
February 9th, 2016 --
As many of you would know, last week I posted a listener survey to SurveyMonkey. I dropped the link on Twitter and then mentioned it in the show. I wasn't really expecting much of a response, but after about a week, 500 of you have already spent the time to fill out the questionnaire. Thanks!
PLUS: Java deserialisation attacks are coming to eat your soul...
February 5th, 2016 --
******Here's a link to the Risky Business listener survey. Please take some time to fill it in! It'll really help the show!********
News, analysis and more!
February 5th, 2016 --
Links to everything discussed in episode 397 of the Risky Business podcast. Please do click through here to our listener survey to help me put together some demographics on the Risky.biz audience. ------------ Oracle deprecates the Java browser plugin, prepares for its demise | Ars Technica http://arstechnica.com/information-technology/2016/01/oracle-deprecates-... Good Riddance to Oracle’s Java Plugin — Krebs on Security
PLUS Martijn Grooten, Haroon Meer and Adam Boileau!
January 28th, 2016 --
On this week's show we've got two feature interviews! We're talking to Chris Wysopal from Veracode about using static analysis techniques to find back doors in software. With Juniper, AMX, Fortinet and Cisco all experiencing either maliciously planted or accidental backdoors, this is a hot topic. Chris joins us to talk about how you go about finding this stuff and whether or not vendors are taking this issue seriously enough.
Links! Links! Get your links!
January 28th, 2016 --
Links to everything discussed in episode 396 of the Risky Business security podcast.
We're back!
January 21st, 2016 --
In this week's feature interview Facebook CISO Alex Stamos joins us to discuss a few things. We'll be talking about moves by both browser developers and some CAs to deprecate SHA1 signed certificates. He says we need to support SHA-1 for now and he explains why soon. We're also chatting with him about the Juniper fiasco. We also get his thoughts on NSA surveillance now he's responsible for the security of user information at the world's biggest social media platform.