Episode 0x14-- Happy Birthday Mr. Gattaca... we'll vote for you too.
There's interesting things afoot. Y'all should pay attention.
This is the 21st episode for those of you that don't have 16 fingers. Not sure we should be revealing this yet, but it's going to be a wild winter solstice celebration this year. The southern folk at Southern Fried Security and this gang of teenage malcontents are up to no good. Well, actually extra special good. Let me sum up - it's Security Charity... Gangnam Style.
Stay tuned for the carnage.
Upcoming over the next hour...
Lots of News Breaches SCADAs DERPs!!! and then our discussion topic--Disaster RecoveryAnd if you've got commentary, please sent it tomailbag@liquidmatrix.org for us to check out.
DISCLAIMER: It's not that explicit, but you may want to use headphones if you're at work.
ADDITIONAL DISCLAIMER: In case it is unclear, this is the story of 4 opinionated infosec pros who have sufficient opinions of their own they don't need to speak for anyone except themselves. Ok? Good.
In this episode:
News Service Sells Access to Fortune 500 Firms U.S. looks to replace human surveillance with computers How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole CSO Online has an opinion too. Broadcom DoS on BCM4325 and BCM4329 devices Auditor General Report: Canada is sucking at the "cyber" The Kiwi .gov makes their internal network kiosk accessible China Unicom replaces Cisco devices over security concerns Huawei gives Australia peeks at its network hardware and code to regain trust Hire great infosec people (and keep them) ! Breaches - The never ending never ending story... Billabong Hacked Again (yes, again), Hackers Claim to Have Obtained 37,000 Account Details Peru Domains Registrar hacked and 207116 Domain panel credentials leaked South Carolina Suffers Massive Data Breach Attacker grabs data for 3.6 million South Carolina taxpayers; governor wants to see culprit "brutalized" Hackers crack Texan bank, Experian credit records come flooding out Vermont credit union discards unencrypted data of 85,000 Anonymous owns a police forum The SCADAs Critical flaw found in software used by many industrial control systems Cybergeddon now? Industrial control systems targeted Errata / DERP of the week awardDear Sir/Madame,
My name is Jakub Walczak, and I work for Hakin9 – the magazine that reaches over 60 000 readers mainly in the USA, India, and Australia.
I have seen your website and I was wondering if you would like to cooperate with us. Please let me know.
I am looking forward to hearing from you.
Regards,
Jakub Walczak
Sorry Jakub, perhaps you should listen to the show or read about our opinions of Hackin9 before you send email like this again. Just sayin. CommentaryYeah, so we ran a little long... the commentary segment has been pulled out into a separate recording. It'll show up on the RSS feed tomorrow, but if you want it right now, you can grab it here.
Foot In The Door - Disaster Recovery c, i and A <-- that="" one="" counts="" li=""> RTO, RPO practice, practice, practice Hardcore - Recovering from the Disaster you didn't plan for Do the post-mortem. Netflix's AWS outage post-mortem do security olde style- use the opportunties provided by the red-print report to get the thing fixed right. Make sure you've prepared yourself Including a "get home" bag at the office Don't make plans that require employees to run on infrastructure that might not be there Mailbag / Bizarro LandThe quick & dirty: Stroz Friedberg evaluated the technical watchdog (MarkMonitor) for the so-called ISP "Six Strikes", and gave it a thumbs-up. However, SF was also actively lobbying for the RIAA between 2004 and 2009.
I want to like this company - they're doing it less wrong than many other folks - and thus I find myself experiencing another bout of Infosec Depression.
Original article, albeit from a non-impartial source here
-Jim
In Closing Matt's Movie Review Argo was so good - That Ben Affleck is DELICIOUS We do research too - Ben's running a survey and will publish results. Check it out! The Security Conference Library If you're interested in helping out with openCERT.ca, drop a line to info@openCERT.ca Contribute to the Strategic Defense Execution Standard (#SDES) and you'll be Doing Infosec Right in no time. Upcoming Appearances: Ben and Dave at HackFest in Quebec City, James at SecurityZone in Cali, Colombia BSidesDave - held immediately after Hackfest, Dave will not be sleeping before his flight home, so keep him company Signing up for a SANS course? Be sure to use the code "Liquidmatrix_150" and save $150 off the course fee! Seacrest Says: "Why are my pants wet?" Hope everyone makes it through #Sandy safelyCreative Commons license: BY-NC-SA