Security Now (Audio) artwork

Security Now (Audio)

215 episodes - English - Latest episode: 12 days ago - ★★★★★ - 1.5K ratings

Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every week.

Records live every Tuesday at 4:30pm Eastern / 1:30pm Pacific / 20:30 UTC.

Tech News News Technology twit technology steve gibson leo laporte security spyware malware hacking cyber crime encryption
Homepage Apple Podcasts Google Podcasts Overcast Castro Pocket Casts RSS feed

Episodes

SN 786: ZeroLogon++ - Amazon Flying Security Cam, ZeroLogon on GitHub, Ransomware Roundup

September 30, 2020 01:00 - 2 hours - 56.7 MB

Amazon flying security cam, ZeroLogon on GitHub, ransomware roundup. What could possibly go wrong: Amazon/Ring's autonomous flying home security webcam Evil ransomware gang deposited $1 million of bitcoin in a hacker recruitment drive Over this past weekend, Universal Health Services was hit by a huge Ryuk ransomware One week ago, there were three ZeroLogon exploits on GitHub. Today there are more than fit on the first page of search results Security Fixes in Chrome's v85.0.4183.121 R...

SN 785: Formal Verification - iOS 14 & Android 11 Security Features, DuckDuckGo Gets Big

September 23, 2020 03:53 - 1 hour - 54.8 MB

iOS 14 & Android 11 security features, DuckDuckGo gets big. The most important iOS 14 privacy & security features All of Android 11's new privacy & security features DuckDuckGo usage growth goes exponential LAN attack bug fixed in Firefox 79 for Android Goodbye Forever Firefox Send and Notes... Oh, how we loved ye Microsoft's catastrophic Zerologon vulnerability Why we're headed toward formal verification of security protocols We invite you to read our show notes at https://www.grc...

SN 784: BlindSide & BLURtooth - Chrome vs Abusive Ads, Patch Tuesday Palooza

September 16, 2020 00:00 - 1 hour - 52.1 MB

Chrome vs abusive ads, patch Tuesday palooza. BlindSide and BLURtooth Chrome gets tough on abusive ads The last hurrah for IE & Flash exploits Chromium Edge on Win10: Forcing the issue Edge enables "Ask me..." for each download Patch Tuesday Palooza! Excessive SSD Defragging also fixed The WordPress File Manager flaw... two weeks downstream Zoom... now with 2FA New Raccoon attack We invite you to read our show notes at https://www.grc.com/sn/SN-784-Notes.pdf Hosts: Steve Gibson...

SN 783: IoT Isolation Strategies - Isolate Your IoT Devices, Threema Goes Open-Source

September 09, 2020 02:54 - 2 hours - 57.3 MB

Isolate your IoT devices, Threema goes open-source. IoT Isolation Strategies DoH coming to Chrome for Android Bye Bye Drive-By Downloads Threema goes Open-Source WordPress File Manage 0-day flaw Facebook's new VDP — Vulnerability Disclosure Policy Facebook's new "WhatsApp Security Advisories" page The Tor Project Membership Program Intel's latest microcode patches We invite you to read our show notes at https://www.grc.com/sn/SN-783-Notes.pdf Hosts: Steve Gibson and Leo Laporte ...

SN 782: I Know What You Did Last Summer - Russian Tries to Hack Tesla, Web Browser History Research

September 02, 2020 01:00 - 1 hour - 50.9 MB

Russian tries to hack Tesla, web browser history research. Chrome 85 security features Russian Attempts to Cyber Attack Tesla More EMV Standard monetary transaction method problems Watch this video on Covid testing I Know What You Did Last Summer: research on web browsing histories We invite you to read our show notes at https://www.grc.com/sn/SN-782-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. You can su...

SN 781: SpiKey - Ransomware Hits Jack Daniel's, Iranian Script-Kiddies, How Ransomware Happens

August 26, 2020 01:30 - 2 hours - 56.6 MB

Ransomware hits Jack Daniel's, Iranian Script-Kiddies, how ransomware happens. SpiKey: using the sound of a key to determine its shape What do The University of Utah, Jack Daniel's Whiskey, and Carnival Cruise Lines all have in common? Ransomware A Remote Code Execution in Chrome's WebGL How ransomware happens: email phishing, remote desktop protocol compromise, and software vulnerability Emergency Windows update! Iranian script-kiddies using RDP to deploy Dharma ransomware The Zero...

SN 780: Microsoft's 0-Day Folly - Microsoft Acts Badly, Canon Ransomware, Mozilla Tries to Pivot

August 19, 2020 00:30 - 2 hours - 57.9 MB

Microsoft acts badly, Canon ransomware, Mozilla tries to pivot. When Microsoft doesn't act responsibly: Parts 1 and 2 Snap Your Dragon / "Achilles: Small Chip, Big Peril" 3rd largest Patch Tuesday ever Mozilla pivoting to VPN, future uncertain The other ransomware shoe drops at Canon Software glitch in California's COVID case reporting Threema gets E2EE Video Calls We invite you to read our show notes at https://www.grc.com/sn/SN-780-Notes.pdf Hosts: Steve Gibson and Leo Laporte ...

SN 779: Geneva - Great Firewall Of China, Black Hat/DEFCON 2020, Have I Been Pwned

August 12, 2020 01:00 - 2 hours - 57.8 MB

Great Firewall Of China, Black Hat/DEFCON 2020, Have I Been Pwned. It's Patch Tuesday! News from Black Hat / DEFCON 2020 Generalizing Speculative Execution Vulnerabilities Canon hit by the Maze ransomware A vBulletin Emergency DoH for Win10 Troy Hunt Hasn't Been Pwned Geneva: China's Great Firewall Tightens We invite you to read our show notes at https://www.grc.com/sn/SN-779-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/sho...

SN 778: BootHole - Twitter Hackers Arrested, Garmin Hackers Get Ransom

August 05, 2020 03:00 - 2 hours - 57 MB

Twitter hackers arrested, Garmin hackers get ransom. Vitamin D fights death by Covid Firefox is now at v79 Twitter hackers arrested Garmin hackers rewarded Tor and Dr. Krawetz Dropping 0Days Blocking Tor Connections the Smart Way Enabling Zoom Meeting Hacking Another SHA-1 Deprecation QNAP and QSnatch BootHole We invite you to read our show notes at https://www.grc.com/sn/SN-778-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv...

SN 777: rwxrwxrwx - Garmin Outage, Twitter Hack Update, GnuTLS

July 29, 2020 00:30 - 1 hour - 47.4 MB

F5 Networks "Big-IP" devices in Big-Trouble Twitter bitcoin hack update GnuTLS vs OpenSSL The Garmin outage then and now Cisco's latest trouble Surprising SpinRite results We invite you to read our show notes at https://www.grc.com/sn/SN-777-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. You can submit a question to Security Now! at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including...

SN 776: A Tale of Two Counterfeits - Twitter Hack, Cloudflare Outage, Zoom's Vanity URL Flaw

July 22, 2020 00:30 - 1 hour - 53.9 MB

Here's how Twitter was hacked. How can we prevent the next Twitter hack? Cloudflare outage takes out huge swath of American internet, including Down Detector. All internet got sent to Atlanta. Zoom's vanity URL flaw: when is a "zero day" not a zero day? Not all VPNs are created equal. Apple updated its iOS and macOS with a handful of useful security patches. SigRed: "This is not just another vulnerability." And speaking of last week's July Patch Tuesday... "Firefox Send" is still not...

SN 775: Tsunami - EARN IT is Still Evil, Google Tsunami

July 15, 2020 00:00 - 1 hour - 46.9 MB

EARN IT is still evil, Google tsunami. Mozilla suspends "Send" due to persistent malware abuse Zoom fixed a new RCE affecting Windows 7 and earlier systems The EARN IT bill, take II is still just as bad as the original Google bans ads on stalkerware A Chinese Internet equipment vendor in the hot seat Locating hidden drone operators Rampant Router Insecurities Tsunami: Google's open-source enterprise network vulnerability scanner We invite you to read our show notes at https://www.g...

SN 775: Tsunami

July 15, 2020 00:00 - 1 hour - 46.9 MB

EARN IT is still evil, Google tsunami. Mozilla suspends "Send" due to persistent malware abuse Zoom fixed a new RCE affecting Windows 7 and earlier systems The EARN IT bill, take II is still just as bad as the original Google bans ads on stalkerware A Chinese Internet equipment vendor in the hot seat Locating hidden drone operators Rampant Router Insecurities Tsunami: Google's open-source enterprise network vulnerability scanner We invite you to read our show notes at https://www.g...

SN 774: 123456 - Boston Bans Face Recognition, Bad Passwords

July 08, 2020 00:30 - 1 hour - 53.3 MB

Boston bans face recognition, bad passwords. Boston bans facial recognition 123456 is still the most popular password iOS 14 catches Linked-In, Tik Tok, and others red handed! US-CERT notes two Emergency Windows Updates HackerOne shares their top 10 public bug bounty programs Sony launches PlayStation bug bounty program with rewards of $50K+ F5 Networks patches a highest-severity vulnerability We invite you to read our show notes at https://www.grc.com/sn/SN-774-Notes.pdf Hosts: St...

SN 774: 123456

July 08, 2020 00:30 - 1 hour - 53.3 MB

Boston bans face recognition, bad passwords. Boston bans facial recognition 123456 is still the most popular password iOS 14 catches Linked-In, Tik Tok, and others red handed! US-CERT notes two Emergency Windows Updates HackerOne shares their top 10 public bug bounty programs Sony launches PlayStation bug bounty program with rewards of $50K+ F5 Networks patches a highest-severity vulnerability We invite you to read our show notes at https://www.grc.com/sn/SN-774-Notes.pdf Hosts: St...

SN 773: Ripple20 Too

July 01, 2020 00:30 - 1 hour - 51.3 MB

Congress wants to kill encryption & face recognition. New information about Ripple20 The Facial Recognition and Biometric Technology Moratorium Act wants to kill face recognition The Lawful Access to Encrypted Data Act wants to kill encryption Michigan State's legislative House passed the "Microchip Protection Act" Apple forces the industry down to one-year web browser certificate lifespans Safari to eschew 16 new web API's for the sake of user privacy Apple also got on the DoH & DoT...

SN 773: Ripple20 Too - Congress Wants to Kill Encryption & Face Recognition

July 01, 2020 00:30 - 1 hour - 51.3 MB

Congress wants to kill encryption & face recognition. New information about Ripple20 The Facial Recognition and Biometric Technology Moratorium Act wants to kill face recognition The Lawful Access to Encrypted Data Act wants to kill encryption Michigan State's legislative House passed the "Microchip Protection Act" Apple forces the industry down to one-year web browser certificate lifespans Safari to eschew 16 new web API's for the sake of user privacy Apple also got on the DoH & DoT...

SN 772: Ripple20 - Zoom Encryption, Windows 10 Printer Error

June 24, 2020 01:00 - 2 hours - 58.4 MB

Zoom encryption, Windows 10 printer error. Ripple20: a set of 19 TCP/IP vulnerabilities that could let remote attackers gain control over your device Russian government lifts its failed ban on Telegram Zoom: everybody gets optional end to end encryption Google removed 106 malicious Chrome extensions collecting sensitive user data Windows 10 update breaks printing VLC Media Player 3.0.11 fixes severe remote code execution flaw Netgear in the doghouse DDoS is alive and well... and gro...

SN 772: Ripple20

June 24, 2020 01:00 - 2 hours - 58.4 MB

Zoom encryption, Windows 10 printer error. Ripple20: a set of 19 TCP/IP vulnerabilities that could let remote attackers gain control over your device Russian government lifts its failed ban on Telegram Zoom: everybody gets optional end to end encryption Google removed 106 malicious Chrome extensions collecting sensitive user data Windows 10 update breaks printing VLC Media Player 3.0.11 fixes severe remote code execution flaw Netgear in the doghouse DDoS is alive and well... and gro...

SN 771: Lamphone - Windows Update Kills Printers & SSDs

June 17, 2020 00:00 - 1 hour - 50.6 MB

Windows update kills printers & SSDs. Lamphone: eavesdrop on a hanging lightbulb Brave Browser caught and chastised for tweaking user-entered URLs for its benefit Microsoft breaks its own record for Patch Tuesday patches TFW Windows 10 loses your printer port Last week's Patch Tuesday broke ALL PRINTING (even to PDFs) for many users. Fix won't come for a month Windows 10 2004 update is messing up SSDs and non-SSDs SMBleed Subject: Your Site Has Been Hacked Authentic database ransom...

SN 771: Lamphone

June 17, 2020 00:00 - 1 hour - 50.6 MB

Windows update kills printers & SSDs. Lamphone: eavesdrop on a hanging lightbulb Brave Browser caught and chastised for tweaking user-entered URLs for its benefit Microsoft breaks its own record for Patch Tuesday patches TFW Windows 10 loses your printer port Last week's Patch Tuesday broke ALL PRINTING (even to PDFs) for many users. Fix won't come for a month Windows 10 2004 update is messing up SSDs and non-SSDs SMBleed Subject: Your Site Has Been Hacked Authentic database ransom...

SN 770: Zoom's E2EE Debacle - Zoom's End-to-End Encryption Fail

June 10, 2020 02:00 - 1 hour - 49.7 MB

Zoom's end-to-end encryption fail. Zoom will offer end-to-end encryption, but only if you pay for it IBM announces no more work on facial recognition The Odd Case of Mozilla's DoH DDoS Cisco's Talos group found two critical flaws in the Zoom client CallStranger UPnP bug has tech press in a tizzy Microsoft has started to replace old Edge with new Edge We invite you to read our show notes at https://www.grc.com/sn/SN-770-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subsc...

SN 770: Zoom's E2EE Debacle

June 10, 2020 02:00 - 1 hour - 49.7 MB

Zoom's end-to-end encryption fail. Zoom will offer end-to-end encryption, but only if you pay for it IBM announces no more work on facial recognition The Odd Case of Mozilla's DoH DDoS Cisco's Talos group found two critical flaws in the Zoom client CallStranger UPnP bug has tech press in a tizzy Microsoft has started to replace old Edge with new Edge We invite you to read our show notes at https://www.grc.com/sn/SN-770-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subsc...

SN 769: Zoom's E2EE Design - Zoom Gets End-to-End Encryption

June 03, 2020 01:00 - 2 hours - 60.6 MB

Zoom gets end-to-end encryption. ACLU takes Clearview to court, but maybe they should worry about their own website first The state of drive-by malvertising downloads Google will be bad listing notification abusing sites Who else is doing the eBay-like ThreatMetrix port scanning? Facebook to require identity verification for high impact posters Google Messaging is apparently heading toward E2EE The return of a much more worrisome StrandHogg The SHA-1 hash to finally be dropped from...

SN 769: Zoom's E2EE Design

June 03, 2020 01:00 - 2 hours - 60.6 MB

Zoom gets end-to-end encryption. ACLU takes Clearview to court, but maybe they should worry about their own website first The state of drive-by malvertising downloads Google will be bad listing notification abusing sites Who else is doing the eBay-like ThreatMetrix port scanning? Facebook to require identity verification for high impact posters Google Messaging is apparently heading toward E2EE The return of a much more worrisome StrandHogg The SHA-1 hash to finally be dropped from...

SN 768: Contact Tracing Apps R.I.P. - Contact Tracing Apps Are Not Going to Work

May 27, 2020 02:33 - 1 hour - 50.7 MB

Contact tracing apps are not going to work. Why contact tracing apps are never going to work Unc0ver: There's a new iOS jailbreak in town, and as jailbreaks go, it looks VERY nice! Firefox 77 picks up a nifty new security trick New features in Chrome 83: cookie management, "Safety Check," blocking third-party cookies by default in Incognito mode, and "Tab Groups" Adobe rushes out four out-of-cycle emergency updates to fix security flaws Zerodium temporarily stops buying iOS remote cod...

SN 768: Contact Tracing Apps R.I.P.

May 27, 2020 02:33 - 1 hour - 50.7 MB

Contact tracing apps are not going to work. Why contact tracing apps are never going to work Unc0ver: There's a new iOS jailbreak in town, and as jailbreaks go, it looks VERY nice! Firefox 77 picks up a nifty new security trick New features in Chrome 83: cookie management, "Safety Check," blocking third-party cookies by default in Incognito mode, and "Tab Groups" Adobe rushes out four out-of-cycle emergency updates to fix security flaws Zerodium temporarily stops buying iOS remote cod...

SN 767: WiFi 6, Apple vs. FBI, Face Masks

May 20, 2020 00:00 - 2 hours - 55.1 MB

WiFi 6, Apple vs. FBI, face masks. Last Tuesday's Windows patch Tuesday was not the biggest ever, but it was the 3rd largest in Microsoft's history, weighing in with a whopping 111 CVE-tracked bug fixes, 16 of which were rated CRITICAL and all but one of which enabled Remote Code Execution by an attacker. The DOJ and FBI again criticize Apple over encryption When is a fix not a fix? Face masks have thwarted the London police's LFR rollout Utah chooses to roll their own contact tracing ...

SN 767: WiFi 6

May 20, 2020 00:00 - 2 hours - 55.1 MB

WiFi 6, Apple vs. FBI, face masks. Last Tuesday's Windows patch Tuesday was not the biggest ever, but it was the 3rd largest in Microsoft's history, weighing in with a whopping 111 CVE-tracked bug fixes, 16 of which were rated CRITICAL and all but one of which enabled Remote Code Execution by an attacker. The DOJ and FBI again criticize Apple over encryption When is a fix not a fix? Face masks have thwarted the London police's LFR rollout Utah chooses to roll their own contact tracing ...

SN 766: ThunderSpy - Thunderbolt Security Flaw, Zoom Buys Keybase

May 12, 2020 22:00 - 1 hour - 54 MB

Thunderbolt security flaw, Zoom buys Keybase. Why the ThunderSpy Thunderbolt security flaw is such a big deal Zoom purchases Keybase to fix encryption Firefox 76 released with new features But Firefox 76 broke Amazon's Assistant! Hallelujah!! Edge moves to silence those annoying notification requests. Critical WordPress plugin bugs present on over one million sites Critical vBulletin patch Samsung has patched a CRITICAL bug affecting the past 6 years of Smartphones DefCon and Blac...

SN 766: ThunderSpy

May 12, 2020 22:00 - 1 hour - 54 MB

Thunderbolt security flaw, Zoom buys Keybase. Why the ThunderSpy Thunderbolt security flaw is such a big deal Zoom purchases Keybase to fix encryption Firefox 76 released with new features But Firefox 76 broke Amazon's Assistant! Hallelujah!! Edge moves to silence those annoying notification requests. Critical WordPress plugin bugs present on over one million sites Critical vBulletin patch Samsung has patched a CRITICAL bug affecting the past 6 years of Smartphones DefCon and Blac...

SN 765: An Authoritarian Internet?

May 06, 2020 02:00 - 1 hour - 54.2 MB

China wants to rebuild the Internet. China's proposal to rebuild the internet is an authoritarian nightmare Bruce Schneier on COVID-19 Contact Tracing Apps Political Correctness hits cybersecurity DHS's CISA says no to 3rd-party DoH "POWER-SUPPLaY: Leaking Data from Air-Gapped Systems by Turning the Power-Supplies Into Speakers" An authorization bypass in SaltStack Adobe's Big Last Tuesday, Non-Patch Tuesday, Update Google has announced its impending clean-up of the Chrome Web Store...

SN 764: RPKI

April 28, 2020 21:40 - 1 hour - 49.4 MB

Apple/Google Contact Tracing, Best VPNs to protect you. Apple/Google Contact Tracing Update iOS 0-Day Alert! Update Apple Mail Best VPNs to protect you from the Five Eyes TypoSquatting attacks Vitamin D linked to COVID-19 mortality Resource Public Key Infrastructure How BGP can break the Internet We invite you to read our show notes at https://www.grc.com/sn/SN-764-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-no...

SN 763: The COVID Effect

April 22, 2020 04:01 - 1 hour - 43.3 MB

Zoom Fixes Security, EARN IT is Evil, Tor in Trouble Zoom gets big-name help with security fixes Google updates Chrome to v81.0.4044.113 to squash a critical flaw FTP in Chrome lives another day! Google "undepreciates" FTP. Windows Patch Tuesday for April 2020 fixes 113 vulnerabilities "Basic Authentication" lives another day! Due to COVID-19, Microsoft and Google will keep "Basic Authentication" around for a little while longer EARN IT Act: call your Senator before it is too late! T...

SN 762: Virus Contact Tracking

April 15, 2020 01:50 - 1 hour - 50.8 MB

Apple+Google Covid Tracker is Secure and RIP John Conway, Creator of The Game of Life Apple & Google Virus Contact Tracing: secure and effective Zoom gets another Zoom-bombing mitigation... and a Class-Action Lawsuit Meanwhile, Zoom has enlisted the aid of Alex Stamos Zoom creates a CISO Council What's next for Zoom? Browser Security News: Chrome 81 and Firefox 75 Android Apps Again in the Crosshairs Sandboxie goes Open Source RIP John Conway, creator of Conway's Game of Life We i...

SN 761: Zoom Go Boom

April 08, 2020 02:52 - 1 hour - 46.3 MB

Zoom is a security nightmare - from zoombombing to encryption issues, Steve Gibson runs down Zoom's security concerns. Plus, Jitsi is a great alternative! Mozilla just patched a pair of CRITICAL 0-days Eight security bugs eliminated from Chrome last week Safari gets a bunch of very important fixes Chrome and Edge join Mozilla in postponing the deprecation of TLS v1.0 and v1.1 Chrome team reversing themselves on the enforcement of Same Site cookies Edge with Vertical Tabs and Smart Cop...

SN 760: Folding Proteins

April 01, 2020 01:45 - 1 hour - 42.1 MB

iOS VPN bug, Coronavirus Folding@Home VPN bug in iOS 13.4 Folding@Home - how to donate your unused CPU cycles to help provide answers to COVID-19. RDP and VPN use skyrocketing To 'www' or not to 'www' Firefox 76 to finally stop assuming "HTTP" Google again revises its schedule for Chrome releases Microsoft moves to support "Shadow Stacks" Cloudflare's 1.1.1.1 DNS is audited by KPMG We invite you to read our show notes at https://www.grc.com/sn/SN-760-Notes.pdf Hosts: Steve Gibson ...

SN 759: TRRespass

March 24, 2020 22:10 - 1 hour - 52.3 MB

This week's stories: Two new un-patched 0-days affecting billions of Windows users - here is the fix! Mozilla reversed itself on TLS v1.0 and 1.1 deprecation... due to the coronavirus A micropatch for Win7 and Server 2008 Chrome's release schedule has been impacted by the coronavirus Avast emergency-disables their internal JavaScript emulator CookieThief - "FireSheep evolves for the 21st century" PwnToOwn Spring 2020 winners Steve's coronavirus journey The fixes for RowHammer have ...

SN 758: The SMBGhost Fiasco

March 18, 2020 00:07 - 2 hours - 58.3 MB

This Week's Stories: Does Steve have coronavirus? Maybe? He got very sick over the weekend and is still coughing, but he couldn't get tested. Mayhem ensues after last week's Patch Tuesday List of free technology services during coronavirus, from Adobe to Zoom The state of open source vulnerabilities The "EARN IT" act is a despicable attack on encryption and freedom of speech. Please call your congressperson and tell them not to support it. The SMBGhost Fiasco Hosts: Steve Gibso...

SN 757: The Fuzzy Bench

March 11, 2020 01:54 - 2 hours - 55.7 MB

This Week's Stories Microsoft, Google, LogMeIn & Cisco offer limited-time free use of telecommuting Tools Hack the Pentagon! The Android security dilemma AMD processors get some unwelcome but necessary side-channel attack scrutiny Intel also has some serious new trouble on its hands SETI@home shuts down its distributed computing project after 21 years Critical PPP daemon flaw opens most Linux systems to remote hackers FuzzBench: fuzzer benchmarking as a service Hosts: Steve...

SN 756: Kr00k

March 04, 2020 04:08 - 2 hours - 55.3 MB

This Week's Stories Lets Encrypt hits 1 BILLION certs Pakistan passes Internet censorship law Clearview AI breach: clients and searches stolen Swiss government submits criminal complaint over CIA Crypto spying scandal Ghostcat - (Apache) Tomcat Users: Update NOW! Revisiting OCSP Must Staple Kr00k: serious WiFi vulnerability affecting more than a billion devices Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. You ...

SN 755: Apple's Cert Surprise

February 26, 2020 03:12 - 2 hours - 61.2 MB

This Week's Security News: More Windows 10 lost profile pain A micropatch for the jscript.dll problem Coming in the next Feature Release (Win10 2004): optional device driver updates A new attack on 4G LTE and 5G Starting today: DoH by default on Firefox A new next-generation WebAssembly sandbox is coming first to Linux and Mac and then to Windows Chrome was just updated to close a 0-day attack Safari will only trust certificates with a validity of 398 days or less Hosts: St...

SN 754: The Internet of Troubles

February 19, 2020 03:04 - 1 hour - 47.6 MB

TWiT Audience Survey- ENDS FEBRUARY 19TH!!! It's time for TWiT's annual audience survey and we want to hear from you! It only takes five minutes. Please visit twit.tv/survey and let us know what you think. There's no sign-up form and we don't track you. Your feedback helps us make TWiT even better." This Week's Stories How to fix the Windows 7 "You don't have permission to shut down this computer." error Win10's "One Button PC Reset" fails after KB4524244. And, also... "The new disap...

SN 753: Promiscuous Cookies

February 12, 2020 03:03 - 1 hour - 53.4 MB

Twitter, Google, and Facebook tell Clearview AI to stop stealing your face to catch crooks The NIST is testing methods to recover data from smashed smartphones Whoa! We get to REMAIN with Security Essentials under Windows 7! Microsoft drops a fix for the wallpaper stretch black screen Windows 7 users are being told: "You don't have permission to shut down this computer." Win10 Firefox users being "reminded" about Edge Last week Google closed an Android RCE flaw in the BlueTooth...

SN 752: The Little Red Wagon

February 05, 2020 02:31 - 2 hours - 55.4 MB

This Week's Stories: - L1D Eviction Sampling becomes "CacheOut" - Only one final version of Windows? - Windows 7 and the Free Software Foundation - Windows 7's final patch broke wallpaper stretching - RCE Exploit for Windows RDP Gateway Demoed by Researcher - Google more than doubles its own bug bounty record - The return of Roskomnadzor! - Facebook DID get fined, but not by Russia - who exactly owns our biometric data? - Avast Jumpshot missed the hoop - An Update on the WireGuar...

SN 751: SHAmbles

January 29, 2020 01:37 - 1 hour - 52.1 MB

This Week's Stories: Is Apple actually encrypting our iCloud storage backups? 250 Million Microsoft Customer Support Records Exposed Online New York state is aiming to ban the use of public funds for Ransomware New Muhstik Botnet Attacks Target Tomato Routers Chrome under attack from browser extensions Firefox under attack from browser extensions NIST publishes a new Privacy Framework Hacker Leaks More Than 500K Telnet Credentials for IoT Devices A Welcome "Micro Patch" for the Win...

SN 747: The Year's Best

December 31, 2019 15:30 - 1 hour - 49.4 MB

The best of Security Now from 2019. Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. You can submit a question to Security Now! at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

SN 746: A Decade of Hacks

December 24, 2019 00:21 - 1 hour - 47.1 MB

On this Eve of 2020, we look back over the hacks of the past decade: The big news of 2010 was Stuxnet -- Boy did THAT make an impression Operation Aurora - the hack that changed Google The Sony Playstation Hack And then we have... Diginotar Edward Snowden The Target hack The Adobe hack Silk Road takedown Have I Been Pwned? The hack of Sony Pictures The hack of Mt. Gox Heartbleed RowHammer Ashley Madison data breach SIM swapping The Ukraine power grid hacks DNC hack Yahoo h...

SN 745: PlunderVolt

December 18, 2019 02:38 - 2 hours - 56.6 MB

This Week's Stories: Google turns over 1500 users' location data to catch Milwaukee arsonist Android's Messenger app offers its users verified SMS messaging conversations with supporting companies US Senate Judiciary Committee threatens Apple and Facebook Apple's iOS v13.3 adds support for hardware key dongle authentication in Safari Patch Tuesday shuts down a widespread elevation of privilege vulnerability Researchers discover prime factor collisions in active RSA certificates ...

SN 744: VPN-geddon Denied

December 11, 2019 03:56 - 1 hour - 50.9 MB

This Week's Stories Microsoft has started forcing feature updates on people who don't want them. Bypass to continue obtaining Win7 updates created. Microsoft's Project Verona continues moving forward. Microsoft's RDP client for iOS is back. Avast / AVG in the doghouse. Making a mountain out of a VPN molehill. We invite you to read our show notes at https://www.grc.com/sn/SN-744-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows...