Zanurz się w nauce angielskiegoRabat -40% na roczny kurs wygasa w niedzielęSPRAWDŹ >>Zamknij

Security Now!

SN 984: CrowdStruck - Crowdstrike, Cellebrite, More Entrust

Dodany: 24 lipca 2024

Cellebrite unlocks Trump's would-be assassin's phone.
Cisco reported on a CVSS of 10.0
Entrust drops the other shoe
Google gives up on removing 3rd-party cookies
Miscellany
Snowflake and data...

SN 983: A Snowflake's Chance - CDN Safety, Microsoft's Behavior, CDK Ransomware Attack

Dodany: 17 lipca 2024

Using Content Delivery Networks Safely
The CDK Global Ransomware Attack
The IRS and Entrust
Polyfill.io fallout
Microsoft's Behavior
A Snowflake's Chance
Show Notes -...

SN 982: The Polyfill.io Attack - Entrust Responds, Passkey Redaction Attacks

Dodany: 10 lipca 2024

Entrust Responds
Other major Certificate Authorities respond
Passkey Redaction Attacks
Syncing passkeys
Port Knocking
Fail2Ban
The Polyfill.io Attack
Show Notes -...

SN 981: The End of Entrust Trust - Open SSH Vulnerability, SyncThing, Endtrust

Dodany: 3 lipca 2024

The regreSSHion Bug
50BTC moved
Voyager 1 Update
Email @ GRC
SyncThing
DNS queries
Recall
The End of Entrust Trust
Show Notes - https://www.grc.com/sn/SN-981-Notes.pdf
Hosts: Steve Gibson...

SN 980: The Mixed Blessing of Lousy PRNG - Kaspersky Ban, EU vs. Google's Privacy Sandbox

Dodany: 26 czerwca 2024

Expected follow-up on CVE-2024-30078
From Russia with Love
An EU privacy agency complains about Google's Privacy Sandbox?
Email @ GRC
Security Now SPAM?
Orange Tsai needs help!
Recall and 3rd...

SN 979: The Angle of the Dangle - "Recall" Recall, IT at the NYT, Private Cloud Compute

Dodany: 19 czerwca 2024

CVE-2024-30078
"Recall" has been recalled
Matthew Green on Apple's Private Cloud Compute
A WGET flaw with a CVSS of 10.0?
Thou shall not Resolve!
Email @ GRC
Downloading email with MailStore...

SN 978: The Rise and Fall of code.microsoft.com - Apple Password Manager, AI Coding

Dodany: 12 czerwca 2024

MS on Recall changes
Thanks for the "Memory"
New York Times (and Wordle) leak
Apple's own password manager app
DJI drones on the defensive
SlashData reveals some interesting developer...

SN 977: A Large Language Model in Every Pot - Problems With Recall, End of ICQ, Email @ GRC

Dodany: 5 czerwca 2024

"Tornado Notes"
Email @ GRC
Have I Been Pwned?
A new "supply chain" attack vector
Another CA in the DogHouse
ICQ to shutter its service
Steve reviews "Déjà vu"
Hide my email
Security in...

SN 976: The 50 Gigabyte Privacy Bomb - Google AI Workarounds, Microsoft Recall

Dodany: 29 maja 2024

The bigger problem with AI Overview
https://udm14.com/ -and- https://tenbluelinks.org/
The horses have left the barn
VPNs and Firewalls
Email @ GRC
Extension to fix Google search
Passwords...

SN 975: 312 Scientists & Researchers Respond - 3 Chrome Zero-Days, Free Laundry

Dodany: 22 maja 2024

When you're the biggest target...
Searching for Search
How long will a Windows XP machine survive unprotected on the Internet?
Free Laundry
VPNs and Firewalls
Netgate SG1100
Ad Industry vs....

SN 974: Microsoft's Head in the Clouds - 4-Digit Pins, Long Range Navigation, Microsoft

Dodany: 15 maja 2024

Picture of the Week.
Most to least common 4-digit pins.
Enhanced LORAN.
Passkeys.
Microsoft's Head in the Clouds.
Show Notes - https://www.grc.com/sn/SN-974-Notes.pdf
Hosts: Steve Gibson and...

SN 973: Not So Fast - GPS Vulnerabilites, VPN Flaw

Dodany: 8 maja 2024

The vulnerability of GPS
Is the sky falling on all VPN systems?
Multi-user Passkeys, YubiKeys?
The iCloud Keychain
The UK and Google's Topics
Show Notes -...

SN 972: Passkeys: A Shattered Dream? - IoT Default Passwords, Passkeys

Dodany: 1 maja 2024

GCHQ: No more default passwords for consumer IoT devices!
What happened with Chrome and 3rd-party cookies?
Race conditions and multi-threading
GM "accidentally" enrolled millions into "OnStar...

SN 971: Chat (out of) Control - Fuxnet, Android Quarantine, Gentoo

Dodany: 24 kwietnia 2024

What do you call "Stuxnet on steroids"??
Voyager 1 update
Android 15 to quarantine apps
Thunderbird & Microsoft Exchange
China bans Western encrypted messaging apps
Gentoo says "no" to AI...

SN 970: GhostRace - AT&T Breach Update, Cookie Notices, Router Buttons

Dodany: 17 kwietnia 2024

An update on the AT&T data breach
340,000 social security numbers leaked
Cookie Notice Compliance
The GDPR does enforce some transparency
Physical router buttons
Wifi enabled button pressers...

SN 969: Minimum Viable Secure Product - Dlink NAS Backdoor, Privnote, Crowdefense

Dodany: 10 kwietnia 2024

Out-of-support DLink NAS devices contain hard coded backdoor credentials
Privnote is not so "Priv"
Crowdfense is willing to pay millions
Engineers Pinpoint Cause of Voyager 1 Issue, Are Working...

SN 968: A Cautionary Tale - XZ Outbreak, AT&T Data Breach

Dodany: 3 kwietnia 2024

A near-Universal (Local) Linux Elevation of Privilege vulnerability
TechCrunch informed AT&T of a 5 year old data breach
Signal to get very useful cloud backups
Telegram to allow restricted...

SN 967: GoFetch - Apple vs. DOJ, ".INTERNAL" TLD

Dodany: 27 marca 2024

Apple vs U.S. DoJ
G.M.'s Unbelievably Horrible Driver Data Sharing Ends
Super Sushi Samurai
Apple has effectively abandoned HomeKit Secure Routers
The forthcoming ".INTERNAL" TLD
The United...

SN 966: Morris The Second - Voyager 1, The Web Turns 35

Dodany: 20 marca 2024

Voyager 1 update
The Web turned 35 and Dad is disappointed
Automakers sharing driving data with insurance companies
A flaw in Passkey thinking
Passkeys vs 2fa
Sharing accounts with Passkeys...

SN 966: Morris The Second - Voyager 1, The Web Turns 35

Dodany: 20 marca 2024

Voyager 1 update
The Web turned 35 and Dad is disappointed
Automakers sharing driving data with insurance companies
A flaw in Passkey thinking
Passkeys vs 2fa
Sharing accounts with Passkeys...