technology

SN 1016: The Bluetooth Backdoor - North Korean Texans, Apple Pushes Back
Security Now (Audio)March 12, 2025
1016
2:56:45162.04 MB

SN 1016: The Bluetooth Backdoor - North Korean Texans, Apple Pushes Back

Utah passes age verification requirement for app stores. The inside story on fake North Korean employees. Is that a Texas accent? An update on the ongoing Bybit cryptoheist saga. The industry may be making some changes in the wake of the Bybit attack. Apple pushes back legally against the UK's secr...

SN 1015: Spatial-Domain Wireless Jamming - Firefox Privacy Policy, Signal Leaving Sweden?
Security Now (Audio)March 05, 2025
1015
2:52:47158.39 MB

SN 1015: Spatial-Domain Wireless Jamming - Firefox Privacy Policy, Signal Leaving Sweden?

Firefox amends their privacy policy -- the world melts down. Signal threatens to leave Sweden. Aftermath of the massive $1.5 billion Bybit ETH heist. It turns out that it wasn't actually Bybit's fault. "The Lazarus Bounty" monitoring and management site. Mozilla's commitment to Manifest V2 (and the...

SN 1014: FREEDOM Administration Login - Apple's UK Privacy Showdown, $1.5 Billion Crypto Heist
Security Now (Audio)February 26, 2025
1014
2:39:37146.48 MB

SN 1014: FREEDOM Administration Login - Apple's UK Privacy Showdown, $1.5 Billion Crypto Heist

Apple disables Advanced Data Protection for new UK users. Paying ransoms is not as cut and dried as we might imagine. Elon Musk's "X" social media blocks "Signal.me" links. Spain's soccer league blocks Cloudflare and causes a mess. Two new (and rare) vulnerabilities discovered in OpenSSH. The U.S. ...

SN 1013: The Chrome Web Store is a mess - Apple Encryption in the UK, Texas Vs. DeepSeek
Security Now (Audio)February 19, 2025
1013
2:31:28138.86 MB

SN 1013: The Chrome Web Store is a mess - Apple Encryption in the UK, Texas Vs. DeepSeek

US lawmakers respond to the UK's outrageous demand about Apple's encryption. What, exactly, is a "backdoor", and can a "backdoor" NOT be secret? Highlights from last week's Windows' Patch Tuesday. A look into RansomHub: The latest king of the Ransomware hill. "TOAD": Telephone-Oriented Attack Deliv...

SN 1012: Hiding School Cyberattacks - SparkCat, Decrypting ADP, AI Fuzzing
Security Now (Audio)February 12, 2025
1012
2:41:26148.02 MB

SN 1012: Hiding School Cyberattacks - SparkCat, Decrypting ADP, AI Fuzzing

New "SparkCat" secret-stealing AI image scanner discovered in App and Play stores. The UK demands that Apple does the impossible: decrypting ADP cloud data. France moves forward on legislation to require backdoors to encryption. Firefox moves to 135 with a bunch of useful new features. The Five Eye...

SN 1011: Jailbreaking AI - Deepseek, "ROUTERS" Act, Zyxel Vulnerability
Security Now (Audio)February 05, 2025
1011
3:01:18166.12 MB

SN 1011: Jailbreaking AI - Deepseek, "ROUTERS" Act, Zyxel Vulnerability

Why was DeepSeek banned by Italian authorities? What internal proprietary DeepSeek data was found online? What is "DeepSeek" anyway? Why do we care, and what does it mean? Did Microsoft just make OpenAI's strong model available for free? Google explains how generative AI can be and is being misused...

SN 1010: DNS Over TLS - Record DDoS, Hackers Get Hacked
Security Now (Audio)January 29, 2025
1010
2:40:40147.25 MB

SN 1010: DNS Over TLS - Record DDoS, Hackers Get Hacked

eM Client CAN be purchased outright. An astonishing 5-year-old typo in MasterCard's DNS. An unwelcome surprise received by 18,459 low-level hackers. DDoS attacks continue growing, seemingly without any end in sight. Let's Encrypt clarifies their plans for 6-day "we barely knew you" certificates. Sp...

SN 1009: Attacking TOTP - Force-Installed Outlook, DJI Firmware Update
Security Now (Audio)January 22, 2025
1009
3:07:19171.65 MB

SN 1009: Attacking TOTP - Force-Installed Outlook, DJI Firmware Update

What do we learn from January's record breaking 0-day critical Patch Tuesday? Microsoft to "force-install" a new Outlook into all Windows 10 and 11 desktops? GoDaddy required to get much more serious about its hosting security. More age verification enforcement is coming, including globally. What a...

SN 1008: HOTP and TOTP - SyncThing, Auto-Updates, Sci-Fi Recs
Security Now (Audio)January 15, 2025
1008
2:49:35155.45 MB

SN 1008: HOTP and TOTP - SyncThing, Auto-Updates, Sci-Fi Recs

Meta winds down 3rd-party content filtering. Is encryption soon to follow? Taking over abandoned Command & Control server domains (strictly for research purposes only). IoT devices to get the "Cyber Trust Mark" — Will anyone notice or care? "SyncThing" receives a (blessedly infrequent) update. ...

SN 1007: AI Training & Inference - Unencrypted Email, Doom Captcha
Security Now (Audio)January 08, 2025
1007
2:46:51153.55 MB

SN 1007: AI Training & Inference - Unencrypted Email, Doom Captcha

The consequences of Internet content restriction. The measured risks of 3rd-party browser extensions. The consequences of SonicWall's unpatched 9.8 firewall severity. The incredible number of still-unencrypted email servers. SonicWall vulnerability patching Shadowserver Foundation & eMail Encry...

SN 1006: Best of 2024 - Apple's Secret Backdoor, CrowdStrike Catastrophe, Recall's Privacy Nightmare
Security Now (Audio)December 23, 2024
1006
2:32:48140.07 MB

SN 1006: Best of 2024 - Apple's Secret Backdoor, CrowdStrike Catastrophe, Recall's Privacy Nightmare

Leo revisits some of the year's top Security Now segments of 2024. 956. Apple's Hardware Backdoor: Steve reflects on the previous week's 'The Mystery of CVE-2023-38606' deep-dive. Did Apple deliberately designed a secure backdoor? 960. Unforeseen Consequences of Google's 3rd-party Cookie Cutoff: As...

SN 1005: 6-Day Certificates? Why? - Android Anti-Tracking, MFA lLogin Bypass, BIMI
Security Now (Audio)December 18, 2024
1005
2:24:42132.65 MB

SN 1005: 6-Day Certificates? Why? - Android Anti-Tracking, MFA lLogin Bypass, BIMI

Is AI the Wizard of Oz? Or is it more? Microsoft's long standing effective MFA login bypass. Is TPM 2.0 not required after all for Windows 11? Meet 14 North Korean IT workers who made $88 million from the West. Android updates its Bluetooth tracking with anti-tracking. The NPM package manager repos...

SN 1004: A Chat with GPT - China's Telecom Hack, Microsoft Activation Cracked, Coding with ChatGPT 4o
Security Now (Audio)December 11, 2024
1004
2:33:05140.33 MB

SN 1004: A Chat with GPT - China's Telecom Hack, Microsoft Activation Cracked, Coding with ChatGPT 4o

This week, Steve and Leo discuss the recent 'Salt Typhoon' hack of U.S. telecom providers by China, TPM 2.0 requirement for Windows 11, Microsoft's newly hacked Windows activation system, Apple patenting AI facial and body recognition, and much more. Steve also shares an intriguing conversation he ...

SN 1003: A Light-Day Away - Digital Epileptic Seizures, Tor Needs You, Zello Password Panic, Wireguard's Open Port Debate
Security Now (Audio)December 04, 2024
1003
2:18:12126.76 MB

SN 1003: A Light-Day Away - Digital Epileptic Seizures, Tor Needs You, Zello Password Panic, Wireguard's Open Port Debate

Steve Gibson and Leo Laporte discuss Microsoft's clarification about AI training data usage, a fascinating breakthrough in understanding autonomous vehicle vulnerabilities, and an urgent call for help from the Tor Network. The show culminates in an in-depth exploration of NASA's incredible Voyager ...

SN 1002: Disconnected Experiences - "Nearest Neighbor" Attack, Repo Swatting, the Return of Recall
Security Now (Audio)November 27, 2024
1002
2:32:04139.44 MB

SN 1002: Disconnected Experiences - "Nearest Neighbor" Attack, Repo Swatting, the Return of Recall

What's the new "nearest neighbor" attack and how do you defend against it? Let's Encrypt just turned 10. What changes has it wrought? Now the Coast Guard is worried about Chinese built ship-to-shore cranes. Pakistan becomes the first country to block Bluesky. There's a new way to get Git repos "swa...

SN 1001: Artificial General Intelligence (AGI) - Gmail Temp Addresses, Russia's Internet Off Switch
Security Now (Audio)November 20, 2024
1001
2:26:44134.55 MB

SN 1001: Artificial General Intelligence (AGI) - Gmail Temp Addresses, Russia's Internet Off Switch

How Microsoft lured the US Government into a far deeper and expensive dependency upon its cybersecurity solutions. Gmail to offer native throwaway email aliases like Apple and Mozilla. Russia to ban several additional hosting companies and give its big Internet disconnect switch another test. Russi...

SN 1000: One Thousand - Windows Server 2025, Malicious Python Typos
Security Now (Audio)November 13, 2024
1000
2:17:4363.22 MB

SN 1000: One Thousand - Windows Server 2025, Malicious Python Typos

Bitwarden reaffirms it's commitment to open source. The rights of German security researchers are clarified. Australia to impose age limits on social media. Free Windows Server 2025 anyone? UAC wasn't getting in the way enough, so they're fixing that. "From Russia with fines" -- obey or else. South...

SN 999: AI Vulnerability Discovery - RT's AI TV Hosts, Windows 10 Updates
Security Now (Audio)November 06, 2024
999
1:53:0551.92 MB

SN 999: AI Vulnerability Discovery - RT's AI TV Hosts, Windows 10 Updates

Google's record-breaking fine by Russia. (How many 0's is that?) RT's editor-in-chief admits that their TV hosts are AI-generated. Windows 10 security updates set to end next October... or are they? When a good Chrome extension goes bad. Windows .RDP launch config files. What could possibly go wron...

SN 998: The Endless Journey to IPv6 - AI-Driven Encryption, Session Messenger, IPv6
Security Now (Audio)October 30, 2024
998
2:53:5679.78 MB

SN 998: The Endless Journey to IPv6 - AI-Driven Encryption, Session Messenger, IPv6

Apple proposes 45-day maximum certificate life. SEC fines four companies for downplaying their SolarWinds attack severity. Google adds 5 new features to Messenger including inappropriate content. Does AI-driven local device-side filtering resolve the encryption dilemma forever? The very nice lookin...

SN 997: Credential Exchange Protocol - DJI Sues DoD, Quantum Vs. RSA, Lost MS Logs
Security Now (Audio)October 23, 2024
997
2:18:3563.59 MB

SN 997: Credential Exchange Protocol - DJI Sues DoD, Quantum Vs. RSA, Lost MS Logs

Did Chinese researchers really break RSA encryption? What did they do? What next-level terror extortion is being powered by the NPD breach data? The EU to hold software companies liable for software security? Microsoft lost weeks of security logs. How hard did the try to fix the problem? The Chines...