Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
News, opinion, advice and research: Chet and Duck (Chester Wisniewski and Paul Ducklin) bring you their unique and entertaining combination of all four in their regular quarter-hour programme.
Chester's been on the road, so this epsiode of the Chet Chat is a couple of days late for logistical reasons.
We apologise for that, but Chet and Duck think it's no less interesting nevertheless!
In fact, this week's main story - the two-in-a-row exploits against Android code verification - intrigued your presenters so much that they resolved to link up and record this show, come what may.
And so, here it is: SSCC Episode #113.
(You can keep up with our podcasts via RSS or iTunes, and catch up on previous Chet Chats and other Sophos podcasts by browsing our podcast archive.)
The news wires have been buzzing with the "master keys" attack, and the "extra field" attack, both of which let you create Android Package files (APKs) that show one set of content to Google's cryptographic verification, and another to the installer.
Chet and Duck explain what happened, come up with some ideas that would have avoided the problem in the first place, explain what to do about it, and wonder how long before the fixes are on your handset.
From Android to iOS, where Tumblr published a version of its app that somehow managed to leave out the part that encrypts your PII before sending it over the internet.
Chet wonders how the average user is supposed to spot that sort of bug.
Nintendo got pounded by crackers who mounted a month-long password guessing attack.
The crooks only got hold of 24,000 passwords as a result (only!), and it looks as though those successes were largely down to using dictionaries of usernames and passwords from earlier hacks.
What to do? Federated identity? Password managers? A slimmer digital lifestyle?
Chet and Duck discuss the pros and cons of various ways to address the problem of password re-use.
And Chet's going to be at BlackHat 2013, and at DEF CON, so be sure to look him up in Vegas and say, "Hi."
Duck won't be there in body but you will find him present in mind and spirit, as he's putting together a special #sophospuzzle for the occasion.
The puzzle will go up on Naked Security, so everyone can have a go, but BlackHatters can enter at Sophos's booth at the trade show and win a secret prize!
(It's a cool secret prize, which Duck lets slip in the podcast, and Chester bemoans being ineligible to win.)
Don't forget: for a regular Chet Chat fix, follow us via RSS or on iTunes.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Filed Under: Featured, Podcast
Episode #110 of our popular Chet Chat podcast series is out.
Chet and Duck (Chester Wisniewski and Paul Ducklin) offer you an infusion of interesting insights into the latest computer security news.
If this is your first time listening to the Chet Chat: episodes come out every two weeks, and usually last about a quarter of an hour.
That makes the Chet Chat podcast ideal for your daily commute or for a spot of lunchtime listening.
(You can keep up with our podcasts via RSS or iTunes, and catch up on previous Chet Chats and other Sophos podcasts by browsing our podcast archive.)
• Microsoft Skype. Is it really a privacy nightmare that Microsoft is extracting URLs from Skype instant messages to scan for dodgy links? Can we reasonably infer from this that Redmond must be listening to our calls as well?
• The IP Commission Report. A US think tank published a report which seems to suggest that we should go after pirates by locking your computer and forcing you to contact law enforcement to get the password. Legalised ransomware? Is that really what the report said? And, even if it did, is that such a bad idea?
• Small business cybersecurity. A UK survey claims that only 36% of small businesses patch regularly. Should we be surprised? Does it matter? What about the 17% that the survey says don't patch (or concern themselves with cybersecurity) at all?
• CSAWs. Cybersecurity Awareness Weeks are a good idea. But what should those of us who already care about cybersecurity do by way of participating?
• The AusCERT 2013 #sophospuzzle. The fastest three finishers didn't win a prize because the prize draw included all 58 finishers randomly. So Chester persuaded Duck to give them a shout out in the podcast: @pirate_security, Lee Cronin and Phil Rhea.
Don't forget: for a regular Chet Chat fix, follow us via RSS or on iTunes.
http://twitter.com/NakedSecurity
http://twitter.com/duckblog
Image of small business crushed by foot courtesy of Shutterstock.
Tags: #sophospuzzle, chet chat, CSAW, ip commission, Patching, Podcast, ransomware, skype, Small Business, sscc, surveillance
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
I had the privilege of interviewing Forbes journalist and author Parmy Olson after the RSA Conference in San Francisco in February.
We sat down in the beautiful Yerba Buena Gardens to discuss her book "We are Anonymous" and her thoughts on the upcoming (at the time) sentencing of the LulzSec hackers.
We also discussed her recent visit to Mobile World Congress in Barcelona and her thoughts on Firefox OS.
It might seem a bit late to publish this podcast, but there was a press embargo in the UK at the time it was recorded and we decided to be respectful of that and wait to publish until the accused were convicted and sentenced.
You may notice some odd noises in the background -- a dog barking, a shopping cart and birds tweeting. I interviewed Parmy in the middle of the park, so you should consider any extraneous noises as ambiance.
(If this is your first time listening to a Sophos podcast they are ideal for your daily commute or for a spot of lunchtime listening. There's an archive of previous podcasts - you can also get our podcasts via RSS or iTunes.)
Have you joined thousands of others, and become a loyal listener to the "Chet Chat" yet?
Sophos has been recording security-related podcasts since 2006.
One of our most popular shows is the regular "Chet Chat" series, hosted by Senior Security Advisor Chester Wisniewski.
Chet discusses the latest security news with a series of experts, and offers actionable advice on what you and your company should do about it.
The latest "Chet Chat", episode 103, features Chet and popular guest Paul "Duck" Ducklin, who bring you their customary and entertaining mixture of insight, expertise, scepticism, and advice:
(24 February 2013, duration 15:24 minutes, size 9.3 MBytes)
Sophos Security Chet Chat #103 (MP3)
The Chet Chat typically lasts about 15 minutes, so why not make it a regular quarter-hour in your lunchtime security fix, or listen to it as part of your commute?
And why not take a look at the back-catalogue of Sophos Podcasts in our archive? We have loads of interesting stuff for your listening pleasure.