Short Explanations Security: Recent Episodes

Short Explanations

Chaim Cohen and Tom Webster try to explain security topics in an easy to understand way.

View Details

Today we talk about two different scams. One involves losing your reward points to be purchased by others (you if you are mean), for real money.

The second is why gift card scams work.

email the show: hosts (at) shortexplanations (dot) com

View Details

Show Notes:On today’s episode we talk about the top 10 things that CISA says is misconfigured.

  • CISA Guide

email the show: hosts (at) shortexplanations (dot) com

View Details

On today’s show we remind everyone to update your computers. Specifically we talk about a flaw in WebP, a lesser known standard that was recently pactched. It is also Cybersecurity Awareness Month, so we go through the steps CISA has told us to do.

  • WebP
  • CISA Guide (Warning PDF)

email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

We get a good, but unexpected update about a site we have recommended in the past. PrivacyGuides.org. If you ever wanted to know what was the best privacy focused tool, PrivacyGuides.org is your place. We won’t mention the other site.

Buy us a Coffee

email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

On this episode we talk about various tracking signals:

  • Proxy Metrics (this person buys a lot of 3D Printer filament, maybe we should advertise 3D printer nozzles)
  • Phone Company Tracking
  • GPS
  • Web Tracking (like buttons, Google Analytics)
  • App Permissions (Location, Network Scanning, etc)
  • Payment Tracking
  • Rewards Cards (Starbucks, Kroger Plus, etc)
  • Debit/Credit tracking
  • Physical Tracking
  • BLE Beacons
  • Wifi Beacons
  • Facebook is not hot-micing your phone

Buy us a Coffee

email the show: hosts (at) shortexplanations (dot) com

View Details

We bring back InfoSecSherpa about what is bothering her in infosec. Today we talk about conferences, specifically HackSummerCamp in Blackhat, Bsides, and Defcon. Maybe you should focus on the smaller conferences, and work your way up.

InfoSecSherpa Linktree.

InfoSecSherpa Twitter

email the show: hosts (at) shortexplanations (dot) com

View Details

On this episode we give a very brief overview of what DNS is. We explain the joke of why it is never DNS, but often it is.

  • https://www.internetsociety.org/resources/deploy360/dns-privacy/intro/
  • https://en.wikipedia.org/wiki/DNS_over_HTTPS
  • https://en.wikipedia.org/wiki/DNS_over_TLS
  • https://en.wikipedia.org/wiki/DNSCrypt
  • https://www.cloudflare.com/learning/dns/dns-over-tls/

The best way to help the show is to subscribe to the podcast, and subscribe on youtube. Donations always help.

email the show: hosts (at) shortexplanations (dot) com

View Details

CIA (Not that CIA)

We talk about what CIA is, from what it stands for, and how to start to implement it.

  • Confidentiality
  • Integrity
  • Availability

The best way to help the show is to subscribe to the podcast, and subscribe on youtube. Donations always help.

[]

email the show: hosts (at) shortexplanations (dot) com

View Details

TOTP

  • Randomness
  • RNGs
  • PRNGs
  • Seeded PRNGs
  • Hash Functions
  • What are they / Where are they used?
  • Important to keep in mind that there are crytpographic and non-cryptographic hash functions
  • TOTP combines Seeded PRNGs and Cryptographic Hash Functions to generate predictable, “random” codes using a seed and the current time.
  • As long as your device has the correct time, you can generate the correct code
  • This seed is present on your device (usually loaded through a QR code) and on the server.
  • When you log in, the server knows what the code should be (based on current time), so it can confirm that you have the right code

email the show: hosts (at) shortexplanations (dot) com

View Details

News

  • HP Printer Update Shenanigans (also HP 9020e - error code 83C0000B)
  • Just buy the Brother Laser Printer Thing
  • .zip tld is a nightmare
  • How to share Netflix with Tailscale
  • Section 230 is still good
  • Keepass Vuln - Physical Attack

Want to join our signal group? It is free, just email the show

email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

We bring back Yael Grauer onto the show to talk about privacy. We have discussed privacy in parts before, but specifically, Yael, did a huge opt out list that we want details on. Did you know your info is on these data broker sites. Yael tells out how to get rid of the info, or if it is even worth it.

Want to join our signal group? It is free, just email the show

email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

On this show, we have Tom explain to us what oAuth is, and should we really care about it.

Pros:

  • Easy
  • Less accounts to track/manage

Cons:

  • Account linking (kinda)
  • [DEPENDING ON IMPLEMENTATION] Your login to a third-party website is controlled by your oauth provider (who you sign in with)
  • Oauth provider bans will affect more than just your primary account

Join our signal group.

As always, Like, Comment, and Subscribe

email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

On this episode we talk about un-needed security. These are the things that you shouldn’t buy/install/use.

  • Virus Scanning
  • Phone Scanning Apps
  • Identity Protection
  • Military Grade Encryption
  • VPNs that claim to stop hackers
  • Any tech product on an informercial

email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

On this show we discuss the big players in secure messengers. Not to spoil the fun, but we both highly recommend Signal.

  • Threat Model discussion
  • What is our “definition of secure messenger”
  • WhatsApp
    • Group and individual messages are encrypted
    • Uses the Signal Protocol
    • Can see metadata
    • Meta harvests the data as much as possible
  • Facebook Messenger
    • Only in secret mode
    • Secret mode is one device only
    • Developed the same way as WhatsApp
  • Threema
    • Audited, recently had an issue
    • Paid
    • Uses usernames, not phone numbers
  • iMessage
  • RCS
  • Signal
  • Telegram is BAD

email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

Editor’s Note: Sorry the first few seconds of the audio was bad.

We bring Yael Grauer onto the show discuss her research:

Turns out Yael liked our VPN show. Go check it out. Go follow her:

Want to join our signal group? It is free, just email the show

email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

Browsers:

  • Use Firefox or Chrome (Tom prefers Firefox)
  • Edge is fine
  • Safari is fine (Haim uses iOS and Mac)
  • Stay away from alternative / non-mainstream browsers
  • Addons
    • uBlock Origin
    • Your favorite password manager
    • Extension Security
  • History of browsers
  • iOS browers
  • Android browsers

email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

VPNs:(we are not making a recommendation)

  • What is a VPN
  • What isn’t a VPN
  • Should you use a VPN
  • anonymous vs obfuscation
  • VPN vs Tor
  • Are VPNs safe
  • pivpn.io
  • tailscale
  • Private Relay
  • next show is from the consumer reports who tried all the VPNs

Join the signal group by emailing us.

email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

We speak to InfoSecSherpa about what is bothering her in infosec. Turns out there is a lot of problems with companies and employers requiring a whole bunch of certificates and degrees for entry level jobs. Are certificates necessary (They are not), or are we just making life harder for everyone?

InfoSecSherpa Linktree.

InfoSecSherpa Twitter

Join the signal group by emailing us.

email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

2FA:

  • What are Factors (Knowledge, Have, Are, Location)
  • Email
  • SMS
  • Dongle-based Code (RSA Tokens, etc)
  • Push-Based Auth (Duo)
  • TOTP (Google Authenticator, Authy, etc)
  • Yubico OTP
  • U2F, FIDO2, WebAuthn
  • Fall Back Safety

[If you are not subscribed to short explanations, please sign up. We forwarded the feed from the other podcast for a month.]

email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

[If you are not subscribed to short explanations, please sign up. We forwarded the feed from the other podcast for a month.]

Show Notes:

  • Don’t re-use passwords across sites
  • How do you even remember each password?
  • Using a password scheme (MyPassw0rd-facebook.com) - This is a bad idea because password cracking software knows this trick and will compromise all of your accounts
  • First: Use your password manager generator
  • Chrome Built in / Firefox built in
  • Cred Stuffing
  • Password Rules
  • WEIRD password rules (8 chars, what?!)
  • Longer is Better*Sharing passwords

Join our signal group. Find us for an invitation

Email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

[If you are not subscribed to short explanations, please sign up. We forwarded the feed from the other podcast for a month.]

We’ve always recommended password managers. Both Tom and Chaim are using Bitwarden, but we have recommended LastPass in the past. In fact we’ve had LastPass on the old show a few times.

On December 21 they explained a breach that caused user vaults to be lost. That is bad. We explain why we are now recommending that you should move.

However, if the choice is LastPass or nothing, stick with LastPass. They have done more for protection than others, but the fact they are not keeping up with newish protocols is a cause for concern.

No Free TierBad legacy securityPoor(ish) Disclosure

Join our signal group. Find us for an invitation

Email the show: hosts (at) shortexplanations (dot) com

View Details

Youtube Video

[If you are not subscribed to short explanations, please sign up. We forwarded the feed from the other podcast for a month.]

Anytime you start a new project, your first goal is to have a backup. That’s what today’s episode is about. Things have changed since we covered it last, so here we go again.

First figure out what you want to backup. It should be way less than before. Most of everything already lives somewhere else. Your bills, statements, and other things have homes somewhere else. You are probably subscribing to music and movies, so that is somewhere else. Basically your documents.

We recommend a cloud provider. They are all good enough for most people.

If you want something more advanced, we mention SyncThing, Restic, and Synology.

Join our signal group. Find us for an inviation

Email the show: hosts (at) shortexplanations (dot) com

View Details

Welcome to our new podcast. We are a beginner security podcast where we try to explain what is going on in the security world in an easy to understand way. Please join us.

In this episode we explain why we’ve moved, and what we plan on doing with this show. Please stay, and join our signal group for more.

email the show: hosts (at) shortexplanations (dot) com

View Details

SEKURITY