View Details
What to do if you want to carry on receiving episodes of the UIS Security Podcast. Depending on your setup, it might be very little...
* UIS Service Desk: servicedesk@uis.cam.ac.uk
* UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
* E-mail CERT: cert@cam.ac.uk
* Phish of the Day: https://help.uis.cam.ac.uk/service/security/stay-safe-online/phishing/phishy
* Sophos RDP report: https://sophos.com/rdp
* Patch RDP: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182
* Patch Sharepoint: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604
Subsequent to recording this, the audio files have been moved over to the SRCF, so that may well become the new home.
View Details
What if you had something to hide? Could you plant it in, say, a podcast episode with nobody noticing?
* UIS Service Desk: servicedesk@uis.cam.ac.uk
* UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
* E-mail CERT: cert@cam.ac.uk
* Phish of the Day: https://help.uis.cam.ac.uk/service/security/stay-safe-online/phishing/phishy
* National Cyber Security Centre: https://www.ncsc.gov.uk/
* US visas: https://www.nytimes.com/2019/06/02/us/us-visa-application-social-media.html
* AMCA breach: http://newsroom.questdiagnostics.com/AMCADataSecurityIncident
* Talktalk non-notification: https://www.bbc.co.uk/news/business-48351900
* MS patches include moribund OSes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
* Sensitive data on used hard drives: https://www.prnewswire.com/news-releases/blancco-reveals-42-of-used-drives-sold-on-ebay-are-holding-sensitive-data-300838201.html
* Windows Hello FIDO2 certified in 1903: https://nakedsecurity.sophos.com/2019/05/14/windows-10-brings-password-free-access-another-step-closer/
Royalty-free music from Purple Planet Music
View Details
Paul and Graham are joined by Joe Irvin who gives us the benefit of his experience fighting emotet. We also look at supply-chain attacks and cross-site scripting.
* UIS Service Desk: service-desk@uis.cam.ac.uk
* UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
* E-mail CERT: cert@cam.ac.uk
* Phish of the Day: https://help.uis.cam.ac.uk/service/security/stay-safe-online/phishing/phishy
* National Cyber Security Centre: https://www.ncsc.gov.uk/
* Exercise in a Box: https://www.ncsc.gov.uk/information/exercise-in-a-box
* Naked Security: https://nakedsecurity.sophos.com/
* Hot for Security: https://hotforsecurity.bitdefender.com/
* OWASP Top 10 (2017): https://www.owasp.org/images/7/72/OWASP_Top_10-2017_%28en%29.pdf.pdf
* OWASP Top 10 on LiL: https://www.linkedin.com/learning/learning-the-owasp-top-10
* ASUS: https://www.reuters.com/article/us-asus-cyber/asus-implements-fix-for-malware-attack-idUSKCN1R710X
* Bitlocker vulnerability: https://pulsesecurity.co.nz/articles/TPM-sniffing
* Second hand USB drives: https://www.comparitech.com/blog/information-security/secondhand-usb-drive-memory-stick-study/
* Japanese police charge 13-yr old: https://www.zdnet.com/article/japanese-police-charge-13-year-old-for-sharing-unclosable-popup-prank-online/
* Windows automatic updating changes: https://blogs.windows.com/windowsexperience/2019/04/04/improving-the-windows-10-update-experience-with-control-quality-and-transparency/#PLKYTL4ai2hMMybG.97
Royalty-free music from Purple Planet Music
View Details
Paul and Graham give their usual round-up of issues both within and outside the University; Graham takes a particular look at Cisco"s SmartInstall.
About four minutes into the episode, Paul alludes to a change in the way people contact CERT but wondered if it might be premature to
mention it. The day after we recorded this, an e-mail went out to the uis-announce mailing list detailing the way that security response
is to become a second-line service from 11 April with immediate issues being resolved by the UIS Service Desk. Perfect timing!
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- Phish of the Day: https://help.uis.cam.ac.uk/service/security/stay-safe-online/phishing/phishy
- National Cyber Security Centre: https://www.ncsc.gov.uk/
- Three Random Words: https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0
- The Human Factor: http://jennyradcliffe.com/the-deception-chronicles/
- US govt certificate non-renewal: http://jennyradcliffe.com/the-deception-chronicles/
- Tampa mayor Twitter hacked: https://nakedsecurity.sophos.com/2019/02/25/hijacker-pwns-tampa-mayors-account-2-weeks-before-election/
- Drupal patching: https://www.theregister.co.uk/2019/02/27/drupal_rce_exploits_seen_wild/
- Chrome flagging lookalikes: https://www.zdnet.com/article/google-chrome-to-get-warnings-for-lookalike-urls/
Royalty-free music from Purple Planet Music
View Details
Graham reports on his tests of systems across the University and the news isn't great, particularly on the password front. Apparently we still have work to do in getting the message across. We also do our usual trawl of security news inside and outside the University.
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- National Cyber Security Centre: https://www.ncsc.gov.uk/
- Three Random Words: https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0
- UIS Friendly Probing: https://probing.csx.cam.ac.uk/
- Home routers: https://cyber-itl.org/assets/papers/2018/build_safety_of_software_in_28_popular_home_routers.pdf
- Phish bypassing (SMS) 2FA: https://blog.certfa.com/posts/the-return-of-the-charming-kitten/
- Worst password list: https://www.teamsid.com/100-worst-passwords-top-50/
- USDHS copying data: https://www.oig.dhs.gov/sites/default/files/assets/2018-12/OIG-19-10-Nov18.pdf
- MS combatting scam support: https://blogs.microsoft.com/on-the-issues/2018/11/29/new-breakthroughs-in-combatting-tech-support-scams/
- Chrome mitigates ads masquerading as clickbait: https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
- Edge and the Mail: https://uk.pcmag.com/news-analysis/119288/microsofts-edge-browser-says-not-to-trust-the-daily-mail
- Wikipedia and the Mail: https://www.theguardian.com/technology/2017/feb/08/wikipedia-bans-daily-mail-as-unreliable-source-for-website
Royalty-free music from Purple Planet Music
View Details
As well as the usual news from the University and further afield, Paul and Graham reflect on the last year, consider password managers and
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- Australian anti-encryption bill: https://thehackernews.com/2018/12/australia-anti-encryption-bill.html
- Russian involvement in bit for US defence: https://www.bbc.co.uk/news/world-us-canada-46489689
- HR phish: https://twitter.com/InfoSecSherpa/status/1062036305146724354
- False detail on Google Maps: https://www.businessinsider.com/scammers-edit-google-maps-bank-listings-fraud-2018-11?r=US&IR=T
- Dashlane: https://www.dashlane.com/
- Keepass: https://www.keepass.info/
Royalty-free music from Purple Planet Music
View Details
Paul goes through the news headlines in the University of Cambridge and further afield in a shorter-than-usual episode.
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- Mobile third-party tracking: https://arxiv.org/pdf/1804.03603.pdf
- Password length and re-use: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3142270
-
OneReset: https://www.cyberaware.gov.uk/blog/one-reset-you-need-protect-your-emails-hackers
Royalty-free music from Purple Planet Music
View Details
Paul and Graham are joined this month by Anna Langley who talks about developments to the friendly probing suite. We also talk about URL shorteners and Graham's observations from recent penetration tests.
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- UIS Friendly Probing: https://probing.csx.cam.ac.uk/
- Financial phishing posters from UIS Comms: https://www.uis.cam.ac.uk/downloads/financial-phishing
- Protecting your privacy when online dating: https://www.makeuseof.com/tag/online-dating-privacy-tips/
- Google reverse image search: https://support.google.com/websearch/answer/1325808?hl=en
- Swytch: https://www.swytch.com/
- Burnermail: https://burnermail.io/
- OpayQ: Link dead
- Latest Facebook data breach: https://nakedsecurity.sophos.com/2018/10/15/facebook-opens-up-about-data-breach-details/
- Brian Acton interview: https://www.forbes.com/sites/parmyolson/2018/09/26/exclusive-whatsapp-cofounder-brian-acton-gives-the-inside-story-on-deletefacebook-and-why-he-left-850-million-behind/#60ff07af3f20
- Chrome password generator: https://www.zdnet.com/article/chrome-69-released-with-new-ui-and-random-password-generator/
- TLS 1.3 in Chrome/Firefox/Safari: https://geekflare.com/enable-tls-1-3-in-browsers/
- Apple Hacky Hack Hack: https://www.bbc.co.uk/news/technology-45219895
- National Cyber Security Centre: https://www.ncsc.gov.uk/
- NCSC Web Check: https://www.ncsc.gov.uk/blog-post/web-check-helping-you-secure-your-public-sector-websites
- URL Scan: https://urlscan.io
- NCBI Blast: https://blast.ncbi.nlm.nih.gov/Blast.cgi
Royalty-free music from Purple Planet Music
View Details
Paul, Graham and Chris Quy gather round the microphones to talk about CERT 9to5, password timeouts, ePO and managing your consultants properly. Plus we telegraph other changes to the podcast line-up and Graham issues a rash challenge...
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- Chrome 68 flagging http: https://www.youtube.com/watch?v=LIHBVwQlosA
- GRU forgets VPN: https://hotforsecurity.bitdefender.com/blog/guccifer-2-0s-schoolboy-error-reveals-hes-hacking-from-moscow-19704.html
- Google claim no successful phishing: https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/
- Money laundering through in-game assets: https://kromtech.com/blog/security-center/digital-laundry
- Photoshop CC patch: https://nvd.nist.gov/vuln/detail/CVE-2018-12810 (and CVE-2018-12811
- UIS Endpoint Security: https://help.uis.cam.ac.uk/service/user-accounts-security/security/antivirus/managed-antivirus-software
Royalty-free music from Purple Planet Music
View Details
Paul, Graham, Kieren and Mr. Squeaky gather round the microphones to discuss financial scams, hacking ships, security networking, memorable passwords and transparancy, patching and how to react to a CERTogram. It also turns out that we've only got two good mics - spot who got the cheap one... We also telegraph a change in the CERT line-up.
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- Hacking ships: https://drive.google.com/file/d/1PyUGqM9KbrSPTdAb-S5bbZvATm6RoEkC/view
- Florida gun checks: http://www.tampabay.com/florida-politics/buzz/2018/06/08/adam-putnams-office-stopped-concealed-weapons-background-checks-for-a-year-because-it-couldnt-log-in/
- NCSC password advice: https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0
- WPA3 launches: https://www.wi-fi.org/news-events/newsroom/wi-fi-alliance-introduces-wi-fi-certified-wpa3-security
- Google dictate OEM updates: https://www.xda-developers.com/google-require-oem-regular-security-patches/
- Zip Slip: https://snyk.io/blog/zip-slip-vulnerability/
Royalty-free music from Purple Planet Music
View Details
Certificates are the order of the day this month as Paul and Graham look at upgrading web servers to HTTPS, the pros and cons of digitally signed e-mail and how with great power comes great responsibility -- particularly if that power is over people's passwords.
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- Telegraph story about EU and GDPR: https://www.telegraph.co.uk/technology/2018/05/30/embarrassing-leak-shows-eu-falls-short-data-law/
- 2FA on eBay: https://nakedsecurity.sophos.com/2018/05/31/how-to-set-up-2fa-on-ebay-go-do-it-now/
- 2FA on Firefox: https://www.zdnet.com/article/firefox-accounts-gets-2fa-security-you-can-use-google-authenticator-one-time-codes/
- Chrome to show HTTP as not secure: https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html
- QuoVadis certificates from UIS: https://help.uis.cam.ac.uk/service/website-resources/website-components/tls-certs
- Let"s Encrypt: https://letsencrypt.org/
- Certbot: https://certbot.eff.org/
- Upgrading connections (Apache): https://httpd.apache.org/docs/2.4/rewrite/avoid.html (first example)
- Upgrading connections (nginx): https://bjornjohansen.no/redirect-to-https-with-nginx
- GPG: https://gnupg.org/
- Why Johnny can"t encrypt: https://www.usenix.org/legacy/events/sec99/full_papers/whitten/whitten_html/index.html
- Why Johnny STILL can"t encrypt: https://www.rsaconference.com/videos/why-johnny-still-cant-encrypt
Royalty-free music from Purple Planet Music
View Details
The big theme that keeps coming up this month is the way that the everyday, boring procedures have a much greater effect on your security than the exciting, flashy toys. Paul and Kieren try to talk about being boring while not actually being so themselves.
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- WhatsApp text bomb overstated (article by last week"s guest, Paul Ducklin): https://nakedsecurity.sophos.com/2018/05/10/the-whatsapp-text-bomb-no-it-wont-destroy-your-phone/
- WhatsApp, Signal flaws: https://www.helpnetsecurity.com/2018/01/11/whatsapp-signal-group-chats/
- Yahoo! fined $35m: https://www.sec.gov/news/press-release/2018-71
- Yahoo! perp gets 8 years and says "The FSB made me do it!": https://krebsonsecurity.com/2017/12/carding-kingpin-sentenced-again-yahoo-hacker-pleads-guilty/
- Patching 7zip: https://sourceforge.net/p/sevenzip/discussion/45797/thread/adc65bfa/
- Fingerprints via WhatsApp photo: https://www.bbc.co.uk/news/av/uk-wales-43754497/drugs-for-sale-message-catches-man-dealing-to-bridgend
- Bitlocker: https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-overview
Royalty-free music from Purple Planet Music
View Details
In this out-of-band episode, we look at Cambridge Analytica and Facebook with the help of Graham Rymer, "next generation" anti-malware with Chris Quy and the new Intrusion Prevention Service with Ashley Culver. Rather than the usual back-and-forth between Paul and Kieren, this episode is essentially three extended interviews.
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- The story as it broke: https://www.wired.com/story/cambridge-analytica-50m-facebook-users-data/
- Was your account affected: https://www.facebook.com/help/1873665312923476?helpref=search&sr=1&query=cambridge
- UIS AV information: https://help.uis.cam.ac.uk/service/user-accounts-security/security/antivirus-individuals
- UIS Managed Firewall: https://help.uis.cam.ac.uk/service/user-accounts-security/security/antivirus-individuals
- UIS IPS: https://help.uis.cam.ac.uk/service/devices-networks-printing/network-services/infoinstitutions/ips
Royalty-free music from Purple Planet Music
View Details
More phishing, new biometrics, anti-malware and an acronym to help with your security audits. And, once again, we forget to announce the date on which we're recording - it was Weds 11 April 2018. There's also a major topical issue that we avoid - more on that next time.
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- Typing style authenticator: https://www.typingdna.com/authenticator
- Intel's support for patching Meltdown: https://newsroom.intel.com/wp-content/uploads/sites/11/2018/04/microcode-update-guidance.pdf
- MoviePass: https://techcrunch.com/2018/03/05/moviepass-ceo-proudly-says-the-app-tracks-your-location-before-and-after-movies/
- Naked Security blog: https://nakedsecurity.sophos.com/
Royalty-free music from Purple Planet Music
View Details
Pwned passwords, obfuscated domains and Paul gets a new co-host, but mostly why 25 May 2018 deserves a place in your diary. Clue: It's GDPR Day.
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- Troy Hunt's blog: https://www.troyhunt.com/
- Have I Been Pwned: https://haveibeenpwned.com/
- UIS Password Changer: https://password.csx.cam.ac.uk/
- Phishing with Punycode (not Tinycode!): https://nakedsecurity.sophos.com/2017/04/19/phishing-with-punycode-when-foreign-letters-spell-english-words/
- IDN Safe for Firefox: https://addons.mozilla.org/en-GB/firefox/addon/idn-safe/
- IDN Safe for Chrome: https://chrome.google.com/webstore/detail/idn-safe/kegeenojcnijgmfgkcokknkbpmjcabdm
- IDN Safe for Opera: https://addons.opera.com/en/extensions/details/idn-safe/?display=en
- BrowseAloud allows Coinmining on ICO etc websites: https://scotthelme.co.uk/protect-site-from-cryptojacking-csp-sri/
- Hurrah for Microsoft: https://nakedsecurity.sophos.com/2018/03/01/microsoft-still-refusing-to-hand-over-private-email-data-stored-in-ireland/
- Flight Simulator password miner: https://motherboard.vice.com/en_us/article/pamzqk/fs-labs-flight-simulator-password-malware-drm
- GDPR Toolkit: https://www.staff.admin.cam.ac.uk/general-news/new-data-protection-toolkit-for-university-institutions
Royalty-free music from Purple Planet Music
View Details
Kieren talks about phishing and unwelcome job opportunities, Paul talks to Chris Quy and Martin Lee and we finish off looking at the NCSC's Cyber Essentials accreditation scheme.
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- KeePass: http://www.keepass.info
- UIS Anti-malware pages: http://www.uis.cam.ac.uk/antivirus
- Meltdown & Spectre: https://meltdownattack.com/
- Hawaiian Missile Alert: https://en.wikipedia.org/wiki/2018_Hawaii_false_missile_alert
- Tinder insecurity: https://www.wired.com/story/tinder-lack-of-encryption-lets-strangers-spy-on-swipes/
- Infected USB sticks as cybersecurity quiz prize: http://www.bbc.co.uk/news/technology-42634571
- National Cyber Security Centre: https://www.ncsc.gov.uk/
- Cyber Essentials: https://www.cyberessentials.ncsc.gov.uk/
- CYBER17: https://www.cyber17.event.cam.ac.uk/
- Cisco Talos https://www.talosintelligence.com/
Royalty-free music from Purple Planet Music
View Details
Paul and Kieren introduce themselves; Kieren talks about UIS and the Technical University of Tallinn testing each others' security, Paul interviews Emma W from the National Cyber Security Centre and we finish with a discussion of passwords vs passphrases. Give us feedback! E-mail Paul at pm107@cam.ac.uk and put the word "Podcast" in the subject line.
- UIS Service Desk: service-desk@uis.cam.ac.uk
- UIS Cyber Security pages: http://www.uis.cam.ac.uk/cybersecurity
- E-mail CERT: cert@cam.ac.uk
- National Cyber Security Centre: https://www.ncsc.gov.uk/
- Three Random Words: https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0
- CYBER17: https://www.cyber17.event.cam.ac.uk/
- Meltdown & Spectre: https://meltdownattack.com/
- My reality is different... https://gizmodo.com/mozilla-slipped-a-mr-robot-promo-plugin-into-firefox-1821332254
- Spam death threats https://nakedsecurity.sophos.com/2017/12/12/ransom-email-scam-from-hitman-demands-pay-up-or-die/