Player FM - Internet Radio Done Right
Checked 8d ago
הוסף לפני two שנים
תוכן מסופק על ידי Robert Vamosi. כל תוכן הפודקאסטים כולל פרקים, גרפיקה ותיאורי פודקאסטים מועלים ומסופקים ישירות על ידי Robert Vamosi או שותף פלטפורמת הפודקאסט שלהם. אם אתה מאמין שמישהו משתמש ביצירה שלך המוגנת בזכויות יוצרים ללא רשותך, אתה יכול לעקוב אחר התהליך המתואר כאן https://he.player.fm/legal.
Player FM - אפליקציית פודקאסט
התחל במצב לא מקוון עם האפליקציה Player FM !
התחל במצב לא מקוון עם האפליקציה Player FM !
פודקאסטים ששווה להאזין
בחסות
O
Our Skin: A Personal Discovery Podcast


1 You Are Your Longest Relationship: Artist DaQuane Cherry on Psoriasis, Art, and Self-Care 32:12
32:12
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי32:12
DaQuane Cherry was once the kid who wore a hoodie to hide skin flare-ups in school. Now he’s an artist and advocate helping others feel seen. He reflects on his psoriasis journey, the power of small joys, and why loving yourself first isn’t a cliché—it’s essential. Plus, a deep dive into the history of La Roche-Posay’s legendary spring. See omnystudio.com/listener for privacy information.…
Error Code
סמן הכל כלא נצפה...
Manage series 3469998
תוכן מסופק על ידי Robert Vamosi. כל תוכן הפודקאסטים כולל פרקים, גרפיקה ותיאורי פודקאסטים מועלים ומסופקים ישירות על ידי Robert Vamosi או שותף פלטפורמת הפודקאסט שלהם. אם אתה מאמין שמישהו משתמש ביצירה שלך המוגנת בזכויות יוצרים ללא רשותך, אתה יכול לעקוב אחר התהליך המתואר כאן https://he.player.fm/legal.
Error Code is a biweekly narrative podcast that provides you both context and conversation with some of the best minds working today toward code resilience and dependability. Work that can lead to autonomous vehicles and smart cities. It’s your window in the research solving tomorrow’s code problems today.
…
continue reading
68 פרקים
סמן הכל כלא נצפה...
Manage series 3469998
תוכן מסופק על ידי Robert Vamosi. כל תוכן הפודקאסטים כולל פרקים, גרפיקה ותיאורי פודקאסטים מועלים ומסופקים ישירות על ידי Robert Vamosi או שותף פלטפורמת הפודקאסט שלהם. אם אתה מאמין שמישהו משתמש ביצירה שלך המוגנת בזכויות יוצרים ללא רשותך, אתה יכול לעקוב אחר התהליך המתואר כאן https://he.player.fm/legal.
Error Code is a biweekly narrative podcast that provides you both context and conversation with some of the best minds working today toward code resilience and dependability. Work that can lead to autonomous vehicles and smart cities. It’s your window in the research solving tomorrow’s code problems today.
…
continue reading
68 פרקים
כל הפרקים
×E
Error Code

Operational technology (OT) systems are no longer limited to nation-states; criminal groups and hacktivists now actively target these systems, often driven by financial or ideological motives. Kurt Gaudette, Vice President of Intelligence and Services at Dragos, explains why these systems might not even be the primary targets.…
E
Error Code

1 EP 66: Secure only the OT code that actually runs 23:11
23:11
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי23:11
Many organizations spend valuable security resources fixing vulnerabilities in code that never actually runs—an inefficient and often unnecessary effort. Jeff Williams, CTO and founder at Contrast Security , says that 62% of open source libraries included in software are never even loaded into memory, let alone executed. This means only 38% of libraries are typically active and worth prioritizing.…
E
Error Code

1 EP 65: Hacking Critical Infrastructure Through Supply Chains 30:22
30:22
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי30:22
Critical Infrastructure software lacks the strict liability standards found in industries like automotive manufacturing, leading to minimal accountability for insecure products when they get exploited. Alex Santos, CEO of Fortress Information Security , explains how they’re typically hired by buyers of ICS equipment—such as utilities—to assess and mitigate supply chain risks, including working with OEMs to improve security.…
While cybersecurity threats targeting critical infrastructure, particularly focusing on the vulnerabilities of operational technology (OT) and industrial control systems (ICS).mostly originate on the business or IT side, there’s increasing concern about attacks crossing into OT, which could result in catastrophic consequences, especially in centralized systems like utilities. Michael Welch, managing director from MorganFranklin Cyber , discusses how Volt Typhoon and other attacks are living off the land, and lying in wait.…
E
Error Code

This is a story about a Chief Hacking Officer who draws on his expertise in physical and virtual security assessments—along with some intuitive AI-driven coding—to safeguard Operational Technology. Colin Murphy of Frenos and Mitnick Security talks about how some of his early assessment work with Kevin Mitnick is helping him with OT security today.…
E
Error Code

1 EP 62: Defending the Unknown in OT Security 31:38
31:38
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי31:38
ROI is always a tricky subject in cybersecurity. If you’re paying millions of dollars in securing your OT networks, you’d want to be able to show that it was worth it. Andrew Hural of UnderDefense talks about the need for continuous vigilance, risk management, and proactive defense, acknowledging both the human and technological elements in cybersecurity and how just because something didn’t happen doesn’t mean that it didn’t.…
E
Error Code

1 EP 61: Applying Zero Trust to OT systems 36:07
36:07
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי36:07
Zero Trust is a security model based on default-deny policies and fine-grained access control governed by identity, authentication, and contextual signals. For RSAC 2025 , John Kindervag, Chief Evangelist of Illumio and the creator of Zero Trust, talks about introducing a "protect surface" into legacy OT systems —isolating critical data, applications, assets, or services into secure zones for targeted Zero Trust implementation.…
E
Error Code

1 EP 60: Hacking Solar Power Inverters 39:21
39:21
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:21
Solar power systems are rapidly becoming essential elements of power grids throughout the world, especially in the US and EU. However, cybersecurity for these systems is often an afterthought, creating a growing risk to grid stability and availability. Daniel de Santos, Head of Research at Forescout , talks about his recent research into vulnerabilities associated with solar panel investors, how they might affect the power grid or the end-user, and what we can do about it.…
E
Error Code

1 EP 59: Automotive Hacking In Your Own Garage 36:15
36:15
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי36:15
Gone are the days when you could repair your own car. Even ICE cars have more electronics than ever before. Alexander Pick is an independent hardware hacker specializing in automotive systems. He says if you start off small, like looking at ECUs, there’s a lot of great research yet to be done by both hobbyists and professionals alike.…
E
Error Code

It’s becoming easier for criminals to use counterfeit or altered chips in common office products, such as printer toner cartridges, with the aim of espionage or simple financial gain. Tony Moor, Senior Director Of Silicon Lab Services For IOActive , explains how the hacking embedded silicon within common objects in our day to day lives is becoming more common, and what the consequences of this lack of security might mean.…
E
Error Code

1 EP 57: Strengthening Embedded Device Security with Cloud-Based SCADA 33:36
33:36
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי33:36
Embedded devices need basic security measures like multi-factor authentication and unique credentials to reduce vulnerabilities and protect against cyber threats. Mauritz Botha, co-founder and CTO of XiO Inc., explains that cloud-based SCADA can update old systems and provide the visibility that’s currently missing.…
E
Error Code

1 EP 56: Hacking OT and ICS in the Era of Cloud and Automation 42:19
42:19
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי42:19
As industrial enterprises lurch toward digital transformation and Industry 4.0, a new report looks at the security OT systems and finds it wanting. Grant Geyer, the Chief Strategy Officer for Claroty , talks about the findings from over one million devices in the field today, and what industries must do now to secure them.…
E
Error Code

1 EP 55: Building Secure Storage for Autonomous Vehicles 28:48
28:48
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי28:48
I recently rode in a Waymo, Google’s self-driving taxi service, and it was fantastic. What if we took that vehicle off the safe roads of California and put it in a warzone like Ukraine? If it was captured, could the enemy get its data or its algorithms? Brent Hansen, Chief Growth Officer at Cigent, talks about the data risks associated with autonomous vehicles and remote servers, and how data security is essential in these in the field locations.…
E
Error Code

1 EP 54: From Cyber Chaos to Control: Lessons from a Kansas Water District 34:01
34:01
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי34:01
Imagine your best worst day during a cyber attack. Can you switch to manual systems in case of a failure? Has your team practiced for that? Dave Gunter, OT Cybersecurity Director at Armexa , discusses how a water and waste water utility in Kansas responded correctly to a cyberattack in 2024 by falling back to manual and issuing clear, and concise press releases to assure the public that their water was safe to drink.…
E
Error Code

1 EP 53: Securing Smart OT Systems Already In The Field 31:17
31:17
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי31:17
This is the story of how the security of OT devices in the field can be modernized virtual isolation in the cloud, adding both authentication and encryption into the mix. Bill Moore, founder and CEO of Xona, explains how you can virtualize the OT network and interact with it, adding 2FA and encryption to legacy systems already in the field.…
E
Error Code

1 EP 52: Hacking Cellular-Enabled IoT Devices 37:59
37:59
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי37:59
This is the story of the secret life of cellular chips and why we need to mitigate against the unintended access they provide. Deral Heiland, Principal Security Research for IoT at Rapid 7 , describes a research project he presented at the IoT Village at DEF CON 32 where they compiled AT command manuals from various vendors, discovering unexpected functionalities, such as internal web services.…
E
Error Code

1 EP 51: Hacking High-Performance Race Cars 43:39
43:39
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי43:39
When we think of IoT, we first think of our smart light bulbs, our smart TVs, our smart baby monitors. However, we don't typically associate IoT with high-performance race cars, and yet they collect terabytes of data each race. Austin Allen, Director of Solutions Architecture at Airlock Digital , discusses the growing presence of smart devices and the responsibility of securing them—should it be the developers who write the code, or the individuals who implement it?…
E
Error Code

1 EP 50: Keeping The Lights On In Ukraine 44:07
44:07
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי44:07
What would happen if your GPS signal were jammed? It would impact more than just navigation – you'd also lose access to financial data and power. Joe Marshall, Senior IoT Strategist and Threat Researcher at Cisco Talos , discusses an innovative solution to maintain the country's power grid operations in the event of GPS jamming, whether it's a precautionary measure or an act of war.…
E
Error Code

1 EP 49: Hacking Android-Based ICS Devices 39:27
39:27
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:27
Cybercriminal tactics against ICS include direct threats against individuals for MFA credentials, sometimes escalating to physical violence if they won’t share. Jim Coyle, US Public Sector CTO for Lookout , warns about the increasing use of Android in critical Industrial Control Systems (ICS), such as HVAC systems, and how stealing MFA tokens from mobile devices could affect critical services like healthcare, finance, and water supply, depending on the goals of the attackers.…
E
Error Code

1 EP 48: The New Insider Threat: Hacking Corporate Office Devices 40:51
40:51
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי40:51
If smart buildings are vulnerable to hacking, what about smart offices? Even devices like printers and lighting systems could give an attacker a way in. John Terrill, CSO at Phosphorus , recalls a moment while working at a hedge fund when he found himself in a room filled with priceless art. He realized that the security cameras safeguarding these artworks were operating on outdated software, potentially containing known vulnerabilities.…
E
Error Code

If you are in IT, you are probably not thinking about the risks associated with the Otis Elevator or the Coke machine. Maybe you should. Chester Wisnieski, the director and global field CTO at Sophos , points out that IoT devices, big and small, create an outsized threat to any organization. And that’s why IoT vendors need to secure these devices, even if they only “phone home” for more Coke. If they’re on your network, they need to be secured.…
E
Error Code

1 EP 46: Hacking Israeli-made Water Treatment Devices In Pennsylvania 33:34
33:34
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי33:34
Political hacktivism once mainly focused on website defacement. Now it has shifted to targeting physical devices, affecting critical infrastructure such as water treatment plants. At Black Hat USA 2024, Noam Moshe from Claroty highlighted how the HMIs in PLC devices from Israeli manufacturers may be susceptible to political attacks by nation-state actors using unknown vulnerabilities in the PComm protocol.…
E
Error Code

1 EP 45: Laser Fault Injections on a Shoestring Budget 32:35
32:35
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי32:35
What if you could build your own embedded security tools, glitching devices for a fraction of the cost that you might expect. Like having a $150,000 laser setup for less than $500. A talk at Black Hat USA 2024 says you can. Sam Beaumont (Panth13r), Director of Transportation, mobility and cyber physical systems at NetSPI , and Larry Trowell (patch), Director of hardware embedded systems at NetSPI , along with a team of others, say that you can. Their talk, Laser Beams & Light Streams: Letting Hackers Go Pew Pew, Building Affordable Light-Based Hardware Security Tooling, should be a wake up call for all IoT and OT device vendors who should defend our IoT and OT devices, even against the unlikely attacks. Because soon enough, those attacks will become likely.…
E
Error Code

1 EP 44: Performing Security Assessments on ICS systems 34:16
34:16
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי34:16
Too few vulnerabilities in industrial control systems (ICS) are assigned CVEs because of client non-disclosure agreements. This results in repeatedly discovering the same vulnerabilities for different clients, especially in critical infrastructure. Don C. Weber from IOActive shares his experiences as an ICS security professional and suggests improvements, including following the SANS best practices for ICS security..…
E
Error Code

1 EP 43: Hacking Large-Scale Off-Grid Solar Systems and Other Consumer IoT Devices 50:45
50:45
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי50:45
At DEF CON 32, in the ICS village, researchers disclosed vulnerabilities in home and commercial solar panel systems that could potentially disrupt the grid. Dan Berte, Director of IoT security for Bitdefender , discusses his more than a decade in IoT, how the vendor maturity often isn’t there for our smart TVs or even for our solar panels, so reporting vulnerabilities sometimes goes nowhere. That doesn’t stop defenders like Dan, who, along with his team, work hard to change and to educate the industry.…
The resources available at small utilities are scarce, and that’s a big problem because small water, gas, and electric facilities are increasingly under attack. Dawn Capelli of Dragos is the Director of OT-CERT, an independent organization that provides free resources to educate and even protect small and medium sized utilities from attack.…
E
Error Code

1 EP 41: Firmware SBOMs, Zero Trust, And IoT Truth Bombs 41:26
41:26
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי41:26
For the last twenty years we’ve invested in software security without parallel development in firmware security. Why is that? Tom Pace, co-founder and CEO of NetRise , returns to Error Code to discuss the need for firmware software bills of materials, and why Zero Trust is a great idea yet so poorly implemented. As in Episode 30, Tom is a straight shooter, imparting necessary truth bombs about our industry. Fortunately he’s optimistic about our future.…
E
Error Code

1 EP 40: Hacking IoT Surveillance Cameras For Espionage Operations 28:27
28:27
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי28:27
That camera above your head might not seem like a good foreign target, yet in the Ukraine there’s evidence of Russian-backed hackers passively counting the number of foreign aid workers at the local train stations. Andrew Hural of UnderDefense talks about the need to secure everything around a person, everything around an organization, and everything around a nation because every one can be a target.…
E
Error Code

1 EP 39: Hacking Water Systems and the OT Skills Gap 40:20
40:20
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי40:20
A critical skills gap in Operational Technology security could have a real effect on your water supply and other areas of the critical infrastructures. Christopher Walcutt from DirectDefense explains how the IT OT convergence, and the lack of understanding of what OT systems are, might be contributing to the spate of water systems attacks in 2024.…
E
Error Code

1 EP 38: Regulating OT Data Breaches And Ransomware Reporting 42:50
42:50
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי42:50
When critical infrastructure is shut down due to ransomware or some other malicious attack, who gets notified and when? Chris Warner, from GuidePoint Security , discusses the upcoming Cyber Incident Reporting for Critical Infrastructure Act or CIRCIA and what it will mean for critical infrastructure organizations.…
E
Error Code

1 EP 37: Solving Mysteries. Saving Lives. Just Another Day with OT Incident Response and Forensics 42:05
42:05
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי42:05
When an enterprise network goes down, you call in the Incident Response team and they do forensics. When your SCADA goes down, who do you call? Meet Lesley Carhart, technical director of incident response at Dragos , who focuses on products and services for the non standard part of cybersecurity. That means things like performing digital forensics on SCADA, industrial control systems, and critical infrastructure. There’s still some normal enterprise computing involved, but very often the stories told by practitioners are … well, just plain weird.…
E
Error Code

1 EP 36: Securing SCADA Systems In The Cloud 26:02
26:02
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי26:02
This is a story about how organizations are moving their SCADA systems to the cloud and how they need to secure them or they’ll be attacked. Chris Doman, co-founder and CTO of Cado Security discusses the new NSC guidelines on SCADA in the Cloud and whether the guidelines are prescriptive enough.
E
Error Code

1 EP 35: Outsized Kinetic Response to OT Attacks 39:13
39:13
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:13
If you knock down an email server, you could stand up a parallel server or you could find workarounds. If you knock down a factory floor, there is no real parallel, alternative to a factory floor. Dane Grace, product manager at Brinqa talks about how the risks to OT carries with it an outsized kinetic response in the real world. For example, what would happen if someone managed to put a botnet on a defibrillator?…
E
Error Code

1 EP 34: Quantifying Risk in IoT and OT Systems 40:44
40:44
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי40:44
One of the problems with security is ROI. If I put in next gen this and next gen that and no security events happen, am I justified in making those expenditures? How do you quantify a risk like that? Padraic O’Reilly, founder and Chief Innovation Officer at CyberSaint, walks us through the risk analysis for IoT and OT systems, and why it’s important to understand this as we secure our critical infrastructure.…
E
Error Code

1 EP 33: Turning EDRs and Cloud Backups into Malicious Wipers 32:48
32:48
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי32:48
This is the story of how a researcher turns commercial and commonly used EDRs and Cloud-based backup systems into wipers against the very data they’re designed to protect. Or Yair, security research team lead at Safe Breach, talks about his two presentations at SecTor 2023 that consider how to turn common security tools into potentially malicious weapons.…
E
Error Code

1 EP 32: Using ChatGPT To Perform Side Channel Attacks On Real Hardware 30:56
30:56
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי30:56
There’s a lot of talk about using AI and LLM in security. For example, could ChatGPT detect the vulnerable spots for power for analysis in particular pieces of code using Advanced Encryption Standard? Witold Waligora, CEO of CloudVA, talks about his Black Hat Europe presentation, How We Taught ChatGPT-4 to Break mbedTLS AES With Side-Channel Attacks.…
E
Error Code

1 EP 31: How Operation Volt Typhoon Shows That IoT & OT Devices Could Be Used In Cyberwarfare 43:31
43:31
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי43:31
You might think that internet connected cameras would be limited in use by a bad actor. Actually such devices can be an entry point into an organization, providing yet another means of accessing the internal network. Mohammad Waqas, a field CTO at Armis, spoke at SecTor 2023 about the threat posed by IoT and OT devices in future cyberwarfare and discusses here why we need to broaden our attack surface defenses to include them.…
E
Error Code

1 EP 30: Of IoT Vulnerabilities and Consumer IoT Labels 43:49
43:49
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי43:49
There’s a fake news report about three million internet-enabled toothbrushes contributing to a botnet. Unfortunately the mainstream media ran with the story before questioning its basic assumptions. This is a story about IoT devices and the fact that we still don’t understand how they are vulnerable. Tom Pace, co-founder and CEO of NetRise , talks about vulnerabilities inherent in the IoT space that are often misconstrued and how we need to ask more questions about the software and the hardware being used if we want to secure critical infrastructure tomorrow.…
E
Error Code

1 EP 29: The Rise of Smash and Grab Data Exfiltration 36:09
36:09
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי36:09
Ransomware groups have bifurcated with some doing pure ransomware and others going straight to extortion; it's whether the data is ransomed on your network or theirs. Nick Biasini from Cisco Talos talks about the threats he’s seeing, in particular, SapphireStealer which is open source and using GitHub to crowdsource new features.…
E
Error Code

1 EP 28: Why Mapping IT Security to OT Networks Doesn’t Always Work 42:28
42:28
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי42:28
The Purdue Model used in OT is essentially network security from the 1990s. New threats and new tech however required us to rethink that on the network side so how do we bring that new thinking to work with legacy OT systems? John Taylor of Versa Networks explains how there's a lot of implicit trust in the IoT and OT devices themselves, yet they don't have antivirus. Or firewalls. Worse, you're basically depending on the manufacturer of that device to provide security updates if necessary, and oftentimes they don't. Perhaps it’s time for a new approach such as SASE or secure access service edge.…
E
Error Code

1 EP 27: Cyber Physical Security As A Shared Responsibility 35:10
35:10
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי35:10
Flaws within the chips in our laptops, in our homes, and in our critical infrastructure could become the access one needs to steal data if not just shut down an assembly line, or hold up production of a vital resource like power or water. Josh Salmanson, senior vice president at Telos , discusses why we’re seeing more and more pre-compromised routers in critical environments today and what we might do to mitigate that in the near future.…
E
Error Code

1 EP 26: Securing Railroad OT Systems 42:13
42:13
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי42:13
Can your OT function if the IT system goes down? OT self-sufficiency is critical for infrastructure such as rail systems. Christopher Warner, from GuidePoint Security , discusses how this infrastructure resilience is important not only for the rail industry but for most of the other critical infrastructures in general.…
E
Error Code

1 EP 25: Crypto Agility And The End Of Diffie Hellman Key Exchange 38:51
38:51
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי38:51
Quantum computers will change and even break the cryptography we have today. To defeat a "Harvest Now, Decrypt Later" strategy by bad actors (even nation states), Denis Mandich, CTO and co-founder of Qrypt , is proposing a type of crypto agility that compiles the keys on your laptop instead of distributing them across the internet. He also talks about how you won’t need a quantum computer in your home; you’ll be able to access one in the cloud the way you can access AWS today.…
E
Error Code

1 EP 24: Securing OT Devices In The Field 44:04
44:04
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי44:04
When we think of massive compute power, we think of the Cloud when we really should consider the millions of unprotected OT devices with even greater slack computer power than all our current Cloud services combined. Sonu Shankar, Vice President of Product at Phosphorus Cybersecurity , talks about the challenge of communicating with PLCs and other devices, the risks from newer OT devices, and how all password-less OT devices really need to be protected. He says attacks aren’t just DDoS; today OT attacks can exfiltrate data as well.…
E
Error Code

There’s much of the electromagnetic spectrum that we cannot see. Like how LED wristbands are triggered at concerts or how to identify someone at DEF CON in a crowd of cellphones and electrical devices. Eric Escobar of SecureWorks provides some really clear analogies to help anyone visualize the differences between NFC, Bluetooth, and Wi Fi such as how your router and your microwave are both 2.4GHz - the difference is the number of watts behind each signal.…
E
Error Code

1 EP 07: Secure Medical IoT Devices 51:10
51:10
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי51:10
IoT can make patient care easier.. But how do we introduce new IoT medical devices into an ecosystem where we can’t even keep tabs on our legacy devices? Mohammad Waqas discusses conversations he’s had with hospitals about the device profiles they don’t necessarily know about – the over-the-counter glucose monitor app on an iPad that hasn’t gone through IT provisioning - and what they can do about it.…
The Vastaamo data breach stands as one of the most heinous of internet crimes because of the 30,000 psychiatric records that were exposed and the lives it ruined. Antti Kurittu discusses his presentation at SecTor 2022, what we know thus far from the public record, and the news of the Finnish arrest warrant for the individual only previously known as “Ransomware_Man”.…
E
Error Code

1 EP 05: Food Production As Critical Infrastructure 45:22
45:22
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי45:22
IoT and Machine Learning can help farmers provide more food with fewer resources, so long as the devices in the field and the backend systems are secure. Seth Hardy, co-founder and CTO of Bug Mars , a precision agtech company for insect farms, discusses his SecTor 2022 presentation, drawing upon his more than 20 years of security experience in his new role in sustainable food production.…
E
Error Code

1 EP 04: Hacking the Quantum Realm 52:40
52:40
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי52:40
Quantum computing will make great advances in science; it will also have the ability to decrypt banking, healthcare, and other industries' stolen data. Skip Sanzeri of QuSecure explains how quantum computing is advancing rapidly, how it has the power to crack RSA 2048 and other encryption that we know take for granted today, and why his and other companies are talking about our post-quantum encryption world today. Dn3NZumn4pPpnVhpt6GH…
E
Error Code

1 EP 03: Hacking Hardware (featuring Joe Grand) 1:03:52
1:03:52
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי1:03:52
This is the history of hardware hacking and the story of Joe Grand. From testifying before Congress to creating badgelife at DEF CON, Joe has done it all. And he’s darn humble about it, too. Joe just wants to share through his classes, website, and YouTube channel all that he’s learned since his days with the L0pht, the tools he’s created, and the work he’s currently doing with Right to Repair. He just wants to make the art of hardware hacking more accessible to others.…
E
Error Code

1 EP 02: Using Digital Twins To Hack Satellites 38:04
38:04
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי38:04
What happens now to the digital test environment built for Hack-A-Sat 3? Well, it becomes a rich testing and training environment for all on GitHub. Login Finch and Frank Pound continue sharing some of the behind-the-scenes challenges presented by hosting a Hack-A-Sat capture the flag competition, this time drilling down details behind the Digital Twins environment that needed to be built in advance of next year’s hack of an actual satellite in orbit.…
E
Error Code

Satellites today lack basic security controls. With as little as $300, you, too, can hack into commercial satellites. So that’s an emerging IoT problem. Frank Pound and Login Finch share in this episode their work with Hack-A-Sat . It’s a unique Capture the Flag challenge that’s never been tried before. Here’s the background story of how the project got started … and where it’s going.…
E
Error Code

Error Code is a biweekly narrative podcast that provides you both context and conversation with some of the best minds working today toward code reliance and dependability. Work that can lead to autonomous vehicles and smart cities. It's your window in the research solving tomorrow's code problems today…
ברוכים הבאים אל Player FM!
Player FM סורק את האינטרנט עבור פודקאסטים באיכות גבוהה בשבילכם כדי שתהנו מהם כרגע. זה יישום הפודקאסט הטוב ביותר והוא עובד על אנדרואיד, iPhone ואינטרנט. הירשמו לסנכרון מנויים במכשירים שונים.