The Southern Fried Security Podcast (podcasts)
Join Andy Willingham, Martin Fisher,Steve Ragan, Yvette Johnson, and Joseph Sokoly as they discuss information security, news, and interview interesting people. Get in the discussion at www.southernfriedsecurity.com.

Martin and Steve discuss the DHS plan to distribute cybersecurity (DRINK!) data through a small set of trusted defense/telecom vendors....who might end up charging users for the data...

Here are some story links:

http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/news/2013/051713-experts-ding-dhs-vulnerability-sharing-269889.html&pagename=/news/2013/051713-experts-ding-dhs-vulnerability-sharing-269889.html&pageurl=http://www.networkworld.com/news/2013/051713-experts-ding-dhs-vulnerability-sharing-269889.html&site=security&nsdr=n

http://mobile.reuters.com/article/article/idUSBRE94E11B20130515?irpc=932

And if you are anywhere near Charlotte on June 7 & 8 you need to attend BsidesCLT!

http://bsidesclt.org/

Direct download: SFS_Podcast_-_Episode_105.mp3
Category:podcasts -- posted at: 12:55 AM

Tonight Martin, Steve, and Joseph discussed one of Steve's recent experiences with open source products and services in a business environment.

As always, you can find the podcast here or on iTunes: http://sfspodcast.libsyn.com
And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter.
Direct download: SFS_Podcast_-_Episode_104.mp3
Category:podcasts -- posted at: 12:23 AM

Three stories get the Southern Fried treatment from Martin, Andy, and Yvette.

Moving from "checkbox compliance" to "GRC"..... Good idea.

http://www.darkreading.com/compliance/can-we-cease-check-box-compliance/240153220

The Washington Post wants government action on all things "cyber".....  Maybe a Good Idea, Maybe a Bad Idea

http://www.washingtonpost.com/opinions/government-private-sector-must-team-up-to-fight-cyberthreats/2013/04/21/0b3b80fc-a913-11e2-a8e2-5b98cb59187f_story.html#

First thing you do when you've been breached?  Advise your customers!  A very, very Bad Idea.

http://www.infosecisland.com/blogview/23092-Into-the-Breach.html

Remember you can always follow our feed at @SFSPodcast or see our website at www.southernfriedsecurity.com

Direct download: SFS_Podcast_-_Episode_103.mp3
Category:podcasts -- posted at: 12:27 AM

This week was another deep dive topic for Martin, Steve, and Joseph. We chose to tackle some of the opinions on the oft-discussed topic of security awareness. Here are a couple of articles that we used to kind of establish a baseline:

http://www.schneier.com/blog/archives/2013/03/security_awaren_1.html

http://searchsecurity.techtarget.com/news/2240162630/Data-supports-need-for-awareness-training-despite-naysayers

http://www.csoonline.com/article/711412/why-you-shouldn-t-train-employees-for-security-awareness

Take a listen, let us know your thoughts!

As always, you can find the podcast here or on iTunes: http://sfspodcast.libsyn.com
And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter.
Direct download: SFS_Podcast_-_Episode_102.mp3
Category:podcasts -- posted at: 12:28 AM

With Andy, Joseph, and Yvette not able to make it Martin and Steve take a deeper dive into the events around Weev....what does this mean for our community, what can we learn....

Direct download: Episode_101_-_Weev.mp3
Category:podcasts -- posted at: 12:43 AM

Here's a quick look behind the scenes here at Southern Fried...  Our Episode 100 Run Sheet...

SFS Podcast Ep100 Run List

 

Open1            -           Jack Daniel Opener

Open2                        -           New Theme

 

Martin Intro & Welcome

 

<Random Discussion>

 

Andy’s Favorite Interview:  Jack Daniel

 

Interview Clip of Jack and the 10 Questions

 

Andy’s Favorite Moment:  Ep9 – Crossing the Streams

 

Ep9 Clip –

 

Andy’s Favorite Show: Offensive Security: Pros and Cons w/ Paul and John Strand (43)

 

Andy – What has changed most in the industry since the start of the podcast?

 

<COMMERCIAL BREAK>

 

Bumper1        -           Liquid Matrix Bumper

Bumper2        -           Bella Security Justice Bumper

 

Steve’s Favorite Interview: ?????

 

Steve’s Favorite Show:   Ep17 – Steve in the Cage

 

Show Clip – Steve in the Cage

 

Steve – What has changed the most on the podcast since we started?

 

Joseph’s Favorite Interview:

 

Joseph’s Favorite Show:   Red Firewall…

 

Joseph – What’s the podcast done/meant for you?

 

<COMMERICAL BREAK>

 

Bumper 1       -           Becky Exotic Liability

Bumper 2       -           Dueling Banjo – Short

 

Yvette’s Favorite Interview

Yvette’s Favorite Show:  Manvirtex (Ep97)

 

Yvette:  As the FNG – how’s it been going?

 

Martin’s Favorite Interview – Shrdlu Ep2

Martin’s Favorite Show - ????

 

Discussion:  What’s changed the most in the world of enterprise infosec since we launched in January of 2010?

 

<Random Discussion & Final Thoughts>

 

Close out

 

Clip 1 – Old bumper plus Hoff’s Security Rock Star

 

Direct download: SFS_Podcast_-_Episode_100.mp3
Category:podcasts -- posted at: 1:27 AM

Episode 99: Making a Point or Making a Difference?

In our last episode before the big 100, Martin, Andy, and Joseph tackled one of the bigger stories recently, the Mandiant Report on "APT1":

http://intelreport.mandiant.com/

That segued nicely into a recent article on Threatpost about "Avoiding Attack Attribution Distraction":

http://threatpost.com/en_us/blogs/avoid-attack-attribution-distraction-022113

We wrapped up the night with a discussion of some of the more common failures that risk and security officers make:

http://blogs.gartner.com/paul-proctor/2013/02/24/risk-and-security-officer-failures/

Be sure to tune in next time for episode 100!

Direct download: SFS_Podcast_-_Episode_99.mp3
Category:podcasts -- posted at: 1:34 AM

Martin, Andy, and Steve get together and, after a brief reflection about ShmooCon, talk about...

13 IT Security Myths and some ranting about Richard Stiennon...

http://m.networkworld.com/news/2013/021514-security-myths-266773.html?page=1

Are we investing the the wrong tech....or is this just another vendor survey?

http://m.networkworld.com/news/2013/021313-security-pros-say-their-companies-266702.html

A new Presidential CyberSecurity Directive....will it change anything?

http://www.zdnet.com/obamas-cybersecurity-executive-order-what-you-need-to-know-7000011221/

As always you can follow the podcast as @SFSPodcast!

Direct download: SFS_Podcast_-_Episode_98.mp3
Category:podcasts -- posted at: 1:24 AM

Martin, Andy, and Yvette get together and discuss a little bit about these stories:

The Three Worst Words in the English Language....

http://www.darkreading.com/identity-and-access-management/blog/240147002/the-three-worst-words-in-the-english-language-can-t-we-just.html

Friend Of The Podcast Nick Selby of the Police Led Intelligence podcast rips Symantec a new one regarding how they treated the New York Times following the recent breach of the Times....

http://policeledintelligence.com/2013/02/04/we-dont-got-your-back-we-got-your-money/

And, finally, another Friend Of The Podcast, Wendy Nather, gives us a great training plan for RSA.  Yvette and Martin are *so* in on this training plan!

http://www.infosecisland.com/blogview/22902-Training-for-RSAC.html

Direct download: SFS_Podcast_-_Episode_97.mp3
Category:podcasts -- posted at: 1:30 AM

Andy and Martin get together to riff on Facebook Graph, Change Management, and 2013 predictions.

Direct download: SFS_Podcast_-_Episode_96.mp3
Category:podcasts -- posted at: 1:25 AM