Fri, 11 January 2019
It's been 9 years and over 210 different content items since we started this thing in January of 2010. As much as we hate it we feel it's time to end this project and start thinking about What Comes Next. Don't worry - the episodes and website aren't going anywhere anytime soon so you'll still be able to download all the content. We're also discussing some new ideas to stay engaged with the cybersecurity community so you'll want to keep this feed live on your podcast listening device to catch updates on where we are on that. All of us would like to thank all of you for your support over the last 9 years. This started as just something Andy, Steve, and Martin did because they 'had things to say and didn't even care if anybody listened' and it's grown into more than any of us could have imagined. Joseph and Yvette joined them for the ride and added so much color and sparkle in every episode. Thank you and we hope to be talking to you again. |
Fri, 31 August 2018
It's another Front Porch episode! |
Sun, 24 June 2018
Episode 206 - The Front Porch….
Welcome to the first of an occasional series of episodes featuring conversations with a variety of interesting people from both inside and outside of information security.
In this inaugural episode you get to listen to dinner conversation between Wendy Nather, Mike Rothman, Wolfgang Goerlich, and Martin Fisher that happened in Atlanta at the Atlas Restaurant. We cover a lot of topics that I’m sure you’ll find interesting.
And, for the record, the “Aristocrat” cocktail at Atlas is something you must try.
I appreciate Duo Security and CBI for helping to make this dinner possible. |
Tue, 8 May 2018
We recorded this episode as the closing keynote at BSides Atlanta on May 5th, 2018. We want to give a big round of thanks to the organizers, volunteers, sponsors, and attendees of BSides Atlanta for a great venue and event. It was a great time and we hope to be there again next year. |
Mon, 12 March 2018
Episode 204 - Evaluating Your Security Program: Communications Plan
|
Mon, 12 February 2018
Show Notes
Episode 203 - Evaluating Your Security Program: Threat Mapping
|
Mon, 29 January 2018
Episode 202 - Evaluating Your Security Program: Awareness & Education
|
Wed, 11 October 2017
We're going to use this episode to allow the cast to talk about reaching 200 episodes and you'll hear what *really* happened on the Lost Episode.
We will be back in 2018 with more episodes. Until then be well and stay secure! |
Tue, 12 September 2017
Episode 200 - Building A Security Strategy - Part III
|
Wed, 9 August 2017
Episode 199 - Building A Security Strategy - Part II
|
Fri, 23 June 2017
Episode 198 – Building a Security Strategy – Part 1
Strategy is the hardest thing a CISO will do in their career...except if they have to explain a massive breach…
In our next episodes we’ll break down each of the steps and talk more about strategy… |
Wed, 7 June 2017
Episode 197 - After the Penetration Test We've kind of talked about how to choose your vendors, and we’ll get more into services soon, but we wanted to take some time to talk about penetration tests and especially what to do as they wrap up, how they affect the organization, and how you can manage your penetration tests to make sure they're actually effective.
|
Wed, 24 May 2017
SFS Podcast - Episode 196
Wannacry: Woulda, Coulda, Shoulda First and foremost: Why was medical hit so hard by WannaCry? See Episode 189 - Medical Device Security and Risky Business 455 - https://risky.biz/RB455/
|
Wed, 10 May 2017
Episode 195 - Annual Policy Review - Making It Worthwhile
More Notes
|
Wed, 26 April 2017
Evaluating Security Product Vendors
In light of recent news about “Vendors Behaving Badly” we want to talk about how a security professional should evaluate vendors and their products.
Recent News: Tanium exposed hospital’s IT while using its network in sales demos: https://arstechnica.com/security/2017/04/security-vendor-uses-hospitals-network-for-unauthorized-sales-demos/ Lawyers, malware, and money: The antivirus market’s nasty fight over Cylance: https://arstechnica.com/information-technology/2017/04/the-mystery-of-the-malware-that-wasnt/
|
Thu, 13 April 2017
Tonight's episode is all about those learning moments. CISOs and security orgs find new and interesting way to screw up all the time. Leaving that Any-Any rule in place on the new firewall… Disabling the CEOs account by accident… Not realizing that Shadow IT had just installed a new egress point…
|
Wed, 15 March 2017
Today's Topic: Security Waste - Buying new tools without maximizing use of current tool set It’s not just a security problem but we often add to our arsenal without fully (or even mostly) utilizing the tools that we do have. Problems associated with this are:
How do we work through this when you’re not the decision maker?
How do we work with our vendors to ensure that we are leveraging their tools without over dependence on one tool or vendor? |
Wed, 1 March 2017
The Southern Fried Security Podcast - Episode 191 - Gone Phishin’
Phishing your employees - Does it make them aware or do they feel mistrusted?
|
Tue, 14 February 2017
Episode 190 - Burnout
|
Wed, 8 February 2017
In this inaugural bonus track we release the interview we did with Nick Selby (@nselby) on his experience validating the work of MedSec on St. Medical devices.
Direct download: SFS_Podcast_-_Episode_189_Bonus_Track.mp3
Category:general -- posted at: 7:55am EDT |
Tue, 31 January 2017
SFS Podcast Episode: 189
Medical Device Security
|
Tue, 22 November 2016
Andy and Martin close out 2016 with a quick run through of the major stories of the year and look forward to what's to come in 2017. Thanks to everyone who came to BSides Atlanta! |
Mon, 24 October 2016
Martin, Steve, and Yvette discuss the recent DDoS of the DNS provider Dyn and what information security people should be considering in a world where terabit DDoS is a reality. |
Mon, 10 October 2016
Martin, Steve, and Yvette talk about recent events at Yahoo and the moral compass questions information security professionals and leaders may be forced to face when their employer appears to be doing something they shouldn't... |
Wed, 21 September 2016
For the first time we can think of it's just Yvette and Martin on this episode. The two of them talk about what to think about and what you might do if you run into some extra budget at the end of the year. Do you invest in shiny? What about services? Some training might be nice? Or so you score points with the team down the hall? |
Mon, 29 August 2016
We interview Nick Selby (@nselby) about a recent blog post where he had a less than optimal experience with a managed security service provider.
https://nselby.github.io/When-Security-Monitoring-Provides-Neither-Security-Nor-Monitoring/
|
Wed, 17 August 2016
Martin, Andy, and Steve talk about third party risk programs in light of breaches at Target, Banner Health, and other unfortunate souls. |
Tue, 28 June 2016
Joseph is on sabbatical but the rest of the crew talks about how infosec professionals should focus on their problems and how to effectively interact with "the business".
|
Mon, 6 June 2016
Guillaume’s last visit to the show: Episode 167 WWDC 2016 Security Rumors and Wishes Wishlist Reduced Annoyances and Increased Security on iOS Find us on Twitter: And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. And if you’ve found our Facebook page, we’re sorry. We’re going to fix that up.
|
Wed, 18 May 2016
This evening, Martin sat down with Patrick Heim from Dropbox. Enjoy the interview, and the gang will be back next episode. |
Mon, 9 May 2016
The 2016 DBIR Find us on Twitter: And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter.
|
Mon, 18 April 2016
This evening, Martin, Steve, and Joseph talk about overhyped vulnerabilities, and how that affects communication with the business. Badlock’s Site Find us on Twitter: And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. And if you’ve found our Facebook page, we’re sorry. We’re going to fix that up. |
Mon, 4 April 2016
Tonight, Martin and Joseph sit down and talk about communicating cautionary tales without turning them into FUD. US-CERT advisory on ransomware Find us on Twitter: And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. And if you’ve found our Facebook page, we’re sorry. We’re going to fix that up. |
Tue, 22 March 2016
InfoSec programs without money are like cereal but no milk, peanut butter but no jelly, Milli but no Vanilli… (Get over it, I’m old - Martin) Martin is doing a talk on “The ABCs of Getting Your InfoSec Program Funded” and we’re going to discuss how this works in the real world at all of the different levels. Find us on Twitter: And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. And if you’ve found our Facebook page, we’re sorry. We’re going to fix that up. |
Mon, 7 March 2016
Episode 175 - RSAC Wrapup and More... Congrats to Risky Business for winning this year’s podcast of the year! RSA: Fear and loathing at RSA: Hacking, security and the limits of protection | TechCrunch Spear Phishing: What Happens When You Dare Expert Hackers to Hack You Backdoors: Transmission Infected with KeRanger Ransomware – MacStories Find us on Twitter: And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. |
Mon, 15 February 2016
We’ve been nominated for the 2016 Security Blogger Awards! Topic: Threat Intel Norse Corp disappears shortly after CEO is asked to step down Digital Shadows announces 14 million series B fund raising Mind Over Matter: The Importance of Intelligence in Your Threat Program - “When it comes down to it, you can’t outsource your business risk management strategy.” Threat Intelligence Indicators are not Signatures // InfoSec Zanshin Find us on Twitter: And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. |
Mon, 1 February 2016
We’ve been nominated for the 2016 Security Blogger Awards! Topic: Vendor Relationships Trend Micro AV gave any website command-line access to Windows PCs Google security researcher excoriates TrendMicro for critical AV defects Find us on Twitter: And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. |
Mon, 18 January 2016
Topic: Security Awareness Some people think it's a waste of time: Why you shouldn’t train employees for security awareness But, that said, it's a requirement for government agencies and regulated industries: HHS Security Awareness and Training Requirements Privacy and Security Training requirements for multiple regulations DISCUSSION & OPINION: Is Security Awareness worth the time? If you have to do it, make it better: Find us on Twitter: And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. |
Mon, 16 November 2015
Tonight, Martin, Joseph, Steve, and Andy got together and went over how their 2015 predictions went, and laid out what their predictions were for 2016. The gang is on break from now until the new year, happy holidays! |
Mon, 9 November 2015
Check for signs of the apocalypse, everyone was here tonight... Comcast resets nearly 200,000 passwords In the era of GPS, Naval Academy revives celestial navigation How Carders Can Use eBay as a Virtual ATM What Flu Season Can Teach Us About Fighting Cyberattacks Find us on Twitter: |
Mon, 26 October 2015
This week, Andy's back! The FBI's Advice on Ransomware? Just Pay The Ransom Find us on Twitter: |
Tue, 20 October 2015
Direct download: SFS_Microcast_-_Interview_With_1Password.mp3
Category:microcasts -- posted at: 8:55pm EDT |
Mon, 12 October 2015
Tonight, Steve and Joseph talked password managers and consumer reports for cybersecurity. Troy Hunt's article on switching from LastPass Websites, Please Stop Blocking Password Managers. It's 2015 Mudge's Consumer Cyber Reports Find us on Twitter: |
Tue, 29 September 2015
This week, Joseph and Guillaume Ross talked content blockers, phishing consequences, and home network monitoring. Accidental Tech Podcast Episode 136 FireEye: Forbes.com served malicious ads to visitors | CSO Online Ad Blocking, Ad Networks, & Your IP Address DHS infosec chief: We should pull clearance of feds who fail phish test | Ars Technica Cujo Is a Smart-Home Device That Protects Against Hacks | Digital Trends Find us on Twitter: |
Mon, 14 September 2015
This week Martin and Joseph sat down and talked about stress, burnout, and why Martin took a break for a while. |
Mon, 31 August 2015
|
Mon, 17 August 2015
This week's show notes: Vegas: Oracle's CSO makes a questionable publishing decision Where you can find us: |
Mon, 3 August 2015
No full episode this week thanks to Security Summer Camp, but Martin got to sit down and chat with good friend of the podcast Wendy Nather. We'll be back soon! |
Tue, 21 July 2015
Life is Short. For some it may get shorter? Archuleta is out at OPM: Who didn't see that one coming? If you look for breaches, you might find them. Darkode Shutdown: Former FireEye Intern Accused Of Creating $65,000 Android Malware - Forbes BREAKING: UCLA Health breach hits data of 4.5M - Modern Healthcare |
Mon, 6 July 2015
Tonight, Joseph and Steve tackled the Hacking Team breach: why it's interesting, what's happening, and some of the data that's come out so far.
Find us on Twitter:
|
Tue, 23 June 2015
This episode, the gang was joined by Chris Burton (@cyberhiker) to talk about the OPM breach. OPM - The Breach that Keeps on Giving: Second OPM Hack Exposed Information About Military, Intelligence Workers - Defense One Report: Hack of government employee records discovered by product demo | Ars Technica Carnal0wnage Attack Research Blog: Hard to Sprint When You Have Two Broken Legs Data hacked from U.S. government dates back to 1985: U.S. official | Reuters Brief: 4 million federal employees affected by data breach at OPM | CSO Online Find us on Twitter: @SFSPodcast
|
Tue, 9 June 2015
The show notes for this episode have some screenshots, see the website for the full notes: http://www.southernfriedsecurity.com/apple-and-privacy-with-guillaume-ross/ Find us on Twitter:
Direct download: Apple_and_Privacy_with_Guillaume_Ross.mp3
Category:podcasts -- posted at: 12:07pm EDT |
Tue, 2 June 2015
This week Steve and Joseph were joined by a guest from America's hat: Guillaume Ross.
The IRS and PII as verification: Security checks that rely on PII put businesses and consumers at risk | CSO Online http://www.csoonline.com/article/2927652/data-protection/security-checks-that-rely-on-pii-put-businesses-and-consumers-at-risk.html If you're not paying for the service, you're probably the product:
Hola VPN client vulnerabilities put millions of users at risk | CSO Online
Facebook Uses PGP Official announcement: https://threatpost.com/facebook-bolsters-message-security-adds-openpgp/113079
Find us on Twitter: |
Mon, 18 May 2015
Joseph and Steve were joined by a special guest tonight, Mr. Kevin Riggins. They tackled mafia-style shakedowns, vulnerabilities in medical equipment, and “stunt hacking.”
"Breach" Extortion: http://money.cnn.com/2015/05/07/technology/tiversa-labmd-ftc/index.html
ICS-CERT issues advisory for medical equipment for the first time: https://ics-cert.us-cert.gov/advisories/ICSA-15-125-01A http://hextechsecurity.com/?p=123
"Stunt Hacking": http://www.wired.com/2015/05/feds-say-banned-researcher-commandeered-plane/ http://idoneous-security.blogspot.com/2015/05/lessons-in-grown-up-security.html http://carnal0wnage.attackresearch.com/2015/05/normal-0-false-false-false-en-us-x-none.html
Find us on Twitter:
|
Mon, 4 May 2015
This week, Joseph and Steve talked about what these "six hacker tribes" are, and the recent rise of some accountability in security in both the government and the private sector. "The Six Hacker Tribes" “Accountability in Security” on multiple fronts: And if you have any feedback, questions, or comments, find us at @SFSPodcast on Twitter. |
Wed, 29 April 2015
The gang is back with some cast changes. Martin will be taking a break for a while, so Joseph will be hosting for the next while. This week, we talked Wordpress, Steve's experiences at RSAC, and this year's DBIR: Wordpress: RSAC: RSAC 2015: RSA Conference (Day 2): http://www.csoonline.com/article/2912475/security-awareness/rsac-2015-rsa-conference-day-2.html RSAC 2015: RSA Conference (Day 3): http://www.csoonline.com/article/2912411/data-protection/rsac-2015-rsa-conference-day-3.html Defcon/BH Attendance: http://venturebeat.com/2014/08/12/black-hat-and-defcon-see-record-attendance-and-thats-not-even-counting-the-spies/ The DBIR: And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. |
Wed, 8 April 2015
It's going to be a little bit before the next episode of the podcast as we work out some changes. Until then take a listen to some news about BSides Las Vegas Proving Grounds! See you in Vegas! |
Mon, 16 March 2015
Episode 156 - Sad Panda Martin, Steve, and Joseph got on tonight to talk about clickbait-that-wasn't, AV eating itself, and 6 ways the Sony breach didn't actually change everything. A great slideshow article from friend of the podcast Michael Santarcangelo http://www.csoonline.com/article/2895341/security-leadership/8-steps-successful-security-leaders-follow-to-drive-improvement.html A bad, bad day for Panda AV http://www.infosecurity-magazine.com/news/panda-labs-detects-itself-as/ http://redd.it/2yofpo "6 Ways The Sony Hack Changes Everything" http://www.darkreading.com/risk/6-ways-the-sony-hack-changes-everything-/a/d-id/1319415 And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. |
Mon, 9 March 2015
The Show Notes
Opening Music
BSides Atlanta
Stories:
It’s hard to find infosec folks… http://www.csoonline.com/article/2894377/infosec-staffing/shortage-of-security-pros-worsens.html
http://www.zdnet.com/article/how-infosec-hiring-lost-its-way-harsh-findings-in-leviathan-report/
The number of things wrong with the editorial are immense… We read it so you don’t have to….
Anthem declines post-breach audit from regulators… https://threatpost.com/anthem-refusing-oig-security-audit-following-breach/111476
www.SouthernFriedSecurity.com |
Mon, 2 March 2015
Martin & Steve get a change to talk to Rob Fuller (@mubix) about his ideas on Open Source Architecture. It's a great conversation where you can see the idea grow in front of your own ears!
The link to the Open Source Architecture group is:
https://groups.google.com/forum/#!forum/ossag
Remember BSidesATL and BSidesLV! |
Mon, 16 February 2015
Episode 153 - Internet Veapon The gang braved the snow to get a show together tonight, here's what they covered: $17 mill-yun dollars scammed from Omaha company… A cautionary tale on business process controls... http://www.csoonline.com/article/2884339/malware-cybercrime/omahas-scoular-co-loses-17-million-after-spearphishing-attack.html You get an attribution! And you get an attribution! You all get attributions! https://threatpost.com/massive-decades-long-cyberespionage-framework-uncovered/111080 Feds want more threat info from private companies. Is this the way to go? http://www.wired.com/2015/02/president-obama-signs-order-encourage-sharing-cyber-threat-information/ Join us next week for episode 1784 of the continuing special “Responsible Disclosure!” http://www.infosecurity-magazine.com/news/google-blinks-first-with-project/ PSAs: BSidesATL 2015 CFP is open http://www.securitybsides.com/w/page/92311122/BSidesATL2015 BSidesLV 2015 CFP and Call for Mentors is open as well http://www.bsideslv.org/ And if you have any feedback, questions, or comments, drop us a comment here or find us at @SFSPodcast on Twitter. |
Mon, 9 February 2015
SFS Podcast Run Sheet for 2/9/15 - Episode 152
The Stories
Anthem…. a megabreach if ever we've seen one...
With the end of Microsoft’s Trusted Computing Group has the overall security posture of products taken a hit? Anecdotes say...maybe.
http://www.itproportal.com/2015/02/02/microsofts-new-ios-outlook-app-serious-security-flaws/
BSides Vegas PSA
Security Model is Broken. In other news, water is wet, and if you stop breathing, you may die.
http://www.scmagazine.com/the-security-model-is-broken/article/393033/
A vendor sponsored survey is slanted so that the “biggest problem” is likely fixed by the sponsor? NO WAY!!
|
Mon, 26 January 2015
Episode 151 -
Tonight, the gang dodged the snow for long enough to talk about some of the stories that have come out in the past week or two.
Can we finally quantify risk? http://www.csoonline.com/article/2874171/data-protection/new-framework-helps-companies-quantify-risk.html
Security budgets seem to be on the rise according to Ponemon: http://www.darkreading.com/attacks-breaches/security-budgets-going-up-thanks-to-mega-breaches/d/d-id/1318714?
Filed under "Duh..." http://www.infosecisland.com/blogview/24236-Fear-Hackers-First-Invest-in-an-IT-Security-Culture-Change.html
There are lots of potential changes to the CFAA, what can you do? http://www.csoonline.com/article/2873537/security-industry/post-state-of-the-union-reaction-to-proposed-legislation-remains-mixed.html
https://medium.com/message/we-should-all-step-back-from-security-journalism-e474cd67e2fa
https://community.rapid7.com/community/infosec/blog/2015/01/26/how-do-we-de-criminalize-security-research-aka-what-s-next-for-the-cfaa
Public Service Announcement: BSidesLV's awesome Proving Grounds track is looking for speakers: http://www.securitybsides.com/w/page/89943218/BSidesLV2015 CircleCityCon's CFP is open: https://circlecitycon.com/ BSidesCharm is looking for sponsors: http://www.securitybsides.com/w/page/80637041/BSidesCharm2015
And if you have any feedback, questions, or comments, drop us a comment here or find us at @SFSPodcast on Twitter. |
Mon, 12 January 2015
Episode 150 - Not Quite Explicit The gang is back after their holiday break, and it sure was nice that nothing big happened between episodes, right? Right? Now, we're not tackling Sony in this episode, but there was still plenty to discuss. Microsoft is ending Advanced Patch Notification Service for everyone except for certain support levels. http://windowsitpro.com/security/microsoft-ends-advanced-patch-notification-service-and-slams-google-early-warning-policy Microsoft and Google are starting up the disclosure discussion all over again. http://blog.erratasec.com/2015/01/a-call-for-better-vulnerability-response.html http://blogs.technet.com/b/msrc/archive/2015/01/11/a-call-for-better-coordinated-vulnerability-disclosure.aspx http://www.csoonline.com/article/2867534/vulnerabilities/microsoft-blasts-google-for-vulnerability-disclosure-policy.html Surprise surprise, politicians are calling for regulation of technology. http://www.nytimes.com/2015/01/12/us/politics/obama-to-call-for-laws-covering-data-hacking-and-student-privacy.html If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes. And if you have any feedback, questions, or comments, drop us a comment here or find us at @SFSPodcast on Twitter. |
Mon, 10 November 2014
The gang got together for one last show before the end of year hiatus to give talk about the year in review, and their predictions for the year to come. We'll be on hiatus until January, so have a safe holiday season, and we'll be back next year. If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes. And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter. |
Mon, 3 November 2014
It's a longer than normal episode with two great interviews. First Martin talks with Jennifer Minella (@jjx) about the upcoming (ISC)2 elections and her experience being on the board for the past year. Then Martin brings Dave Shackleford (@daveshackleford) on to talk about what it wrong with security cons today. We'll be back next week! |
Mon, 20 October 2014
Tonight Martin, Steve, and Joseph tackled FUD, stolen medical data, and executive orders. Remember, if it says X number of Y, you should probably just move on. http://www.csoonline.com/article/2835080/data-breach/15-of-the-scariest-things-hacked.html Stolen Medical Data is Now Worth Something http://www.reuters.com/article/2014/09/24/us-cybersecurity-hospitals-idUSKCN0HJ21I20140924 A great step forward by the government?! http://www.csoonline.com/article/2835476/data-protection/obama-signs-executive-order-to-bolster-federal-credit-card-security.html There are also a lot of upcoming SecurityBSides events that you should check out here: http://www.securitybsides.com/w/page/12194156/FrontPage If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes. And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter. |
Wed, 15 October 2014
In case of breach, ask reporters for money? http://motherboard.vice.com/read/hacked-snapchat-website-demands-payment-bitcoin-to-talk-about-getting-hacked-snapsaved POODLE explained. Is this really what the future of vulnerability disclosure looks like? http://www.wired.com/2014/10/poodle-explained/ Rethinking the Security “Con” http://daveshackleford.com/?p=1063 If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes. And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter. |
Tue, 7 October 2014
Sorry for the delay in getting episodes out, folks. Life...it happens. Today's episode is two fantastic interviews. First, Sparkles interviews Dave Kennedy (@hackingdave) at DerbyCon. Next, Martin interviews Ally Miller (@selenakyle) on PCI, Chips, PINs, and other amazing stuff. We'll be back to what passes for a normal schedule shortly. |
Mon, 22 September 2014
Episode 144 - The Ballad of Ricky Joe Tonight marked the return of Yvette back to the podcast, joining Martin, Andy, and Joseph to talk about what else but more Home Depot. http://arstechnica.com/security/2014/09/home-depot-ignored-security-warnings-for-years-employees-say/ http://arstechnica.com/security/2014/09/home-depots-former-security-architect-had-history-of-techno-sabotage/ We also managed to fit in a great discussion on chip and pin and it's effectiveness here in the US. http://www.csoonline.com/article/2685514/data-protection/chip-and-pin-no-panacea-but-worth-the-effort-and-the-cost.html If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes. And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter. |
Mon, 15 September 2014
|
Mon, 8 September 2014
It kind of felt like Groundhog Day on the show this evening as Martin, Steve, and Joseph talked about some of the pressing stories that have come to light over the past week. Steve also gave some insight into discussion of breaches in the media. Home Depot has issued a statement confirming that they have been breached, and have posted a FAQ for the breach. http://www.csoonline.com/article/2604320/data-protection/what-you-need-to-know-about-the-home-depot-data-breach.html https://corporate.homedepot.com/MediaCenter/Pages/Statement1.aspx A simple misconfiguration error led to a development server compromise for Healthcare.gov. http://www.csoonline.com/article/2602964/data-protection/configuration-errors-lead-to-healthcare-gov-breach.html If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes. And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter. |
Tue, 2 September 2014
Episode 141 - What's goin' on? Tonight Martin and Joseph tackled some of the breaking news of the week. Breaking news: Home Depot breached? http://krebsonsecurity.com/2014/09/banks-credit-card-breach-at-home-depot/ 'Celebgate' is upon us, apparently. http://www.theverge.com/2014/9/2/6098107/apple-denies-icloud-breach-celebrity-nude-photo-hack And according to Kaspersky, if we've done nothing wrong, we have nothing to fear. http://www.theregister.co.uk/2014/08/29/kaspersky_backpedals_on_done_nothing_wrong_nothing_to_fear_company_article/ If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes. And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter |
Tue, 19 August 2014
Tonight was an interesting news night for Martin, Steve, and Joseph. This was an episode filled with healthcare discussion. First, CHS Hacked via Heartbleed? https://www.trustedsec.com/august-2014/chs-hacked-heartbleed-exclusive-trustedsec/ http://www.sec.gov/Archives/edgar/data/1108109/000119312514312504/d776541d8k.htm Second, CMS refuses to reveal details on the security behind Healthcare.gov http://bigstory.ap.org/article/us-wont-reveal-records-health-website-security If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes. And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter |
Tue, 5 August 2014
We talk with Adam Shostack, author of the recently released Threat Modeling masterpiece, about his keynote at BSidesLV... |
Mon, 4 August 2014
Let's chat with Michelle Klinger about BSidesLV and the Security BSides organization... |
Mon, 4 August 2014
It's Security Summer Camp time!
Join Martin and Jack Daniel over some breakfast and listen in. |
Mon, 21 July 2014
Tonight Martin, Steve, and Joseph took the opportunity to get a little ranty. It must be a slow news week in the weeks leading up to Security Summer Camp, so there was some great fodder for the guys tonight.
Elon Musk - Dreamy Hero or Dreamiest Hero? http://news.hitb.org/content/tesla-model-s-hacked-security-contest
It's time to schedule another World Cup final, it seems. http://www.darkreading.com/attacks-breaches/website-hacks-dropped-during-world-cup-final/d/d-id/1297370
Great post by Spencer Hsieh on the realities of targeted attacks. http://www.csoonline.com/article/2456221/security-awareness/misconceptions-about-targeted-attacks.html
"We're like sheep waiting to be slaughtered" apparently. http://www.nytimes.com/2014/07/21/business/a-tough-corporate-job-asks-one-question-can-you-hack-it.html
If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes.
And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter |
Tue, 15 July 2014
Tonight Martin, Yvette, Steve, and Joseph tackled some fun topics, stories are below.
Is this the end of password managers? No. http://arstechnica.com/security/2014/07/severe-password-manager-attacks-steal-digital-keys-and-data-en-masse/
Bitcoin isn't Money http://www.wired.com/2014/07/silkroad-bitcoin-isnt-money/
What can you do to help your security budget? http://www.csoonline.com/article/2369048/security-leadership/do-these-3-things-to-get-the-security-budget-you-want.html
Clearly we should track all of our special snowflakes. http://www.npr.org/blogs/alltechconsidered/2014/07/10/330406463/a-new-device-lets-you-track-your-preschooler-and-listen-in
If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes.
And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter |
Mon, 7 July 2014
Tonight went a little off the rails, but Martin (@armorguy), Steve (@steveD3), and Joseph (@jsokoly) had some fun talking about stories. |
Wed, 2 July 2014
Episode 136 - Let's talk about pri-va-cy
Tonight Joseph, Andy, and Steve continued their theme of talking about themes. Joseph brought up a discussion of privacy and got the guys talking. The stories that they discussed are below.
http://www.macworld.com/article/2366921/why-apple-really-cares-about-your-privacy.html
http://www.wired.com/2014/06/usable-security/
http://www.networkworld.com/article/2393044/security/german-government-to-drop-verizon-because-of-us-spying.html
If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes.
And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter |
Wed, 25 June 2014
onight was a little different of an episode. Joseph, Steve, and Andy talked about how tired they were of the "Breach of the Week," how what is old is new again, and the Code Spaces nightmare scenario.
http://www.csoonline.com/article/2137033/network-security/meetup-struggles-under-the-weight-of-a-massive-ddos-attack.html http://www.csoonline.com/article/2114873/network-security/after-refusing-to-pay-ransom--basecamp-hit-with-ddos.html http://www.csoonline.com/article/2362004/cloud-security/ddos-triggers-massive-evernote-outage.html http://www.csoonline.com/article/2362243/malware-cybercrime/feedly-hit-by-ddos-after-refusing-extortion-demands.html http://www.csoonline.com/article/2365062/disaster-recovery/code-spaces-forced-to-close-its-doors-after-security-incident.html http://www.csoonline.com/article/2365772/cloud-security/how-to-avoid-having-your-cloud-hosted-business-destroyed-by-hackers.html
If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes.
And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter |
Mon, 16 June 2014
Tonight Martin, Joseph, Yvette, and Steve managed to pull themselves away from the US vs Ghana World Cup game long enough to talk about some stories tonight. |
Mon, 9 June 2014
Episode 133 - The Doctor is In Martin, Joseph, and Steve talk about health care and your phone...
|
Thu, 5 June 2014
Episode 132 - place holder text.
Tonight it was just Joseph and Steve on the podcast, and they had themselves a grand old time.
http://www.wired.com/2014/05/ebay-demonstrates-how-not-to-respond-to-a-huge-data-breach/ http://www.csoonline.com/article/2157782/security-awareness/raising-awareness-quickly-the-ebay-database-compromise.html
http://blog.erratasec.com/2014/05/can-i-drop-pacemaker-0day.html
http://www.darkreading.com/endpoint/the-mystery-of-the-truecrypt-encryption-software-shutdown-/d/d-id/1269323 https://www.grc.com/misc/truecrypt/truecrypt.htm
If you’d like to subscribe, you can find the RSS feed here: http://sfspodcast.libsyn.com/rss or on iTunes.
And if you have any feedback, drop us a comment or find us at @SFSPodcast on Twitter |
Mon, 19 May 2014
Martin & Steve handle the 'cast without the rest of the crew tonight...
Here's the stories we comment upon:
Dan Geer blows our mind....again.
https://securityledger.com/2014/05/blade-runner-redux-do-embedded-systems-need-a-time-to-die/
Martin disagrees (kinda) with Michael Santarchangelo for the first time ever..
http://www.csoonline.com/article/2156104/security-leadership/thinking-about-security-beyond-winning-and-losing.html
To redefine winning you gotta get rid of the myths...
http://www.darkreading.com/risk/dispelling-the-myths-of-cyber-security/a/d-id/1251171
Like always the Twitter feed is at @SFSPodcast and the website is www.southernfriedsecurity.com
See you in two weeks! |
Mon, 12 May 2014
Martin, Andy, Steven, and Yvette talk about Nick Selby's high school experiences, the Internet of Things, and why Martin doesn't sleep well at night.
http://www.darkreading.com/threat-intelligence/why-threat-intelligence-is-like-teenage-sex/a/d-id/1235049
https://securityledger.com/2014/05/no-silver-bullet-for-securing-internet-of-things/
http://www.wired.com/2014/04/hospital-equipment-vulnerable/
|
Thu, 8 May 2014
Joseph is in charge this week and that's about all I've got to say about that.
-Martin
:)
|
Mon, 28 April 2014
Episode 128 - $VULN_pocalypse |
Mon, 21 April 2014
Episode Number 127 - Advanced Malware Attack |
Mon, 7 April 2014
It's just Andy and Martin for the first time in years on this episode. The boys talk about the impending demise of Windows XP and then rant/rage/wax philosophic on all things PCI/QSA...
Follow the podcast twitter feed at @SFSPodcast and check out our website at www.southernfriedsecurity.com |
Mon, 17 March 2014
|
Mon, 10 March 2014
This week Yvette, Martin, Andy, and Steve debated the issue of trust when it |
Mon, 3 March 2014
Episode 123 - Outrage Outrage |
Mon, 24 February 2014
It feels good to be back in the saddle again, and the gang hit some fun articles tonight: |
Mon, 17 February 2014
This week, Martin, Andy, and Steve - in an attempt to capture the golden |
Tue, 17 December 2013
Well, we close out 2013 doing a fantastic interview with Mark Horstman of the Manager Tools podcast (www.manager-tools.com). We highly recommend these folks to anyone who wants to learn effective ways of doing what managers are supposed to do. Also - we'll be on hiatus until sometime in February 2014. We wish you and yours a very Merry Christmas and a Blessed New Year. |
Mon, 25 November 2013
Episode 119 - All PCI All The Time |
Mon, 18 November 2013
Martin got the chance to interview Jennifer Minella (@JJX) to talk about her candidacy for the Board of Directors of (ISC)2, the challenges and opportunities that (ISC)2 has, and her drive to get a slate of write-in candidates elected. http://securityuncorked.com/2013/11/jjs-complete-unofficial-isc2-voter-guidebook/ |
Mon, 11 November 2013
Episode 117 – End Times The end is coming when the podcast is put out 2 weeks in a row AND Andy Willingham is on… J Martin, Andy, and Yvette wax philosophic on these stories… Automated Hacking Tools….94% of all web login attempts? http://www.networkworld.com/news/2013/110713-automated-hacking-tools-swarm-web-275723.html Also, as promised, here are the slides Matt Bing of Arbor Networks ASERT used during his talk on Fort Disco at this years University of Michigan SUMIT conference. It was a GREAT talk. http://safecomputing.umich.edu/events/sumit13/docs/Bing_FortDisco_SUMIT2013b.pdf Can the new HIPAA rule cut down on ePHI breaches? Ummmm….no? http://www.networkworld.com/news/2013/110813-can-the-new-hipaa-rule-275790.html And, finally, just realize leadership isn’t about you. It’s about helping people solve their problems.’’ http://www.npr.org/2013/11/11/230841224/lessons-in-leadership-its-not-about-you-its-about-them
|