EPISODE · Jan 19, 2016 · 52 MIN
DtSR Episode 177 - NewsCast for January 19th, 2016
from Down the Security Rabbithole Podcast (DtSR)
In this episodeFTC imposes a $250,000 fine for "false advertising" of encryptionInteresting case, where there really was 'false advertising'Would this even have been a 'security issue'?https://www.ftc.gov/news-events/press-releases/2016/01/dental-practice-software-provider-settles-ftc-charges-it-misledNY wants to ban encrypted smart phone salesAnother clear case of legislators being clueless?What about all the existing technology, and kit you can buy across state lines?http://www.zdnet.com/article/apple-iphone-ban-new-york-looks-to-outlaw-sale-of-encrypted-smartphones/Las Vegas casino is suing cybersecurity firm over "woefully inadequate" workAre there ethical implications here of a competitor defining negligence?Burden of proof is on casino to prove "woefully inadequate" - but against what standard?Does this ultimately raise quality, price or both for IR services?http://thehackernews.com/2016/01/casino-hacker.htmlThe FDA issues draft guidance of security guidelinesIf everyone is doing it, why not the FDA?As James points out, why does every industry need their own unique (exactly the same issues as everyone else) guidelines?Interesting mention of "full lifecycle" and disclosure of vulnerabilitiesOf course it's all non-enforceablehttp://www.fda.gov/downloads/MedicalDevices/DeviceRegulationandGuidance/GuidanceDocuments/UCM482022.pdfOpenSSH bug found, fixedOpenSSH bug creates a "malicious server" scenarioUser has to successfully authenticate first, then server can read/steal memoryCan be used to compromise SSH private key from hostGreat pivot method if you've compromised an SSH server w/this bug, to compromise the users of the serverhttp://arstechnica.com/security/2016/01/bug-that-can-leak-crypto-keys-just-fixed-in-widely-used-openssh/Have something to say? Let's hear it.Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast
Embed this episode
What this episode covers
In this episode FTC imposes a $250,000 fine for "false advertising" of encryption Interesting case, where there really was 'false advertising'Would this even have been a 'security issue'?https://www.ftc.gov/news-events/press-releases/2016/01/dental-practice-software-provider-settles-ftc-charges-it-misledNY wants to ban encrypted smart phone sales Another clear case of legislators being clueless?What about all the existing technology, and kit you can buy across state lines?http://www.zdne...
NOW PLAYING
DtSR Episode 177 - NewsCast for January 19th, 2016
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.