Security Now

SN 1013: Chrome Web Store is a mess - Apple Encryption in the UK, Texas Vs. DeepSeek

Security Now - Tue, 02/18/2025 - 11:23pm
  • US lawmakers respond to the UK's outrageous demand about Apple's encryption.
  • What, exactly, is a "backdoor", and can a "backdoor" NOT be secret?
  • Highlights from last week's Windows' Patch Tuesday.
  • A look into RansomHub: The latest king of the Ransomware hill.
  • "TOAD": Telephone-Oriented Attack Delivery.
  • The state of Texas -versus- DeepSeek.
  • Disabling Apple's "Restricted Mode".
  • Where did I put that $800 million in Bitcoin?
  • A Sci-Fi author update.
  • And a deep dive into the misoperation of Chrome's critically important Web Extension Store

Show Notes - https://www.grc.com/sn/SN-1013-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

Sponsors:

Categories: Security Now

SN 1012: Hiding School Cyberattacks - SparkCat, Decrypting ADP, AI Fuzzing

Security Now - Tue, 02/11/2025 - 10:00pm
  • New "SparkCat" secret-stealing AI image scanner discovered in App and Play stores.
  • The UK demands that Apple does the impossible: decrypting ADP cloud data.
  • France moves forward on legislation to require backdoors to encryption.
  • Firefox moves to 135 with a bunch of useful new features.
  • The Five Eyes alliance publishes edge-device security guidance.
  • Six NetGear routers contain CVSS 9.6 and 9.8 vulnerabilities.
  • Sysinternals utilities allow malicious Windows DLL injection.
  • Google removes restrictive do-gooder language from AI application policies.
  • "AI Fuzzing" successfully jailbreaks the most powerful ChatGPT o3 model.
  • Examining the well and deliberately hidden truth behind ransomware cyberattacks on U.S. K-12 schools

Show Notes - https://www.grc.com/sn/SN-1012-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

Sponsors:

Categories: Security Now

SN 1011: Jailbreaking AI - Deepseek, "ROUTERS" Act, Zyxel Vulnerability

Security Now - Tue, 02/04/2025 - 10:40pm
  • Why was DeepSeek banned by Italian authorities?
  • What internal proprietary DeepSeek data was found online?
  • What is "DeepSeek" anyway? Why do we care, and what does it mean?
  • Did Microsoft just make OpenAI's strong model available for free?
  • Google explains how generative AI can be and is being misused.
  • An actively exploited and unpatched Zyxel router vulnerability.
  • The new US "ROUTERS" Act.
  • Is pirate-site blocking legislation justified or is it censorship?
  • Russia's blocked website count tops 400,000.
  • Microsoft adds "scareware" warnings to Edge.
  • Bitwarden improves account security.
  • What's still my favorite disk imaging tool?
  • And let's take a close look into the extraction of proscribed knowledge from today's AI

Show Notes - https://www.grc.com/sn/SN-1011-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

Sponsors:

Categories: Security Now

SN 1010: DNS Over TLS - Record DDoS, Hackers Get Hacked

Security Now - Tue, 01/28/2025 - 9:54pm
  • eM Client CAN be purchased outright.
  • An astonishing 5-year-old typo in MasterCard's DNS.
  • An unwelcome surprise received by 18,459 low-level hackers.
  • DDoS attacks continue growing, seemingly without any end in sight.
  • Let's Encrypt clarifies their plans for 6-day "we barely knew you" certificates.
  • SpinRite uncovers a bad brand new 8TB drive.
  • Listener feedback about TOTP, Syncthing and UDP hole punching, email spam, ValiDrive speed, AI neural nets, DJI geofencing, and advertising in the "New" Outlook.
  • A look into the tradeoffs required to obtain privacy for our DNS lookups

Show Notes - https://www.grc.com/sn/SN-1010-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Sponsors:

Categories: Security Now