An Information Security Place Podcast – Episode 02-2011

We have a little bit of innuendo humor on this episode, and we all break into some hysterics (it’s all in the geek toys section, so fast forward if you want to hear all that). Around that is some information and opinion on InfoSec stuff. We figured we would throw that in there because of the name of the podcast, but whatever…

Show Notes:

InfoSec News Update -

  • HouSecCon 2011 Call for Papers – Link Here
  • Busting DLP Myths or Playing with Hype? Link Here
  • Google collecting kid’s info (including last 4 of SSN) for Doodling contest – Link Here
  • Smartphone security threats overdramatized – Link Here
  • 7 Deadly Sins – Link Here
  • Another certification debate – Link Here
  • Abusing HTTP Status Codes to Expose Private Information – Link Here

Geek Toys –

Discussion Topic – Saying No to Bad Patents – Link 1 / Link 2 / Link 3

Music Notes:

Special Thanks to the guys at RivetHead for use of their tracks – http://www.rivetheadonline.com/

Tour dates:

  • Feb 26th – in Carlsbad NM
  • March 19 – The American Airlines Center at the Dallas Stars Hockey Game

Intro – RivetHead – “Stirring It Up Again”
News Bed – RivetHead – “Beautiful Disaster”
Discussion Bed – RivetHead - “Difference”
Outro – RivetHead – “Zero Gravity”

An Information Security Place Podcast – Episode 01-2011

We have started recording the Info Sec Place Podcast again!

Show Notes:

InfoSec News Update -

    • Study shows non-compliance more expensive than compliance (study was sponsored by Tripwire) – Article Link / Report Link
    • Security Fail – When Trusted IT members go bad!! – Link Here

“It’s a CIO’s worst nightmare: You get a call from the Business Software Alliance (BSA), saying that some of the Microsoft software your company uses might be pirated.

You investigate and find that not only is your software illegal, it was sold to you by a company secretly owned and operated by none other than your own IT systems administrator,
a trusted employee for seven years. When you start digging into the admin’s activities, you find a for-pay porn Web site he’s been running on one of your corporate servers.
Then you find that he’s downloaded 400 customer credit card numbers from your e-commerce server.

And here’s the worst part: He’s the only one with the administrative passwords.”

  • Looking back at old security news – have we made progress?? – Link Here (Registration required for full article)
  • A SLOW Death! – Link Here
  • Egypt gets Internet connection back – Link Here
  • Ever Cookie’s Anyone? – Link Here

Discussion Topic #1 – CSRF and Clickjacking – Link Here

Music Notes:

Special Thanks to the guys at RivetHead for use of their tracks – http://www.rivetheadonline.com/

Tour dates:

  • Feb 19th – Playing Curtain Club Dallas, TX
  • Feb 26th –  in Carlsbad, NM
  • March 19th – American Airlines Center at a Dallas Stars Hockey game
  • Intro – RivetHead – “Stirring It Up Again”
  • Outro – RivetHead – “Zero Gravity”