Episodes
The Linux remote code execution flaw
The CRUCIAL importance of Domain Control Security
Roskomnadzor strikes a discordant note
VLC gets a security update
Tor and Tails Merge
Telegram changes its long-standing "zero cooperation" policy
Enshittification
Bobiverse book 5
Windows 10 notifications
Experian woes
Nuevomailer
SpinRite
Peter F. Hamilton
Recall's Re-Rollout
Show Notes - https://www.grc.com/sn/SN-994-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to...
Published 10/02/24
The case of the exploding pagers and walkie-talkies
"Ford seeks patent for tech that listens to driver conversations to serve ads"
Another large chunk of personal data exposed
Passkeys takes a big step forward: Now supported by Chrome
A nascent 9.9 Linux Unauthenticated RCE?
Freezing Credit
Credit Bureaus
Drobo 5N
SN email labeled as spam
Public Wi-fi saftey
SN for Certs
Windows Defender
Kaspersky exits the U.S.
Show Notes - https://www.grc.com/sn/SN-993-Notes.pdf
Hosts: Steve...
Published 09/25/24
Windows Endpoint Security Ecosystem Summit
Aging storage media does NOT last forever
How Navy chiefs conspired to get themselves illegal warship Wi-Fi
adam:ONE named the #1 best Secure Access Service Edge (SASE) solution
AI Talk
Password Manager Injection Attacks
Show Notes - https://www.grc.com/sn/SN-992-Notes.pdf
Hosts: Steve Gibson and Mikah Sargent
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at...
Published 09/18/24
Offer to uninstall Recall was a bug, not a feature
YubiKeys can be cloned
Miscellany
Is WhatsApp secure?
Telegram vs Signal
French elevators
Freezing your credit
The Quiet Canine
Unix time
Bobiverse book 5
Exodus: The Achemedes Engine
Watching SpinRite
RAMBO
Show Notes - https://www.grc.com/sn/SN-991-Notes.pdf
Hosts: Steve Gibson and Mikah Sargent
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at...
Published 09/11/24
Telegram puts End-to-End Privacy in the Crosshairs
Free security logging is good for everyone
CrowdStrike hemorrhaging customers
Microsoft to meet privately with EDR (Endpoint Detection & Response) vendors
Yelp's Unhappy with Google
Telegram as the hotbed for DDoSass – DDoS as a Service
Chrome grows more difficult to exploit
Cox Media Group's "Active Listening" has apparently not ended
Cascading Bloom Filter follow-up
Closing the Loop
Is Telegram an encrypted app?
Show Notes -...
Published 09/04/24
CrowdStrike Exec's "Most Epic Fail" Award
Hardware backdoors discovered in Chinese-made key cards
Counterfeit CISCO networking gear
SpinRite
Errata
NPD breach updates from listeners
Looking back at old SN episodes
Cascading Bloom Filters
Show Notes - https://www.grc.com/sn/SN-989-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
You can submit a...
Published 08/28/24
Revocation Update
GRC's next experiment
Patch Tuesday
"The Famous Computer Café"
IsBootSecure
GRC Email
Working through WiFi Firewalls
Transferring DNS
OCSP attestation vs. TLS expiration
Platform key expiration
National Public Data
Show Notes - https://www.grc.com/sn/SN-988-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
You can submit a...
Published 08/21/24
Sitting Ducks DNS attack
A Bad RCE in another Microsoft server
SinkClose
The CLFS.SYS BSoD
IsBootSecure
Rethinking Revocation
Show Notes - https://www.grc.com/sn/SN-987-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including...
Published 08/14/24
Platform Key Disclosure
Firefox's 3rd-party Cookie mess
The W3C Finally Weighs-in
CrowdStrike Damages.
GRC's Email
How Revoking!
Show Notes - https://www.grc.com/sn/SN-986-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including...
Published 08/07/24
Crowdstrike post-mortem
PiDP-11
What Crowdstrike is fixing
Marcus Hutchins on who is to blame
Entrust's Updated Info
3rd-Party Cookie Surprise
Security training firm mistakenly hires a North Korean attacker
Google and 3rd party cookies
Google's influence
The auto industry and data brokers
DNS Benchmark on Mac
Platform Key Disclosure
Show Notes - https://www.grc.com/sn/SN-985-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at...
Published 07/31/24
Cellebrite unlocks Trump's would-be assassin's phone.
Cisco reported on a CVSS of 10.0
Entrust drops the other shoe
Google gives up on removing 3rd-party cookies
Miscellany
Snowflake and data warehouse applications
CDK auto dealership outage
Polyfill.io and resource hashes
MITM
Blocking Copilot
Blocking incoming connections via IP
CrowdStruck
Show Notes - https://www.grc.com/sn/SN-984-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at...
Published 07/24/24
Using Content Delivery Networks Safely
The CDK Global Ransomware Attack
The IRS and Entrust
Polyfill.io fallout
Microsoft's Behavior
A Snowflake's Chance
Show Notes - https://www.grc.com/sn/SN-983-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions,...
Published 07/17/24
Entrust Responds
Other major Certificate Authorities respond
Passkey Redaction Attacks
Syncing passkeys
Port Knocking
Fail2Ban
The Polyfill.io Attack
Show Notes - https://www.grc.com/sn/SN-982-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts,...
Published 07/10/24
The regreSSHion Bug
50BTC moved
Voyager 1 Update
Email @ GRC
SyncThing
DNS queries
Recall
The End of Entrust Trust
Show Notes - https://www.grc.com/sn/SN-981-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including fixes), visit...
Published 07/03/24
Expected follow-up on CVE-2024-30078
From Russia with Love
An EU privacy agency complains about Google's Privacy Sandbox?
Email @ GRC
Security Now SPAM?
Orange Tsai needs help!
Recall and 3rd Party Leakage
Errata
The Mixed Blessing of a Crappy PRNG
Show Notes - https://www.grc.com/sn/SN-980-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
You...
Published 06/26/24
CVE-2024-30078
"Recall" has been recalled
Matthew Green on Apple's Private Cloud Compute
A WGET flaw with a CVSS of 10.0?
Thou shall not Resolve!
Email @ GRC
Downloading email with MailStore Home
IT at The New York Times
ReMarkable
The Angle of the Dangle
Show Notes - https://www.grc.com/sn/SN-979-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at...
Published 06/19/24
MS on Recall changes
Thanks for the "Memory"
New York Times (and Wordle) leak
Apple's own password manager app
DJI drones on the defensive
SlashData reveals some interesting developer statistics
Are we going to turn programming over to AIs?
The Linux Kernel Project goes CVE crazy
Email @ GRC
Pizza in 2024
Microsoft Recall at work
Google Domains to Squarespace DNS migration
T2F2-NFC-Dual keys
The rise and fall of code.microsoft.com
Show Notes -...
Published 06/12/24
"Tornado Notes"
Email @ GRC
Have I Been Pwned?
A new "supply chain" attack vector
Another CA in the DogHouse
ICQ to shutter its service
Steve reviews "Déjà vu"
Hide my email
Security in Windows
SpinRite update
A Large Language Model in Every Pot
Show Notes - https://www.grc.com/sn/SN-977-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
You...
Published 06/05/24
The bigger problem with AI Overview
https://udm14.com/ -and- https://tenbluelinks.org/
The horses have left the barn
VPNs and Firewalls
Email @ GRC
Extension to fix Google search
Passwords and SPAM
Fixing motherboard components
Vertical tabs in Firefox
FritzBox routers
Too many PINs
More Google search fixes
Testing Windows XP
The 50 Gigabyte Privacy Bomb
Show Notes - https://www.grc.com/sn/SN-976-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this...
Published 05/29/24
When you're the biggest target...
Searching for Search
How long will a Windows XP machine survive unprotected on the Internet?
Free Laundry
VPNs and Firewalls
Netgate SG1100
Ad Industry vs. Google Privacy Sandbox
Bitwarden and passkeys
Token2 passkey dongle
312 Scientists & Researchers Respond
Show Notes - https://www.grc.com/sn/SN-975-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes...
Published 05/22/24
Picture of the Week.
Most to least common 4-digit pins.
Enhanced LORAN.
Passkeys.
Microsoft's Head in the Clouds.
Show Notes - https://www.grc.com/sn/SN-974-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including fixes), visit...
Published 05/15/24
The vulnerability of GPS
Is the sky falling on all VPN systems?
Multi-user Passkeys, YubiKeys?
The iCloud Keychain
The UK and Google's Topics
Show Notes - https://www.grc.com/sn/SN-973-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes...
Published 05/08/24
GCHQ: No more default passwords for consumer IoT devices!
What happened with Chrome and 3rd-party cookies?
Race conditions and multi-threading
GM "accidentally" enrolled millions into "OnStar Smart Driver +" program
Steve recommends Ryk Brown's "Frontiers Saga"
SpinRite update
Passkeys: A Shattered Dream?
Show Notes - https://www.grc.com/sn/SN-972-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to this show at https://twit.tv/shows/security-now.
Get episodes...
Published 05/01/24
What do you call "Stuxnet on steroids"??
Voyager 1 update
Android 15 to quarantine apps
Thunderbird & Microsoft Exchange
China bans Western encrypted messaging apps
Gentoo says "no" to AI
Cars collecting diving data
Freezing your credit
Investopedia
Computer Science Abstractions
Lazy People vs. Secure Systems
Actalis issues free S/MIME certificates
PIN Encryption
DRAM and GhostRace
AT&T Phishing Scam
Race Conditions and Multi-core processors
An Alternative to the...
Published 04/24/24