Adventures in Security

This is a weekly podcast. Each week we present commentary, reviews, and tips relevant to anyone responsible for information security. Additional episodes are available at AdventuresinSecurity.com.

Episode 56 - Suspect Interviewing Techniques

Finding and dealing with rogue employees, crack WEP in less than 60 seconds, rainbow table LM password cracking, a really naive 419 scam victim, and tips on interviewing insider suspects.

11-04
17:21

Episode 55 - Recipe for Mobile Data Security

SOX Television, an inexpensive file encryption utility, and using TPM, Bitlocker, and Active Directory to secure laptop data.

10-28
23:50

Episode 54 - IT Security Essential Body of Knowledge

Security enhancements in XP SP3, review of native data encryption, properly classifying security tests, Swiss move quantum cryptography into production, and DHS releases IT Security Essential Body of Knowledge.

10-14
18:41

Episode 53 - Desktop Application Virtualization

Information Security is about protecting the data,desktop application virtualization and application streaming

10-08
19:20

Episode 52 - Phishing Undercover

Inexpensive lockable USB memory stick, risk management, large Web sites expose authentication tokens, phishing undercover, and attaining network-wide visibility.

09-29
19:20

Episode 51 - Computer Forensics Part 3

Another government security foul-up, BlueFur Anti-phishing solution, Interpol security checklist, cracking a protected BIOS, and finding "hidden" data.

05-27
16:03

Episode 50 - Computer Forensics Part 2

MOICE Office 2003 security plug-in, source routing infests IPv6, the continuing risk of removable storage, preparing for electronic evidence acquisition, preventing data leakage through swap and hibernation files.

05-14
14:38

Episode 49 - Computer Forensics Part 1

Cisco NAC defaults create vulnerability, Vista may be no more secure than XP, Securing and initial processing of a crime scene.

04-29
26:17

Episode 48 - The Problem with NetBIOS

Wireless RFID encryption, CarderIM, Banker Trojans, Cisco NAC vulnerabilities, data encryption, and NetBIOS challenges.

04-01
15:52

Episode 47 - Ad Hoc Wireless Networks

Losing the war with malware, Xbox support team is a hole in the dyke, College campuses are wide open, External pen tests, Software assurance, and Protecting your laptop from ad hoc wireless networks.

03-25
18:10

Episode 46 - Security Leadership

Bot driven spam, discretionary faxing, quantum leaps, Oracle security, 7 habits of effective security leaders, pros and cons of risk management

03-18
18:33

Episode 45 - Keep your eye on the data

Vendor bullying, AV software evaluation, Fuzzing, new SPP issue, kernel malware, and data protection

03-04
18:46

Episode 44 - Virtual Server Security

Key carrying photons, VoIP vulnerabilities, outsourcing security, memory debugging, Exchange DST woes, and hypervisor-based virtual server security

02-25
20:07

Episode 43 - Risk Management

Commentary on iPods as criminal tools, users are not stupid, AJAX vulnerability monitoring, dangers of pirated software, and Risk Management

02-18
17:04

Episode 42 - Stepping up to meet security challenges

Commentary on iPods in business, security as a process, and how some programming teams are stepping up to meet security challenges.

10-28
09:17

Episode 41 - Cyber-Espionage

Customer Welfare vs. Vendor Public image, Establishing System Assurance, Cyber-espionage.

10-15
18:16

Episode 40 - Keystroke Dynamics (KD)

Examination of biometrics in general. Introduction of Keystroke Dynamics as a low impact biometric alternative.

10-02
17:43

Episode 39 - The Home PC Threat

The importance of choosing the right source for audit artifacts, and the growing threat of employee home PCs to the business enterprise

09-24
14:20

Episode 38 - Desperation doesn't justify bad security

The importance of change management, the potential security risks when desperation enters the project lifecycle, how virtual floors can provide secure flexible business-to-business connectivity, and finally, a look at some ways to handle sensitive information once printed copied or faxed.

09-09
14:49

Episode 37 - Web Application Security, Part 8

The vulnerabilities and safeguards associated with Application Denial of Service and Insecure Configuration Management

08-20
18:12

Recommend Channels