DiscoverSecurity Now (Video)SN 1009: Attacking TOTP - Force-Installed Outlook, DJI Firmware Update
SN 1009: Attacking TOTP - Force-Installed Outlook, DJI Firmware Update

SN 1009: Attacking TOTP - Force-Installed Outlook, DJI Firmware Update

Update: 2025-01-22
Share

Description


  • What do we learn from January's record breaking 0-day critical Patch Tuesday?

  • Microsoft to "force-install" a new Outlook into all Windows 10 and 11 desktops?

  • GoDaddy required to get much more serious about its hosting security.

  • More age verification enforcement is coming, including globally.

  • What another instance of a widely exposed management interface teaches us.

  • DJI drone's official firmware update lifts geofencing for unrestricted flight.

  • CISA's efforts pay off with MUCH improved critical infrastructure security.

  • Listener feedback about TOTP, HOTP and age-verification.

  • And we take a deep dive into cracking authenticator keys

Show Notes - https://www.grc.com/sn/SN-1009-Notes.pdf


Hosts: Steve Gibson and Leo Laporte


Download or subscribe to Security Now at https://twit.tv/shows/security-now.


Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit


You can submit a question to Security Now at the GRC Feedback Page.


For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.


Sponsors:

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

SN 1009: Attacking TOTP - Force-Installed Outlook, DJI Firmware Update

SN 1009: Attacking TOTP - Force-Installed Outlook, DJI Firmware Update

TWiT