Martin is off in the wonderland known as Madison, WI; home of The Onion. Which means, of course, that I did the recording this week and the audio isn’t quite up to Martin’s standards. I blame him though, since it was mostly his Skype connection.

There was a lot to talk about this week, from the great nation of Texas requiring private investigator licenses for PC techs, to sysadmins run amok in San Francisco, to cold boot encryption, and… what was it… oh yeah, some little DNS issue rearing its head again.

Network Security Podcast Episode 113, July 22, 2008

Posted by rmogull, filed under Uncategorized. Date: July 22, 2008, 9:00 pm | 1 Comment »

Tonight Rich and I are joined by Andrew Storms, Director of Security Operations at nCircle and fellow blogger. We continue talking about Dan Kaminsky’s DNS vulnerability and the role Rich continues to play. We also talk about lost laptops and new iPhones.

Show Notes:

Network Security Podcast, Episode 112, July 15, 2008

Time: 50:00

Posted by martin, filed under Podcast. Date: July 15, 2008, 4:29 pm | 2 Comments »

Today, CERT is issuing an advisory for a massive multivendor patch to resolve a major issue in DNS that could allow attackers to easily compromise any name server (it also affects clients). Dan Kaminsky discovered the flaw early this year and has been working with a large group of vendors on a coordinated patch.

The issue is extremely serious, and all name servers should be patched as soon as possible. Updates are also being released for a variety of other platforms since this is a problem with the DNS protocol itself, not a specific implementation. The good news is this is a really strange situation where the fix does not immediate reveal the vulnerability and reverse engineering isn’t directly possible.

Dan asked for some assistance in getting the word out and was kind enough to sit down with me for an interview. We discuss the importance of DNS, why this issue is such a problem, how he discovered it, and how such a large group of vendors was able to come together, decide on a fix, keep it secret, and all issue on the same day.

Dan, and the vendors, did an amazing job with this one. We’ve also attached the official CERT release and an Executive Overview document discussing the issue.

Executive Overview (pdf)

CERT Advisory (doc)

Update: Dan just released a “DNS Checker” on his site Doxpara.com to see if you are vulnerable to the issue.

Network Security Podcast, Episode 111, July 8, 2008

Posted by rmogull, filed under Podcast. Date: July 8, 2008, 10:56 am | 5 Comments »

Ever have one of those days where just about nothing seems to go right? That just about describes today. Rich had to bail tonight due to family obligations, though it sounds like it’s the fun type of obligation, not like having dinner with Aunt Ethel or something. We had a guest lined up, but due to poor planning on our (read: my) part, we didn’t communicate the recording time well enough and that didn’t work out. Luckily Michael Santarcangelo was available to join me tonight as co-host, so you aren’t stuck listening to me drone on by myself for half an hour or so. I know that’s what I used to do every week, but it just seems so much harder than it used to.

Network Security Podcast, Episode 110

Time: 1:03:17

Show Notes:

Posted by martin, filed under Podcast. Date: July 1, 2008, 8:24 pm | 2 Comments »

Long podcast tonight! Rich and I are joined by Adam Shostack, bandleader of the Emergent Chaos Jazz Combo of the Blogosphere and co-author of The New School of Information Security. Oh yeah, he does this thing during the day where he does security stuff for some company called Microsoft. Adam’s been around a while, done more than a few things in his time, and has a lot to say about security. Funny thing is, Rich and I both agree with most of what he has to say; kinda scary isn’t it?

Show Notes:

Yes, even with only two articles, we almost went an hour.

Network Security Podcast, Episode 109, June 24, 2008

Time: 55:31

Posted by martin, filed under Podcast. Date: June 24, 2008, 7:10 pm | 3 Comments »

Back to just Rich and I this week. We’re both running around like chickens with out heads cut off, so we were lucky to be able to get a show in this week. Coordinating with a guest would have been more than we could handle. I’m sure we’ll be back to a more normal schedule next week. More ‘hoping’ than ’sure’, but only one way to find out.

Show Notes:

Network Security Podcast, Episode 108, June 17, 2008

Time: 30:49

Posted by martin, filed under Podcast. Date: June 17, 2008, 6:58 pm | No Comments »

Long podcast today, but worth every moment of it. Author, blogger, podcaster and CTO of Cigital Software Security, Gary McGraw joined us on the podcast this week. This is the second time Gary has been on the podcast and in another 100 or so podcasts I’m sure we’ll be inviting him back.

Show notes:

Network Security Podcast, Episode 107, June 10, 2008

Time: 58:55

Posted by martin, filed under Podcast. Date: June 10, 2008, 6:33 am | No Comments »

03  Jun
No podcast tonight

Rich is in Las Vegas and I’m buried under a pile of work. So no podcast tonight. We’ll return next week with a special guest.

Posted by martin, filed under Podcast. Date: June 3, 2008, 6:14 pm | No Comments »

Short show tonight folks, Rich is under the weather and our guest had to bail at the last minute due to a personal emergency. We’ll work at getting Jeremiah Grossman from White Hat on in the next couple of weeks. In the mean time Rich and I dug up a few news stories to talk about.

Show Notes:

Network Security Podcast, Episode 106, May 27, 2008

Time: 25:47

Posted by martin, filed under Podcast. Date: May 27, 2008, 7:09 pm | No Comments »

Rich and I were joined tonight by a Phoenix local and fellow security blogger, Adrian Lane. Adrian is the CTO at IPLocks and blogs about data security at Information Centric Security. We had a lot of topics to talk about tonight and wrapped up by spending a few minutes discussing security at the information level. Go figure. Adrian brought two decades worth of security experience (and ‘network hair’) to tonight’s podcast. And to no one’s surprise, we had a privacy issue that we spent more time on than we probably should have.

Show Notes:

Network Security Podcast, Episode 105, May 20, 2008

Time: 45:09

Posted by martin, filed under Uncategorized. Date: May 20, 2008, 7:14 pm | 3 Comments »

« Previous Entries