Showing posts with label brakeing down security. Show all posts
Showing posts with label brakeing down security. Show all posts

Thursday, December 3, 2015

2015-049-Can you achieve Security Through Obscurity?


That's the question many think is an automatic 'yes'.  Whether your Httpd is running on port 82, or maybe your fancy #wordpress #module needs some cover because the code quality is just a little lower than where it should be, and you need to cover up some cruft
This week, Mr. Boettcher and I discuss reasons for obscuring for the sake of security, when it's a good idea, and when you shouldn't #obscure anything (hint: using #ROT-14, for example)
#encryption #security #infosec
Direct Link: http://traffic.libsyn.com/brakeingsecurity/2015-049-Security_by_Obscurity.mp3
iTunes:
Mr. Boettcher's Twitter: http://www.twitter.com/boettcherpwned
Bryan's Twitter: http://www.twitter.com/bryanbrake
TuneIn Radio App: http://tunein.com/radio/Brakeing-Down-Security-Podcast-p801582/
BrakeSec Podcast Twitter: http://www.twitter.com/brakesec
Join our Patreon!: https://www.patreon.com/bds_podcast
Comments, Questions, Feedback: bds.podcast@gmail.com

Here is a new episode of Brakeing Down Security!

Tuesday, January 14, 2014

#12: Here it is folks! Episode #1!

I hate sound editing.  I hate the sound of my voice when it's not reverberating in my head.  But doing this was all worth it. HERE IT IS!!!!  Episode #1 of "Brake"ing Down Security!!!!!111ELEVENTY!!

It's all about hashes.  I have included the show notes below in case you want to do more research.

Here is the link to access it on LibSyn:

http://traffic.libsyn.com/brakeingsecurity/final1.mp3

LibSyn also gives us an easy RSS feed, and you can follow in your favorite Feed by using the following link:

http://brakeingsecurity.libsyn.com/rss

We will try to get into iTunes very soon, but I will be posting this on my LinkedIn, and Twitter.

There are errors... We are working out the issues.  Sometimes it only sounds like we are out of sync... we talk over each other...

Something for readers just of this blog... I will post the heretofore unpublished first try of our podcast...  I give you EPISODE 0!!!  A prequel, if you will.  This was our first try at the podcast in our office.  We jumped around a little too much, which is why we re-did it.  If you click here, you can listen to it.  Uncut, unedited...

http://traffic.libsyn.com/brakeingsecurity/old_ep1.mp3

https://docs.google.com/document/d/1k5tK4OsH6M--UidcvArbfW0rjOkHeSEDm1_UrF64iyY/edit?usp=sharing

Feedback is welcome, thank you...

Friday, January 3, 2014

#10: It's really happening folks...

Hell yea!  The new podcast "Brakeing Down Security" will happen on 10 January 2014.  Also, I'll have a co-host!

Before you go "Aw hell, ANOTHER security podcast", don't you fret my army of followers.  I have been following the "I am the Calvary" mailing list for a while (and if you aren't, you should be), and there is a real need out there for training and awareness.  Both those in the IT industry who do it on a daily basis, that maybe don't understand why they are doing what they are doing, or maybe that college student looking to expand her/his knowledge of Information Security and may not have a good place to go.

In the past year or so, I have seen many excellent speakers at the Capital of Texas ISSA chapter, talk about the difficulties of getting people to understand something as simple as password complexity or why we can't have Post-its on our monitors. This podcast is to be for folks like that, so if you're looking for techniques on how to reverse engineer Windows binaries, or creating malware for fun and profit, this won't be your bag. Ideally, I'd like to get up to that point, but that is probably many years in the future.

We are hoping to bring you interviews from people in the industry, people from the Privacy realm, from Healthcare, from Legal, you name it...  What we want to show is how vast the industry truly is, so we may have a pentester on one month, and a lawyer specializing in Privacy law next month, or a compliance "check box weasel" the next month (I apologize to all the Compliance Officers out there).  We want to do multimedia stuff as well, but just learning the sound editing is gonna be a pain, not even sure how video editing will do.

We're not trying to be the next Pauldotcom or Network Security Podcast (who am I kidding, that'd be awesome!), but we just want to put ourselves out there to be another reference for people who may not want a deep technical discussion.

This is going to be a labor of love, plus, we get CPEs for doing research and preparing for the podcast, so there is a plus in that.

So look here, or on my Twitter feed @bryanbrake, or on my LinkedIn for the post to the podcast.  We'll most likely be using LibSyn for hosting, since I've been told by more than one person that they are pretty awesome.

I hope you enjoy it, we definitely want feedback and emails and constructive criticism