Thanks for tuning in for another crime busting episode of Healthy Paranoia. Today, we’ll be getting down and dirty with some actual practitioners to discuss what’s wrong with PCI DSS. Joining me in the secret Healthy Paranoia hideout will be Mr. Stits, an actual PCI QSA. We also have Mrs. Dystie, expert in exploding crypto […]
That’s right listeners, you’re not in Kansas anymore! It’s time to follow that Yellow Brick Road to another episode of Healthy Paranoia. Today, we’ll be discussing phone phreaking, hacking and fraud, oh my! So we’re off to see Wizard, the Wonderful Wizard of VoIP security, Patrick McNeil. Joining me over the rainbow for this trip […]
Ladies and gentleman, unicorns of all ages, get ready for the greatest podcast on earth, Healthy Paranoia. Where the email is always encrypted and the firewalls are ever stateful. On this episode, we’ll be discussing Net Neutrality. Joining us is Sherry Lichtenberg, Principal for Telecommunications at the National Regulatory Research Institute; Andrew Gallo, network architect […]
That’s right, it’s time for another surveillance-free, EFF-approved episode of Healthy Paranoia! Where the passwords are salted and the packets are always encrypted. This episode is hosted by the infamous Mrs. Y, queen of metadata and official privacy advocate for Healthy Paranoia, and recorded in the NSA-proofed SCIF with Grecs, of Novainfosec.com and Shmoocon Firetalks. […]
The known universe has been ruled by the monolithic network device. In this time, the most precious substance in the Universe is the ASIC. The ASIC extends life. The ASIC expands consciousness. The ASIC is vital, it provides the ability to fold space. That is, travel to any part of the network. The ASIC exists […]
Hello boys and girls! What time is it? That’s right, it’s time for another fun-filled episode of Healthy Paranoia! Joining us in the top secret Healthy Paranoia treehouse and just in time for the release of PCI DSS 3.0 is special guest, Dr. Anton Chuvakin, Research Director at Gartner and recognized security expert in the […]
Ladies and gentleman, prepare to be mystified and amazed by another episode of Healthy Paranoia. Where even the unicorns are nerdy and the evil bit is always set on your packets. Just in time for Halloween, get ready for some tricks and definitely treats, because we’re going to discuss the intersection of magic, social engineering […]
Greetings fair ladies and kind sirs, I present yet another episode of Healthy Paranoia. In this episode we examine the notoriously mad, bad and dangerous to know; pentest dropbox. Joining Mrs. Y are some poètes maudits of the security realm, including; Taylor Banks, Dan Tentler, Kyle Stone, Nick Lennox and Jay James. A dropbox or […]
I previously wrote a post in response to an article that equated Snowden’s CEH certification to James Bond’s “license to kill.” Well, it looks like some technically-challenged media types are at it again. They’ve called Snowden “brilliant” for his ability to “impersonate” users on various systems in order to obtain certain documents and I felt […]
Willkommen, bienvenue, welcome! Meine Damen und Herren, Mesdames et Messieurs, Ladies and Gentlemen. Introducing the latest installment in that grand epic known as Healthy Paranoia. Where the nerds are a little nerdier, and the evil bit is always set on your packets. In this episode, we help launch the very first Security Oktoberfest, aka BSides DC. […]
Unless you’ve been living under a rock for the last couple of years, I’m sure you’ve read the articles about how bad prolonged sitting is for your health. If you sit for a major part of your day (at work, in traffic and at home), your risk of diabetes and heart disease is doubled. The […]
Today’s word of the day comes to Packetpushers courtesy of Seth Godin*: Stoogecraft. Stoogecraft is what happens when people or organizations in power do what feels right in the short run without thinking at all about the alternatives or the implications. It’s the result of fear or boredom or a misplaced focus. Sound familiar? Stoogecraft […]
It’s the latest dudilicious episode of Healthy Paranoia! This time we’ll be covering the topic of information sharing and analysis centers (ISAC), specifically in the research and educational networking sector, aka REN-ISAC. Joining Mrs. Y on this adventure into the land of dudeness is Wes Young, REN-ISAC Principal Security Engineer and Architect (El Duderino), Keith […]
This morning I read an article in which the writer thought that wireless security was too inconvenient and difficult, so he simply disabled it, leaving his network wide open. He was tired of his complex password being too hard for guests to use and made the comparison that they didn’t have to use these kinds […]
Recently the New York Times posted an article stating that while Edward Snowden was at the NSA, he learned to be a hacker by taking a CEH course and getting the certification. But the certification, listed on a résumé that Mr. Snowden later prepared, would also have given him some of the skills he needed […]
Get ready for another nerdilicious episode of Healthy Paranoia featuring Andrew Case, digital forensics researcher and a core developer for the Volatility Framework. Liam Randall joins Mrs. Y. as they discuss topics such as: The difference between forensics and incident response. Malware analysis vs. reverse engineering. Why you should treat a compromised system like a […]
Welcome to another lofty episode of Healthy Paranoia where we take on the profound problem of security certifications, specifically the Certified Information Systems Security Professional (CISSP). Joining Mrs. Y and Greg Ferro is an illustrious cast of infosec luminaries, including; well-known security analyst Wendy Nather, Novainfosec.com founder Grecs, IPv6 fanatic Joe Klein, and the enigmatic […]
I make no secret of my love for Seth Godin and his amazing insight into the world. Besides being a marketing genius, he’s like Ockham’s Razor in getting to the essence of a problem. Take today’s posting, which really resonated with me, because it seems to reflect my own frustration with a common problem in […]
Recently Greg Ferro published an e-book for bloggers, “Arse First Method of Technical Blogging.” It has some great suggestions (although I’m not sure what an arse is), but after reading it, I realized it really doesn’t apply to security blogging. Without further ado, here are some of my tips for good infosec blog posts. 1. […]
Grift’s like anything else, Roy. You don’t stand still. You either go up or down. Usually down, sooner or later. Lilly Dillon from “The Grifters” At Interop this month, every vendor had product sheets that claimed, “Now with SDN!” It’s the latest industry buzzword and I started to recall some previous one-hit wonders from the past. Remember […]
