Securing the International IoT Supply Chain

Together with Nate Kim (former student) and Trey Herr (Atlantic Council Cyber Statecraft Initiative), I have written a paper on IoT supply chain security. The basic problem we try to solve is: ...

Another Intel Speculative Execution Vulnerability

Remember Spectre and Meltdown? Back in early 2018, I wrote: Spectre and Meltdown are pretty catastrophic vulnerabilities, but they only affect the confidentiality of data. Now that they -- and the research ...
remote work security

Planning a Secure Transition From WFH to the Office

Organizations need to safely return devices and transition people back into the workplace post-COVID-19. What does that mean? As of this writing, all 50 states have allowed some sort of re-opening efforts ...
Security Boulevard
corporate networks

Report: More Unknown Devices on Corporate Networks

A report published this week by Sepio Systems suggests the number of devices being attached to corporate networks since the start of the COVID-19 pandemic began has increased sharply. Sepio Systems, a ...
Security Boulevard

USB Cable Kill Switch for Laptops

BusKill is designed to wipe your laptop (Linux only) if it is snatched from you in a public place: The idea is to connect the BusKill cable to your Linux laptop on ...

DEF CON 27, Bio Hacking Village, Dr Avi Rubin’s ‘Beyond The Firmware: The Attack Surface of a Networked Medical Device’

Thanks to Def Con 27 Volunteers, Videographers and Presenters for publishing their superlative conference videos via their YouTube Channel for all to see, enjoy and learn. Permalink ...

TPM-Fail Attacks Against Cryptographic Coprocessors

Really interesting research: TPM-FAIL: TPM meets Timing and Lattice Attacks, by Daniel Moghimi, Berk Sunar, Thomas Eisenbarth, and Nadia Heninger. Abstract: Trusted Platform Module (TPM) serves as a hardware-based root of trust ...
Not Google’s Quantum AI....

Quantum Of Tuesday: Google Quantum AI’s Paper, Whereabouts Known

Not Google’s Quantum AI.... via Bianca Bharti - writing for Canada's National Post, comes news of Google, Inc's (Nasdaq: GOOGL) stunning accomplishment in quantum computation. Described in a paper entitled 'Quantum supremacy ...
automation

IBM Adds Encryption Everywhere Capabilities to the Mainframe

IBM today unveiled a z15 mainframe that takes advantage of additional processing horsepower to create Trusted Data Objects that allow organizations to employ Privacy Passports technology to encrypt data across a hybrid ...
Security Boulevard
BSides London 2019

Security BSides London 2019, Corey Forbes’ ‘Aletheia: GPU Accelerated File Carving’

Many thanks to Security BSides London for publishing their outstanding conference videos on YouTube. Permalink ...