102 episodes

Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every week.

Records live every Tuesday at 4:30pm Eastern / 1:30pm Pacific / 20:30 UTC.

Security Now (Audio‪)‬ Security Now

    • Technology
    • 4.7 • 120 Ratings

Listen on Apple Podcasts
Requires subscription and macOS 11.4 or higher

Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every week.

Records live every Tuesday at 4:30pm Eastern / 1:30pm Pacific / 20:30 UTC.

Listen on Apple Podcasts
Requires subscription and macOS 11.4 or higher

    Passkeys: A Shattered Dream? - IoT Default Passwords, Passkeys

    Passkeys: A Shattered Dream? - IoT Default Passwords, Passkeys

    GCHQ: No more default passwords for consumer IoT devices!
    What happened with Chrome and 3rd-party cookies?
    Race conditions and multi-threading
    GM "accidentally" enrolled millions into "OnStar Smart Driver +" program
    Steve recommends Ryk Brown's "Frontiers Saga"
    SpinRite update
    Passkeys: A Shattered Dream?
    Show Notes - https://www.grc.com/sn/SN-972-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:
    business.eset.com/twit
    vanta.com/SECURITYNOW
    1bigthink.com
    lookout.com

    • 2 hrs 11 min
    Chat (out of) Control - Fuxnet, Android Quarantine, Gentoo

    Chat (out of) Control - Fuxnet, Android Quarantine, Gentoo

    What do you call "Stuxnet on steroids"??
    Voyager 1 update
    Android 15 to quarantine apps
    Thunderbird & Microsoft Exchange
    China bans Western encrypted messaging apps
    Gentoo says "no" to AI
    Cars collecting diving data
    Freezing your credit
    Investopedia
    Computer Science Abstractions
    Lazy People vs. Secure Systems
    Actalis issues free S/MIME certificates
    PIN Encryption
    DRAM and GhostRace
    AT&T Phishing Scam
    Race Conditions and Multi-core processors
    An Alternative to the Current Credit System
    SpinRite Updates
    Chat (out of) Control
    Show Notes - https://www.grc.com/sn/SN-971-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:
    canary.tools/twit - use code: TWIT
    lookout.com
    kolide.com/securitynow
    zscaler.com/zerotrustAI

    • 2 hrs 15 min
    GhostRace - AT&T Breach Update, Cookie Notices, Router Buttons

    GhostRace - AT&T Breach Update, Cookie Notices, Router Buttons

    An update on the AT&T data breach
    340,000 social security numbers leaked
    Cookie Notice Compliance
    The GDPR does enforce some transparency
    Physical router buttons
    Wifi enabled button pressers
    Netsecfish disclosure of Dlink NAS vulnerability
    Chrome bloat
    SpinRite update
    GhostRace
    Show Notes - https://www.grc.com/sn/SN-970-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:
    kolide.com/securitynow
    bitwarden.com/twit
    vanta.com/SECURITYNOW
    1bigthink.com

    • 1 hr 52 min
    Minimum Viable Secure Product - Dlink NAS Backdoor, Privnote, Crowdefense

    Minimum Viable Secure Product - Dlink NAS Backdoor, Privnote, Crowdefense

    Out-of-support DLink NAS devices contain hard coded backdoor credentials

    Privnote is not so "Priv"

    Crowdfense is willing to pay millions

    Engineers Pinpoint Cause of Voyager 1 Issue, Are Working on Solution

    SpinRite Update

    Minimum Viable Secure Product

    Show Notes - https://www.grc.com/sn/SN-969-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:
    zscaler.com/zerotrustAI
    business.eset.com/twit
    lookout.com
    joindeleteme.com/twit promo code TWIT

    • 1 hr 51 min
    A Cautionary Tale - XZ Outbreak, AT&T Data Breach

    A Cautionary Tale - XZ Outbreak, AT&T Data Breach

    A near-Universal (Local) Linux Elevation of Privilege vulnerability
    TechCrunch informed AT&T of a 5 year old data breach
    Signal to get very useful cloud backups
    Telegram to allow restricted incoming
    HP exits Russia ahead of schedule
    Advertisers are heavier users of Ad Blockers than average Americans!
    The Google Incognito Mode Lawsuit
    Canonical fights malicious Ubuntu store apps
    Spinrite update
    A Cautionary Tale
    Show Notes - https://www.grc.com/sn/SN-968-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:
    1bigthink.com
    kolide.com/securitynow
    Melissa.com/twit
    vanta.com/SECURITYNOW

    • 1 hr 45 min
    GoFetch - Apple vs. DOJ, ".INTERNAL" TLD

    GoFetch - Apple vs. DOJ, ".INTERNAL" TLD

    Apple vs U.S. DOJ
    G.M.'s Unbelievably Horrible Driver Data Sharing Ends
    Super Sushi Samurai
    Apple has effectively abandoned HomeKit Secure Routers
    The forthcoming ".INTERNAL" TLD
    The United Nations vs AI.
    Telegram now blocked throughout Spain
    Vancouver Pwn2Own 2024
    China warns of incoming hacks
    Annual Tax Season Phishing Deluge
    SpinRite update
    Authentication without a phone
    Are Passkeys quantum safe?
    GoFetch: The Unpatchable vulnerability in Apple chips
    Show Notes - https://www.grc.com/sn/SN-967-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:
    zscaler.com/zerotrustAI
    bitwarden.com/twit
    canary.tools/twit - use code: TWIT
    panoptica.app
    kolide.com/securitynow

    • 2 hrs 1 min

Customer Reviews

4.7 out of 5
120 Ratings

120 Ratings

center15 ,

Steve Please Ditch Leo Go Solo

The best security podcast on the planet totally ruined by Leo’s leftist agenda. When he’s not eating he’s butting in. Steve setup your own podcast and go solo with donations.

p.turpie ,

Good content, but too long

There’s a lot of good content in this podcast, but it’s FAR TOO LONG. Even listening to this podcast at 2x speed (I listen to most podcasts at 1.5x) makes me wish Apple had an even faster mode.

Please stop reading press releases and new laws in detail.

Steve’s occasional rants are frustrating as they go on forever and often show a lack understanding of the reasons behind whatever he it is disagrees with.

I understand the need for ads, but they go for so long that I usually skip them. On other podcasts where the ads are 30-60 seconds it’s not worth the effort to skip them, but on Security Now there are several 5 minute ad breaks. It’s over the top. Especially if you’ve already heard a previous ad for that product.

I don’t mind the off topic discussions of sci-fi, tv, etc. I’ve quite liked a few of the suggestions.

(We also probably don’t need any more pictures of the week of ineffective gates.)

sonarb ,

Excellent show but too long

Anyone who writes quality code in assembler is worthy of respect. And so too is Mr Gibson. I have learned a lot through this podcast from this guy. The part I don’t like is when he spends a lot of time reading excepts (especially the USA centric legislature). It’s quite boring and I find myself wishing I didn’t have to waste my valuable time listening to this. I like it when Steve explains things in his own words I don’t need someone reading other people’s work to me. Thanks Steve for your excellent work. I would appreciate shorter and more concise podcast episodes ... if possible please.

Top Podcasts In Technology

Acquired
Ben Gilbert and David Rosenthal
Lex Fridman Podcast
Lex Fridman
All-In with Chamath, Jason, Sacks & Friedberg
All-In Podcast, LLC
The Gatekeepers
BBC Radio 4
Hard Fork
The New York Times
Darknet Diaries
Jack Rhysider

You Might Also Like

Windows Weekly (Audio)
TWiT
This Week in Tech (Audio)
TWiT
Smashing Security
Graham Cluley & Carole Theriault
MacBreak Weekly (Audio)
TWiT
CyberWire Daily
N2K Networks
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich

More by TWiT TV

This Week in Tech (Audio)
TWiT
MacBreak Weekly (Audio)
TWiT
Windows Weekly (Audio)
TWiT
This Week in Tech (Video)
TWiT
MacBreak Weekly (Video)
TWiT
iOS Today (Audio)
TWiT