Spoiler Alert

15/03/2019 33 min

Listen "Spoiler Alert"

Episode Synopsis

Josh tells us about the RSA security conference, and there are some new vulnerabilities that affect processors; one even has its own website. We also bring you some news about Facebook using phone numbers when they said they wouldn't, and Firefox's new secure file-transfer service.
RSA Conference (https://www.rsaconference.com)
Josh's article, RSA Conference 2019 Highlights: A Mac Perspective
"I Am Root": A Retrospective on a Severe Mac Vulnerability
If you want online privacy, change your phone number immediately (https://www.wired.co.uk/article/change-your-phone-number-online-privacy)
Two-Factor Authorization Apps for iOS
Mozilla launches its free, encrypted file-sharing service, Firefox Send (https://techcrunch.com/2019/03/12/mozilla-launches-its-free-encrypted-file-sharing-service-firefox-send/)
Apple's Mail Drop (sorry, I said AirDrop in the podcast) (https://support.apple.com/kb/ph2629?locale=en_US)
You. Shall. Not. Pass... word: Soon, you may be logging into websites using just your phone, face, fingerprint or token (https://www.theregister.co.uk/2019/03/05/web_authentication/)
Why 'ji32k7au4a83' Is a Remarkably Common Password (https://gizmodo.com/why-ji32k7au4a83-is-a-remarkably-common-password-1833045282)
Thunderclap (https://thunderclap.io)
Thunderbolt 3 'Thunderclap' vulnerabilities let malicious peripherals attack a Mac's memory (https://appleinsider.com/articles/19/02/27/thunderbolt-3-thunderclap-vulnerabilities-let-malicious-peripherals-attack-a-macs-memory)
SPOILER alert, literally: Intel CPUs afflicted with simple data-spewing spec-exec vulnerability (https://www.theregister.co.uk/2019/03/05/spoiler_intel_processor_flaw/)
All Intel chips open to new Spoiler non-Spectre attack: Don't expect a quick fix (https://www.zdnet.com/article/all-intel-chips-open-to-new-spoiler-non-spectre-attack-dont-expect-a-quick-fix/)
SPOILER: Speculative Load Hazards Boost Rowhammer and Cache Attacks (PDF) (https://arxiv.org/pdf/1903.00446.pdf)
Get 50% off Mac Premium Bundle X9, fully compatible with macOS Mojave, with the code PODCAST19. Download Intego Mac Premium Bundle X9 now at intego.com.