Listen "Spoiler Alert"
Episode Synopsis
Josh tells us about the RSA security conference, and there are some new vulnerabilities that affect processors; one even has its own website. We also bring you some news about Facebook using phone numbers when they said they wouldn't, and Firefox's new secure file-transfer service.
RSA Conference (https://www.rsaconference.com)
Josh's article, RSA Conference 2019 Highlights: A Mac Perspective
"I Am Root": A Retrospective on a Severe Mac Vulnerability
If you want online privacy, change your phone number immediately (https://www.wired.co.uk/article/change-your-phone-number-online-privacy)
Two-Factor Authorization Apps for iOS
Mozilla launches its free, encrypted file-sharing service, Firefox Send (https://techcrunch.com/2019/03/12/mozilla-launches-its-free-encrypted-file-sharing-service-firefox-send/)
Apple's Mail Drop (sorry, I said AirDrop in the podcast) (https://support.apple.com/kb/ph2629?locale=en_US)
You. Shall. Not. Pass... word: Soon, you may be logging into websites using just your phone, face, fingerprint or token (https://www.theregister.co.uk/2019/03/05/web_authentication/)
Why 'ji32k7au4a83' Is a Remarkably Common Password (https://gizmodo.com/why-ji32k7au4a83-is-a-remarkably-common-password-1833045282)
Thunderclap (https://thunderclap.io)
Thunderbolt 3 'Thunderclap' vulnerabilities let malicious peripherals attack a Mac's memory (https://appleinsider.com/articles/19/02/27/thunderbolt-3-thunderclap-vulnerabilities-let-malicious-peripherals-attack-a-macs-memory)
SPOILER alert, literally: Intel CPUs afflicted with simple data-spewing spec-exec vulnerability (https://www.theregister.co.uk/2019/03/05/spoiler_intel_processor_flaw/)
All Intel chips open to new Spoiler non-Spectre attack: Don't expect a quick fix (https://www.zdnet.com/article/all-intel-chips-open-to-new-spoiler-non-spectre-attack-dont-expect-a-quick-fix/)
SPOILER: Speculative Load Hazards Boost Rowhammer and Cache Attacks (PDF) (https://arxiv.org/pdf/1903.00446.pdf)
Get 50% off Mac Premium Bundle X9, fully compatible with macOS Mojave, with the code PODCAST19. Download Intego Mac Premium Bundle X9 now at intego.com.
RSA Conference (https://www.rsaconference.com)
Josh's article, RSA Conference 2019 Highlights: A Mac Perspective
"I Am Root": A Retrospective on a Severe Mac Vulnerability
If you want online privacy, change your phone number immediately (https://www.wired.co.uk/article/change-your-phone-number-online-privacy)
Two-Factor Authorization Apps for iOS
Mozilla launches its free, encrypted file-sharing service, Firefox Send (https://techcrunch.com/2019/03/12/mozilla-launches-its-free-encrypted-file-sharing-service-firefox-send/)
Apple's Mail Drop (sorry, I said AirDrop in the podcast) (https://support.apple.com/kb/ph2629?locale=en_US)
You. Shall. Not. Pass... word: Soon, you may be logging into websites using just your phone, face, fingerprint or token (https://www.theregister.co.uk/2019/03/05/web_authentication/)
Why 'ji32k7au4a83' Is a Remarkably Common Password (https://gizmodo.com/why-ji32k7au4a83-is-a-remarkably-common-password-1833045282)
Thunderclap (https://thunderclap.io)
Thunderbolt 3 'Thunderclap' vulnerabilities let malicious peripherals attack a Mac's memory (https://appleinsider.com/articles/19/02/27/thunderbolt-3-thunderclap-vulnerabilities-let-malicious-peripherals-attack-a-macs-memory)
SPOILER alert, literally: Intel CPUs afflicted with simple data-spewing spec-exec vulnerability (https://www.theregister.co.uk/2019/03/05/spoiler_intel_processor_flaw/)
All Intel chips open to new Spoiler non-Spectre attack: Don't expect a quick fix (https://www.zdnet.com/article/all-intel-chips-open-to-new-spoiler-non-spectre-attack-dont-expect-a-quick-fix/)
SPOILER: Speculative Load Hazards Boost Rowhammer and Cache Attacks (PDF) (https://arxiv.org/pdf/1903.00446.pdf)
Get 50% off Mac Premium Bundle X9, fully compatible with macOS Mojave, with the code PODCAST19. Download Intego Mac Premium Bundle X9 now at intego.com.
More episodes of the podcast Intego Mac Podcast
Episode 394: The Last One
30/04/2025
Episode 393: Reverse Engineering
24/04/2025
Episode 389: Gaming on the Mac
27/03/2025
Episode 388: RCS, FBI, and Alexa
20/03/2025
Episode 387: Defense in Depth
13/03/2025