SN 601: The First SHA-1 Collision

Security Now (Video HI) show

Summary: <p>This week, Leo and Steve discuss the "CloudBleed" adventure, another project zero 90-day timer expires for Microsoft, this week's IoT head-shaker, a New York airport exposes critical server data for a year, another danger created by inline third party TLS-intercepting "middleboxes", more judicial thrashing over fingerprint warrants, Amazon says no to Echo data warrant, a fun drone-enabled proof on concept is widely misunderstood, another example of A/V attack surface expansion, some additional Crypto education pointers and miscellany... and what does Google's deliberate creation of two SHA-1-colliding files actually mean?</p><p>We invite you to read our <a href="">show notes</a>.</p> <p><strong>Hosts:</strong> <a href="">Steve Gibson</a> and <a href="">Leo Laporte</a></p> <p>Download or subscribe to this show at <a href=""></a>.</p><p>You can submit a question to Security Now! at the <a href="" target="_blank">GRC Feedback Page</a>.</p><p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="" target="_blank"></a>, also the home of the best disk maintenance and recovery utility ever written <a href="" target="_blank">Spinrite 6</a>.</p><p>Bandwidth for Security Now is provided by <a href="" target="_blank">CacheFly</a>.</p>