SN 677: The Foreshadow Flaw

Security Now (Video LO) show

Summary: <p>As we head into our 14th year of Security Now​, this week we look at some of the research released during last week's USENIX Security symposium, we also take a peek at last week's Patch Tuesday details, Skype's newly released implementation of Open Whisper Systems' Signal privacy protocol, Google's Chrome browser's increasing pushback against being injected into, news following last week's observation about Google's user tracking, Microsoft's announcement of more spoofed domain takedowns, another page table sharing vulnerability, believe it or not... "Malicious Regular Expressions", some numbers on how much money CoinHive is raking in, flaws in browser and their add-ons that allow tracking-block bypasses, two closing-the-loop bits of feedback, and then a look at the details of the latest Intel Speculation disaster known as "The Foreshadow Flaw".</p> <p>We invite you to read our <a href="">show notes.</a></p> <p><strong>Hosts:</strong> <a href="">Steve Gibson</a> and <a href="">Leo Laporte</a></p> <p>Download or subscribe to this show at <a href=""></a>.</p> <p>You can submit a question to Security Now! at the <a href="" target="_blank">GRC Feedback Page</a>.</p> <p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="" target="_blank"></a>, also the home of the best disk maintenance and recovery utility ever written <a href="" target="_blank">Spinrite 6</a>.</p> <p><strong>Sponsors:</strong></p><ul> <li><a href=""> offer code SECURITYNOW</a></li> <li><a href=""></a></li> <li><a href=""></a></li> </ul>