<?xml version="1.0" encoding="utf-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/" version="2.0">
<channel>
<title> UIS Security Podcast </title>
<description> Paul Mazumdar and Graham Rymer discuss the month's security issues and occasionally manage to interview experts beyond the University of Cambridge </description>
<itunes:author>Paul Mazumdar </itunes:author>
<link> http://www.uis.cam.ac.uk/cybersecurity </link>
<itunes:image href="http://people.ds.cam.ac.uk/pm107/d5bc2066-d2da-417f-ab21-d6527ec540ec.png"/>
<pubDate>Tue, 22 Oct 2019 16:27:00 +0100 </pubDate>
<language>en-gb</language>
<copyright> Copyright 2018-2019 University of Cambridge Information Services </copyright>

<atom:link href="http://pm107.user.srcf.net/podcast.rss" rel="self" type="application/rss+xml"/>
<itunes:explicit>no</itunes:explicit>
<itunes:owner>
  <itunes:name>Paul Mazumdar</itunes:name>
  <itunes:email>pm107@cam.ac.uk</itunes:email>
</itunes:owner>

<itunes:summary>Paul Mazumdar and Kieren Lovell discuss the month's security issues and occasionally manage to interview experts beyond the University of Cambridge </itunes:summary><itunes:subtitle>Paul Mazumdar and Kieren Lovell discuss the month's security issues and occasionally manage to interview experts beyond the University of Cambridge </itunes:subtitle><itunes:category text="Technology"/><item>
<title>Summer 2019: Announcement</title>
<description>What to do if you want to carry on receiving episodes of the UIS Security Podcast.  Depending on your setup, it might be very little...
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:servicedesk@uis.cam.ac.uk"&gt;servicedesk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Phish of the Day:         &lt;a href="https://help.uis.cam.ac.uk/service/security/stay-safe-online/phishing/phishy"&gt;https://help.uis.cam.ac.uk/service/security/stay-safe-online/phishing/phishy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sophos RDP report:         &lt;a href="https://sophos.com/rdp"&gt;https://sophos.com/rdp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Patch RDP:         &lt;a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182"&gt;https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Patch Sharepoint:                &lt;a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604"&gt;https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Subsequent to recording this, the audio files have been moved over to the SRCF, so that may well become the new home.
</description>
<pubDate> Thu, 29 Aug 2019 17:30:00 +0100 </pubDate>
<enclosure length="3521857" type="audio/mpeg" url="https://pm107.user.srcf.net/sp017.mp3"/>
<guid>https://pm107.user.srcf.net/sp017.mp3</guid>
<itunes:summary>Podcast migration and server patching</itunes:summary>
<itunes:subtitle>Podcast migration and server patching</itunes:subtitle>
<itunes:duration>00:03:40</itunes:duration>
<itunes:author> Paul Mazumdar </itunes:author>
<itunes:explicit>no</itunes:explicit></item>

<item>
<title>June 2019: Steganography</title>
<description>What if you had something to hide?  Could you plant it in, say, a podcast episode with nobody noticing?
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:servicedesk@uis.cam.ac.uk"&gt;servicedesk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Phish of the Day:         &lt;a href="https://help.uis.cam.ac.uk/service/security/stay-safe-online/phishing/phishy"&gt;https://help.uis.cam.ac.uk/service/security/stay-safe-online/phishing/phishy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;National Cyber Security Centre:         &lt;a href="https://www.ncsc.gov.uk/"&gt;https://www.ncsc.gov.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;US visas:         &lt;a href="https://www.nytimes.com/2019/06/02/us/us-visa-application-social-media.html"&gt;https://www.nytimes.com/2019/06/02/us/us-visa-application-social-media.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AMCA breach:                &lt;a href="http://newsroom.questdiagnostics.com/AMCADataSecurityIncident"&gt;http://newsroom.questdiagnostics.com/AMCADataSecurityIncident&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Talktalk non-notification:                &lt;a href="https://www.bbc.co.uk/news/business-48351900"&gt;https://www.bbc.co.uk/news/business-48351900&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MS patches include moribund OSes:  &lt;a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708"&gt;https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sensitive data on used hard drives:  &lt;a href="https://www.prnewswire.com/news-releases/blancco-reveals-42-of-used-drives-sold-on-ebay-are-holding-sensitive-data-300838201.html"&gt;https://www.prnewswire.com/news-releases/blancco-reveals-42-of-used-drives-sold-on-ebay-are-holding-sensitive-data-300838201.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Windows Hello FIDO2 certified in 1903: &lt;a href="https://nakedsecurity.sophos.com/2019/05/14/windows-10-brings-password-free-access-another-step-closer/"&gt;https://nakedsecurity.sophos.com/2019/05/14/windows-10-brings-password-free-access-another-step-closer/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<pubDate> Thu, 04 Jul 2019 10:21:00 +0100 </pubDate>
<enclosure length="39327845" type="audio/mpeg" url="https://pm107.user.srcf.net/sp016b.mp3"/>
<guid>https://pm107.user.srcf.net/sp016b.mp3</guid>
<itunes:summary>Windows 7 and network segregation</itunes:summary>
<itunes:subtitle>Supply-chain hacking and cross-site scripting</itunes:subtitle>
<itunes:duration>00:40:55</itunes:duration>
<itunes:author> Paul Mazumdar </itunes:author>
<itunes:explicit>no</itunes:explicit></item>

<item>
<title>April 2019: Supply chain shenanigans</title>
<description>Paul and Graham are joined by Joe Irvin who gives us the benefit of his experience fighting emotet. We also look at supply-chain attacks and cross-site scripting.
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Phish of the Day:         &lt;a href="https://help.uis.cam.ac.uk/service/security/stay-safe-online/phishing/phishy"&gt;https://help.uis.cam.ac.uk/service/security/stay-safe-online/phishing/phishy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;National Cyber Security Centre:         &lt;a href="https://www.ncsc.gov.uk/"&gt;https://www.ncsc.gov.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Exercise in a Box:         &lt;a href="https://www.ncsc.gov.uk/information/exercise-in-a-box"&gt;https://www.ncsc.gov.uk/information/exercise-in-a-box&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Naked Security:                &lt;a href="https://nakedsecurity.sophos.com/"&gt;https://nakedsecurity.sophos.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hot for Security:                &lt;a href="https://hotforsecurity.bitdefender.com/"&gt;https://hotforsecurity.bitdefender.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OWASP Top 10 (2017):  &lt;a href="https://www.owasp.org/images/7/72/OWASP_Top_10-2017_%28en%29.pdf.pdf"&gt;https://www.owasp.org/images/7/72/OWASP_Top_10-2017_%28en%29.pdf.pdf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OWASP Top 10 on LiL:  &lt;a href="https://www.linkedin.com/learning/learning-the-owasp-top-10"&gt;https://www.linkedin.com/learning/learning-the-owasp-top-10&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ASUS: &lt;a href="https://www.reuters.com/article/us-asus-cyber/asus-implements-fix-for-malware-attack-idUSKCN1R710X"&gt;https://www.reuters.com/article/us-asus-cyber/asus-implements-fix-for-malware-attack-idUSKCN1R710X&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Bitlocker vulnerability:  &lt;a href="https://pulsesecurity.co.nz/articles/TPM-sniffing"&gt;https://pulsesecurity.co.nz/articles/TPM-sniffing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Second hand USB drives:                &lt;a href="https://www.comparitech.com/blog/information-security/secondhand-usb-drive-memory-stick-study/"&gt;https://www.comparitech.com/blog/information-security/secondhand-usb-drive-memory-stick-study/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Japanese police charge 13-yr old: &lt;a href="https://www.zdnet.com/article/japanese-police-charge-13-year-old-for-sharing-unclosable-popup-prank-online/"&gt;https://www.zdnet.com/article/japanese-police-charge-13-year-old-for-sharing-unclosable-popup-prank-online/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Windows automatic updating changes:  &lt;a href="https://blogs.windows.com/windowsexperience/2019/04/04/improving-the-windows-10-update-experience-with-control-quality-and-transparency/#PLKYTL4ai2hMMybG.97"&gt;https://blogs.windows.com/windowsexperience/2019/04/04/improving-the-windows-10-update-experience-with-control-quality-and-transparency/#PLKYTL4ai2hMMybG.97&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<pubDate> Fri, 26 Apr 2019 17:28:00 +0100 </pubDate>
<enclosure length="54233149" type="audio/mpeg" url="https://pm107.user.srcf.net/sp015.mp3"/>
<guid>https://pm107.user.srcf.net/sp015.mp3</guid>
<itunes:summary>Supply-chain hacking and cross-site scripting</itunes:summary>
<itunes:subtitle>Supply-chain hacking and cross-site scripting</itunes:subtitle>
<itunes:duration>00:44:01</itunes:duration>
<itunes:author> Paul Mazumdar </itunes:author>
<itunes:explicit>no</itunes:explicit></item>


<item>
<title>February/March 2019: Device passwords</title>
<description>Paul and Graham give their usual round-up of issues both within and outside the University; Graham takes a particular look at Cisco"s SmartInstall.
&lt;br /&gt;
About four minutes into the episode, Paul alludes to a change in the way people contact CERT but wondered if it might be premature to
mention it.  The day after we recorded this, an e-mail went out to the uis-announce mailing list detailing the way that security response
is to become a second-line service from 11 April with immediate issues being resolved by the UIS Service Desk.  Perfect timing!
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Phish of the Day:         &lt;a href="https://help.uis.cam.ac.uk/service/security/stay-safe-online/phishing/phishy"&gt;https://help.uis.cam.ac.uk/service/security/stay-safe-online/phishing/phishy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;National Cyber Security Centre:         &lt;a href="https://www.ncsc.gov.uk/"&gt;https://www.ncsc.gov.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Three Random Words:         &lt;a href="https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0"&gt;https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Human Factor:                &lt;a href="http://jennyradcliffe.com/the-deception-chronicles/"&gt;http://jennyradcliffe.com/the-deception-chronicles/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;US govt certificate non-renewal:  &lt;a href="https://nakedsecurity.sophos.com/2019/02/25/hijacker-pwns-tampa-mayors-account-2-weeks-before-election/"&gt;http://jennyradcliffe.com/the-deception-chronicles/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Tampa mayor Twitter hacked:                &lt;a href="http://jennyradcliffe.com/the-deception-chronicles/"&gt;https://nakedsecurity.sophos.com/2019/02/25/hijacker-pwns-tampa-mayors-account-2-weeks-before-election/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Drupal patching: &lt;a href="https://www.theregister.co.uk/2019/02/27/drupal_rce_exploits_seen_wild/"&gt;https://www.theregister.co.uk/2019/02/27/drupal_rce_exploits_seen_wild/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chrome flagging lookalikes:  &lt;a href="https://www.zdnet.com/article/google-chrome-to-get-warnings-for-lookalike-urls/"&gt;https://www.zdnet.com/article/google-chrome-to-get-warnings-for-lookalike-urls/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<pubDate> Fri, 29 Mar 2019 17:00:00 +0000 </pubDate>
<enclosure length="33264265" type="audio/mpeg" url="https://pm107.user.srcf.net/sp014.mp3"/>
<guid>https://pm107.user.srcf.net/sp014.mp3</guid>
<itunes:summary>Router security</itunes:summary>
<itunes:subtitle>Router security</itunes:subtitle>
<itunes:duration>00:34:39</itunes:duration>
<itunes:author> Paul Mazumdar </itunes:author>
<itunes:explicit>no</itunes:explicit></item>
<item>

<title>January 2019: Passwords again....again!</title>
<description>Graham reports on his tests of systems across the University and the news isn't great, particularly on the password front.  Apparently we still have work to do in getting the message across.  We also do our usual trawl of security news inside and outside the University.
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;National Cyber Security Centre:         &lt;a href="https://www.ncsc.gov.uk/"&gt;https://www.ncsc.gov.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Three Random Words:         &lt;a href="https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0"&gt;https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Friendly Probing:                &lt;a href="https://probing.csx.cam.ac.uk/"&gt;https://probing.csx.cam.ac.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Home routers:  &lt;a href="https://cyber-itl.org/assets/papers/2018/build_safety_of_software_in_28_popular_home_routers.pdf"&gt;https://cyber-itl.org/assets/papers/2018/build_safety_of_software_in_28_popular_home_routers.pdf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Phish bypassing (SMS) 2FA:                &lt;a href="https://blog.certfa.com/posts/the-return-of-the-charming-kitten/"&gt;https://blog.certfa.com/posts/the-return-of-the-charming-kitten/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Worst password list: &lt;a href="https://www.teamsid.com/100-worst-passwords-top-50/"&gt;https://www.teamsid.com/100-worst-passwords-top-50/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;USDHS copying data:  &lt;a href="https://www.oig.dhs.gov/sites/default/files/assets/2018-12/OIG-19-10-Nov18.pdf"&gt;https://www.oig.dhs.gov/sites/default/files/assets/2018-12/OIG-19-10-Nov18.pdf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MS combatting scam support:                &lt;a href="https://blogs.microsoft.com/on-the-issues/2018/11/29/new-breakthroughs-in-combatting-tech-support-scams/"&gt;https://blogs.microsoft.com/on-the-issues/2018/11/29/new-breakthroughs-in-combatting-tech-support-scams/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chrome mitigates ads masquerading as clickbait:  &lt;a href="https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html"&gt;https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Edge and the Mail:                &lt;a href="https://uk.pcmag.com/news-analysis/119288/microsofts-edge-browser-says-not-to-trust-the-daily-mail"&gt;https://uk.pcmag.com/news-analysis/119288/microsofts-edge-browser-says-not-to-trust-the-daily-mail&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Wikipedia and the Mail: &lt;a href="https://www.theguardian.com/technology/2017/feb/08/wikipedia-bans-daily-mail-as-unreliable-source-for-website"&gt;https://www.theguardian.com/technology/2017/feb/08/wikipedia-bans-daily-mail-as-unreliable-source-for-website&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<pubDate> Mon, 28 Jan 2019 16:00:00 +0000 </pubDate>
<enclosure length="27486817" type="audio/mpeg" url="https://pm107.user.srcf.net/sp013.mp3"/>
<guid>https://pm107.user.srcf.net/sp013.mp3</guid>
<itunes:summary>Passwords again...again!</itunes:summary>
<itunes:subtitle>Passwords again...again!</itunes:subtitle>
<itunes:duration>00:28:37</itunes:duration>
<itunes:author> Paul Mazumdar </itunes:author>
<itunes:explicit>no</itunes:explicit></item>

<item>
<title>December 2018: Christmas Special</title>
<description>As well as the usual news from the University and further afield, Paul and Graham reflect on the last year, consider password managers and
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Australian anti-encryption bill:  &lt;a href="https://thehackernews.com/2018/12/australia-anti-encryption-bill.html"&gt;https://thehackernews.com/2018/12/australia-anti-encryption-bill.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Russian involvement in bit for US defence:                &lt;a href="https://www.bbc.co.uk/news/world-us-canada-46489689"&gt;https://www.bbc.co.uk/news/world-us-canada-46489689&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;HR phish: &lt;a href="https://twitter.com/InfoSecSherpa/status/1062036305146724354"&gt;https://twitter.com/InfoSecSherpa/status/1062036305146724354&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;False detail on Google Maps:  &lt;a href="https://www.businessinsider.com/scammers-edit-google-maps-bank-listings-fraud-2018-11?r=US&amp;IR=T"&gt;https://www.businessinsider.com/scammers-edit-google-maps-bank-listings-fraud-2018-11?r=US&amp;IR=T&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Dashlane:                &lt;a href="https://www.dashlane.com/"&gt;https://www.dashlane.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Keepass: &lt;a href="https://www.keepass.info/"&gt;https://www.keepass.info/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<pubDate> Tue, 25 Dec 2018 12:00:00 +0000 </pubDate>
<enclosure length="25913739" type="audio/mpeg" url="https://pm107.user.srcf.net/sp012.mp3"/>
<guid>https://pm107.user.srcf.net/sp012.mp3</guid>
<itunes:summary>Christmas Special</itunes:summary>
<itunes:subtitle>Christmas Special</itunes:subtitle>
<itunes:duration>00:26:59</itunes:duration>
<itunes:author> Paul Mazumdar </itunes:author>
<itunes:explicit>no</itunes:explicit></item>

<item>
<title>November 2018: Podcast-lite</title>
<description>Paul goes through the news headlines in the University of Cambridge and further afield in a shorter-than-usual episode.
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Mobile third-party tracking:                &lt;a href="https://arxiv.org/pdf/1804.03603.pdf"&gt;https://arxiv.org/pdf/1804.03603.pdf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Password length and re-use:                &lt;a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3142270"&gt;https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3142270&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;#OneReset: &lt;a href="https://www.cyberaware.gov.uk/blog/one-reset-you-need-protect-your-emails-hackers"&gt;https://www.cyberaware.gov.uk/blog/one-reset-you-need-protect-your-emails-hackers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<pubDate> Fri, 30 Nov 2018 17:00:00 +0000 </pubDate>
<enclosure length="10524345" type="audio/mpeg" url="https://pm107.user.srcf.net/sp010.mp3"/>
<guid>https://pm107.user.srcf.net/sp010.mp3</guid>
<itunes:summary>Podcast-lite</itunes:summary>
<itunes:subtitle>Podcast-lite</itunes:subtitle>
<itunes:duration>00:10:57</itunes:duration>
<itunes:author> Paul Mazumdar </itunes:author>
<itunes:explicit>no</itunes:explicit></item>


<item>
<title>October 2018: Probing and shrinkage</title>
<description>Paul and Graham are joined this month by Anna Langley who talks about developments to the friendly probing suite.  We also talk about URL shorteners and Graham's observations from recent penetration tests.
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Friendly Probing:                &lt;a href="https://probing.csx.cam.ac.uk/"&gt;https://probing.csx.cam.ac.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Financial phishing posters from UIS Comms:                &lt;a href="https://www.uis.cam.ac.uk/downloads/financial-phishing"&gt;https://www.uis.cam.ac.uk/downloads/financial-phishing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Protecting your privacy when online dating: &lt;a href="https://www.makeuseof.com/tag/online-dating-privacy-tips/"&gt;https://www.makeuseof.com/tag/online-dating-privacy-tips/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google reverse image search:                &lt;a href="https://support.google.com/websearch/answer/1325808?hl=en"&gt;https://support.google.com/websearch/answer/1325808?hl=en&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Swytch: &lt;a href="https://www.swytch.com/"&gt;https://www.swytch.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Burnermail:                &lt;a href="https://burnermail.io/"&gt;https://burnermail.io/&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;OpayQ: Link dead  &lt;/li&gt;
&lt;li&gt;Latest Facebook data breach: &lt;a href="https://nakedsecurity.sophos.com/2018/10/15/facebook-opens-up-about-data-breach-details/"&gt;https://nakedsecurity.sophos.com/2018/10/15/facebook-opens-up-about-data-breach-details/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Brian Acton interview:                &lt;a href="https://www.forbes.com/sites/parmyolson/2018/09/26/exclusive-whatsapp-cofounder-brian-acton-gives-the-inside-story-on-deletefacebook-and-why-he-left-850-million-behind/#60ff07af3f20"&gt;https://www.forbes.com/sites/parmyolson/2018/09/26/exclusive-whatsapp-cofounder-brian-acton-gives-the-inside-story-on-deletefacebook-and-why-he-left-850-million-behind/#60ff07af3f20&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chrome password generator: &lt;a href="https://www.zdnet.com/article/chrome-69-released-with-new-ui-and-random-password-generator/"&gt;https://www.zdnet.com/article/chrome-69-released-with-new-ui-and-random-password-generator/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;TLS 1.3 in Chrome/Firefox/Safari:                &lt;a href="hhttps://geekflare.com/enable-tls-1-3-in-browsers/"&gt;https://geekflare.com/enable-tls-1-3-in-browsers/&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;Apple Hacky Hack Hack: &lt;a href="https://www.bbc.co.uk/news/technology-45219895"&gt;https://www.bbc.co.uk/news/technology-45219895&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;National Cyber Security Centre:         &lt;a href="https://www.ncsc.gov.uk/"&gt;https://www.ncsc.gov.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NCSC Web Check:         &lt;a href="https://www.ncsc.gov.uk/blog-post/web-check-helping-you-secure-your-public-sector-websites"&gt;https://www.ncsc.gov.uk/blog-post/web-check-helping-you-secure-your-public-sector-websites&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;URL Scan:                &lt;a href="https://urlscan.io"&gt;https://urlscan.io&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NCBI Blast:                &lt;a href="https://blast.ncbi.nlm.nih.gov/Blast.cgi"&gt;https://blast.ncbi.nlm.nih.gov/Blast.cgi&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<pubDate> Wed, 31 Oct 2018 17:35:35 +0000 </pubDate>
<enclosure length="41247496" type="audio/mpeg" url="https://pm107.user.srcf.net/sp009.mp3"/>
<guid>https://pm107.user.srcf.net/sp009.mp3</guid>
<itunes:summary>Friendly probing, URL shorteners and Blast.</itunes:summary>
<itunes:subtitle>Friendly probing, URL shorteners and Blast.</itunes:subtitle>
<itunes:duration>00:34:22</itunes:duration>
<itunes:author> Paul Mazumdar </itunes:author>
<itunes:explicit>no</itunes:explicit></item>

<item>
<title>August 2018: Challenge Graham!</title>
<description>Paul, Graham and Chris Quy gather round the microphones to talk about CERT 9to5, password timeouts, ePO and managing your consultants properly.  Plus we telegraph other changes to the podcast line-up and Graham issues a rash challenge...
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chrome 68 flagging http:                &lt;a href="https://www.youtube.com/watch?v=LIHBVwQlosA"&gt;https://www.youtube.com/watch?v=LIHBVwQlosA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;GRU forgets VPN: &lt;a href="https://hotforsecurity.bitdefender.com/blog/guccifer-2-0s-schoolboy-error-reveals-hes-hacking-from-moscow-19704.html"&gt;https://hotforsecurity.bitdefender.com/blog/guccifer-2-0s-schoolboy-error-reveals-hes-hacking-from-moscow-19704.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google claim no successful phishing:                &lt;a href="https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/"&gt;https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Money laundering through in-game assets: &lt;a href="https://kromtech.com/blog/security-center/digital-laundry"&gt;https://kromtech.com/blog/security-center/digital-laundry&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Photoshop CC patch:                &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12810"&gt;https://nvd.nist.gov/vuln/detail/CVE-2018-12810&lt;/a&gt; (and CVE-2018-12811&lt;/li&gt;
&lt;li&gt;UIS Endpoint Security:                &lt;a href="https://help.uis.cam.ac.uk/service/user-accounts-security/security/antivirus/managed-antivirus-software"&gt;https://help.uis.cam.ac.uk/service/user-accounts-security/security/antivirus/managed-antivirus-software&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<pubDate> Fri, 31 Aug 2018 17:35:35 +0000 </pubDate>
<enclosure length="33386206" type="audio/mpeg" url="https://pm107.user.srcf.net/sp008.mp3"/>
<guid>https://pm107.user.srcf.net/sp008.mp3</guid>
<itunes:summary>This month we cover a wide variety of topics including CERT 9to5, password timeouts, ePO and managing your consultants properly.</itunes:summary>
<itunes:subtitle>This month we cover a wide variety of topics including CERT 9to5, password timeouts, ePO and managing your consultants properly.</itunes:subtitle>
<itunes:duration>00:27:49</itunes:duration>
<itunes:author> Paul Mazumdar </itunes:author>
<itunes:explicit>no</itunes:explicit></item>


<item>
<title>July 2018: All change!</title>
<description>Paul, Graham, Kieren and Mr. Squeaky gather round the microphones to discuss financial scams, hacking ships, security networking, memorable passwords and transparancy, patching and how to react to a CERTogram.  It also turns out that we've only got two good mics - spot who got the cheap one... We also telegraph a change in the CERT line-up.
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hacking ships:                &lt;a href="https://drive.google.com/file/d/1PyUGqM9KbrSPTdAb-S5bbZvATm6RoEkC/view"&gt;https://drive.google.com/file/d/1PyUGqM9KbrSPTdAb-S5bbZvATm6RoEkC/view&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Florida gun checks: &lt;a href="http://www.tampabay.com/florida-politics/buzz/2018/06/08/adam-putnams-office-stopped-concealed-weapons-background-checks-for-a-year-because-it-couldnt-log-in/"&gt;http://www.tampabay.com/florida-politics/buzz/2018/06/08/adam-putnams-office-stopped-concealed-weapons-background-checks-for-a-year-because-it-couldnt-log-in/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NCSC password advice:                &lt;a href="https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0"&gt;https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;WPA3 launches: &lt;a href="https://www.wi-fi.org/news-events/newsroom/wi-fi-alliance-introduces-wi-fi-certified-wpa3-security"&gt;https://www.wi-fi.org/news-events/newsroom/wi-fi-alliance-introduces-wi-fi-certified-wpa3-security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google dictate OEM updates:                &lt;a href="https://www.xda-developers.com/google-require-oem-regular-security-patches/"&gt;https://www.xda-developers.com/google-require-oem-regular-security-patches/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Zip Slip:                &lt;a href="https://snyk.io/blog/zip-slip-vulnerability/"&gt;https://snyk.io/blog/zip-slip-vulnerability/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<itunes:author> Paul Mazumdar </itunes:author>
<pubDate> Fri, 13 Jul 2018 15:25:35 +0000 </pubDate>
<enclosure length="28104574" type="audio/mpeg" url="https://pm107.user.srcf.net/sp007.mp3"/>
<guid>https://pm107.user.srcf.net/sp007.mp3</guid>
<itunes:summary>This month we cover a wide variety of topics before coming back to the importance of patching.  It's boring, but needs to be done.</itunes:summary>
<itunes:subtitle>This month we cover a wide variety of topics before coming back to the importance of patching.  It's boring, but needs to be done.</itunes:subtitle>
<itunes:duration>00:29:16</itunes:duration>
<itunes:explicit>no</itunes:explicit></item>

<item>
<title>June 2018: Get certified!</title>
<description>Certificates are the order of the day this month as Paul and Graham look at upgrading web servers to HTTPS, the pros and cons of digitally signed e-mail and how with great power comes great responsibility -- particularly if that power is over people's passwords.
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Telegraph story about EU and GDPR: &lt;a href="https://www.telegraph.co.uk/technology/2018/05/30/embarrassing-leak-shows-eu-falls-short-data-law/"&gt;https://www.telegraph.co.uk/technology/2018/05/30/embarrassing-leak-shows-eu-falls-short-data-law/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;2FA on eBay:                &lt;a href="https://nakedsecurity.sophos.com/2018/05/31/how-to-set-up-2fa-on-ebay-go-do-it-now/"&gt;https://nakedsecurity.sophos.com/2018/05/31/how-to-set-up-2fa-on-ebay-go-do-it-now/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;2FA on Firefox:                &lt;a href="https://www.zdnet.com/article/firefox-accounts-gets-2fa-security-you-can-use-google-authenticator-one-time-codes/"&gt;https://www.zdnet.com/article/firefox-accounts-gets-2fa-security-you-can-use-google-authenticator-one-time-codes/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chrome to show HTTP as not secure: &lt;a href="https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html"&gt;https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;QuoVadis certificates from UIS:                &lt;a href="https://help.uis.cam.ac.uk/service/website-resources/website-components/tls-certs"&gt;https://help.uis.cam.ac.uk/service/website-resources/website-components/tls-certs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Let"s Encrypt:                &lt;a href="https://letsencrypt.org/"&gt;https://letsencrypt.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Certbot:                &lt;a href="https://certbot.eff.org/"&gt;https://certbot.eff.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Upgrading connections (Apache):                &lt;a href="https://httpd.apache.org/docs/2.4/rewrite/avoid.html"&gt;https://httpd.apache.org/docs/2.4/rewrite/avoid.html&lt;/a&gt; (first example)&lt;/li&gt;
&lt;li&gt;Upgrading connections (nginx):          &lt;a href="https://bjornjohansen.no/redirect-to-https-with-nginx"&gt;https://bjornjohansen.no/redirect-to-https-with-nginx&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;GPG:                &lt;a href="https://gnupg.org/"&gt;https://gnupg.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Why Johnny can"t encrypt:         &lt;a href="https://www.usenix.org/legacy/events/sec99/full_papers/whitten/whitten_html/index.html"&gt;https://www.usenix.org/legacy/events/sec99/full_papers/whitten/whitten_html/index.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Why Johnny STILL can"t encrypt:   &lt;a href="https://www.rsaconference.com/videos/why-johnny-still-cant-encrypt"&gt;https://www.rsaconference.com/videos/why-johnny-still-cant-encrypt&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<itunes:author> Paul Mazumdar </itunes:author>
<pubDate> Tue, 19 Jun 2018 12:15:15 +0000 </pubDate>
<enclosure length="29349242" type="audio/mpeg" url="https://pm107.user.srcf.net/sp006.mp3"/>
<guid>https://pm107.user.srcf.net/sp006.mp3</guid>
<itunes:summary>This month we focus on the use of certificates to validate both web traffic and e-mail.</itunes:summary>
<itunes:subtitle>This month we focus on the use of certificates to validate both web traffic and e-mail.</itunes:subtitle>
<itunes:duration>00:24:27</itunes:duration>
<itunes:explicit>no</itunes:explicit></item>

<item>
<title>May 2018: Keeping it boring, keeping it secret</title>
<description>The big theme that keeps coming up this month is the way that the everyday, boring procedures have a much greater effect on your security than the exciting, flashy toys.  Paul and Kieren try to talk about being boring while not actually being so themselves.
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;WhatsApp text bomb overstated (article by last week"s guest, Paul Ducklin): &lt;a href="https://nakedsecurity.sophos.com/2018/05/10/the-whatsapp-text-bomb-no-it-wont-destroy-your-phone/"&gt;https://nakedsecurity.sophos.com/2018/05/10/the-whatsapp-text-bomb-no-it-wont-destroy-your-phone/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;WhatsApp, Signal flaws:                &lt;a href="https://www.helpnetsecurity.com/2018/01/11/whatsapp-signal-group-chats/"&gt;https://www.helpnetsecurity.com/2018/01/11/whatsapp-signal-group-chats/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Yahoo! fined $35m:                &lt;a href="https://www.sec.gov/news/press-release/2018-71"&gt;https://www.sec.gov/news/press-release/2018-71&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Yahoo! perp gets 8 years and says "The FSB made me do it!":                &lt;a href="https://krebsonsecurity.com/2017/12/carding-kingpin-sentenced-again-yahoo-hacker-pleads-guilty/"&gt;https://krebsonsecurity.com/2017/12/carding-kingpin-sentenced-again-yahoo-hacker-pleads-guilty/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Patching 7zip:                &lt;a href="https://sourceforge.net/p/sevenzip/discussion/45797/thread/adc65bfa/"&gt;https://sourceforge.net/p/sevenzip/discussion/45797/thread/adc65bfa/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fingerprints via WhatsApp photo:                &lt;a href="https://www.bbc.co.uk/news/av/uk-wales-43754497/drugs-for-sale-message-catches-man-dealing-to-bridgend"&gt;https://www.bbc.co.uk/news/av/uk-wales-43754497/drugs-for-sale-message-catches-man-dealing-to-bridgend&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Bitlocker:                &lt;a href="https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-overview"&gt;https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-overview&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<itunes:author> Paul Mazumdar </itunes:author>
<pubDate> Wed, 16 May 2018 15:15:15 +0000 </pubDate>
<enclosure length="39196362" type="audio/mpeg" url="https://pm107.user.srcf.net/sp005.mp3"/>
<guid>https://pm107.user.srcf.net/sp005.mp3</guid>
<itunes:summary>The big theme that keeps coming up this month is the way that the everyday, boring procedures have a much greater effect on your security than the exciting, flashy toys.</itunes:summary>
<itunes:subtitle>The big theme that keeps coming up this month is the way that the everyday, boring procedures have a much greater effect on your security than the exciting, flashy toys.</itunes:subtitle>
<itunes:duration>00:32:39</itunes:duration>
<itunes:explicit>no</itunes:explicit></item>

<item>
<title>April 2018 Extra: A busy period... </title>
<description>In this out-of-band episode, we look at Cambridge Analytica and Facebook with the help of Graham Rymer, "next generation" anti-malware with Chris Quy and the new Intrusion Prevention Service with Ashley Culver.  Rather than the usual back-and-forth between Paul and Kieren, this episode is essentially three extended interviews.
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The story as it broke: &lt;a href="https://www.wired.com/story/cambridge-analytica-50m-facebook-users-data/"&gt;https://www.wired.com/story/cambridge-analytica-50m-facebook-users-data/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Was your account affected:                &lt;a href="https://www.facebook.com/help/1873665312923476?helpref=search&amp;sr=1&amp;query=cambridge"&gt;https://www.facebook.com/help/1873665312923476?helpref=search&amp;sr=1&amp;query=cambridge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS AV information:                &lt;a href="https://help.uis.cam.ac.uk/service/user-accounts-security/security/antivirus-individuals"&gt;https://help.uis.cam.ac.uk/service/user-accounts-security/security/antivirus-individuals&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Managed Firewall:                &lt;a href="https://help.uis.cam.ac.uk/service/user-accounts-security/security/antivirus-individuals"&gt;https://help.uis.cam.ac.uk/service/user-accounts-security/security/antivirus-individuals&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS IPS:                &lt;a href="https://help.uis.cam.ac.uk/service/devices-networks-printing/network-services/infoinstitutions/ips"&gt;https://help.uis.cam.ac.uk/service/devices-networks-printing/network-services/infoinstitutions/ips&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<itunes:author> Paul Mazumdar </itunes:author>
<pubDate> Fri, 04 May 2018 11:00:00 +0000 </pubDate>
<enclosure length="28858961" type="audio/mpeg" url="https://pm107.user.srcf.net/sp004a.mp3"/>
<guid>https://pm107.user.srcf.net/sp004a.mp3</guid>
<itunes:summary>In this out-of-band episode, we look at Cambridge Analytica and Facebook with the help of Graham Rymer, "next generation" anti-malware with Chris Quy and the new Intrusion Prevention Service with Ashley Culver.</itunes:summary>
<itunes:subtitle>In this out-of-band episode, we look at Cambridge Analytica and Facebook with the help of Graham Rymer, "next generation" anti-malware with Chris Quy and the new Intrusion Prevention Service with Ashley Culver.</itunes:subtitle>
<itunes:duration>00:30:03</itunes:duration>
<itunes:explicit>no</itunes:explicit></item>


<item>
<title>April 2018: Call the CIA! </title>
<description>More phishing, new biometrics, anti-malware and an acronym to help with your security audits. And, once again, we forget to announce the date on which we're recording - it was Weds 11 April 2018.  There's also a major topical issue that we avoid - more on that next time.
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Typing style authenticator: &lt;a href="https://www.typingdna.com/authenticator"&gt;https://www.typingdna.com/authenticator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Intel's support for patching Meltdown:                &lt;a href="https://newsroom.intel.com/wp-content/uploads/sites/11/2018/04/microcode-update-guidance.pdf"&gt;https://newsroom.intel.com/wp-content/uploads/sites/11/2018/04/microcode-update-guidance.pdf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MoviePass:                &lt;a href="https://techcrunch.com/2018/03/05/moviepass-ceo-proudly-says-the-app-tracks-your-location-before-and-after-movies/"&gt;https://techcrunch.com/2018/03/05/moviepass-ceo-proudly-says-the-app-tracks-your-location-before-and-after-movies/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Naked Security blog:                &lt;a href="https://nakedsecurity.sophos.com/"&gt;https://nakedsecurity.sophos.com/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<itunes:author> Paul Mazumdar </itunes:author>
<pubDate> Fri, 20 Apr 2018 19:31:00 +0000 </pubDate>
<enclosure length="31771854" type="audio/mpeg" url="https://pm107.user.srcf.net/sp004.mp3"/>
<guid>https://pm107.user.srcf.net/sp004.mp3</guid>
<itunes:summary>More phishing, new biometrics, anti-malware and an acronym to help with your security audits.</itunes:summary>
<itunes:subtitle>More phishing, new biometrics, anti-malware and an acronym to help with your security audits.</itunes:subtitle>
<itunes:duration>00:33:05</itunes:duration>
<itunes:explicit>no</itunes:explicit></item>

<item>
<title>March 2018: GDPR Special </title>
<description>Pwned passwords, obfuscated domains and Paul gets a new co-host, but mostly why 25 May 2018 deserves a place in your diary.  Clue: It's GDPR Day.
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Troy Hunt's blog:   &lt;a href="https://www.troyhunt.com/"&gt;https://www.troyhunt.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Have I Been Pwned:   &lt;a href="https://haveibeenpwned.com/"&gt;https://haveibeenpwned.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Password Changer:     &lt;a href="https://password.csx.cam.ac.uk/"&gt;https://password.csx.cam.ac.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Phishing with Punycode (not Tinycode!):         &lt;a href="https://nakedsecurity.sophos.com/2017/04/19/phishing-with-punycode-when-foreign-letters-spell-english-words/"&gt;https://nakedsecurity.sophos.com/2017/04/19/phishing-with-punycode-when-foreign-letters-spell-english-words/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;IDN Safe for Firefox:         &lt;a href="https://addons.mozilla.org/en-GB/firefox/addon/idn-safe/"&gt;https://addons.mozilla.org/en-GB/firefox/addon/idn-safe/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;IDN Safe for Chrome:         &lt;a href="https://chrome.google.com/webstore/detail/idn-safe/kegeenojcnijgmfgkcokknkbpmjcabdm"&gt;https://chrome.google.com/webstore/detail/idn-safe/kegeenojcnijgmfgkcokknkbpmjcabdm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;IDN Safe for Opera:         &lt;a href="https://addons.opera.com/en/extensions/details/idn-safe/?display=en"&gt;https://addons.opera.com/en/extensions/details/idn-safe/?display=en&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;BrowseAloud allows Coinmining on ICO etc websites:         &lt;a href="https://scotthelme.co.uk/protect-site-from-cryptojacking-csp-sri/"&gt;https://scotthelme.co.uk/protect-site-from-cryptojacking-csp-sri/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hurrah for Microsoft:         &lt;a href="https://nakedsecurity.sophos.com/2018/03/01/microsoft-still-refusing-to-hand-over-private-email-data-stored-in-ireland/"&gt;https://nakedsecurity.sophos.com/2018/03/01/microsoft-still-refusing-to-hand-over-private-email-data-stored-in-ireland/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Flight Simulator password miner:         &lt;a href="https://motherboard.vice.com/en_us/article/pamzqk/fs-labs-flight-simulator-password-malware-drm"&gt;https://motherboard.vice.com/en_us/article/pamzqk/fs-labs-flight-simulator-password-malware-drm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;GDPR Toolkit:                    &lt;a href="https://www.staff.admin.cam.ac.uk/general-news/new-data-protection-toolkit-for-university-institutions"&gt;https://www.staff.admin.cam.ac.uk/general-news/new-data-protection-toolkit-for-university-institutions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<itunes:author> Paul Mazumdar </itunes:author>
<pubDate> Fri, 16 Mar 2018 18:12:00 +0000 </pubDate>
<enclosure length="32865309" type="audio/mpeg" url="https://pm107.user.srcf.net/sp003.mp3"/>
<guid>https://pm107.user.srcf.net/sp003.mp3</guid>
<itunes:summary>Pwned passwords, obfuscated domains and Paul gets a new co-host, but mostly why 25 May 2018 deserves a place in your diary.  Clue: It's GDPR Day.</itunes:summary>
<itunes:subtitle>Pwned passwords, obfuscated domains and Paul gets a new co-host, but mostly why 25 May 2018 deserves a place in your diary.  Clue: It's GDPR Day. </itunes:subtitle>
<itunes:duration>00:27:23</itunes:duration>
<itunes:explicit>no</itunes:explicit></item>

<item>
<title>February 2018: We're Having A Meltdown! </title>
<description> Kieren talks about phishing and unwelcome job opportunities, Paul talks to Chris Quy and Martin Lee and we finish off looking at the NCSC's Cyber Essentials accreditation scheme.
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;KeePass:   &lt;a href="http://www.keepass.info"&gt;http://www.keepass.info&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Anti-malware pages:   &lt;a href="http://www.uis.cam.ac.uk/antivirus"&gt;http://www.uis.cam.ac.uk/antivirus&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Meltdown &amp; Spectre:     &lt;a href="https://meltdownattack.com/"&gt;https://meltdownattack.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hawaiian Missile Alert:         &lt;a href="https://en.wikipedia.org/wiki/2018_Hawaii_false_missile_alert"&gt;https://en.wikipedia.org/wiki/2018_Hawaii_false_missile_alert&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Tinder insecurity:         &lt;a href="https://www.wired.com/story/tinder-lack-of-encryption-lets-strangers-spy-on-swipes/"&gt;https://www.wired.com/story/tinder-lack-of-encryption-lets-strangers-spy-on-swipes/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Infected USB sticks as cybersecurity quiz prize:         &lt;a href="http://www.bbc.co.uk/news/technology-42634571"&gt;http://www.bbc.co.uk/news/technology-42634571&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;National Cyber Security Centre:         &lt;a href="https://www.ncsc.gov.uk/"&gt;https://www.ncsc.gov.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cyber Essentials:         &lt;a href="https://www.cyberessentials.ncsc.gov.uk/"&gt;https://www.cyberessentials.ncsc.gov.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CYBER17:                    &lt;a href="https://www.cyber17.event.cam.ac.uk/"&gt;https://www.cyber17.event.cam.ac.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cisco Talos  &lt;a href="https://www.talosintelligence.com/"&gt;https://www.talosintelligence.com/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Royalty-free music from &lt;a href="https://www.purple-planet.com/"&gt;Purple Planet Music&lt;/a&gt;
</description>
<itunes:author> Paul Mazumdar </itunes:author>
<pubDate> Mon, 12 Feb 2018 16:00:00 +0000 </pubDate>
<enclosure length="30819415" type="audio/mpeg" url="https://pm107.user.srcf.net/sp002.mp3"/>
<guid>https://pm107.user.srcf.net/sp002.mp3</guid>
<itunes:summary>Kieren talks about phishing and unwelcome job opportunities, Paul talks to Chris Quy and Martin Lee and we finish off looking at the NCSC's Cyber Essentials accreditation scheme.  </itunes:summary>
<itunes:subtitle>Kieren talks about phishing and unwelcome job opportunities, Paul talks to Chris Quy and Martin Lee and we finish off looking at the NCSC's Cyber Essentials accreditation scheme. </itunes:subtitle>
<itunes:duration>00:25:40</itunes:duration>
<itunes:explicit>no</itunes:explicit></item>

<item>
<title> January 2018: New Year, New Podcast </title>
<description> Paul and Kieren introduce themselves; Kieren talks about UIS and the Technical University of Tallinn testing each others' security, Paul interviews Emma W from the National Cyber Security Centre and we finish with a discussion of passwords vs passphrases.  Give us feedback!  E-mail Paul at pm107@cam.ac.uk and put the word "Podcast" in the subject line.
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;UIS Service Desk:   &lt;a href="mailto:service-desk@uis.cam.ac.uk"&gt;service-desk@uis.cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UIS Cyber Security pages:   &lt;a href="http://www.uis.cam.ac.uk/cybersecurity"&gt;http://www.uis.cam.ac.uk/cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;E-mail CERT:                &lt;a href="mailto:cert@cam.ac.uk"&gt;cert@cam.ac.uk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;National Cyber Security Centre:         &lt;a href="https://www.ncsc.gov.uk/"&gt;https://www.ncsc.gov.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Three Random Words:         &lt;a href="https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0"&gt;https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CYBER17:                    &lt;a href="https://www.cyber17.event.cam.ac.uk/"&gt;https://www.cyber17.event.cam.ac.uk/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Meltdown &amp; Spectre:     &lt;a href="https://meltdownattack.com/"&gt;https://meltdownattack.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;My reality is different...  &lt;a href="https://gizmodo.com/mozilla-slipped-a-mr-robot-promo-plugin-into-firefox-1821332254"&gt;https://gizmodo.com/mozilla-slipped-a-mr-robot-promo-plugin-into-firefox-1821332254&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Spam death threats          &lt;a href="https://nakedsecurity.sophos.com/2017/12/12/ransom-email-scam-from-hitman-demands-pay-up-or-die/"&gt;https://nakedsecurity.sophos.com/2017/12/12/ransom-email-scam-from-hitman-demands-pay-up-or-die/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
<itunes:author> Paul Mazumdar </itunes:author>
<pubDate> Tue, 16 Jan 2018 00:00:00 +0000 </pubDate>
<enclosure length="31224296" type="audio/mpeg" url="https://pm107.user.srcf.net/sp001.mp3"/>
<guid>https://pm107.user.srcf.net/sp001.mp3</guid>
<itunes:summary>Paul and Kieren introduce themselves; Kieren talks about UIS and the Technical University of Tallinn testing each others' security, Paul interviews Emma W from the National Cyber Security Centre and we finish with a discussion of passwords vs passphrases.  </itunes:summary>
<itunes:subtitle>Paul and Kieren introduce themselves; Kieren talks about UIS and the Technical University of Tallinn testing each others' security, Paul interviews Emma W from the National Cyber Security Centre and we finish with a discussion of passwords vs passphrases. </itunes:subtitle>
<itunes:duration>00:26:01</itunes:duration>
<itunes:explicit>no</itunes:explicit></item>

</channel>

</rss>