Artwork

Content provided by Chaos Lever, Ned Bellavance, and Chris Hayner. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Chaos Lever, Ned Bellavance, and Chris Hayner or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Negligence as a Service | Chaos Lever

40:05
 
Share
 

Manage episode 487025692 series 3378962
Content provided by Chaos Lever, Ned Bellavance, and Chris Hayner. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Chaos Lever, Ned Bellavance, and Chris Hayner or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

Welcome back, fellow humans (and bots in disguise)! This week on Chaos Lever, Chris and Ned dive into the dusty archives and slap us with a two-by-four of cybersecurity déjà vu. We’re talking legendary hacks that should have taught us better—and yet, here we are. From Emacs-enabled espionage in 1986 to Equifax’s honor-system security policies, it's a masterclass in how not to protect your data.

🧠 Lessons? Sure. But mostly it's about how we never learn them. We dissect what really caused these breaches—not slick zero-days, but plain old negligence and a fondness for not patching things. Also featured: expired SSL certs, trust as a security model, and how managing your asset inventory is more crucial than ever.

💥 Oh, and Ned tried to do a handstand for a cloud video and bled. Not relevant to cybersecurity, but 100% relevant to the Chaos Lever experience. Stick around for reenactments, rants, and ruminations on how saying “I accept the risk” is not a security policy.

🔗 LINKS
Apache Struts bug: https://blog.talosintelligence.com/apache-0-day-exploited/
Nova episode about the 1986 hack: https://archive.org/details/The_KGB_The_Computer_and_Me_1990
Senate investigation into Equifax: https://www.hsgac.senate.gov/wp-content/uploads/imo/media/doc/FINAL%20Equifax%20Report.pdf
CVE system creation by MITRE: https://www.cve.org/Resources/General/Towards-a-Common-Enumeration-of-Vulnerabilities.pdf

  continue reading

250 episodes

Artwork
iconShare
 
Manage episode 487025692 series 3378962
Content provided by Chaos Lever, Ned Bellavance, and Chris Hayner. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Chaos Lever, Ned Bellavance, and Chris Hayner or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

Welcome back, fellow humans (and bots in disguise)! This week on Chaos Lever, Chris and Ned dive into the dusty archives and slap us with a two-by-four of cybersecurity déjà vu. We’re talking legendary hacks that should have taught us better—and yet, here we are. From Emacs-enabled espionage in 1986 to Equifax’s honor-system security policies, it's a masterclass in how not to protect your data.

🧠 Lessons? Sure. But mostly it's about how we never learn them. We dissect what really caused these breaches—not slick zero-days, but plain old negligence and a fondness for not patching things. Also featured: expired SSL certs, trust as a security model, and how managing your asset inventory is more crucial than ever.

💥 Oh, and Ned tried to do a handstand for a cloud video and bled. Not relevant to cybersecurity, but 100% relevant to the Chaos Lever experience. Stick around for reenactments, rants, and ruminations on how saying “I accept the risk” is not a security policy.

🔗 LINKS
Apache Struts bug: https://blog.talosintelligence.com/apache-0-day-exploited/
Nova episode about the 1986 hack: https://archive.org/details/The_KGB_The_Computer_and_Me_1990
Senate investigation into Equifax: https://www.hsgac.senate.gov/wp-content/uploads/imo/media/doc/FINAL%20Equifax%20Report.pdf
CVE system creation by MITRE: https://www.cve.org/Resources/General/Towards-a-Common-Enumeration-of-Vulnerabilities.pdf

  continue reading

250 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play