IoT

Mikko Hypponen's Vision of the Cybersecurity Future

0%
100%

BLACK HAT USA 2017 -- Twenty years from now, will everything be a thing in the Internet of Things? If so, how does the security industry need to prepare? F-Secure's chief research officer Mikko Hypponen visits the Dark Reading News Desk to weigh in on this, and what else the future promises (and threatens).

Watch all 45 News Desk interviews at DarkReading.com/DRNewsDesk.

Learn from the industry’s most knowledgeable CISOs and IT security experts in a setting that is conducive to interaction and conversation. Click for more info and to register.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
menuisier69
50%
50%
menuisier69,
User Rank: Apprentice
9/6/2017 | 5:15:43 AM
Re: Mikko Hypponen;s Security Talk
"Much as I respect his position, I think he is talking linearly and not laterally"

 

100% agree but Mikko Hypponen is still a genius :P
tcritchley07
50%
50%
tcritchley07,
User Rank: Moderator
9/5/2017 | 9:19:29 AM
Mikko Hypponen;s Security Talk
Much as I respect his position, I think he is talking linearly and not laterally. E,g. "I cant see SW in IOT devices". Nobody could see men landing on the moon 100 years ago be we did. IOT devices in a year or so can easily hold a 128 MB /(or GB) memory/storage and enough briains to  encrypt data and commands and to take part in a later cyber security architecture, However, the IoT manufacturers will have to toe the IoT function implementation line drawn by Goverments and businesses who carry very large sticks in the pursuit of security.

Even today, the bad guys are practising their IoT breach skills, e.g. Iranian nucclear plant, Ukraine power station, cars stopped in 'flight'  (by friendly hackers as a trial). They are an order of magnitude greater hazard than current exposures and 2 orders of magniude in number.
White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
Lessons from My Strange Journey into InfoSec
Lysa Myers, Security Researcher, ESET,  7/12/2018
What's Cooking With Caleb Sima
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-14339
PUBLISHED: 2018-07-19
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE dissector could go into an infinite loop. This was addressed in epan/proto.c by adding offset and length validation.
CVE-2018-14340
PUBLISHED: 2018-07-19
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors that support zlib decompression could crash. This was addressed in epan/tvbuff_zlib.c by rejecting negative lengths to avoid a buffer over-read.
CVE-2018-14341
PUBLISHED: 2018-07-19
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM dissector could go into a large or infinite loop. This was addressed in epan/dissectors/packet-dcm.c by preventing an offset overflow.
CVE-2018-14342
PUBLISHED: 2018-07-19
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop. This was addressed in epan/dissectors/packet-bgp.c by validating Path Attribute lengths.
CVE-2018-14343
PUBLISHED: 2018-07-19
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash. This was addressed in epan/dissectors/packet-ber.c by ensuring that length values do not exceed the maximum signed integer.