
The chips are down, as tech companies struggle to protect against the Meltdown and Spectre flaws. The White House is getting tough on leakers by banning personal devices from the West Wing. And someone has been embedding a Bitcoin wallet into their hand…
All this and much much more is discussed in latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by David McClelland.
Show full transcript ▼
This transcript was generated automatically, probably contains mistakes, and has not been manually verified.
Nothing's getting in.
It's the only way to deal with this. There's so many breadcrumbs.
Hello, hello, and welcome to another episode of Smashing Security, episode 60. My name is Graham Cluley.
The grind?
With Cloudberry, you can back up files, folders, and system images to the cloud storage of your choice with built-in 256-bit encryption, ensuring your precious data remains private.
Cloudberry supports over 30 cloud storage providers, working on Windows, Mac, and Linux. Plus, no subscription. You pay only once. So download a free trial at cloudberrylab.com.
But there's more. You could also go to smashingsecurity.com/cloudberrylab to get a whopping 30% off the Windows desktop version. That goes for about $20.
And this vulnerability could lead to data being leaked from somewhere on your computer that it simply shouldn't have been possible to leak data.
And at which point, of course, the acronym got a new name and some funky logos. And we all began to talk about something called Meltdown and Spectre.
And this has caught the imagination of many in the media. It's suddenly escaped from the purely technical press.
It's caused by two major flaws in computer chips called Meltdown and Spectre.
Maybe your private keys, maybe your passwords. And not really very easy to fix that kind of problem.
Or, you know, can update your operating system or install the latest version of iOS and that solved it.
But when the problem is actually residing on your hardware chip, what are you meant to do? And at first, I think US CERT actually gave the advice.
They said, well, just replace the chips when you want to.
And there are no finer superheroes, I think, than software developers. You can imagine them right now.
Pulling on their Y-fronts over their trousers and leaping out of the window to rescue us all. What they had to do was they had to update operating systems.
They had to update the software, which was actually talking to the chips because they had previously been relying upon the chips to control these sensitive parts of memory and make sure that data wouldn't leak from one program to another.
And now the operating systems had to do that for them, which meant potentially operating systems are having to do more.
At a very low level and maybe would slow your computer down as well, which frankly I think is something that we all relish, isn't it? We all want slower computers.
Apple, Microsoft, Amazon cloud services, all of these chaps started pushing out updates.
And so you may have seen the headline saying, oh, all iPhones are at risk, followed very rapidly by install the latest version of iOS or install the latest version of macOS.
If you can. But there have been problems as well. So Microsoft have had a fix for what we won't call fuckwit, what we'll call Meltdown and Spectre.
But it turned out that some of Microsoft's fixes wouldn't necessarily work with all antivirus programs.
In fact, if you were running some antivirus programs and applied Microsoft's patch, your computer would start to blue screen. Gee! Which is worse than the vulnerability.
A vulnerability, by the way, which no one's seen any evidence of being maliciously exploited.
And, you know, this is a— I guess it's a bigger point because, you know, it's all well and good security researchers pointing out, oh, look, there's a potential vulnerability here or there or somewhere else with this bit of code or this bit of hardware, but I think we need sometimes to take a bigger picture view to say, okay then, on a score between 1 and 10 or on a red, amber, green, you know, whatever, how likely, how dangerous, how urgent is this?
And I guess that's my question for what we've been seeing here with Meltdown and Spectre.
What is the real risk to people who are listening to this podcast, you know, to their PCs and their phones?
And I said, just don't panic, make yourself a cup of tea. You know, there's nothing that you can do whatsoever about this problem other than wait for a patch.
Now, unfortunately, some of these patches have had problems with certain products and Microsoft has actually halted pushing out its patch for PCs with AMD chips because devices were getting bricked as well.
So you can certainly argue that some of these patches have caused much, much more of a problem than the vulnerabilities themselves.
It's a fascinating story of how they all found it at the same sort of time. But they told these vendors months ago about these problems.
It's only been made public in the last week or so. So there has been some time.
I'm still impressed because suddenly people will have worked over the holiday period to get these things ready and to get them out as soon as possible.
But, okay, so maybe right now there's only a small chance of anyone being attacked by this.
But imagine if you were in a critical, maybe government position and you had secrets on your device. It may not be beyond the nous of enemy, enemy, of enemy. You have to be careful.
Oh dear.
In the case of the problem with antivirus software, what Microsoft have done is they've said, look, there are some antivirus programs right now which are breaking the rules.
They're doing some naughty, cheeky tricks. They're doing double somersaults in order to access features of the chip, for instance, which are incompatible with our fix.
And so therefore, if you have our fix and these antivirus programs, your computer may blue screen.
They will make sure that they're playing the game as Microsoft want them to play because they have to, frankly.
No one's going to accept that their antivirus is preventing them from getting other security patches. So I think it will work from that point of view.
But I think many of us, especially because the consumer press got hold of this, they're going to be alarmed because people have got old— I've got an old iPad Mini, for instance, right?
And I'm used to complaining about Android having an appalling upgrade path, but it's equally true of many applications.
You know, on baths, you get those sort of old telephone handle receiver things where you put the shower head.
I can hook it round there and then I can have a bath and my iPad Mini is up there and I can go on YouTube.
But I have to say, I didn't really see anything interesting yet by the time we're recording right now.
However, something else did catch my eye this week that I thought might be worth bringing up.
So many others, I've looked on with interest over the last, I guess, couple of months or so as this bitcoin roller coaster has soared and dived and soared again.
And it's been quite a ride for those who join the queue early doors. Sadly not me. But of course, bitcoin isn't the only crypto roller coaster in town.
The thrill seekers have been jumping aboard things Litecoin, Ethereum, Dogecoin. I don't know if we got to the bottom of what that's actually called. Dogecoin.
But Ripple, that rose by a staggering 35,000% and is now vying for second place alongside Ethereum, which many more people have heard of to be the biggest cryptocurrency by market cap behind bitcoin.
So what's this got to do with security, you might ask? Well, I'm coming to that.
So on the podcast, I have been listening, you've been talking about secure cryptocurrency wallets with Mikko Hypponen and Peter Ulrich over the last couple of weeks.
Well, I came across this Danish firm called ByChip that's just announced that its microchip implant will make sure your cryptocurrency is always close at hand by storing it literally inside your hand.
So these are those implantable— I guess they're rice-grain-sized RFID NFC chips.
And, you know, they've been very popular as a party trick at tech conferences for a number of years, and they commonly let you exchange business cards and open hotel room doors and even use public transportation and so on.
They give them to me. I just think, oh, I'm going to do this. So maybe if I claim that I've got a business card receiver in my hand, I can say, oh, just put it there, right?
And I don't actually have to have the chip implanted, right?
Now, I know, I've got a few questions around this story. We'll put a link to it in the show notes, I'm sure.
And there's not a lot of information about ByChip online, but I thought it was an interesting theme nonetheless, because obviously when you've got things like this embedded in your hand, there are some security implications, also some moral ones I've been learning too.
So Graham, Carole, do either of you have any of these implants, or would you?
I mean, it's all right for the dog, you know, if the dog gets lost.
Let me turn the tables on you, David McClelland.
Would you take your BBC pass and have that injected into your hand? Would you allow your personal information to be embedded in you in some fashion?
Is that something which makes you feel comfortable?
First of all, I'm as squeamish as a baby, and I pass out at the slightest hint of the colour red, let alone actual dirty great big needles going into my hand.
So as much as I'm curious, I must admit that there is a bit of me that's curious about this, I don't think I could go through with it because I am such a crybaby.
But, you know, I did cover a news story last year whereby a US firm was offering this to its staff, and I think it was a vending machine firm in the United States were offering this to the staff, and the staff were queuing up to have it done.
They were more than happy because it means they didn't have to carry around their security pass anymore.
They didn't have to hand over any actual cash or, you know, a cashless vending card. They could just wave their hand to buy their lunch.
So, you know, when you look at it like that, it seems like it's, you know, not that big a deal.
Because what's happening there is they're all inside the organisation, there's all this peer pressure, and they're thinking, oh, this is a normal thing to do because my boss is doing it, and Sandra over there in marketing, she seems to think it's all right.
Maybe my concern—
So people have got to actually stand up for themselves, say, no, I'm sorry, this is crazy and unnecessary.
And furthermore, if I'm the one with the implant, I'm gonna be the one who keeps, you know, I'll have to be the one who keeps going to the vending machine, aren't I?
It's not like you can get your pal to do it instead and say, here's a pound coin, go and get me a drink as well.
Even thinking about it, don't pass out.
You know, I go to bed at night, you know, I go swimming, whatever else, I can just leave that behind. I can turn my phone or my laptop off. That's easy.
But when you've got something under your skin like that, it's kind of there, and to get rid of it's going to be a lot of pain.
Transhumanism is another term. And so these people are also called Grinders, and there's a great conference that takes place every year.
And there's in London, where I live, there's also a— it takes place, I think it's every month, there is a meetup for people who are into body modding.
There was one body modification whereby you embed it on your chest or in your chest, and it's got a compass built into it.
I kind of called it the homing pigeon modification, and it just gives you a little tap if I remember, whenever you face magnetic north.
And people are like, what on earth is that all about? But people see it as adding extra senses to themselves. Again, that's certainly not something I'd be interested in doing.
But for a certain kind of person, this kind of body modification, adding, augmenting ourselves with different senses, is both an interest and also an art form as well.
And there's lots of art projects where people have embedded different bits of tech under their skins on different bits of their body.
Carole, what have you got for us this week?
So late last week, White House Press Secretary Sarah Huckabee Sanders released the following statement, which I've shortened slightly.
The security and integrity of the technology systems at the White House is a top priority.
Starting next week, the use of all personal devices for both guests and staff will no longer be allowed in the West Wing.
Staff will be able to conduct business on their government-issued devices.
So in other words, due to security and integrity concerns, they have to say adieu to their personal devices when in the West Wing.
And that means everything— phones, laptops, Roombas, fridges, whatever. Nothing's getting in.
However, there are rumors that this ban is actually the result of the publication of a tell-all romp of Trump's first year as pres called Fire and Fury: Inside the Trump White House, penned by Michael Wolff.
So some juicy morsels that were pre-released include, "Trump didn't expect to win!" and "Trump is semi-illiterate!" and "Ivanka wants to be the first female president!" It wouldn't really be a surprise if Trump hadn't expected to win.
It was the best publicity they could dream of.
If we can get Sarah Huckabee Sanders to say that I've heard Graham Cluley and Carole Theriault and that dreadful David McClelland have been saying some outrageous things about Donald Trump.
That could really help us on the iTunes chart.
So they call the author's logic ridiculous. They say the reporting is not actually reporting due to uncorroborated serious factual errors. But who are they to judge?
Interestingly, Trump actually agrees with The New Yorker on this one occasion.
On the 5th of January, he tweeted that Michael Wolff is a total loser who made up stories in order to sell this really boring and untruthful book.
He used sloppy Steve Bannon, who cried when he got fired and begged for his job. Now sloppy Steve has been dumped like the dog by almost everyone. Too bad.
So he probably does have a secure one, doesn't he? I mean, obviously they're concerned about leaks, I would think.
Whereas if they are private devices, it all becomes so much more difficult. Because there are secure messaging apps out there.
How many people do you think might work in the West Wing?
The White House Chief of Staff Office, Counselor to the President, Senior Advisor to the President, White House Press Secretary, and all their supporting staff are in there.
So this means that whilst they do their average of 12-hour days, they can't easily access their family, right?
So, there's a lot of people complaining about this, but it got me thinking how, whether this will become a trend in actual offices, right?
Do we think that companies might start having secure rooms where people are not allowed to bring in any devices?
Because let's just face it, these phones now are basically very powerful computers that can record video, audio quickly and upload it to the cloud in seconds.
And I think the typical company probably actually has begun to embrace BYOD a bit or has actually given more flexibility to the typical employee as to which devices they use.
I'd like to think, though, that there is some middle ground here rather than saying you can only use these particular devices.
But I think the White House is in a particularly unusual position right now.
That would make me somewhat uncomfortable. I wonder how we could get in. So imagine, right, so we all know Donald Trump is a big fan of the show.
If we were to approach him about appearing and we went to visit him in the Oval Office and we're not allowed to take our phones, how could we take some sort of electronic device in with us to record it?
Because this may be our only chance to get him on the show, Carole.
And there's one in the middle who's got this reel-to-reel tape recording, recording round and round. Fantastic. Or we could do brass rubbings, something like that.
So if you do want to come on the show, we'd be happy to have you and let you do your bit for the allotted 7 minutes. That'd be fantastic. It'd be great to have you. Okay.
We'll be back after this break with our picks of the week.
There's no subscription, plus you get 20% off the Windows desktop version if you go to smashingsecurity.com/cloudberry. On with the show.
Could be a funny story, a book they've read, a TV show, a movie, a record, an app, a website, a podcast, whatever you like. It doesn't have to be security-related necessarily.
And my choice this week is— oh, by the way, first of all, Carole, I have to thank you for one of your past Picks of the Week because of course we had Christmas recently and, you know, I was stumped.
What on earth am I going to get people? And I was looking back on some of the Picks of the Week and one of the Picks of the Week you suggested was this Snap-on Electric—
You do learn a lot of stuff, and it gives you all these exercises.
And people who don't know, it's kind of like Meccano or Lego, but with electronics, and you build electrical circuits, and you have fans and light bulbs, and it's really, really cool and fun.
And so that was one Christmas present which I got my son.
And then another Christmas present I got him— we have a Nintendo Switch at home and I have been playing a terrific game with him called Portal Knights, which I don't think is that well known, but it is tremendous.
It is a 3D open world game.
I've included a link in the show notes which you guys are welcome to check out as well if you want to, a YouTube video where you can see the game in action.
And it's a bit like Minecraft in a way, but with much better graphics, and to my mind, a whole lot more charm. It's an open-world game where you can build—
You have little quests, there's an RPG element as well, and you can play it in co-op mode, so both of you can be on the screen sat on the sofa together helping each other as you're building or as you're beating up skeletons.
You can also play it online. It's also available on Steam, Xbox, PlayStation.
I think it may even have come out for smartphones too, but it's utterly charming, good fun, and the video is very nostalgic of Zelda. I agree, it is.
I must admit, as Black Friday happened and the sales over the festive period happened, I was looking at the Nintendo Switch and I was kind of getting twitchy fingers as to whether I should go for that or go for a PlayStation 4.
I'm still living the dream with a Nintendo Wii from, what's that, 10, 11 years ago now, and Mario Kart is pretty much the only game that me and my daughters play.
So obviously Mario Kart's there on the Switch as well.
So as much as I'd like a PlayStation 4 for me, and lots of my friends have PlayStation 4s, that would be good sort of gamer buddy stuff, I think the Switch would get more use in my household.
It was very unfortunate. I thought Nintendo really screwed up. The Switch has seen them reemerge, and it's been selling like hotcakes.
And there are lots of third-party games, including some independent games. I think this is an independent game, which have come out.
I also spoke about another hilarious game for the Switch in a past Pick of the Week called Overcooked.
And that is why it is my pick of the week.
Oh yes, 2018's got off to a great start for me because I felt the need to download something to just make me a little bit more productive, to give me an app-fueled kick up the backside.
So the app that I've been trying out, and I have to say it really has been working for me so far, which is why it's my pick of the week, is called Focus-Productivity Timer.
The dash is a dash, it's not the word dash. But if you just type in Focus in the App Store, you don't really get it.
And it revolves around this thing you may have heard of called the Pomodoro time management technique. And it's perfectly suited to easily distracted freelancers like me.
So whether I'm at home or on a client site, it's really difficult to focus sometimes when there's lots of noise going on around the outside, or when I'm sat in my office at home, I just see loads of jobs happening.
So a Pomodoro, the name comes— there's an Italian guy called Francesco Cirillo, and back in the '80s, I think it was, he created this time management technique where you have 25-minute chunks of time.
And I think 25 minutes was the amount of time that he could twist his tomato kitchen timer around to, whatever you can say, which is where it gets its base.
You set up your tasks at the beginning of the day and you divide them down into, I think this thing's going to take two Pomodoros, let's say.
So it will tell you to, right, focus 25 minutes, then you've got a 5-minute break, then you do another Pomodoro worth of work and you get 4 Pomodoros before you get a longer break, 20 minutes worth of work.
And this works on my phone, it works on my Mac and on my watch as well. These apps are only as good as what you invest in them.
But I've found that by not checking my emails for 25 minutes, by not, you know, I might just check Twitter for 25 minutes.
Actually, 25 minutes is a good chunk of time for my brain to focus on a particular task.
And when I've got my 5-minute break, I come up for air, I do whatever else needs to be done, and then I go back in again for another 25 minutes' worth of focus.
It's really worked for me. I think it's a great app. And I think that you, if you get easily distracted, might find it useful.
So, at the end of your Pomodoro, it gives you an option whereby you can extend for another 5 minutes or just skip on to the next, or just skip on to your next chunk of work.
So, you do have some flexibility there. It doesn't completely rule my day, but I found, you know, I just I do 3 or 4 Pomodoros a day.
Right, okay.
If I could combine that with the app Vanja spoke about the other week, the WeCroak, which tells me on a regular basis that I'm definitely going to die.
What's all this? I said I'd miss you.
So this is an Australian podcast, actually won Australian Podcast of the Year for what that's worth, and it's called Casefile.
So if you like kind of the post-analysis of real crime, this one's for you. The Host Case File is anonymous, so even on the website, there's no entry form, which I kind of love.
It's very kind of factual, well-researched, and really rather gripping.
And what makes it kind of unusual and a bit weird is that the entire show is read almost eerily without emotion or flair.
So very straight reading of a document, and you'd think it would be dull, but it's very not dull.
And I think if I ever suggested that here for this podcast, Graham would poop in his pants. He'd be so shocked at that approach.
But I love I love this podcast and I cannot wait for it to come back on air.
And if anyone has trouble sleeping or just likes to unwind at the end of the day, this is the one for you.
If people want to follow you, where should they do that?
And you can go to smashingsecurity.com for past episodes and for details of how to get in touch with us. Until next time, all that remains is for us to say cheerio, bye-bye.
Hosts:
Graham Cluley:
Carole Theriault:
Guest:
David McClelland – @DavidMcClelland
Show notes:
- Apple fixes the Meltdown and Spectre flaws in Macs, iPhones, and iPads
- Spectre? Meltdown? F*CKWIT? Calm down and make yourself some tea
- Until your anti-virus adds this Registry key, you aren't getting any more Windows security updates
- Important information about Microsoft Meltdown CPU security fixes, antivirus vendors and you
- Ouch! Microsoft's Meltdown and Spectre security update bricks some AMD-powered PCs
- Ripple soars, becomes second-biggest cryptocurrency by market cap
- BICHIP
- Would you store Ripple and Bitcoin in 'mark of the beast' microchip?
- Biohacker Summit 2017 – Uniting Technology & Nature
- Meet the first humans to sense where north is
- White House bans use of personal devices from West Wing
- “Fire and Fury” Is a Book All Too Worthy of the President
- Portal Knights – The award-winning sandbox action-RPG adventure game
- Portal Knights trailer for Nintendo Switch – YouTube
- Focus – Productivity Timer on the App Store
- Casefile: True Crime Podcast
- Smashing Security on Facebook
- Smashing Security merchandise (t-shirts, mugs, stickers and stuff)
- Support us on Patreon!
Backup files, folders and system images to the cloud storage of your choice – with built-in 256 bit encryption ensuring your precious data remains private.
CloudBerry supports over 30 cloud storage providers, and works on Windows, Mac, Linux.
And unlike many of the other online backup solutions out there, you pay only once – rather than a subscription.
Find out more at cloudberrylab.com, where you can download a free trial and also explore CloudBerry’s solutions for businesses and MSPs.
And if you’re a Windows desktop user go to smashingsecurity.com/cloudberrylab to get 30% off the Windows desktop version. Meaning you can get this great software for the super price of around 20 bucks. Offer expires February 10th 2018.
Follow the show:
Follow the show on Bluesky at @smashingsecurity.com, or visit our website for more episodes.
Remember: Subscribe on Apple Podcasts or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!

A very interesting podcast. Security is a daily challenge that will never end and will only ever become more complex