Firewalls Don't Stop Dragons Podcast

CrowdStrike Lessons Learned

Jul 29, 2024
A recent cybersecurity incident revealed how a single company can disrupt major airlines and hospitals. Google's shift on third-party cookies raises concerns about online privacy. The ethical dilemmas of using mobile ad location data for tracking individuals are scrutinized. Notable vulnerabilities in digital payment systems and mobile forensics are discussed, highlighting risks like sextortion that target minors. Plus, useful tips on protecting public data online are shared.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Leaked Matrix Shows Cellebrite Limits On Modern Phones

  • Leaked Cellebrite matrices show many modern iPhones and some Androids resist forensic unlocking as of April 2024.
  • The documents list supported models and OS versions, with iOS 17.4+ devices largely labeled 'in research' for access.
INSIGHT

Modern iOS Hardens Against Forensic Extraction

  • iOS devices running recent updates are increasingly resistant to forensic tools, shifting successful extraction toward some Android devices.
  • Kerry suggests the shooter’s phone may have been Android since FBI reportedly accessed it quickly.
INSIGHT

Global Update Crash Took Down Customer Endpoints

  • CrowdStrike outage was caused by a globally pushed data/update file that crashed endpoint agents at boot time.
  • The corrupted rule file made Windows machines fail to boot until technicians deleted the specific file in safe mode or applied a fixed update.
Get the Snipd Podcast app to discover more snips from this episode
Get the app