ISC StormCast for Friday, December 18th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 December 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, December 18th, 2020 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.4 | My name is Johannes Ulrich. |
| 0:09.0 | And I'm recording from Jacksonville, Florida, but teaching virtually in Washington, D.C. |
| 0:14.8 | I'm teaching the defending web application security class. |
| 0:18.6 | If you are interested in learning more about how to defend |
| 0:22.0 | web applications, the next run of this class will be on January 11th and you'll find links |
| 0:29.6 | to the class in the show notes. GitHub announced that starting August 13th next year, you will no longer be able to use passwords |
| 0:40.3 | when you're authenticating Git operations. So if you're making updates to your repository, |
| 0:46.0 | if you're pushing code, you will need either an Oath key GitHub app installation, or you |
| 0:53.7 | need to use S.S.H in order to push the update and then |
| 0:57.5 | of course as H with keys. |
| 1:00.1 | Until then you should be looking out for any warnings that you're using an outdated third |
| 1:05.2 | party integration. |
| 1:06.5 | That may mean that your client does not support these authentication methods, and you should definitely |
| 1:13.9 | update. Also, in order to essentially warn developers of this change, GitHub will implement |
| 1:21.5 | two brownouts, as they call it. This will happen on June 30th and July 28th. During a couple hours on each day, |
| 1:31.6 | you will be unable to log in with password and basically they will temporarily already |
| 1:38.3 | implement the behavior that will become normal on August 13th to kind of give you a warning |
| 1:44.1 | that it's now really time |
| 1:46.0 | to update your off vacation. Of course, what I'm trying to solve here is fishing that has often |
| 1:52.6 | been used in the past to gain access to developers' GitHub repostories and then has been used |
| 1:59.5 | to compromise code and inject backdoors, for example. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

