ISC StormCast for Friday, February 14th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 February 2020
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, February 14th, 2020 edition of the Sansonet Storms and a Stormcast. |
| 0:07.6 | My name is Johannes Ulrich. |
| 0:09.0 | And then I'm recording from Jacksonville, Florida. |
| 0:13.5 | When it comes to network traffic these days, most of it, of course, is encrypted and the big leader here tends to be HTTP, harder to actually find a website these days that does not support HTTP. |
| 0:28.5 | But aside from HTTP, there are a number of other protocols that could benefit from TLS, and one of these protocols is LDAB. |
| 0:36.3 | So mid-last year, Microsoft did publish some guidance |
| 0:40.7 | where they recommended that you should use L-DabS, |
| 0:45.1 | essentially L-DAP over TLS or L-DAP signing, |
| 0:49.2 | and another L-DAP feature referred to as channel binding. |
| 0:53.9 | And of course, given that Microsoft an active directory does rely on LDAP, |
| 1:00.1 | this is a substantial improvement in security and does prevent a number of real attacks. |
| 1:07.6 | So Microsoft was going to go ahead and make LDAB as the default behavior starting in March |
| 1:15.5 | with the March Patch Tuesday update. |
| 1:18.8 | But, well, deploying TLS, deploying it correctly isn't all that straightforward. |
| 1:23.8 | You first need certificates and all of that good stuff. |
| 1:27.2 | So a number of Microsoft customers complained about this deadline and Microsoft earlier in February moved away from the March deadline and now states that they will introduce this new default behavior sometime second half of the year. Of course, the problem with |
| 1:46.3 | any deadline that's a few months out is, well, it sounds far enough that you're probably going |
| 1:51.8 | to get surprised again. And if sometime in September or October, this new default behavior |
| 1:57.9 | will be released by Microsoft. |
| 2:07.1 | Well, to get you ready for it, we do have two diaries today by Rob about how to check which systems your network do use LDAB versus LDAB S and how to script some of the |
| 2:15.1 | configuration options. |
| 2:16.9 | So he made public a number of pretty neat PowerShell scripts that should you help tackle this |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

