meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, February 28th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 28 February 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Ultrasonic Assistance; Browser Data Leakage; Cloud Snooper

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, February 28, 2020 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich, and I'm recording from San Francisco, California.

0:13.4

First of all, thanks to everybody who came to our workshop and our keynote panel today.

0:20.7

Real great turnout for both sessions.

0:24.1

And if you have any questions about either sessions, just email me for the workshop.

0:29.7

We talked about some of the mobile web application authentication challenges.

0:36.6

There will be a website off on the move.com that will be make

0:42.6

available with all the material that we discussed during the workshop right now. You'll already

0:48.4

see sort of some of the little demo code fragments and such that we talked about during the workshop.

0:56.4

As far as the panel goes, RZA will make available a recording may already be available by the time you are listening to this.

1:05.4

Let's take a look at what we have in other news.

1:09.4

Well, first of all, the surfing attack comes out of Washington University

1:13.8

in St. Louis. And essentially, what it's all about is that a lot of mobile phone microphones

1:20.9

are actually quite sensitive to ultrasonic waves. So what this means is that ultrasonic sound can be used to trigger,

1:30.3

for example, digital assistants like Siri or the Google Assistant.

1:36.3

Not this basic idea has been demonstrated before. What's a little bit new in this particular paper

1:41.3

is that ultrasonic sound can also get carried quite well by solid objects,

1:47.2

so it's a little bit easier to inject a command through, for example, a piece of wood,

1:54.8

like a desk or something like this, that can be used to conduct ultrasonic waves.

2:00.2

And of course, it's a little bit more difficult to defend against than sort of a traditional attack

2:04.6

where just someone in the room speaks a command because it makes it more difficult to actually

2:11.6

realize what's happening.

2:14.6

And Douglas Leith from the training college in Dublin did a nice, fairly exhaustive study of

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.