ISC StormCast for Friday, February 2nd, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 February 2024
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, February 2nd, 2024 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.4 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.1 | Today in my diary I expand a little bit on what top level domains are and what this means for identifying domain names. |
| 0:24.0 | Typically, of course, a domain name would be two labels, the domain name and then the top level |
| 0:28.7 | domain, but that's not always strictly true. Typically, a domain name is sort of considered |
| 0:35.7 | something that belongs to an entity, a company, |
| 0:39.0 | an organization, and then they may assign host names, subdomains within that domain name, |
| 0:46.0 | but those domain names then have some trusts with respect to each other. |
| 0:51.3 | Well, there are some interesting domains like, for example, CO.U.K. |
| 0:57.2 | That behave like a top-level domain, meaning, as Mozilla puts it, that domains being assigned |
| 1:04.4 | within CO.U.K. may be owned by mutually untrusting parties, basically different organizations. |
| 1:13.1 | So if you are trying to define a domain, then you first need to figure out what are these |
| 1:20.3 | sort of pseudo top-level domain, I want to call it, or as they're officially called, public suffixes. |
| 1:27.0 | Luckily, Mozilla maintains a list of public suffixes. |
| 1:31.9 | There are about 9,500 domains in that list that should be treated as top-level domains when it comes |
| 1:40.9 | to security. One effect of this is cookies. |
| 1:45.6 | You cannot assign a cookie in current browsers to a public suffix, |
| 1:52.2 | just like you can't to a traditional top-level domain. |
| 1:56.0 | So if you're writing some scripts that, for example, |
| 1:58.3 | try to identify unique domains or what's the most |
| 2:01.8 | frequently visited domains and the like, you need to consider this public suffix list. |
| 2:06.8 | Luckily, there are Python libraries and such that will read it for you and then extract |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

