ISC StormCast for Friday, January 31st 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 31 January 2020
⏱️ 10 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, January 31st, 2020 edition of the Sands and the Storm Center's Stormcast. My name is Johannes Ulrich and I'm recording from Augusta, Georgia. |
| 0:14.2 | I want to start today with a little bit longer segment talking about some upcoming changes to Chrome. Chrome is going to release version 80 next week |
| 0:26.3 | on February 4th and it comes with some changes to the cookie policies that I think are worth |
| 0:35.0 | mentioning and some of the details really haven't been discussed well, |
| 0:39.4 | I think some of the impact these changes may have on applications. |
| 0:44.9 | Until recently, so of the way cookies worked essentially was that a site would set a cookie |
| 0:50.9 | and whenever a request for a browser was sent to that site, the browser |
| 0:57.6 | would include the cookie no matter what triggered the particular request. |
| 1:03.4 | This of course led to heavy abuse. |
| 1:06.0 | It led to some user tracking. |
| 1:09.1 | It also was some of the reason why cross-site request forging became such a |
| 1:15.0 | big deal. When a malicious site triggers a request to a website to which the user was already |
| 1:21.5 | logged in to, then the browse of course would send the session cookie and with that sort of malicious requests |
| 1:29.8 | could be triggered if the site didn't implement additional steps to prevent cross-site |
| 1:34.3 | request forgery. So to prevent some of these issues a new cookie parameter was introduced same site. |
| 1:43.9 | The same site parameter essentially limits what |
| 1:47.7 | requests that are triggered by sites that did not set the particular cookie will actually |
| 1:54.5 | send the cookie along. So if I'm logging into a website, the website sets a session cookie. I'm |
| 2:00.4 | going to another website without logging into a website, the website sets a session cookie, I'm going to another |
| 2:02.3 | website without logging out, and that other website will now trick a request by submitting |
| 2:09.2 | a forum, by loading an image or whatever, then I can limit whether or not the cookie is being |
| 2:15.6 | sent along with that request. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

