ISC StormCast for Friday, January 8th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 8 January 2021
⏱️ 16 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, January 8, 2021 edition of the Sandcent, Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.3 | Rob today started a series of diaries that he'll be publishing over the next couple days, couple weeks about parsing |
| 0:23.6 | and using the national vulnerability database. NIST publishes this database and it's sort of the |
| 0:30.0 | authoritative source of vulnerability information and offers a nice structured view of vulnerabilities. |
| 0:38.3 | For example, you can query the database by products, |
| 0:43.3 | and products are organized using standardized strings or CPEs, |
| 0:48.3 | the common platform enumeration. |
| 0:51.3 | So many tools, like for example NMAPAP will, for example, create output that includes this |
| 0:58.0 | common platform enumeration string, and then you can quickly feed that into the NVD API in order |
| 1:06.0 | to retrieve related vulnerabilities. |
| 1:09.0 | With Rob's diary, you get some samples in an introduction |
| 1:13.0 | into the information that is available via NVD and also tools that allow you to retrieve |
| 1:20.5 | and organize the data. And security researchers from Ninja Lab took a closer look at the Google Titan security key. |
| 1:31.3 | And while they did find a site channel vulnerability, I think they actually proved that exploitation of this vulnerability is not exactly practical. |
| 1:43.3 | If you're not familiar with Google Titan, it's a key that |
| 1:48.6 | implements the U2F or Fido2 protocol that can be used for authentication. There are a couple different |
| 1:56.0 | versions of it, either with USB, Bluetooth low energy, or with NFC interfaces. |
| 2:03.6 | And essentially, a browser, for example, is able to send a challenge to the key that will |
| 2:09.9 | then be digitally signed and returned to the browser to prove a particular individual's |
| 2:16.6 | identity. And of course, the big advantage of a token like this compared to, let's say, Google Authenticator or other soft tokens is that it should be very hard to impossible to actually copy these security keys. |
| 2:31.3 | In order to copy the security key, you need to be able to retrieve a |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

