4.9 • 696 Ratings
🗓️ 29 July 2016
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Friday, July 29, 2016 edition of the Sansonet Storms and Stormcast. |
0:07.0 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
0:12.0 | SSL, very hot topic, but also a topic that's often not quite well understood. |
0:19.0 | So today, Boyan is walking you through the exact steps required |
0:24.6 | to verify SSL certificate. Yes, there are tools that will do it for you, but with Boyan's |
0:30.6 | step doing it mostly on the command line with OpenSL, you actually sort of get to go through all the steps, verify the signatures |
0:40.2 | and see how it actually works, that you can for example make sure that a particular certificate |
0:46.5 | is signed by a particular certificate authority. |
0:51.4 | And yesterday I mentioned vulnerabilities in LastPass, the password manager. |
0:57.7 | Well, today LastPass did release an update for this product. |
1:03.2 | It also did clarify the differences between the two reported vulnerabilities. |
1:08.7 | The first one was reported actually over a year ago to last |
1:12.7 | pass by Matthias Carlson and then promptly patched. Mathias just took his time for users |
1:20.2 | to patch and such to publish the details. Just happened that also yesterday Tavis Ormandy |
1:26.2 | from Google did publish a tweet about a vulnerability that he found. |
1:31.3 | Now, he just found a vulnerability, reported it to LastPass. |
1:35.3 | He didn't report any details. |
1:37.3 | LastPass did immediately patch the vulnerability and did release an update. |
1:43.3 | So these were two different vulnerabilities |
1:46.0 | that were found at very different points in time. Just Mathias did wait a while to actually |
1:53.0 | release the details. Turns out that the vulnerability that Ormandy found only affects the last |
2:00.0 | past Firefox add-on, so that has been |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.