ISC StormCast for Friday, June 2nd 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 June 2017
⏱️ 11 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, June 2nd, 2017 edition of the Sands and its Storm Center's Stormcast. My name is Johannes Ulrich. Entertainment recording from Jacksonville, Florida. |
| 0:12.2 | Quick morning from Xavier. Xaviévié discovered some webcast invite links, which apparently do include personal data about the user, the link was sent to |
| 0:23.2 | us part of the URL. |
| 0:25.4 | The idea here is that if you click on the link, then this information can be pre-filled into |
| 0:29.9 | the form that you're using to sign up for the webcast, but if you are, for example, forwarding |
| 0:36.5 | this link to a friend or even verse posted on social media, |
| 0:41.2 | you're also delivering your personal information, which may include things like phone number, |
| 0:47.0 | email address, name and address. |
| 0:50.0 | Of course, the problem that you're running into here is that you need to authenticate the user somehow before you are displaying personal information. |
| 0:59.7 | Even if they would have just included a record locator in the URL, the data would still be pulled out of their database. |
| 1:09.2 | And it may have actually been worse if they would have for example |
| 1:12.7 | included sequential ID instead of just the actual data. So well, no good work around here. Make |
| 1:21.2 | your users either log in or make them fill in the form again. So the usual rule of thumb that I'm teaching when I'm teaching |
| 1:28.7 | web application security is if you're never asked for a user in a password, something is probably |
| 1:34.2 | wrong with the site. And cloud-based identity and access management company, one login apparently |
| 1:41.1 | suffered a substantial breach that put all of their customer information |
| 1:46.5 | at risk. |
| 1:47.8 | This is of course particular critical given the role that one login plays in companies' infrastructure. |
| 1:55.0 | Essentially what you're doing if you're signing up with One Login is that all of your identity |
| 2:00.4 | management is done by One Login in the cloud. |
| 2:03.6 | They also call it Identity as a Service. |
| 2:07.0 | Now the advantage of this, of course, is that you do not have to run your own identity management |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

