meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, November 10th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 10 November 2017

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Twilio Credentials Found in Mobile Apps; Drive By Crypto Currency; Intel ME Decode via USB

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, November 10th, 2017 edition of the San Bernard Storm Center's Stormcast. My name is Johannes Ulrich,

0:08.8

and I'm recording from Jacksonville, Florida. We continue to have problems with developers storing credentials

0:16.0

in code being delivered to users. The latest case are Twilio credentials.

0:22.6

Twilio, if you're not familiar with that, is a very popular service that allows you to send SMS messages,

0:29.6

also allows for voice interaction, voice messages, even some video conferencing capabilities.

0:35.6

So a lot of mobile applications that use these functionalities are using Twilio for sort of the

0:43.3

plumbing part of actually sending the messages and then the app itself will just send a request

0:50.3

to Twilio's web service in order to, for example, establish a call.

0:56.4

Now, Twilio on its website actually has some guidance for different applications and languages,

1:02.7

how to set up per user tokens for authentication.

1:06.7

Essentially, what you're supposed to do is that the user will connect to the developers,

1:11.6

web service will receive a token from the developer and then use that token to directly authenticate to Tuileo.

1:20.6

Now this process of course requires some extra work, so a lot of developers will just include their own key in the application,

1:31.0

which then results in all applications or all users using the same code.

1:37.8

Once different users share the same API key, there is of course no separation anymore

1:43.0

between these users as far as Twilio is concerned.

1:46.0

And now all of these users have access to all data being submitted to Twilio.

1:52.0

Like for example, call logs, logs of messages, and well, everything Tvillo has to offer.

2:00.0

This isn't the first time something like this happens.

2:03.4

We have seen this quite often, for example, with credentials for Amazon web servers

2:09.3

that are just being embedded in mobile applications.

2:13.1

Too often developers believe that by delivering a binary blob to the user, that the user will not be able to extract these credentials.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.