4.9 • 696 Ratings
🗓️ 22 September 2016
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Friday, September 23rd, 2016 edition of the Sandus Stormcast. |
0:07.0 | My name is Johannes Ulrich and the day I'm recording from Baltimore, Maryland. |
0:13.0 | As expected, OpenSL released an update today. |
0:16.0 | This update fixes a total of 14 different vulnerabilities. Most of them only apply to the 1.01 and 1.02 |
0:26.6 | branch, but a couple of them do apply also to the just released 1.1.0.0 branch. |
0:35.6 | All three branches are still fully supported, so you should be okay with either |
0:40.4 | one of these of course the latest and greatest one dot one does support some of |
0:45.9 | the newer features there was one particular vulnerability here and OCSP |
0:52.3 | status request vulnerability that was rated high for all three releases. |
1:00.0 | This is a memory leak issue where essentially you end up with a denial of service condition because memory fills up. |
1:08.0 | This was also the only high vulnerability. The suite 32 vulnerability is also |
1:14.6 | mitigated in this particular release. Now the only thing they did is they downcrated the |
1:21.6 | death ciphers from high to medium. So if you already configured these ciphers to no longer be used, then you're fine. |
1:31.3 | This change just makes it easier and a little bit more obvious to configure OpenSL. |
1:37.3 | So in short, no heart bleed here, nothing that you have to rush out. |
1:41.3 | Just wait for your respective Linux release or whatever you're using |
1:47.0 | OpenSL on to actually come up with a patch for this particular update. |
1:54.0 | ATM machines have often been compromised in the past with skimmers and banks are looking into new ways to authenticate customers |
2:03.3 | and one way of course they're considering is biometrics with fingerprints and iris scans |
2:10.7 | being used to identify the user apparently bad guys are getting ready as well in order to defeat these authentication |
2:20.6 | mechanisms by collecting the same biometric data with their skimmers. Kasperski did publish a report |
2:28.0 | where they're sort of speculating with possible attacks against these new generation of ATMs. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.