4.9 • 696 Ratings
🗓️ 20 February 2023
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, February 20th, 2020, 3 edition of the San San Antonio Storm Center's Stormcast. |
0:09.1 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:15.1 | This weekend, we had a couple of quick diaries, one by Guy about, well, fishing emails that we actually got in |
0:22.6 | our internet storm center inbox. Yes, we do get fishing emails too, thanks to all the |
0:30.0 | fishing actors, sending them to us to give us something to write about. Guy used it to actually, |
0:36.5 | well, look at some recent trends here in these phishing emails. |
0:40.8 | One thing he noticed is a lot of use of IPFS.io to host some of the malicious content. IPFSio is the |
0:49.4 | interplanetary file system. I think I mentioned a couple times before. It's sort of a distributed system |
0:55.4 | to host files, which of course makes it quite difficult to take anything down there, even though |
1:01.5 | they do have some takedown mechanism built into this side, if I remember correctly. Also, |
1:08.9 | one important note here, many of these emails, well, no longer any |
1:12.8 | typos. Sometimes actually, real emails have more typos than some of these phishing emails. |
1:19.1 | Fishing emails do know about spell checkers. So that makes them, of course, a little bit more |
1:26.3 | difficult to identify. |
1:29.2 | Looking for DNS requests for IPFS.io, certainly worthwhile, I think, but yes, there are some |
1:36.0 | legitimate uses here. So keep an eye on it, but I wouldn't outright block it at this point. |
1:44.0 | And Twitter late last weekend, this weekend, caused quite a stir by altering the way they're |
1:49.4 | using two-factor authentication. |
1:52.1 | And now you had always three different ways to do two-factor authentication with Twitter. |
1:59.9 | There was SMS, so text messages. There was the |
2:03.4 | one-time passport authentication app, also sometimes known as Google Authenticator, and then you could |
2:09.2 | also use security keys. The change now is that you are no longer able to use SMS. If you're |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.