4.9 • 696 Ratings
🗓️ 25 July 2016
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, July 26, 2016 edition of the Sansonet Storm Center's Stormcast. |
0:08.2 | My name is Johannes Ulrich, and the day I'm recording from Jacksonville, Florida. |
0:12.8 | NIST published a preview of the next version of its digital authentication guide. |
0:18.8 | Haven't read all of it, but one of the highlights that has been |
0:23.2 | noted is that out-of-band authentication using SMS is deprecated according to this new standard. |
0:32.9 | Now as an alternative, they offer the use of mobile application. |
0:38.5 | They also state that push notifications are okay if they provide sufficient entropy, 64 bits |
0:47.3 | of entropy which of course isn't really true for these usual five digit numbers. |
0:54.1 | Now if you do have an authenticator with a smaller |
0:58.3 | entropy, then you do need to implement a throttling mechanism in order to prevent |
1:03.7 | prud forcing. Remember, a few months ago, Facebook had a problem with this where you could |
1:09.5 | essentially just prude-force the identification |
1:13.4 | number that was sent via email or SMS. |
1:17.1 | Now in the meantime, what they're saying is if you're still using SMS, you can continue |
1:22.4 | to do so for now, but you do need to make sure that the receiving number is actually a number on a mobile carrier and not a voice over IP number or a number provided by some kind of software service. |
1:39.3 | So in short, if you are using SMS messages right now, you have to make sure that the recipient |
1:48.0 | is actually on a mobile network, not on a voice over IP system. |
1:53.0 | In the future, it sounds to me like systems like Google Authenticator, for example, are |
1:58.0 | still okay, but with systems like Google |
2:01.1 | Authenticator that provide pretty short identifiers you do need to make sure |
2:06.3 | that you prevent brute forcing NIST guidance typically applies to the federal |
2:10.9 | government but a lot of private industry standards are referring to NIST |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.