4.9 • 696 Ratings
🗓️ 27 March 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, March 27th, 2003 edition of the Sandsenet Storms Center's Stormcast. My name is Johannes Ulrich and that I'm recording from Jacksonville, Florida. |
0:15.0 | Well, we do have an update from Microsoft regarding the issues with ineffectively cropping images in the Windows 11 |
0:24.3 | Snipping tool. |
0:25.6 | There is an update available now in the Microsoft store. |
0:30.1 | There's also an update for the Windows 10 Snippin Sketch tool, which apparently is affected as well. |
0:38.0 | Seen some reports on Twitter that there are other sort of random image tools that appear |
0:43.2 | to have been updated. |
0:44.6 | Not clear if that's just accidental or if that's also related to this problem of cropping |
0:51.7 | images. |
0:53.2 | May as well update them. So visit the Microsoft store and see if you have any updates available. |
1:01.6 | And early on Friday, GitHub did rotate its S.H keys. |
1:07.2 | Apparently, the original S.S.H. |
1:10.7 | Key was compromised, or at least was available. Apparently, the original SSH key was compromised, or at least was available publicly, |
1:15.9 | so that's why they took the step. It only affected the RSA key. The elliptic curve keys |
1:22.5 | are still good and have not been changed. But if you're using the RSA-SH key, then you may get a |
1:31.5 | warning that the key changed. So updated, updated properly. I'll link to the GitHub blog regarding |
1:41.0 | this. Don't just accept sort of random keys that apparently have been updated. |
1:47.1 | That's, of course, of another weakness of that entire ZH process that developers often don't |
1:53.6 | verify these ZH keys properly. Not a lot of more details from GitHub, so we don't really know |
1:59.9 | how long these keys have been publicly accessible |
2:02.6 | and what their confidence level is that they haven't been compromised. |
2:07.6 | An attacker could essentially use these keys in order to play then machine. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.