meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, November 18th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 18 November 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. TPM-Fail Update; Office Update Breaks Access; WhatsApp Update

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, November 18th, 2019 edition of the Sansanet Storm Center's Stormcast.

0:08.1

My name is Johannes Ulrich, and I'm recording from Riyadh, Saudi Arabia.

0:13.4

Now, let's start with a quick update on the TPM fail-warnability that came up last week.

0:20.6

There is still some confusion as to what patches are available and where to get them.

0:26.8

If your system has an Intel FTPM 2.0 chip, well, there is a bias update available.

0:34.9

Now for the STTPM chips, you do have a firmware update tool that directly

0:41.0

updates the TPM firmware. Intel also released a CSME version detection tool. Now CSME, this is what

0:51.0

used to be the management engine ME. It's now called Conversion Security and Management Engine.

0:57.6

And this tool will check your firmer.

1:00.8

And part of this is also the TPM 2.0 firmer.

1:06.3

So if you run behind here, this tool will alert you and will give you a link to Intel's

1:14.5

download page.

1:16.2

Now, on that page, you still have to find the right update.

1:19.7

And Haise, the German computer magazine, actually found that, for example, the German version

1:24.8

of that page doesn't have all the latest update listed

1:28.4

that you do find on the English version.

1:32.2

Dell has also released updates.

1:34.4

Now, HP did release bias updates.

1:37.8

HP is actually not using the Intel FTPM 2.0, but instead the other affected TPM version STTPM.

1:47.0

So in general, not easy to figure out which patch you need for what system.

1:52.0

Motherboard manufacturers also have their own lists of various updates.

1:57.0

Looks like it will take quite a while for everybody to figure out what needs to be patching and where to get the right patch.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.