meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, November 2nd 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 2 November 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. CAA Records; Unpatched Windows Bug Exploited; Operation Kitsone

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, November 2, 2020 edition of the Sandtonet Storm Center's Stormcast.

0:07.4

My name is Johannes Ulrich.

0:09.0

And I'm recording from Jacksonville, Florida.

0:13.4

On Friday, Xavier took a look at the adoption rate for the CAA DNS record.

0:20.0

The CAA is short for certification authority authorization, and it essentially tells

0:27.1

certifications if they are authorized to issue certificates on behalf of the domain.

0:33.9

Now, whenever we talk about TLS vulnerabilities, we often get lost in these highly technical weaknesses in the TLS protocol, which actually are hardly ever exploited.

0:45.2

On the other hand, there have been a number of high-profile issues with certificate authorities being tricked to issue a certificate for a particular domain without

0:56.4

actually properly verifying that request.

1:00.9

So the CIA record in that sense is actually preventing some real attacks in that a

1:06.8

certificate authority will first check that record to make sure that it is authorized to issue

1:12.7

the certificate and it will otherwise reject to issue a certificate. So this record is not

1:18.9

checked by browsers as they verify a certificate. It's only checked by certificate authorities.

1:27.1

Well, some of the bad news here, not a lot of domains are using it.

1:31.3

Xavier only found 3% of Alexa's top 1 million domains using a CIA record.

1:38.3

I believe one reason why organizations are hesitant in using the CIA record is that they often, in addition to

1:48.0

self-hosted websites and certificates are taking advantage of con-delivery networks or CDNs.

1:55.4

And these CDNs will now request certificates on behalf of that organization. And then of course you need to include

2:04.5

whatever certificate authority the CDN is using, which may not always be that clear. And then you

2:12.2

have sort of again that trade-off between a denial of service or a potential machine in the middle attack with

2:20.0

someone issuing a bad certificate. Another issue, of course, and I'm not sure how widespread

2:25.8

that still is these days, but there have been some domain registrars that had no provision

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.