meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Sunday, October 8th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 8 October 2017

⏱️ 8 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Payment Handler API; OpenSSH Version 7.6 Released; Microsoft Unanounced Patches;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, October 9th, 2017 edition of the Sands and the Storm Center's

0:06.4

Stormcast. My name is Johannes Ulrich, and I am recording from Singapore.

0:11.8

With me in Singapore for the next two weeks, the podcast may be published sometimes at a little bit

0:17.0

odd times of day, but I still should have a podcast once a day. First, I want to start

0:23.8

out with a relatively new web browser API, and that's the Payment Handler API. The last draft

0:32.3

was published October 4th, so late last week, and I think it's time to look at that API a little bit more

0:40.9

closely. The basic idea of this API is to have a uniform way to deal with payments and with that

0:49.6

also with stored credit card information and other payment information that's stored in the browser.

0:57.5

Now, overall, this payment API actually does a couple of things quite nice and more secure

1:05.3

than it's done in a traditional web application. In a traditional web application, the user enters their credit card

1:13.3

information, and that information is sent to the merchant. Of course, we have learned over the last

1:18.7

years that this is very problematic, given that you're sending the same data, the same credit

1:25.1

card number, to multiple merchants, if one

1:28.3

of these merchants gets compromised, then of course you have a problem that the

1:33.1

credit card has to be replaced. Of course, the number one reason why a

1:38.0

merchant would implement something like a payment handler API is to make it

1:42.5

easier and faster to checkout.

1:44.6

There are a lot of orders being lost or not being placed because the user can't find a credit

1:51.1

card number or can't enter it.

1:53.6

So as a result, we want to store it in the browser.

1:57.1

But while this may be a little bit problematic from a security point of view, what this payment handler API does right is that it no longer sends the payment card information to the merchant.

2:10.3

Instead, the payment card information is only sent to the processor.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.