ISC StormCast for Thursday, December 7th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 6 December 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, December 7th, 2017 edition of the Sands and the Storm Center's Stormcast. My name is Johannes Ulrich and I am recording from Jacksonville, Florida. |
| 0:12.1 | As expected, Apple today released all the updates that we were kind of missing after the Sutton iOS update that was released this weekend. |
| 0:22.5 | Now, with that, we also got a new version of OS10, watchOS, and TVOS, where TVOS also was |
| 0:31.2 | released earlier this week. |
| 0:33.2 | But what we really got is all the security details. |
| 0:37.0 | Apple released now the iOS security details that were originally missing. |
| 0:42.3 | There was also a Safari update and so far there are no details available for that. |
| 0:49.3 | I tried something a little bit different today with our diary about this. I just actually made |
| 0:55.6 | this live if you saw the diary earlier you may not have seen this and that's sort |
| 1:00.9 | of comparing macOS iOS TV OS and watch OS as far as the different patches overlap. |
| 1:09.3 | Well not quite unexpected the the overlap is quite big. |
| 1:15.6 | Most, I would say, more than half of the patches or vulnerabilities do apply to all four |
| 1:22.6 | operating systems. |
| 1:23.6 | Somewhat of note is that the MacOS update does include the passwordless route account fix. |
| 1:32.3 | There has been a problem where people updated to the last version of macOS after applying the patch, which kind of undid the patch again. |
| 1:41.3 | So now you have a proper new version of macOS that you can update to that avoids this problem. |
| 1:50.0 | Also for everything but macOS, there are also patches for the crack vulnerability again. |
| 1:57.0 | It only affects certain pieces of hardware, so apparently for those they hadn't quite |
| 2:03.9 | the patch ready for earlier versions, there were earlier releases that were supposed to fix |
| 2:09.5 | this vulnerability. |
| 2:10.5 | We have seen this similarly from other vendors like Microsoft and Google, where they |
| 2:16.2 | have released multiple patches for this |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

