4.9 • 696 Ratings
🗓️ 21 February 2019
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, February 21st, 2019 edition of the Santernut Storm Center's |
0:07.0 | Stormcast. My name is Johannes Lurich. I'm recording from Jacksonville, Florida. |
0:14.0 | Google today released details of a problem that Microsoft fixed in Microsoft Edge with its February update. |
0:23.6 | The problem here is it wasn't really a bug or vulnerability as more an intentional weakness |
0:31.6 | that was introduced to allow certain websites to run Flash. |
0:36.6 | Most web browsers have for a while now introduced the concept where in order to run flash |
0:42.3 | on a website you first have to give that site permission by typically clicking on the |
0:48.0 | applet before it runs. |
0:50.3 | Now this particular white list allowed about 58 different websites to run Flash without |
0:58.3 | asking for permission first. |
1:01.5 | To make things somewhat more tricky, the list was actually not in clear text. |
1:06.4 | It was a list of Shah-256 hashes. |
1:10.2 | Now, given that most of them were well-known websites, brute forcing it, was relatively trivial, |
1:16.8 | but a lot of sites that are listed here, I had no idea what they actually are. |
1:22.9 | So you may be a little bit curious about why Microsoft allowed these sites to actually run Flash |
1:29.6 | without asking for permission. |
1:31.9 | Another sort of interesting part to this is that yes, Microsoft modified this white list. |
1:38.8 | They didn't eliminate it. |
1:40.6 | The only entry that's left now is Facebook. |
1:43.7 | So Facebook is still allowed to run Flash without user permission. |
1:49.0 | If the user uses Microsoft Edge, the other thing they sort of fixed, but given it's only two entries, not really all that meaningful. |
1:57.0 | But the old white list didn't actually even verify whether used HTPS or HDP, so anybody |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.