meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, January 25th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 25 January 2024

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Bad Infosec UI; Google Sys:All Loophole; Automotive Pwn2Own; Android Bluetooth Exploit; @sans_edu Deans List

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, January 25th, 2024 edition of the Sands and at Storm Center's Stormcast. My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:14.1

I wrote up a quick story today about, well, just some bad user interface design in information security tools, in particular when you're

0:23.5

talking about consumer-based tools. The reason I wrote about this is that, as many of you,

0:30.0

I imagine, often get asked for help from friends, neighbors, dog park, acquaintances, and such,

0:40.7

about issues they have had with their mobile phones, with their computers, and so often it's, well, really not much, but sometimes actually

0:47.9

gets worse because of bad user interface design, in particular how some of the security

0:53.9

tools are almost flooding you with

0:56.2

pretty much useful alerts, which then of course desensitizes some users to fall for fake alerts.

1:04.6

And that's sort of an issue that I ran into recently.

1:09.1

And that sort of prompted a little bit that post. Also, that if you are trying

1:15.6

to understand more about the alert, well, these tools are off not that forthcoming with the necessary

1:21.5

details to actually help you understand what's going on. This is not a specific tool I'm talking about here.

1:29.9

I find that this is pretty much true for more or less any of in particular the consumer

1:36.0

targeting security tools.

1:38.9

And part of it I think is that in particular when it comes to alert messages, the goal here

1:43.1

is less to inform the user,

1:45.0

but more to essentially make a sale, show value to the user, that, hey, the tool apparently

1:52.0

did something good for you, but that's exactly what the bad guys are going for then.

1:58.0

Their messages are then also designed to make a sale, just with their fake

2:03.8

support hotline and such, which of course leads to both tools using pretty much the same

2:09.6

language, the same type of pop-up message.

2:13.8

And Orca Security has an interesting blog post post in particular if you're using Google Kubernetes

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.