meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, January 31st 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 31 January 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Chrome Update; Firefox Update; Facbook/Google iOS Spy VPN; Samsung Store RCE

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, January 31st, 2019 edition of the Sansonet Storm Center's

0:07.0

Stormcast. My name is Johannes Ulrich. I'm recording from Jacksonville, Florida.

0:13.0

Let's start out with browser updates. Today, Google released a new version for Google Chrome, Google Chrome 72, fixes a number

0:22.8

of bugs but also makes a couple of security relevant changes.

0:28.1

First of all, this version of Google Chrome starts the deprecation of TLS 1.0 and 1.1.

0:36.5

Most users won't see a difference yet. You'll only see warnings in the developer

0:41.3

console, but starting early 2020, so about a year from now in Google Chrome 81, Google

0:50.4

TLS 1.0 and 1.1 will be removed all together.

0:56.0

Right? This is likely going to be a problem is things like devices, like web-based cameras and such.

1:03.0

They may not support anything beyond, usually actually TLS 1.0.

1:08.0

In those cases, you may actually be forced then to fall back to HTTP. Another

1:14.7

change to TLS is that public key pinning will be removed and that probably has less

1:21.9

on impact. Few sites have used it in the past. We used it for a while for a Nord-Storm Center.

1:28.6

But the reason it's being removed is that people found it too complex to maintain these

1:34.4

public key pinning headers.

1:36.3

And there was a real chance here of a denial of service and a fairly nasty sort of persistent

1:42.8

denial of service, which is why browsers start removing this feature again.

1:48.1

Another change is the way FTP is being dealt with in Chrome 72.

1:53.8

Now, you'll still be able to see FTP director release things, but if you download a file, it will just be downloaded.

2:00.1

It will not be

2:01.7

rendered inside the browser.

2:05.1

And the second browser, we got an update for today is Firefox.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.