ISC StormCast for Thursday, July 11th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 11 July 2019
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, July 11th, 2019 edition of the Sansonet Storms, Stormcast. My name is Johannes Ulrich, and that I'm recording from London, England. |
| 0:12.9 | In yet another sign of S&B version 1 going away, the latest preview release of Samba. Samba 4.11 has disabled SmbB version 1 by default. |
| 0:27.6 | With Samba being an open source implementation of Smb that is often used on Linux systems, |
| 0:35.6 | it was sort of one of the holdouts when it came to SMP version one. And one of |
| 0:42.4 | the reasons that some organizations still keep it enabled, in particular since many network |
| 0:48.9 | storage devices are using Samba. Now Samba, of course, has supported new versions of SMP for a while, |
| 0:56.8 | but has kept SMP version 1 enabled, |
| 1:00.8 | even though Windows has further and further moved away from it. |
| 1:05.8 | Also, with this latest update, |
| 1:07.3 | the Samba team is requesting feedback |
| 1:10.0 | regarding the complete removal of S&B version 1 from its code |
| 1:14.8 | and it is requesting that users who require S&B1 support will please file a bug report. |
| 1:24.7 | And remember how about a week ago I mentioned that public key servers have issues with spam signatures. |
| 1:33.8 | The problem here was that individuals are downloading popular keys from these key servers, signing them, then re-uploading them with their signatures and this way attaching |
| 1:46.6 | thousands of signatures, which then in turn can lead to a denial of service condition if |
| 1:53.2 | someone happens to download this key and import it into their key ring. |
| 1:59.5 | Well, to respond to this problem, the latest version of KnewPG, version 2217, |
| 2:06.1 | will have a new option self-6 only that is enabled by default |
| 2:12.3 | to no longer import any signatures from public key servers. |
| 2:17.0 | Instead, only the own self-signature |
| 2:20.3 | of the key will be imported. So in some ways, this is a big move away from the Web of Trust |
| 2:27.8 | that is really sort of the foundation of the idea of PGP. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

