meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, June 30th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 30 June 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Moving MFA; Managing Human Risk Report; Service Fabric PoC; Zimbra RCE; Deepfake Interviews;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, June 30th, 2020 edition of the Sandstone at Storm Center's

0:06.6

Stormcast. My name is Johannes Ulrich, and I'm recording from Stockholm, Germany. Today's diary,

0:13.8

we got one from Rob. He sort of took a quick informal survey of different multifactor authentication applications that you typically have on a phone

0:23.9

and how easy or difficult it is to move those authenticators to a new phone. Now, of course,

0:32.0

most authenticators these days are using some variation of what's commonly known as Google

0:37.3

Authenticator or these

0:38.5

time-based one-time passwords. They tend to be reasonably easy to move if the application

0:46.5

cooperates in allowing to do this. And of course, many password-safe applications are supporting

0:53.9

now this form of authenticator.

0:56.0

Where it gets more tricky are sort of proprietary applications, which often are specific

1:02.6

designed to not allow the user to register the same multifactor authentication token on different

1:10.8

devices.

1:11.4

That's often seen as a security feature because it does prevent the unintentional copying

1:17.6

of the authenticator.

1:19.8

In these cases, I actually would probably still prefer if organizations are allowing

1:25.3

registering multiple authenticators in order to make the move

1:29.5

to a different phone easier.

1:33.1

Then we also have a new managing human risk report from Sands Security Awareness, targeting

1:41.1

professionals who are dealing with security awareness program.

1:44.9

So really not so much about the different awareness topics,

1:48.4

but really more sort of how these professionals work within organizations.

1:54.4

Well, sort of interesting, if you are working full time on security awareness,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.