meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, May 11th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 11 May 2017

⏱️ 9 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Review OAUTH Permissions; OS X EFI Monitor; MS Edge SOP Bypass

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, May 11th, 2017 edition of the San Antonio Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich.

0:10.0

And today I'm recording from San Diego, California.

0:14.0

One of the big events last week, of course, was the Google Docs'-Oth flash fishing attack.

0:21.6

While Google was pretty quick in blocking the account responsible for the attack,

0:27.6

it still showcased how O-Oth can be abused.

0:31.6

A much more common scenario is applications that users no longer need or applications that request many more

0:39.7

privileges than are actually required to use the application. Rob has a nice diary today about

0:46.6

how to review the Oath permissions on various social media accounts. You will often find a list of applications within your account privacy or security settings,

1:00.8

but every site does a little bit different.

1:03.4

So Rob gives you a lot of the direct URLs that get you to the area where you do adjust

1:10.7

and review these application permissions,

1:13.6

something you probably should put in your calendar every few months to do.

1:18.6

And Apple apparently is working on a system to warn users of firmware updates or firmware changes, I should say.

1:26.6

Firmware integrity is a long ongoing issue and has been moved more and more into the spotlight again

1:34.3

after recent leaks of government hacking tools that are used to manipulate firmware

1:40.3

in order to gain persistence on exploited machines.

1:45.0

Now, Apple's proposed system would warn the user of changes made to the firmware

1:51.0

and then would give the user the option to transmit these changes to Apple for review.

1:58.0

So similar like a crash dialogue that you often see where it tells you are an application

2:03.8

crashed and you can submit details about the crash to Apple or to whoever made the application.

2:12.5

The tool that does review the firmware EFI check was part of the beta version of the current

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.