meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, November 12th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 12 November 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Traffic Analysis Quiz; OSS Security Scorecards; Bitdefender UPX Issues;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, November 12, 2020 edition of the Sands and at Storm Center's

0:06.3

Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida.

0:13.3

Well, in case you missed it, we had another traffic analysis quiz by Brad, where he does present a

0:20.7

P-CAP of an actual infection, and then

0:23.8

you get to analyze it and in this case figure out what kind of infection, what type of malware

0:30.5

was used in this case. So a pretty neat way to hone your skills, and of course Brad will for sure shortly post

0:41.5

a solution to this quiz.

0:45.4

And the Open Source Security Foundation has published its first of real product after being

0:52.5

initiated this summer by the Linux Foundation, and that's

0:59.0

security scorecards for open source projects.

1:04.0

The problem that's trying to solve is that when you're using a particular open source project,

1:08.0

it's really hard to sort of gauge how secure,

1:12.6

insecure a particular project is. So they're now publishing an automatable scorecard

1:20.6

that is going to help to judge the security posture of open source projects.

1:28.3

So of course, this has a little bit a checklist feeling to it, but I think the items they're

1:34.3

looking for do make sense, for example, is there a code review being done?

1:40.3

They're really just checking if one is done, not whether or not it's done right or wrong, or are they using, for example, some fussing, are they using some static code analysis?

1:51.5

I think it makes a ton of sense.

1:53.3

Of course, can always find someone who says, hey, but if I just do a code review and I don't really put any effort in it, I still have insecure software.

2:03.2

That's not really what this is trying to solve.

2:05.6

It just shows if you bother to do a code review that you have thought at least somewhat about security.

2:13.1

And it's better than not doing a code review.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.