meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, November 17th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 17 November 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Cheap Evil Maid Defenses; F5 Big-IP PoC; CVE-2022-32899 iOS Neural Engine; Disneyland Malware Team

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, November 17, 2020 edition of the Sands and the Storm Center's Stormcast.

0:09.0

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.7

I've got an interesting guest post today from Gephard.

0:18.6

Gephardt is proposing a fairly simple and cheap and easy way to fight back against the

0:25.5

evil mate attack.

0:27.2

The evil mate attack comes from the scenario where you are leaving a laptop in a hotel room,

0:34.4

and an evil mate has physical access to the system and is then of course potentially

0:41.1

able to disrupt or compromise the system. We have multiple technical controls for this like various

0:50.6

sort of pre-boot protections or fully encrypted thrives and the like.

0:56.1

But there's, of course, always a chance that some kind of implant is being installed or such,

1:00.9

and that's difficult to defend against.

1:05.0

But Gephardt is proposing is a fairly simple little trick where before you leave your laptop alone,

1:14.5

you are just typing the first letter of your password in the screen.

1:20.5

Has to be the real password, so the first letter of your actual password, not a random letter.

1:26.9

And then the idea is when you come back, you just type the remainder of your password.

1:33.0

If someone got a hold of your system, first of all, they may have just removed that letter

1:41.2

because they rebooted the system or such, and that would be pretty obvious.

1:45.2

But even if they would have seen that you already typed one letter, well, they don't know your

1:49.8

password, so they don't know what the letter is. And yes, they have a one in, whatever, you know,

1:55.2

a 60 or so chance if you're counting lower uppercase special characters and such,

2:01.3

but still a fairly low chance in actually getting the right letter type there.

2:07.0

Interesting proposal and Gaphart is really just looking,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.