ISC StormCast for Thursday, October 20th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 October 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, October 20th, 2020 edition of the Sansonet Storm Center's |
| 0:08.8 | Stormcast. My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida. |
| 0:16.2 | Xavier, who is currently attending the CTI summit in Luxembourg, listened to a talk by Patrice of Red, |
| 0:24.3 | and the founder of Onifay, I pronounce this correctly, Onifay is one of the companies performing |
| 0:33.0 | internet-wide scans for open ports to identify exposed services. These type of scans, |
| 0:40.3 | Shodan, for example, being another one that does that and it's quite famous for it, |
| 0:44.5 | have happened for quite some time, often for research purposes. But lately, so if the business model |
| 0:50.6 | of attack surface detection for organizations has a little bit evolved around |
| 0:56.7 | this and there have been a good number of companies that basically have collected the same |
| 1:02.8 | kind of data. In a diary posted day, Xavier is going over some of the ethical issues |
| 1:09.3 | evolve with these scans, some of the things that |
| 1:12.4 | these companies should take care of before they sort of just start scanning. I've always been |
| 1:19.1 | a bit ambivalent about these services. What I do think there is a purpose for them, but the |
| 1:25.9 | question really is, you know, how many of them do we need? |
| 1:28.4 | And there is a significant percentage of the scans that we are seeing that are attributable |
| 1:34.1 | to these companies. So in addition to the consideration Xavier put forward, I would probably |
| 1:41.3 | add that they also should make some of the data available publicly in return for the cost of the public's network that they are using to perform these scans. |
| 1:55.2 | This week, the US government started accepting applications for student loan forgiveness via a website, |
| 2:03.8 | student aid.gov. |
| 2:05.9 | As expected applications do require a number of sensitive personal information like social security |
| 2:14.3 | numbers and the like. |
| 2:15.7 | And the FBI today warned and shouldn't really be a surprise, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

