ISC StormCast for Tuesday, April 7th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 7 April 2020
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, April 7, 2020 edition of the Sandtonet Storm Center's Stormcast. |
| 0:07.0 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.1 | BGP Mon reported that this weekend, Sunday around noon, a large number of prefixes. |
| 0:20.4 | They counted about 8,000 different prefixes. |
| 0:24.0 | We're all of a sudden being rerouted through Roscom, a Russian ISP, |
| 0:29.2 | who has had a pretty rich history in these kind of fraudulent or mistaken BGP announcements. |
| 0:39.0 | The problem is always with this BGP hijacking. |
| 0:43.1 | It's never really clear whether that's intentional |
| 0:45.3 | in that someone is trying to reroute traffic to intercept it |
| 0:50.0 | or whether it's just a mistake. |
| 0:53.5 | But Roscom and China Telecom happen to be the two ISPs that do the most of it. |
| 1:00.2 | Where we have seen it sometimes happens sort of semi-maliciously |
| 1:04.3 | is where certain countries do require ISPs to block access to certain networks. And of course, Russia, China are right up |
| 1:14.2 | there on the list. And sometimes in establishing these blocks, they are making mistakes where |
| 1:21.6 | they are actually affecting many other networks. It should be noted that one of the affected networks was Facebook, but aside of that, |
| 1:31.6 | there were multiple others of large cloud providers and such that were affected. |
| 1:36.9 | Well-implemented TLS, of course, should protect you from any rerouting like this and for |
| 1:42.6 | most practical purposes you shouldn't really rely on any particular route across |
| 1:49.4 | the internet. |
| 1:51.5 | Now, one recent trend in software development is often referred to as shifting left. |
| 1:57.8 | And what this means is that we're trying to take care of security issues and |
| 2:03.9 | functional issues for that matter as well as early in the development life cycles as possible. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

