ISC StormCast for Tuesday, December 17th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 December 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, December 17th, 2019 edition of the Santernet Storm Center's |
| 0:06.3 | Stormcast. My name is Johannes Ulrich. And then I'm recording from Jacksonville, Florida. |
| 0:12.8 | If you ever shared a file online, you probably realized that whoever received this file can take it and |
| 0:20.3 | reshare it. |
| 0:21.6 | Apparently, cloud authorization company Polyrise considered this sort of a new and unwanted |
| 0:28.6 | functionality in Slack and reported it as a security vulnerability. |
| 0:34.6 | The problem Polyrise outlined is that once a file is shared in a private |
| 0:39.6 | conversation, any member of that conversation can take the file shared in the public channel |
| 0:46.0 | and with that make it public. And this is not undone if the original owner unshairs the file. |
| 0:54.0 | If you unshare the file, you just remove it |
| 0:56.4 | from the location that you shared it, which would be this private channel in this example. |
| 1:02.8 | Slack pretty much told Polyrise that, well, this is just how it works on the internet and |
| 1:08.2 | they're not really going to fix this. |
| 1:11.6 | I actually agree a little bit with Slack here in the sense that once you share a file |
| 1:15.0 | with someone they can download it, they can add it to an email and send it away so it's |
| 1:21.8 | not that Slack is implementing some kind of DRM here or so to limit the distribution of these files beyond Slack. |
| 1:30.3 | And sticking with the authorization topic here, Google announced a plan to turn off |
| 1:38.3 | a password-based authentication for G Suite apps. If you do want to use an app in G Suite, you have to essentially |
| 1:48.2 | switch to OAuth. Now, you do have a little bit of time here. It starts happening June 15th next |
| 1:56.2 | year, so you have about, what is it, six months left to switch your applications. After that date, |
| 2:03.6 | new users can no longer use any applications to connect via password-based authentication. Now, after |
| 2:12.3 | February 15th, 2021, which is essentially a little bit more than a year from today, then all LSAs |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

