ISC StormCast for Tuesday, December 29th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 29 December 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, December 29th, 2020 edition of the Santernet Storm Center's |
| 0:06.5 | Stormcast. My name is Johannes Ulrich, and the air recording from Jacksonville, Florida. |
| 0:13.8 | January 11th was supposed to be originally a fairly critical date for old Android operating systems and Let's Encrypt. |
| 0:23.8 | Historically, Let's Encrypted not have its own root certificate authority. |
| 0:29.6 | Instead, they used a certificate authority based on IDEN trust. |
| 0:34.6 | Now, more recently, they used their own route certificate, but then also had it still |
| 0:41.1 | cross-signed with ident trust. And the reason for that was that not all operating systems yet |
| 0:47.8 | recognized Let's Encrypt's Own Certificate Authority. Well, this was supposed to change come January 11th, at which point |
| 0:58.2 | the original identtrust certificate authority expired and going forward, let's encrypt was no longer |
| 1:06.1 | going to use ident trust but only let's encrypt. Problem, while older Android versions did not include |
| 1:14.5 | the Let's Encrypt Set of Authority and as a result they would no longer trust any |
| 1:20.2 | Let's Encrypt certificate issued after January 11th. |
| 1:24.6 | All we're talking about Android versions that are quite old, pretty much anything prior |
| 1:31.0 | to 7.1.1. |
| 1:33.8 | It's still affected a significant percentage of the user population. |
| 1:40.1 | So what's actually going to happen now on January 11th is that Let's Encrypt will continue to use the expired ident trust certificate authority in addition to its own. |
| 1:54.5 | Now, you may ask, how can this work if identrust is expired? |
| 2:00.3 | Well, it turns out that Android actually ignores the expiration |
| 2:04.6 | for a set of authorities that are implicitly trusted. So this will still keep the older Android |
| 2:11.7 | versions in business. And of course, newer ones will just ignore the identrust one and then use the self-signed |
| 2:21.8 | set of authority that's now included as an anchor in Android and other operating systems. |
| 2:29.3 | This new arrangement will stay in place until 2004 when this expire |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

