meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, January 30th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 30 January 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Insecure Security: Lenovo Fingerprints; ClamAV; Malware Bytes; Cisco

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, January 30th, 2018 edition of the Santernut Storm Center's Stormcast.

0:07.8

My name is Johannes Ulrich and the name recording from Miami, Florida.

0:12.6

Sort of the theme of today's podcast is insecurities in security products.

0:19.2

We do have a number of them to report about today, starting with

0:23.6

Lenovo's implementation of its fingerprint scanner. Biometrics in laptops has been around for a while,

0:30.2

and one of the companies that actually, I think, sort of pioneered this somewhat, was Lenovo,

0:35.6

or actually back in the IBM ThinkPad days, fingerprint

0:39.6

scanners were quite common accessories.

0:43.0

More recently, Lenovo introduced Fingerprint Manager Pro.

0:47.7

The application implements a password safe and allows users to log into websites and log into Windows by scanning a fingerprint.

0:58.1

Sadly, the password safe is implemented quite poorly.

1:01.9

Not only does it use a weak algorithm to encrypt the passwords, but you don't even have

1:08.3

to decrypt them.

1:09.1

All it takes is a hard-coded backdoor password to decrypt the data that's stored within Lenovo's fingerprint manager pro.

1:18.5

The vulnerability was disclosed to Lenovo by Jackson Torsami of Security Compass.

1:25.9

Lenovo has released an update last week.

1:30.8

And running Clam AV as an antivirus scanner, it is time to update.

1:36.9

And actually, this is a system that you often see, for example, implemented on mail servers,

1:42.3

not so much on workstations.

1:45.0

Clam AV released an update fixing seven different vulnerabilities.

1:50.0

Some of the vulnerabilities may be used to execute arbitrary code.

1:55.0

Vulnerabilities affect, for example, the PDF parser within this antivirus tool as well as various compressed impact file formats like

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.