meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, November 28th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 28 November 2017

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Golden SAML Ticket; Facebook Poll Image Leak;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, November 28th, 2017 edition of the Sands and the Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich, and today I'm recording from Augusta, Georgia.

0:12.0

The Golden Sammel attack has made some news these last few days, and I want to spend a little bit time talking about it. So Sammel is a standard that's

0:24.2

being used to authenticate users and the one application that is really affected here is

0:31.3

something called federated identity. If you as an organization sign up for a web service, for example, Office 365 or Amazon,

0:41.6

support this, you can basically tell Microsoft, hey, if someone from my organization is trying to

0:48.2

connect to you, send them to us, we'll authenticate them, and then verify whether they are a legitimate user.

0:56.0

Now, this is first of all a pretty good idea.

0:58.5

You now have one central spot, your existing Active Directory service that you use to manage your users.

1:05.3

And your users have a consistent user interface, one username and password that they use in order to

1:12.8

authenticate to these cloud services.

1:15.4

In addition, it allows you to implement things like two-factor authentication relatively cheaply.

1:21.3

You just need one token, for example, that is used with your Active Directory service,

1:27.2

and then again, you can leverage this

1:29.1

to authenticate users for these different cloud services. The way the mechanics of this work is

1:35.8

that a user is going to the cloud service trying to log in. The cloud service will now redirect the

1:42.0

user to your authentication service.

1:45.0

With that redirect, there will be a challenge that's being attached to the URL.

1:50.0

Your service after authenticating the user signs that challenge using a secret key,

1:57.0

and that signature is now used to verify that this is a legitimate user.

2:01.6

Things go bad and that shouldn't really be a surprise if someone compromises your active directory service

2:07.6

and gets a hold of that secret key.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.