4.9 • 696 Ratings
🗓️ 9 October 2018
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, October 9th, 2018 edition of the Sancton Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich, and I'm recording from Honolulu, Hawaii. |
| 0:13.0 | We got two updates from Apple, one for iCloud for Windows. |
| 0:19.0 | It fixes a number of web kit vulnerabilities, |
| 0:23.5 | an addition, a SQL light issue. |
| 0:26.8 | Then we also got an update for iOS. |
| 0:29.3 | This is iOS 1201. |
| 0:31.6 | This is a quick bug fix release that fixes some critical bugs |
| 0:35.9 | that came up in iOS 12, which was released a couple weeks ago. |
| 0:41.5 | Both vulnerabilities being addressed here are lock screen bypass vulnerabilities, one affected |
| 0:47.9 | voiceover and would allow access to photos and contacts from a locked phone. And the second lock screen bypass was related |
| 0:56.8 | to allowing user access to the share function on a locked device. This was fixed via updating |
| 1:04.0 | quick look. And Intel announced its ninth generation CPUs. with that but only as a footnote on a slide, |
| 1:15.6 | they also announced that this next generation of CPU will include mitigation against various versions of Spectre and Meltdown. |
| 1:26.6 | This footnote lists five different vulnerabilities, two of which are mitigated in hardware. |
| 1:33.3 | That's Meltdown version 3, the Roke Data Cash Load, as well as the L1 terminal fault, which was one of the more recent discoveries. |
| 1:43.3 | Other vulnerabilities are mitigated with a mix of microcode and software. |
| 1:49.5 | This matches up with what Intel promised back in March. |
| 1:53.1 | What we of course don't know is if some of these fixes will mitigate some of the performance issues |
| 2:00.0 | that people have reported from prior |
| 2:03.1 | patches. And Microsoft late last week had to withdraw its October 2018 update for Windows 10. Now, this |
| 2:13.4 | was a functional update, not a security update, also known as version 1809. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.