ISC StormCast for Tuesday, September 15th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 September 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, September 15th, 2020 edition of the Sandinand Storm Center's Stormcast. |
| 0:08.8 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:15.0 | Today I wrote a quick diary about the dot well-known directorates, something we have mentioned in diaries in the past, but |
| 0:23.1 | figured it's time to really take a look at all the different features that are available |
| 0:29.5 | in this directory and of course what files you may find in it. |
| 0:34.0 | I highlighted six different ones that I found interesting, also from a security point of view, |
| 0:41.5 | and also some that are actually being used. |
| 0:45.6 | Like many features, of course, there are probably a couple dozen different files that are |
| 0:51.1 | defined for dot well-known, but many of them you won't really see used much. |
| 0:57.5 | Now, the one that's the most commonly used is the Agmi challenges. |
| 1:02.5 | That's, of course, for the ACMI protocol to retrieve TLS certificates from certificate authorities, |
| 1:10.0 | like Let's Encrypt. |
| 1:12.9 | One that's a bit new but Safari started to implement this is the change password file. |
| 1:22.2 | This actually just redirects to a web page on your site that will allow the user to change their password. |
| 1:30.8 | And the idea is to make it for password managers if a user would like to change a password |
| 1:37.1 | in the password manager to then automatically send the user to the right page to change their |
| 1:44.0 | password. |
| 1:44.9 | Pretty simple standard, actually. |
| 1:47.7 | Not a half a certain sure how useful it is. |
| 1:49.7 | The Safari implementation I find a little bit clumsy. |
| 1:54.4 | But, well, take a look. |
| 1:56.1 | I think it's something it's easy to implement, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

