meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, August 28th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 28 August 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. TLS 1.2 For Email; xHelper Android Trojan; LYCEUM Threat Group

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, August 28, 2019 edition of the Sandstone Storms and Stormers Stormcast.

0:07.7

My name is Johannes Ulrich.

0:09.3

And I'm recording from Jacksonville, Florida.

0:13.6

Based on a question from a couple weeks ago from Michael Vance about whether or not it's safe to require TLS or turn off older versions of TLS for email.

0:25.6

I did a little experiment to figure out whether or not large email providers are now accepting

0:33.6

email using TLS and if they are supporting TLS 1.2. Over the last few years of course

0:41.2

there has been a lot of emphasis on TLS configurations for web servers but other

0:49.7

servers like email of course are using TLS, and they often have been sort of neglected.

0:56.2

And what I found kind of confirms that, yes, most email providers and somewhere around 90% are

1:05.8

supporting TLS, are supporting TLS, but there are a couple outliers.

1:13.2

Now, I've found only one provider that supports TLS and only supports TLS 1.0.

1:21.8

There are a few providers, however, that don't support TLS at all. And of course, that makes it difficult to enforce

1:30.0

the use of TLS. The largest ISP within the United States that doesn't support TLS is United

1:37.8

Online. That's Juno and Net Zero. There are a couple of ISPs in China. Yahoo! Japan does not support TLS.

1:47.7

And then there are a few other countries like one Brazilian, a couple Italian ISPs that do

1:55.3

not support TLS at all.

1:58.2

Now after posting this, I got some feedback from a couple other users via Twitter.

2:04.2

One stated that Denmark now requires TLS for email. And the state government in Germany just

2:12.6

announced last week that they will only use TLS 1.2 for email and reject all other TLS connections.

2:21.3

Now, based on my results, I personally think it's a little bit too early to outright require

2:27.3

TLS. You will run into some issues. I don't have a good handle as to how many email users

2:33.5

are behind these ISPs that don't support TLS.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.