meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, August 4th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 3 August 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 2FA Issues; Crazy Smishing; Google Chrome and Android Patch; NSA Kubernetes Hardening Guides

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, August 4, 2021 edition of the Sandcent,

0:05.6

Internet Storm Center's Stormcast. My name is Johannes Ulrich, and then I'm recording from

0:10.5

Stockholm, Germany. Well, first of all, on the Internet Storm Center, I wrote up a quick

0:16.7

diary about some issues I've seen with two-factor authentication. One problem I want to

0:22.6

point out here as part of podcast is where the password reset only requires the token. So

0:30.1

that really reduces it back to one token or one factor. If you're losing your token,

0:36.6

an attacker could easily use that token to reset

0:40.3

your password and with that gain full access to the account.

0:46.0

Having two factor authentication and having like in this case a physical token will make an attack

0:51.8

more difficult if the password is weak, but doesn't mean that you should

0:56.6

just give up on passwords.

1:00.2

And the rest of it really comes down to that how you're implementing two-factor authentication.

1:04.7

If you're implementing it really depends a lot on the risk that you're trying to protect

1:10.4

against.

1:15.9

Of course, something like an online banking application should be better protected than like your average e-commerce application or a blog post site.

1:21.6

At an issue, I pretty much see as unsolved as sort of good guidelines, good practices on recovering from a stolen or lost

1:32.0

second factor like a hardware token. I haven't really seen an implementation here that I really

1:37.8

liked. And second diary was today really a bit more on the lighter side and that's a real

1:43.8

sort of crazy

1:45.1

SMS that I received, the claim to come from a doctor that was going to perform some surgery

1:53.7

and asked for all kinds of details, including pictures.

1:59.2

I'm 99.99% sure that this is not a real doctor who just got the wrong number,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.