ISC StormCast for Wednesday, December 4th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 4 December 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, December 4, 2019 edition of the San Antonio Storm Center's Stormcast. |
| 0:07.8 | My name is Johannes Ulrich. |
| 0:09.4 | And today, I'm recording from San Francisco, California. |
| 0:13.3 | If you're installing anti-malver on your systems, there are a couple of techniques that anti-malrower often uses in order to |
| 0:23.7 | verify whether or not a website that you're browsing to is malicious. Now, some antivirus |
| 0:30.8 | solutions implement little proxies. In the past, we had vulnerabilities in some of these |
| 0:36.9 | proxies because they didn't properly filter |
| 0:39.0 | which requests they accepted. The second method is of course a browser plugin. And that's the |
| 0:46.6 | route that Avast went with its online security and also its Avast secure browser, which is really |
| 0:52.3 | just Firefox with these extensions pre-installed. Now the problem with Avast Secure Browser, which is really just Firefox with these extensions pre-installed. |
| 0:56.5 | Now, the problem with Avast was that whenever you visit a website, the entire URL is reported back to |
| 1:05.0 | AVAS. Now, you may say, hey, they actually need to know the URL in order to figure out if it is |
| 1:10.4 | malicious. |
| 1:11.6 | Well, other tools like most notably Google Secure Prowsing don't report the actual URL back. |
| 1:18.6 | Instead, they do report a hash of the URL, making it more difficult, maybe even impossible, to fully reconstruct users' sessions. Also, if a URL |
| 1:32.6 | is already known as malicious, and that can be checked locally based on periodically updated blacklists, |
| 1:39.4 | then of course there is no need to report the URL back to the mothership, so to speak. |
| 1:46.7 | Because this particular behavior of Avast was considered to be too intrusive, |
| 1:52.5 | Mozilla now has blocked this Firefox add-on from its extension list. |
| 2:05.6 | So you cancel install it, but it's no longer listed in the Firefox add-on directory. The plugin is also available for Chrome and other |
| 2:12.9 | browsers directly from the avast.com website. |
| 2:22.9 | And Google released its December update for Android, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

