meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, February 5th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 5 February 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Google Chrome 80; Whats App File Read Vuln; HiSilicon DVR

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, February 5th, 2020 edition of the Sandinand Storm Center's Stormcast.

0:08.4

My name is Johannes Ulrich.

0:09.9

And today I'm recording from Jacksonville, Florida.

0:14.3

So today was the day and Google did release Google Chrome 80 with this Google fixed a good number of security vulnerabilities

0:24.9

and as sort of announced before the release, the same site cookie feature will actually

0:32.5

be delayed and not turned on until two weeks from today.

0:43.7

And at this point, it will only be turned on for a small fraction of Google Chrome users.

0:49.3

So Google is playing a little bit with a stage rollout for this feature.

0:56.0

Another sort of change in security feature that's coming with Google Chrome. Ity is that if you have mixed content on HTTP website, so the website itself is

1:02.0

HTTP but it's loading, for example, audio files, video files via HTTP, Google Chrome will

1:09.3

try to automatically upgrade that content to HDPS. Also remember that with the last

1:16.0

Microsoft update mid-January, we did get Microsoft Edge based on Google Chrome. So all of these changes

1:24.6

will also apply if you're running the most recent version of Edge.

1:29.5

In general, upgrades are pretty straightforward and automatic with Google Chrome.

1:35.8

So really not much you have to do at this point.

1:39.5

Now, talking about Google Chrome, there is a pretty popular platform that I've mentioned a couple times when

1:46.4

it came to a security vulnerability called Electron. Electron is a platform based on, in part,

1:53.6

chromium, the open source part of Chrome, and it allows developers to create desktop applications

2:00.7

that at their core use essentially

2:04.6

HTML and JavaScript.

2:07.0

So this makes it easy to turn a web application into a desktop application.

2:13.2

Slack is probably the biggest example of an application written using Electron, but there are a number

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.