meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 15th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 15 January 2020

⏱️ 10 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Microsoft January 2020 Patch Tuesday and #CryptoAPI Flaw

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 15th, 2020 edition of the Santernut Storm Center's

0:07.0

Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida.

0:13.0

Well, of course, Patch Tuesday, the big topic today. And at first, it actually doesn't look all that bad if you're just looking

0:22.7

at the numbers we had a total of 49 one at least that were patched today and eight of them

0:30.5

are rated criticals none of them were publicly disclosed before today and none of them have

0:37.3

been exploited in the wild so far.

0:40.2

But of course these last couple days we had all these pre-announcements, rumors about a critical

0:47.4

vulnerability in the crypto API, and yes, this was one of the big patches that Microsoft released today.

0:56.0

So the problem here is how the crypto API in Windows does validate Liptic curve certificates.

1:05.0

So whenever a system receives a certificate, it has to check if the certificate is properly signed by a

1:14.6

trusted certificate authority. And that sort of where things go wrong here. An attacker could

1:21.5

create a certificate that appears to be validly signed by a trusted set of authority, but in fact isn't.

1:29.3

So the end effect is that that hacker can essentially create arbitrary certificates that appear valid.

1:35.3

Now arbitrary as long as they're elliptic curve certificates.

1:39.3

Leptic curve certificates are still, I would say, less common than the older RSA certificates.

1:46.3

They're a bit more modern, they're more efficient, and the world is certainly moving away

1:50.9

from RSA somewhat towards the elliptic curve certificates.

1:56.2

Probably the best way to illustrate the impact of this issue is to just go through some cases where certificates

2:04.9

matter.

2:05.9

And I put this a little bit in the diary, but just knew you're receiving an email from a vendor

2:09.9

telling you about an update.

2:12.4

Well, if the vendor did their job right, then they digitally signed this email.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.