ISC StormCast for Wednesday, July 31st 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 31 July 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, July 31st, 2019 edition of the Sandinert Storm Center's Stormcast. My name is Johannes Ulrich, |
| 0:10.1 | and I'm recording from Boston, Massachusetts. Came across an interesting fish today that I quickly wrote up in a diary. |
| 0:20.0 | What was sort of interesting about this fish was |
| 0:22.2 | that it did capture two-factor credentials, but also the user's email address and password. |
| 0:30.6 | What wasn't quite clear was why all this information was collected. Often the username and |
| 0:37.4 | password for an email account is collected |
| 0:39.3 | in order to reset the password for the account being fished here. But what apparently was |
| 0:46.5 | happening here was that the target website, luno.com cryptocurrency exchange, is actually using, well, a fairly common but not |
| 0:57.7 | really very well thought out two-factor authentication scheme. And it isn't really two-factor. |
| 1:04.5 | What's happening is that when you're logging into this site, the site will send a one-time password to your email address. |
| 1:13.9 | So that's why the attacker needs your email account details in order to retrieve that second |
| 1:19.6 | password. But really, the email account is definitely nothing that you have. It's really just |
| 1:27.3 | something else. You know a second password, |
| 1:30.3 | so it doesn't really qualify as two-factor. Now, Luno allows you to set up SMS as second factor, |
| 1:38.3 | and without really talking about the drawbacks of SMS and why it shouldn't really be used for a high value website |
| 1:46.1 | like a financial website as a second factor. In this case, it's actually just an additional |
| 1:51.7 | destination for this one-time password code. So in addition to email, it will also be sent as an |
| 2:00.2 | SMS. |
| 2:01.6 | Luno is not alone here. |
| 2:03.4 | A lot of regular banks, so not just crypto coin exchanges and such, are making the exactly |
| 2:09.4 | same mistakes if they even offer sort of a second factor at all. |
| 2:16.3 | And Google today released Google Chrome 76, which fixes 43 different security vulnerabilities. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

