4.9 • 696 Ratings
🗓️ 18 May 2022
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, May 18, 2020 edition of the Sands and Storm Center's Stormcast. My name is Johannes Ulrich. |
0:10.3 | Entertainment from Jacksonville, Florida. |
0:14.2 | Passwords, of course, always get in our way and we know they don't really work, but we still use them. |
0:21.3 | And one way to balance usability and security with passwords is password managers. |
0:28.9 | Now, if you are installing and using a third-party application as a password manager, |
0:34.9 | those applications typically go through quite a bit of pain to make sure |
0:39.9 | the passwords are properly protected. However, on the other end, we also have still building |
0:47.4 | password managers that come with your browser. And the question is really, you know, |
0:51.5 | how good, how bad are they? And that's something that Xavier ran into recently when he looked at this in Google Chrome. |
0:59.2 | The way this came up was that they had an incident and apparently some administrator passwords were compromised. |
1:06.9 | Now, of course, the question was, where did these passwords come from? |
1:11.3 | In this particular case, Xavier found the account names in Google Chrome, |
1:17.0 | and then he took a closer look at how the passwords were encrypted. |
1:20.2 | They were encrypted. |
1:21.5 | However, the key is exposed, and that's a very common problem |
1:25.7 | when you're dealing with encryption at rest where |
1:29.3 | keys are exposed of course a better password manager probably would have protected that key |
1:36.6 | with a password or maybe even some secure enclave that many operating systems are offering |
1:43.7 | these days. |
1:45.2 | Good question from one of our readers. |
1:47.7 | Why did Google Chrome not take advantage of something like keychain or such? |
1:53.1 | Well, don't have an answer for it. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.