meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, October 25th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 25 October 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Google Samsung False Positive; OAuth Hijacking

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, October 25, 2020,

0:04.3

edition of the Sansonet Stormontas Stormcast.

0:08.3

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.2

Let's start today with a false positive.

0:17.6

Apparently, Android has been alerting users that Samsung messages as well as Samsung

0:24.8

wallet are harmful and they have been removed from some

0:30.0

devices by Google Protect. There have been a number of post-Google

0:34.2

forums. I'll link to an article by 925 Google who also wrote about it

0:40.1

and has links to help in case your device is affected and these applications were removed

0:47.4

the main problem here is likely Samsung wallet Samsung in the meantime has posted that this was apparently caused by a server failure on

0:59.6

Google's end should be fixed by now and you should no longer see these messages.

1:07.9

And Salt Labs published the third installment of its blog series about problems with Oath implementations.

1:16.2

Now, what they're specifically looking at in this particular blog post is websites that are supporting things like login with Facebook.

1:26.8

In order for this to work, the user is connecting to Facebook,

1:30.5

is getting a token, basically proving that this is the particular user, and then passing that

1:37.9

token to a particular application that supports login with Facebook. The problem here is that, well, what if a malicious user is setting up an application, is having

1:52.4

users log into that application?

1:55.2

Can the attacker then use the tokens that user submitted to the attacker's application and use them to log

2:03.9

into other websites that are supporting login with Facebook.

2:09.2

It's not just login with Facebook.

2:10.9

This is the other of all the login with another site if OAuth is being used here.

2:15.4

And the answer is, well, a yes for some sites like, for example,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.