4.9 • 696 Ratings
🗓️ 26 September 2018
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, September 26, 2018 edition of the Sandton and Storm Center's |
0:06.7 | Stormcast. My name is Johannes Ulrich, the time recording from Las Vegas, Nevada. |
0:14.3 | Mozilla apparently is attempting to distinguish itself as a more security-focused alternative |
0:20.5 | to some of the other browsers. |
0:23.4 | As part of this, Firefox has been rolling out some new security features, |
0:29.0 | either within the browser or as part of the Mozilla website. |
0:32.7 | The latest example is an integration with the Have I Been Pond web service. |
0:39.5 | Haffirbin Pond collects email addresses, passwords that are leaked at various breaches, |
0:44.8 | and offers a free API to query for your email address. |
0:51.2 | Now, Firefox, I've implemented this kind of interestingly using what |
0:55.3 | Hava BinPon called their range API. Instead of sending a hash of your email address back, |
1:02.7 | which of course could be linked to your email address by simply reversing the hash or |
1:08.6 | brute forcing it. They're just sending the first few digits of that hash to have I been powned. |
1:15.7 | And then a list of all the hashes that have been breached is returned, which then can be |
1:21.9 | compared to a hash of your email address locally. |
1:26.7 | So this way, not even have I been poned, knows that you query their database. |
1:32.3 | Mozilla also set up a service where you can actually give them your email address |
1:36.3 | and then have them periodically moderate for new preaches. |
1:41.3 | Essentially, it is just a front end for the have I been powned service. |
1:47.0 | So if you already signed up for it directly, no need to do so again via Mozilla. |
1:53.0 | Several password save tools, like for example one password, of course, have implemented similar features. Now sticking with browsers for another |
2:04.5 | story, Chrome 69 has gotten some bad press for how it preferentially treats Google |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.