SANS Stormcast Friday, July 17th, 2026: Windows Hello for Business; NGINX Vuln; 7-zip vuln
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 755 Ratings
🗓️ 17 July 2026
⏱️ 6 minutes
🔗️ Recording | Apple Podcasts | RSS
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, July 17, 20206 edition of the Sands Inherst Storm Center's Stormcast. |
| 0:13.1 | My name is Johannes Ulrich, recorded today from Washington, D.C. |
| 0:18.3 | And this episode is brought you by the S sans.edu graduate certificate program in Purple Team |
| 0:24.7 | Operations. And thanks to listener Gephardt for pointing me to a study published by the German |
| 0:32.9 | Federal Information Security Office that did in detail dissect Windows Hello for business. |
| 0:41.9 | It's part of a larger effort of the office to better understand and document some of the |
| 0:48.5 | internals of Windows. In this particular study, they spent 169 pages looking at all the details and some of the potential security shortcomings of Windows Hello for Business. |
| 1:02.2 | They're focusing on the business part of it because, well, that's of course where people are more interested in all of these details. |
| 1:10.2 | Couple interesting findings here. |
| 1:12.2 | So first of all, the different security modes that you have available in Windows |
| 1:17.4 | Hello, the enhanced sign-in security or ESS is quite important as it turns out as |
| 1:24.6 | it ensures that some of the biometric data is actually protected by the |
| 1:30.2 | TPM and not just stored as an encrypted file on the file system. Also surprising to me is that |
| 1:39.5 | the biometric use of this feature actually does not give you additional entropy in how keys are being generated for Windows Hello compared to just a simple pin. |
| 1:54.0 | They do, however, point out that there are a number of advantages of doing biometrics over a pin. |
| 1:59.9 | One being that, well, a pin is easily lost without the user |
| 2:04.0 | knowing that it was lost. While in order to use the biometrics, the attacker would have to |
| 2:10.3 | steal the device, which is much easier to discover than a stolen pin. So that's, I think, some important lessons here. |
| 2:21.1 | They're also pointing out, I think that's not surprising to me, |
| 2:23.9 | that if you have multiple users on the device, that your risk increases. |
| 2:29.2 | And then in doing some of the reverse analysis, |
| 2:33.3 | they actually are uncovering some of the sort of not well documented features in Windows Hello and how they exactly work and how all of these different bits and pieces of this larger ecosystem are exactly fitting together. |
... |
Transcript will be available on the free plan in 17 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

