4.9 • 696 Ratings
🗓️ 18 February 2025
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Tuesday, February 18th, |
0:04.1 | 2000-25 edition of the Sands and then at Storm Center's Stormcast. |
0:10.3 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:15.7 | Well, today's diary was a little bit more of an opinion piece, but with a practical background. |
0:21.4 | And that's the we are seeing so many vulnerabilities in these edge devices. |
0:26.0 | SISA and a couple of other international, also government agencies did come up with their |
0:31.4 | guidance. |
0:31.8 | I found it a little bit too abstract in some ways. |
0:34.9 | So I wanted to distill it down in particular with sort of a small, medium-sized business |
0:39.7 | background and what you can do to really make an impact here and reduce your attack |
0:46.1 | surface. |
0:46.5 | And that's really one of the big things is reduce your attack surface. |
0:49.6 | Don't expose those admin interfaces. |
0:53.0 | Expose as little as possible. Never expose a web application that you |
0:58.5 | don't have to expose. Simple SSH access, maybe a VPN, like OpenVPN or a WireGuard or |
1:08.0 | whatever your preferred VPN technology is. And even at that, you know, leave it at one VPN technology. |
1:14.2 | Don't have like two or three exposed. |
1:17.4 | That'll make life so much easier. |
1:20.0 | And then, of course, no, patching and such follows. |
1:23.1 | But that then becomes a little bit less important. |
1:27.3 | And it's one of those things where you don't have to be quite behind it |
1:32.5 | to really get stuff update as quickly as possible |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.