Cookie Crumbles: Unveiling Web Session Integrity Vulnerabilities with Pedro Adão and Marco Squarcina

Channel:
Subscribers:
4,540
Published on ● Video Link: https://www.youtube.com/watch?v=C9qdXAYCfrY



Duration: 30:45
59 views
1


Guests:

Pedro Adão, Associate Professor, Instituto Superior Técnico, Universidade de Lisboa [@istecnico

On Linkedin | https://www.linkedin.com/in/pedro-ad%C3%A3o-b5b792/?

Marco Squarcina, Senior Scientist, TU Wien [@tu_wien]

On Linkedin | https://www.linkedin.com/in/squarcina/?originalSubdomain=at

Website | https://minimalblue.com/
____________________________

Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]

On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin

Marco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society Podcast and Audio Signals Podcast

On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli

____________________________

This Episode’s Sponsors

Island.io | https://itspm.ag/island-io-6b5ffd

____________________________

Episode Notes

In this Chats on the Road to Black Hat USA, hosts Sean and Marco are joined by guests Pedro and Marco to explore the vulnerabilities and challenges of web security. The conversation begins with an explanation of the Double Submit and Synchronized Token patterns used to protect against CSRF (cross site request forgery) attacks. They discuss the limitations of these patterns, particularly when it comes to the integrity of cookies.

The guests highlight the potential for attackers to modify cookies and the need for better solutions. The conversation then unpacks the complexities of web security, including the difficulties of maintaining backward compatibility and the challenges of multiple components and parties involved in web development, delivery, and operations. They address the importance of revising the security of subdomains and implementing security mechanisms like HSTS (HTTP strict transport security) with the inclusive domain directive.

The conversation also raises philosophical questions about the responsibility of companies and the development community in addressing web security, as well as the role of legislation in this space. The group emphasizes the need for better platforms and frameworks that prioritize security from the start.

The conversation concludes with a discussion on the importance of ongoing research, reporting vulnerabilities to developers, and finding solutions to improve the overall security of web applications. Listeners can expect to gain a deeper understanding of web security challenges and the ongoing efforts to address vulnerabilities and improve the security of the internet ahead of Pedro's and Marco's research presentation at Black Hat USA 2023.

Stay tuned for all of our Black Hat USA 2023 coverage: https://www.itspmagazine.com/bhusa

____

Resources

Cookie Crumbles: Unveiling Web Session Integrity Vulnerabilities: https://blackhat.com/us-23/briefings/schedule/#cookie-crumbles-unveiling-web-session-integrity-vulnerabilities-32551

For more Black Hat USA 2023 Event information, coverage, and podcast and video episodes, visit: https://www.itspmagazine.com/black-hat-usa-2023-cybersecurity-event-coverage-in-las-vegas

Are you interested in telling your story in connection with our Black Hat coverage? Book a briefing here:
👉 https://itspm.ag/bhusa23tsp

Want to connect you brand to our Black Hat coverage and also tell your company story? Explore the sponsorship bundle here:
👉 https://itspm.ag/bhusa23bndl

To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:https://www.itspmagazine.com/redefining-cybersecurity-podcast

Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships




Other Videos By ITSPmagazine


2023-08-10Follow the Money | From Bugs to Bad Intentions: Evolving Perspectives on Product Security
2023-08-08From Sci-Fi to Reality: are we prepared for AI's Impact on Movies and TV? Probably not.
2023-08-08Knowing When to Pivot | A Conversation With Ian Hamilton | Tech Done Different Podcast
2023-08-07Budgets and Breakthroughs: Navigating Proactive Security and Other Cybersecurity Trends
2023-08-07Becoming a Dark Knight: Adversary Emulation Demonstration for ATT&CK Evaluations
2023-08-06Superalignment - Turtles all the way Down | Cyber Cognition Podcast with Hutch
2023-08-04CEO Direct Engagement Matters in Leadership | A Conversation with Gene Fay | The Leadership Student
2023-08-03Exploitation of Humans by AI Assistants | A Conversation with Matthew Canham and Ben Sawyer
2023-08-03Your two favorite cyber chicks are BACK! | 2 Cyber Chicks Podcast With Erika McDuffie And Jax Scott
2023-08-03I Was Tasked With Enrolling Millions of Developers in 2FA - Here's What Happened at GitHub
2023-08-02Cookie Crumbles: Unveiling Web Session Integrity Vulnerabilities with Pedro Adão and Marco Squarcina
2023-08-01BOOK | All Pride, No Ego: A Queer Executive’s Journey to Living and Leading Authentically
2023-08-01Aerospace Village: Build—Inspire—Promote | A Hacker Summer Camp 2023 Event Coverage Conversation
2023-08-01Houston, We Have a Problem: Analyzing the Security of Low Earth Orbit Satellites w/Johannes Willbold
2023-08-01Why be a Mentor | A Conversation With David Tyler | Tech Done Different Podcast
2023-08-01Unleashing End-User Productivity Through Secure Browsing: What is the Enterprise Browser?
2023-08-01How to Navigate Compliance vs. Security Conundrum with Ian Hill | Secure Your Strategy Podcast
2023-07-31Devising and Detecting Phishing: Large Language Models vs. Smaller Human Models with Fredrik Heiding
2023-07-27Embracing Diversity in Cybersecurity SquadCon Las Vegas '23 Redefines Inclusion in Infosec Industry
2023-07-26The Art of Building Security Products: Balancing Innovation and User-Friendly Design
2023-07-25Thinking Like a Bad Guy | A Conversation With Ethan Dietrich | Tech Done Different Podcast



Tags:
web security
vulnerabilities
CSRF
Synchronized Token
cookies
double submit pattern
subdomain takeover
integrity
backward compatibility
HSTS
inclusive domain directive
legislation
development community
solutions
technology
research
reporting
challenges
developers
companies
responsibility
Marco
Sean
Pedro
web development