Most cryptographic findings on your vulnerability report will never be exploited by a real attacker. So why do they keep showing up — and why should you still fix them?
In this episode of the Cyber Threat Perspective, Brad Causey and Jordan Natter break down OWASP Top 10 A04: Cryptographic Failures — the entry they openly call their least favorite on the list. They explain why SWEET32, BEAST, and the other scary-sounding named TLS vulnerabilities almost never translate into real-world compromise, why platforms like Security Scorecard and BitSight inflate their severity anyway, and where genuine cryptographic risk actually lives.
Jordan also walks through a real penetration test finding: a JSON Web Token signed with HS256, an exposed configuration backup sitting on the web server, and the signing secret that turned a standard user into an administrator.
In this episode:
- Why A04 dropped on the OWASP Top 10 without becoming less important - The difference between exploitable risk, hygiene risk, and brand reputational risk - An honest take on Security Scorecard and BitSight scores — what they measure, what they miss, and why a perfect score can coexist with a weak password policy and no MFA - The two halves of A04: data in transit (TLS/HTTPS, integrity, tampering) and data at rest (secure storage of credentials, PII, and payment data) - What a JWT actually is, and why pen testers love pulling them apart - Real pen test story: exposed config backup → leaked JWT secret → signature tampering → privilege escalation to admin - Broken server-side signature validation and other improperly implemented cryptography - Why MD5 and SHA-1 still show up for password storage 20 years too late — and what to use instead (Argon2, scrypt, bcrypt) - HSTS, secure renegotiation, and certificate expiration as A04 subcategories - The coffee shop scenario: the full chain of conditions required to exploit SWEET32 — including roughly 250 GB of captured traffic — and why no one has ever documented it happening in the wild - Why a decade-plus-old vulnerability in your environment says more about your vulnerability management program than about your crypto - Quantum computing: how today's theoretical attacks may not stay theoretical
The takeaway: classify your data, choose modern algorithms, retire deprecated protocols, and keep a functioning vulnerability management program. Not because a threat actor is sitting in your local coffee shop waiting to derive your session key — but because leaving decade-old findings in place is a signal about everything else you might be missing.
Next up: OWASP A05, which Brad promises is way cooler than A04.
Podden och tillhörande omslagsbild på den här sidan tillhör
SecurIT360. Innehållet i podden är skapat av SecurIT360 och inte av,
eller tillsammans med, Poddtoppen.