Light

Episode #1005 Quiz

Six-Day Certificates? Why?
Date: 2024-12-17 | Length: 2 hrs | Episode page at twit.tv

About this episode

This episode covers a critical vulnerability in Microsoft’s Azure MFA allowing brute-force bypass via parameter interception and lack of rate limiting, later remediated by strict throttling. It discusses Google's Android Bluetooth anti-tracking enhancements, North Korean IT worker cyber-espionage generating $88M, and open source supply chain threats with 540K malicious NPM packages.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What was the critical vulnerability discovered in Microsoft's Azure Multi-Factor Authentication (MFA) implementation as discussed in this episode?
Question 2: According to this episode, what is the main reason Let's Encrypt plans to reduce their TLS certificate lifetime from 90 days to six days?
Question 3: What operational risk arises from nearly 500 million websites using six-day Let's Encrypt certificates as described in the episode?
Question 4: What is the specific weakness in Microsoft's time-based MFA code expiration policy identified in the episode?
Question 5: What new anti-tracking feature did Android introduce for Bluetooth trackers as per this episode's discussion?
Cancel