Light

Episode #1066 Quiz

Password Leakage
Date: 2026-02-24 | Length: 2.5 hrs | Episode page at twit.tv

About this episode

Security Now! Episode 1066 addresses password leakage risks in cloud-based password managers Bitwarden, LastPass, and Dashlane, which are vulnerable to attacks if the server infrastructure is subverted. Researchers found flaws in key escrow, vault integrity, sharing features, and backward compatibility, emphasizing the difficulty securing feature-rich managers under a fully malicious server model.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What is the primary reason that the CA/Browser Forum reduced the domain validation reuse period from 397 days to 199 days as mentioned by DigiCert?
Question 2: According to the ETH Zurich research discussed, what common cryptographic mistake did LastPass have that impacted vault integrity?
Question 3: Why is it technically impractical for 3D printers to comply with legislation requiring them to block printing of firearm parts?
Question 4: What does the 'ClickFix' attack exploit to achieve over half of all malware loader activity in 2025 according to Huntress Labs?
Question 5: Regarding passwords generated directly by Large Language Models (LLMs), what is the fundamental weakness highlighted in the episode?
Cancel