Light

Episode #1079 Quiz

Daybreak and Codename MDASH
Date: 2026-05-19 | Length: 2.5 hrs | Episode page at twit.tv

About this episode

Security Now! #1079 covers Microsoft Edge’s initial insecure design of storing plaintext passwords in RAM, later fixed to reduce exposure. It details a local BitLocker bypass named YellowKey exploiting Windows Recovery environment loading to access encrypted drives without credentials, mitigated by BitLocker PIN and BIOS passwords.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What was the initial Microsoft Edge behavior regarding password storage in RAM, and how did Microsoft respond upon media exposure?
Question 2: Regarding the BitLocker bypass vulnerability (YellowKey) disclosed by Chaotic Eclipse, what is the primary mitigation recommended by security researchers?
Question 3: What distinguishes Microsoft’s multi-model agentic scanning harness (Codename MDASH) from single-model AI vulnerability scanners?
Question 4: How does Microsoft’s threat modeling for Edge relate to the password storage vulnerability discovered by Tom Rønning?
Question 5: According to the episode, what risk arises from using AI to generate production websites without security expertise?
Cancel