Light

Episode #802 Quiz

Where the Plaintext Is
Date: 2021-01-19 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

Google restricted Chrome sync APIs to Chrome only, removing third-party Chromium access to private account data. Project Zero analyzed a watering-hole campaign using iframe-delivered renderer exploits, sandbox escapes, and Android post-exploitation, emphasizing root-cause analysis. Microsoft patched Defender RCE, prepared Zerologon enforcement, and NSA urged enterprise-controlled DoH. Titan keys were cloned via electromagnetic ECDSA leakage.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the Project Zero analysis described in the episode, what combination of exploit chains did the attackers use against Windows users before the exploit servers were taken down?
Question 2: What did Google say it was going to do on March 15 regarding Chrome sync access from third-party Chromium-based browsers?
Question 3: In the NSA's advisory on encrypted DNS in enterprise environments, what was the recommended stance toward external DoH resolvers?
Question 4: What was the key recovery result reported by NinjaLab for the Google Titan Security Key attack?
Question 5: What was the final point Steve made with the phrase 'Where the plaintext is'?
Cancel