Light

Episode #807 Quiz

Dependency Confusion: The Build Chain Hack
Date: 2021-02-23 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Trend Micro exposed SHAREit Android flaws after ignored disclosure, leaving billion-plus users vulnerable to permission abuse until a patch. Researchers then showed favicon cache tracking using 32 subdomain redirects, bypassing cache clears and incognito modes. Brave fixed .onion DNS leaks; Microsoft emphasized secrets-free code, Zero Trust, and credential protection.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In the favicon-tracking attack described in the episode, what mechanism did the researchers use to encode and later reconstruct a browser identifier?
Question 2: What browser behavior made the favicon-based tracking especially persistent and privacy-breaking, according to the episode?
Question 3: Why was Firefox, at the time of the researchers' submission, not actually vulnerable to the favicon tracking attack despite having favicon cache code?
Question 4: In Brave's .onion privacy bug, what internal feature caused DNS queries for onion domains to leak onto the public Internet?
Question 5: What was the key flaw in Python dependency resolution that Alex Birsan highlighted as enabling dependency confusion?
Cancel