Episode #808 Quiz
CNAME Collusion
Date: 2021-03-02 | Length: 1.75 hrs | Episode page at twit.tv
About this episode
Chrome 90 will default schemeless URLs to HTTPS first; Firefox 86 adds Total Cookie Protection to confine cookies per site. SolarWinds may have been compromised by weak credentials, while Rockwell PLCs and VMware vCenter faced critical RCE flaws. Most notably, CNAME cloaking lets trackers bypass defenses and leak authentication cookies.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.