Light

Episode #808 Quiz

CNAME Collusion
Date: 2021-03-02 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Chrome 90 will default schemeless URLs to HTTPS first; Firefox 86 adds Total Cookie Protection to confine cookies per site. SolarWinds may have been compromised by weak credentials, while Rockwell PLCs and VMware vCenter faced critical RCE flaws. Most notably, CNAME cloaking lets trackers bypass defenses and leak authentication cookies.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In Firefox 86’s new Total Cookie Protection, what is the fundamental effect on third-party cookies according to the episode?
Question 2: What was the specific Chrome behavior change described as coming in Chrome 89 as an experiment and then Chrome 90 more broadly?
Question 3: What was the root of the Rockwell Automation PLC vulnerability discussed in the episode?
Question 4: Why did VMware vCenter become a mass-scanning target immediately after the patch for CVE-2021-21972 was released?
Question 5: How did the CNAME-based tracking technique let trackers receive cookies that were meant for the visited site?
Cancel