Light

Episode #813 Quiz

A Spy in Our Pocket
Date: 2021-04-06 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Ubiquiti allegedly suffered a two-month AWS compromise exposing admin credentials, SSO cookies, source code, signing keys, logs, databases, and cloud accounts, potentially enabling remote takeover of mandatory-cloud devices. Google is restricting Android package visibility. QNAP NAS flaws permit unauthenticated shell access. iOS and Android routinely transmit telemetry, IMEI, SIM, location, and nearby MACs.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what was the key architectural problem with Ubiquiti’s newer setup model for managing devices like the UniFi Dream Machine?
Question 2: What did Brian Krebs’ source say the attackers obtained from Ubiquiti’s AWS-hosted environment?
Question 3: What specific change did Troy Hunt make to Have I Been Pwned after the Facebook leak became public again?
Question 4: What action by the Kansas water district case did Steve describe as especially concerning?
Question 5: Which pair of Android package-visibility details did Google’s March 31 policy update reserve for apps with a real core need?
Cancel