Light

Episode #814 Quiz

PwnIt and OwnIt
Date: 2021-04-13 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Chrome and Firefox are blocking browser access to abuse-prone remote ports, including 10080, to thwart NAT Slipstreaming and unsolicited LAN traversal. Google’s FLoC uses weekly browsing history plus SimHash to assign cohort IDs, while EFF offers an opt-out test and site owners can send Permissions-Policy: interest-cohort=().

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, why did Chrome plan to add TCP port 10080 to its blocked-port list, even though the port is used by some legitimate software?
Question 2: What did the EFF's "Am I FLoCed" page determine about Chrome users during the origin trial?
Question 3: What was the legacy HTTPS back channel in the PHP incident that bypassed gitolite entirely?
Question 4: What immediate remediation did the PHP team make regarding passwords after the git.php.net incident?
Question 5: Which specific flaw and outcome did Kaspersky describe in the later ransomware attacks against unpatched FortiGate SSL VPN devices?
Cancel