Light

Episode #823 Quiz

TLS Confusion Attacks
Date: 2021-06-15 | Length: 2 hrs | Episode page at twit.tv

About this episode

ALPACA describes TLS application-layer confusion: because TLS authenticates only the TCP session, not the intended service, attackers can MITM-redirect HTTPS to SMTP, IMAP, POP3, or FTP endpoints sharing certificates. Research found 1.4 million vulnerable web servers, enabling cookie theft or JavaScript injection. ALPN is the main mitigation.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In Kaspersky's reconstruction of the Chrome attack chain, which timeline detail most strongly suggested that the attackers were using the second Chromium bug rather than the Pwn2Own bug in the April 14–15 intrusions?
Question 2: What was the main reason Steve gave for why the 1.4 million TLS-confusable web servers remained a practical cross-protocol attack surface despite ALPN being the recommended fix?
Question 3: Which browsers did the researchers say were vulnerable to all of the presented cross-protocol attacks because of content sniffing?
Question 4: What exact combination of outcomes convinced Steve that the Lenovo laptop's NVMe drive itself was healthy, despite the WHEA error and failed laptop boot?
Question 5: According to the episode, what was the key architectural feature of ANOM that let law enforcement monitor all messages without needing remote access to the devices?
Cancel