Light

Episode #831 Quiz

Apple's CSAM Mistake
Date: 2021-08-10 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Bishop Fox found many IoT devices mishandle hardware RNG APIs by ignoring failure codes when entropy is exhausted, yielding zeroes or uninitialized memory and breaking TLS keys. Separate flaws affected Pulse Secure and Cisco VPN appliances. Forescout/JFrog exposed 14 NicheStack bugs enabling RCE, DoS, spoofing, and cache poisoning.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In the episode’s description of the IoT RNG flaw, what specific failure mode did the researchers identify in many SDKs and IoT OSes when calling the hardware RNG API?
Question 2: What did the episode identify as the primary exploitable reason the Pulse Secure Connect Secure flaw could fail open into remote code execution?
Question 3: For the Cisco VPN router vulnerabilities discussed in the episode, what was the default state of the remote management WAN interface?
Question 4: In the NicheStack / INFRA:HALT discussion, what did the episode say about the DNS packet parsing flaw involving compression pointers?
Question 5: Which statement best captures the distinction Steve drew between Apple’s two newly announced systems in this episode?
Cancel