Light

Episode #862 Quiz

QWACs On? or QWACs Off?
Date: 2022-03-15 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Patch Tuesday fixed 71 Windows flaws, including remote code execution, privilege escalation, and Edge issues; Android and Firefox also received emergency patches for active zero-days. Binarly found 23 InsydeH2O UEFI flaws, risking Secure Boot bypass, persistence, and backdoors. Linux and QWAC certificate proposals likewise threaten trust, integrity, and browser security.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In the Firefox zero-day discussion, what condition could a remote attacker exploit to trigger arbitrary code execution in the XSLT flaw?
Question 2: Which statement best captures the security impact of the InsydeH2O UEFI flaws Binarly found?
Question 3: What unusual detail made NVIDIA's leaked driver-signing certificates immediately useful for signing malware components?
Question 4: What was the first of the two main technical models described for the EU's proposed QWAC system?
Question 5: According to the episode, why did the Linux 'Dirty Pipe' flaw become especially actionable for privilege escalation?
Cancel