Light

Episode #869 Quiz

Global Privacy Control
Date: 2022-05-03 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

DIB-VDP’s vetted HackerOne bug bounty found 401 actionable flaws in 348 defense-industrial assets, proving sanctioned disclosure works. OpenSSF’s Package Analysis scanned PyPI and npm, flagging 200 malicious packages via static heuristics, typosquatting, and dependency confusion. Connecticut’s privacy bill mandates Global Privacy Control, a Sec-GPC: 1 HTTP header, revocable opt-out signal.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What specific observation did the OpenSSF Package Analysis project use to identify the npm package `roku-web-core/ajax` as malicious during its first month of analysis?
Question 2: According to the episode, what is the key new enforcement feature that distinguishes Global Privacy Control from the earlier Do Not Track effort?
Question 3: Which state-privacy-law timing detail did Steve highlight as making Connecticut part of the “3Cs” with California and Colorado?
Question 4: What did the `random-voucher-code-generator` npm package do when imported, according to OpenSSF’s analysis?
Question 5: What did Moxie Marlinspike say was the fundamental reason port knocking is even necessary?
Cancel