Light

Episode #870 Quiz

THAT "PASSKEYS" THING
Date: 2022-05-10 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Android patched actively exploited Linux kernel double-free CVE-2021-22600, enabling privilege escalation from malicious apps. Connecticut’s privacy law now mandates honoring Global Privacy Control without prompts. F5 fixed unauthenticated BIG-IP RCE. Nozomi found predictable DNS transaction IDs in uClibc/uClibc-ng IoT devices. FIDO “passkeys” sync per-site keys across devices, trading hardware-key security for usability.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What specific mechanism did the FIDO Alliance describe for letting a phone act as a roaming authenticator in the new WebAuthn work discussed in the episode?
Question 2: In the episode's discussion of FIDO Level 3 and so-called passkeys, what problem is cloud synchronization meant to solve?
Question 3: What did Steve identify as the key weakness in the newly discovered uClibc/uClibc-ng DNS flaw affecting many embedded IoT devices?
Question 4: Which exact capability did F5's critical BIG-IP vulnerability expose according to the episode's summary of F5's disclosure?
Question 5: According to the episode, what was the central architectural compromise in the new passkeys approach compared with the original FIDO direction Steve had worked on?
Cancel