Light

Episode #873 Quiz

DuckDuckGone?
Date: 2022-05-31 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Australia’s NSW Digital Driver’s License stored encrypted JSON with AES-256-CBC, but the key was only a four-digit PIN, enabling brute-force decryption, tampering, and re-encryption from backups without signatures or server validation. Microsoft Office’s Follina abused ms-msdt protocol handling for remote code execution. Ghost Touch injected capacitive touch events via EMI.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What key weakness in the New South Wales Digital Driver's License made offline tampering feasible after an attacker obtained the stored data?
Question 2: Why did the Dvuln researchers say the DDL application's pull-to-refresh feature did not actually protect against a modified license display?
Question 3: What was the exact reason Microsoft MSRC gave for closing the April 12 Follina report on April 21?
Question 4: According to the Ghost Touch research summarized in the episode, what technique did the attackers use to generate fake touchscreen input?
Question 5: What was the specific contractual limitation DuckDuckGo said prevented its browser from fully blocking Microsoft-owned trackers on third-party sites?
Cancel