Light

Episode #876 Quiz

Microsoft's Patchy Patches
Date: 2022-06-21 | Length: 2 hrs | Episode page at twit.tv

About this episode

The episode explains why double encryption resists divide-and-conquer brute force: a correct inner key yields no recognizable plaintext because strong ciphers produce entropy-like output. It also notes FIDO2 passkeys need cross-device synchronization, warns of lock-in, describes Firefox’s cookie isolation, DDoS growth, NTLM relay abuse, and deserialization RCEs in Windows, WordPress, and Java.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: Why did Steve say the double-encryption thought experiment does not reduce to a divide-and-conquer attack like the WPS PIN flaw did?
Question 2: What specific limitation of FIDO's current passkey proposal did Steve identify as the main usability problem for cross-vendor users?
Question 3: According to the Bitwarden forum answer Steve cited, what FIDO2/WebAuthn capability did Bitwarden already support at the time?
Question 4: What did Steve say was necessary to make Firefox's Total Cookie Protection test actually show third-party-cookie blocking on his system?
Question 5: What sequence did Orca Security describe in the Azure Synapse vulnerability remediation that showed Microsoft needed multiple patches?
Cancel