Light

Episode #879 Quiz

The Rolling Pwn
Date: 2022-07-12 | Length: 2 hrs | Episode page at twit.tv

About this episode

OpenSSL 3.0.4 had a remote heap memory corruption bug on x64 systems with AVX-512-IFMA, potentially enabling RCE during RSA private-key operations; upgrade to 3.0.5. NIST selected Kyber, Dilithium, Falcon, and SPHINCS+ for post-quantum encryption and signatures. Apple added Lockdown Mode, blocking risky attachments, JIT, requests, profiles, and USB data.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In the OpenSSL 3.0.4 issue discussed in the episode, what combination of conditions had to be present for the bug to matter on a server platform?
Question 2: Why did NIST say it was selecting the first four post-quantum algorithms in two stages instead of all eight at once?
Question 3: Which post-quantum signature algorithm did NIST recommend as the primary choice, according to the episode?
Question 4: How did the ANOM app conceal the FBI's presence in users' contact lists, according to the episode?
Question 5: What mitigation did the researchers say was the common recommended solution for the Rolling-Pwn Honda issue?
Cancel