Light

Episode #887 Quiz

Embedding AWS Credentials
Date: 2022-09-06 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Symantec found 1,859 iOS and Android apps leaking hard-coded AWS credentials; 77% enabled private AWS services, 47% exposed S3 files, and 53% reused tokens across apps via shared SDKs and libraries. Hard-coded keys granted access to images, backups, biometrics, source code, and even root accounts.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what condition on Google’s OSS VRP submissions was required when a bug was found in a third-party dependency rather than Google’s own code?
Question 2: In the TikTok breach discussion, which detail was central to why Troy Hunt remained unconvinced by the initial claims?
Question 3: What exactly did the Chromium team say about clipboard behavior when discussing the issue highlighted by webplatform.news?
Question 4: What was the key technical reason Symantec found for the AWS credentials appearing across many unrelated mobile apps?
Question 5: For the PyPI pip behavior described in the episode, under what package condition did the unexpected code execution occur when a package was downloaded?
Cancel