Light

Episode #889 Quiz

Spell-Jacking
Date: 2022-09-20 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

Chrome and Edge enhanced spellcheck can exfiltrate form contents, including passwords, usernames, and sensitive PII, to Google or Microsoft whenever text is not in the local dictionary; clicking Show Password also leaks credentials. Mitigations include disabling enhanced spellcheck, adding spellcheck="false" to sensitive fields, and auditing affected sites.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what specific lockout-related lesson did Steve draw from the Uber incident involving multifactor authentication?
Question 2: What did LastPass say separated its Development environment from Production, helping prevent customer vault exposure after the breach?
Question 3: What indicator of compromise did Wordfence say was the most common sign of the WPGateway exploit?
Question 4: Which performance regression did the VMware engineer report after Linux kernel 5.19 enabled the Retbleed mitigation?
Question 5: Which mitigation did Otto-js recommend to stop the browser spellcheck leak on sensitive form pages, and what example did Steve cite as already using it?
Cancel