Light

Episode #892 Quiz

Source Port Randomization
Date: 2022-10-11 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Linux adopted RFC 6056 source-port randomization, replacing sequential ephemeral ports with double-hash selection to reduce blind spoofing and hijacking. Researchers found the new algorithm leaks a per-device collision pattern, enabling cross-browser, container, IPv4/IPv6, and VPN tracking until reboot. Linux patched the flaw in May 2022.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what did the Linux kernel’s newer TCP source-port selection algorithm unintentionally enable attackers to do?
Question 2: What practical detail about the Celsius bankruptcy filing did Steve highlight as the reason customer data became public?
Question 3: Which app category was by far the largest among the more than 400 malicious mobile apps Meta identified as stealing Facebook credentials?
Question 4: What was the specific mechanism Steve said the ZimaBoard made practical for his SpinRite development workflow?
Question 5: What did IBM’s survey of 1,100 incident responders find about mental health support and help-seeking?
Cancel