Light

Episode #893 Quiz

Password Change Automation
Date: 2022-10-18 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Microsoft left Office 365 Message Encryption using ECB, leaking repeated plaintext patterns so archived emails can be analyzed offline without keys or BYOK. Separately, Windows driver blocklists for HVCI and ASR failed to update for years, enabling BYOVD attacks. A new .well-known change-password URL standard may streamline password page discovery and automation.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what specific weakness made Microsoft Office 365 Message Encryption vulnerable to offline analysis?
Question 2: What did WithSecure say about the practicality of exploiting the Office 365 Message Encryption issue?
Question 3: What did Microsoft do after being told about the Office 365 Message Encryption flaw in January 2022?
Question 4: What was the core failure in Microsoft's driver-blocklist protection against BYOVD attacks?
Question 5: What local-account hardening did Microsoft add in the October 11, 2022 updates for new machines?
Cancel