Light

Episode #894 Quiz

Data Breach Responsibility
Date: 2022-10-25 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

This episode examined security-by-design efforts using Google’s KataOS and seL4 microkernel, Rust, and formal verification to prevent whole bug classes, plus Windows Mark-of-the-Web bypasses exploiting malformed signed downloads, Apple’s out-of-bounds kernel zero-day, VMware’s critical XStream deserialization RCE, and malware shifts driven by MFA, ransomware, and initial access brokers.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What foundation did Google say it chose for KataOS because it is mathematically proven secure with guaranteed confidentiality, integrity, and availability?
Question 2: Which feature of Firefox 106 was added on macOS 10.15 and higher to let users extract text from selected images?
Question 3: What mechanism did Windows use to flag files as originating from the Internet and trigger SmartScreen and Office protection behavior?
Question 4: What did Microsoft reportedly say after Will Dormann shared the malformed-signature proof of concept for the Mark-of-the-Web bypass?
Question 5: According to Steve’s discussion of the Australian proposal, what was the new maximum penalty for serious or repeated privacy breaches set to be the greater of?
Cancel