Light

Episode #899 Quiz

Freebie Bots & Evil Cameras
Date: 2022-11-29 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

The episode covered takedown of the iSpoof caller-ID spoofing service, abused for more than one million spoofed calls monthly; “freebie bots” exploiting retail mispricing at scale; and a cryptocurrency phishing chain using chat, TeamViewer, and device-authorization bypasses. It also noted Boa’s obsolete, non-TLS IoT web server and malicious Docker Hub images.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what specific chain of actions did the cryptocurrency phishing group use when the victim's initial login attempts were blocked by an "authorized device" check?
Question 2: What was the key operational detail behind the so-called Freebie Bots described in the episode?
Question 3: What did the episode say was the core problem with the Boa web server in the IoT/ICS context?
Question 4: Why did Steve say the Carnival Cruises Passkey implementation did not provide the normal phishing resistance promised by Passkeys?
Question 5: What was the practical interaction Steve described for using his EV code-signing hardware module?
Cancel