Light

Episode #906 Quiz

The Rule of Two
Date: 2023-01-17 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

LastPass’s client-side PBKDF2-derived vault key remains protected only by local iteration counts; server-side 100,000-round PBKDF2 plus Scrypt secures the login hash, not the vault. Norton LifeLock likely lacked brute-force defenses against credential stuffing. Google’s Rule of Two limits untrusted inputs, unsafe languages, and high-privilege code, driving Rust adoption.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what did LastPass's server-side PBKDF2 and scrypt processing actually protect?
Question 2: Why did Steve conclude that changing the LastPass iteration count did not mitigate the weakness he had worried about?
Question 3: What was the practical effect of changing a vault's iteration count on older ECB-mode items, based on the listener feedback Steve discussed?
Question 4: What was the specific vulnerable driver used in the CrowdStrike-documented BYOVD attempt against the Scattered Spider / Roasted 0ktapus / UNC3944 adversary?
Question 5: In Google's Rule of Two, which combination is explicitly the one to avoid?
Cancel