Light

Episode #907 Quiz

Credential Reuse
Date: 2023-01-24 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

Credential reuse attacks automate login attempts using breached username-password pairs, succeeding when users recycle credentials across sites. Bot fleets distribute attempts across IPs, time, and targets to evade throttling. Mitigations include delaying failures, tracking suspicious cookies, CAPTCHA, device fingerprinting, and strongest of all, multifactor authentication with time-based tokens or persistent cookies.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to Steve Gibson’s discussion of PayPal’s incident, what was the reported outcome after the credential stuffing attack was investigated?
Question 2: What specific obstacle did the CyberArk researchers report overcoming in order to get ChatGPT to produce functional malware code?
Question 3: In Check Point’s first case study, what did the ChatGPT-generated stealer do with files it found on the system?
Question 4: What was Bitwarden’s announced short-term plan for Passwordless.dev in relation to passkeys?
Question 5: When Steve compared the two strongest mitigations for credential reuse, what combination did he say gave the best of both worlds?
Cancel