Light

Episode #914 Quiz

Sony Sues Quad9
Date: 2023-03-14 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Quad9 learned that malicious Chrome extensions can exfiltrate URLs and persistent cookies, enabling session hijacking. A DFIR report showed phishing caused 69.2% of intrusions, while Microsoft’s macro blocking reduced document-based attacks. Kudelski’s “polynonce” attack exploits weak ECDSA nonces to recover private keys from Bitcoin, Ethereum, TLS, and other signatures.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In the episode's discussion of the 'Get Cookies.txt' Chrome extension, what specific data did the later version begin exfiltrating in addition to the browser-tracking details first reported in January?
Question 2: What was the episode's key statistic from the DFIR report about the dominant initial intrusion method used by attackers?
Question 3: What change in Microsoft behavior did the episode identify as having materially reduced macro-based attack volume in the DFIR data?
Question 4: According to the episode's summary of Kudelski's work, what minimum set of conditions was required to run their ECDSA key-recovery attack in practice?
Question 5: How did the episode describe the court's remedy in Sony's case against Quad9?
Cancel