Light

Episode #936 Quiz

When Heuristics Backfire
Date: 2023-08-22 | Length: 2 hrs | Episode page at twit.tv

About this episode

This episode covered real-world security failures: defective SanDisk/Western Digital SSD firmware corrupting data, YouTube “made for kids” tracking violating COPPA expectations, crypto wallet MPC/TSS flaws enabling theft, Chrome’s HTTPS-first upgrades and extension warnings, WinRAR RCE fixes, and Microsoft’s Secure Time Seeding heuristic, which misreads random TLS timestamp data and skews clocks.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What change did Microsoft make in 2016 that later proved able to reset Windows clocks to wildly incorrect values?
Question 2: Why did the Windows Secure Time Seeding heuristic sometimes become "highly confident" about a wrong time?
Question 3: What did Microsoft recommend to affected administrators as the practical mitigation for Secure Time Seeding problems?
Question 4: What specific OpenSSL behavior did the episode identify as the source of the misleading time data consumed by STS?
Question 5: How did Steve say STS should have been protected against the bad conclusions produced by its heuristic?
Cancel