Light

Episode #939 Quiz

LastMess
Date: 2023-09-12 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

The episode covers the UK’s Online Safety Bill retreat from mandatory encrypted-message scanning, Microsoft’s Storm-0558 investigation showing a consumer signing key leaked via crash-dump race condition, insecure transfer, and missed validation, Mozilla’s finding that all 25 car brands over-collect, share, and sell driver data, and evidence LastPass vaults are being cracked and exploited.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to Microsoft’s postmortem on the Storm-0558 incident, what sequence most likely let the attacker obtain the signing key used to forge login tokens?
Question 2: What did Microsoft say about why a consumer signing key could be used to access enterprise email in the Storm-0558 case?
Question 3: What was the key privacy finding in Mozilla’s car research that made Steve say he was glad his car is 19 years old?
Question 4: What detail did Steve give about browser extensions and sensitive browsing that reflects the practical mitigation discussed in listener feedback?
Question 5: According to the episode, what was the core reason Steve thought many LastPass users might still be safe even after the vault theft?
Cancel