Light

Episode #965 Quiz

Passkeys vs 2FA
Date: 2024-03-12 | Length: 2.25 hrs | Episode page at twit.tv

About this episode

CERT declined a live-site report despite proof-of-concept RCE against outdated nginx, while VMware patched critical USB virtualization use-after-free flaws enabling guest-to-hypervisor escape. Microsoft’s Friday disclosure coincided with Midnight Blizzard source-code theft and password spraying. Passkeys use asymmetric challenge-response, keep private keys local, and should replace weaker password-plus-MFA fallbacks.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: Why did CERT’s Vulnerability Analysis Team decline to handle the listener’s report about the major enterprise website?
Question 2: What mitigation did VMware recommend if immediate patching of the USB controller flaws could not be done?
Question 3: According to the episode, what data did the Signal version 7 username feature allow users to hide from people who did not already have it saved?
Question 4: What did Meta say third-party messaging providers must use, or at least match, to interoperate with WhatsApp and Messenger under the DMA?
Question 5: What was the core security distinction Steve emphasized between Passkeys and traditional password-plus-MFA logins?
Cancel