Light

Episode #968 Quiz

A Cautionary Tale
Date: 2024-04-02 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

XZ Utils 5.6.0/5.6.1 hid a multi-year supply-chain backdoor that abused systemd-linked liblzma to alter sshd pre-authentication behavior, enabling remote RSA-keyed code execution with root privileges across Linux. Discovery came from anomalous SSH CPU use. Separately, Linux kernels 5.14–6.6.14 needed patching for a local privilege escalation bug.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what was the key technical reason AT&T's leaked four-digit account passcodes could be inferred from the dataset?
Question 2: What was the specific architectural path by which XZ Utils could influence SSH on affected Linux systems, as described in the episode?
Question 3: What did the episode say happened when the malicious XZ backdoor package versions were pushed into Linux distributions?
Question 4: What did Ghostery's report find about ad blocker usage among the professional groups it surveyed?
Question 5: What internal characterization of Chrome Incognito Mode did the lawsuit discovery reveal, according to the episode?
Cancel