Light

Episode #1009 Quiz

Attacking TOTP
Date: 2025-01-21 | Length: 2.75 hrs

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1

According to the Security Now! #1009 episode, what is the minimum secret key length recommended by the HOTP RFC for TOTP authenticators, and what implication does using a shorter 80-bit key have?

Question 2

In the episode, what is the primary reason that an attacker cannot feasibly recover the full TOTP secret key from a single observed 6-digit code?

Question 3

What does the episode say about the brute force attack complexity when using multiple TOTP code samples at known times to recover the secret key?

Question 4

What mitigation does the episode recommend for organizations still using on-premise Active Directory (AD) regarding the hashing and salting of user password hashes?

Question 5

Regarding DJI's firmware update discussed in the episode, what change did DJI implement for the geofencing system in the United States?

Cancel