1. Supply Chain Security advanced

    A critical CVE is announced in a widely-used library. Walk me through the first four hours.

    2 min answer vulnerabilitysbomresponsepatching
  2. Supply Chain Security advanced

    A data-protection platform depends on hundreds of third-party libraries. What controls meaningfully reduce supply chain risk, and which are theatre?

    2 min answer druvasupply-chainsbomprovenance
  3. Supply Chain Security advanced

    A developer tools company distributes software used inside thousands of organisations. What supply chain controls matter most, and why is this threat model different from a typical SaaS?

    2 min answer supply-chainprovenancesigningbuild-integrity
  4. Supply Chain Security advanced

    An organisation wants to reduce software supply-chain risk. What actually reduces it, in what order, and which popular measures provide less than they appear to?

    3 min answer supply-chainsbomprovenancedependencies
  5. Supply Chain Security advanced

    Codecov disclosed in 2021 that its Bash Uploader script had been modified to exfiltrate continuous integration environment variables, that the modification had been live since late January and that it was found on 1 April by a customer comparing checksums. What made this compromise so productive for the attacker, and what would have limited it?

    3 min answer codecovsupply chaincisecrets
  6. Supply Chain Security advanced Multiple choice

    Your pipeline signs every container image. Is your supply chain secure?

    2 min answer supply-chainprovenanceverification
  7. Threat Modelling advanced

    Run a threat model on a new payment integration: our service calls a third-party payment provider and receives webhooks. Where are the interesting threats?

    2 min answer threat-modellingstridewebhookspayments
  8. Tokens & JWTs advanced

    A platform uses signed tokens for service-to-service and client authentication. Which properties must be verified on every use, and what goes wrong when they are not?

    2 min answer jwttokensvalidationrevocation
  9. Tokens & JWTs advanced

    A team is designing token-based authentication for a distributed system. What are the significant design decisions, and which common JWT choices cause problems later?

    2 min answer jwttokensrevocationsessions
  10. Tokens & JWTs advanced

    After a routine signing key rotation, roughly 3% of API requests start failing with 401s. The rate decays over about ten minutes and returns on the next rotation. Tokens look valid and clocks are synchronised. What is happening?

    3 min answer jwtjwkskey rotationcaching
  11. Tokens & JWTs advanced

    An identity provider issues tokens that applications validate locally without a network call. What does that buy, and what is the necessary consequence for revocation?

    2 min answer clerkauth0jwtrevocation
  12. Tokens & JWTs advanced

    Your JWT-based auth means a fired employee keeps access for 15 minutes after their account is disabled. Security says that is unacceptable. What are the options?

    2 min answer jwtrevocationtokenstradeoffs