Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Shame Boy
Mar 2, 2010

so far only one user asked me why we were loading stuff from anal.whatever and i'm just like "it's for analysis, what did you think it was for"

now that i've said this i bet someone's going to update the adblock lists with ^https?://anal\..* and that would be real funny so i'm fine with that

Adbot
ADBOT LOVES YOU

haveblue
Aug 15, 2005



Toilet Rascal
https://www.nydailynews.com/news/national/truck-plows-analtech-odor-leads-hazmat-situation-article-1.3189762

Shaggar
Apr 26, 2006

Jabor posted:

Essentially yeah, signed javascript doesn't give you any discriminatory power that you don't already have based on origin.

this is the part that's not true. signing is totally independent of host origin. while you definitely can have something signed by "somethingawful llc" on somethingawful.com, you could also have something signed by "Not russian miners llc" on somethingawful.com. signing gives you the ability to whitelist somethingawful llc so code from not Russian miners llc wont run even though the origins are the same.

its really not different from downloaded native software. That javascript is commonly edited in production and that signing would make that more difficult is not a really good argument against signing.

Shaggar
Apr 26, 2006

Main Paineframe posted:

because, ultimately, the only reason most malicious code shows up on people's websites is because the website owner intentionally chose to run that code on their site

either they put it there themselves, or they willingly added the ability for a third-party to inject literally any code they want into their website

trust-based or identity-based measures are largely useless, because basically every website owner on the planet is willingly sticking backdoors into their code for money. code signing doesn't stop regular software devs from cramming malware downloaders into their software either

this is a pretty stupid take

MononcQc
May 29, 2007

You can train your users to proper javascript hygiene by including this script on your website:

<script src="https://ferd.ca/static/js/adblock-only.js"></script>

Shaggar
Apr 26, 2006
lol

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shaggar posted:

this is a pretty stupid take

the expert has spoken

Pile Of Garbage
May 28, 2007



accepting cookies is the first step of the site usage training program

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shaggar posted:

activex was sandboxed too

lol sandboxing was shoehorned in years afterward and didn't work for poo poo

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/eightytank/status/1214895767099494400?s=21

haveblue
Aug 15, 2005



Toilet Rascal
would that count as giving the computer an STD

what level of cyberpunk hell future is this

The Fool
Oct 16, 2003


Main Paineframe posted:

because, ultimately, the only reason most malicious code shows up on people's websites is because the website owner intentionally chose to run that code on their site

either they put it there themselves, or they willingly added the ability for a third-party to inject literally any code they want into their website

This is objectively wrong

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

haveblue posted:

would that count as giving the computer an STD

what level of cyberpunk hell future is this

Haven't there already been a couple of talks about internet connected dildo exploits? This sounds familiar.

Shaggar
Apr 26, 2006

The Fool posted:

This is objectively wrong

he may have been making a joke, but it’s hard to tell in the context of web “development”.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Volmarias posted:

Haven't there already been a couple of talks about internet connected dildo exploits? This sounds familiar.

teledildonics have been a running industry joke for decades but yes it is possible though to what end. there was also that chinese clothes iron someone figure out was embedded with some kind of wifi board to do nefarious things for networks in range

haveblue
Aug 15, 2005



Toilet Rascal
I think there have been a few instances of it working in the other direction, people gaining unauthorized access to IOT sex toys

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

as far as I am aware those were all from your usual suspects of a 0000 pairing pin or that exploit that forces negotiation key strength down to something absurd like 8-bit

Schadenboner
Aug 15, 2011

by Shine

BangersInMyKnickers posted:

as far as I am aware those were all from your usual suspects of a 0000 pairing pin or that exploit that forces negotiation key strength down to something absurd like 8-bit

Love too encrypt via chiptunes.

dougdrums
Feb 25, 2005
CLIENT REQUESTED ELECTRONIC FUNDING RECEIPT (FUNDS NOW)

BangersInMyKnickers posted:

as far as I am aware those were all from your usual suspects of a 0000 pairing pin or that exploit that forces negotiation key strength down to something absurd like 8-bit
Brings another meaning to mitm

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

for those that missed it first time around

https://techbeacon.com/security/knob-attack-confirms-bluetooth-horribly-insecure-episode-2914

quote:

This time, we learn that the classic Bluetooth standards were badly written: Just about every implementation fails to ensure enough encryption-key entropy. So a nearby malicious actor could break into a pairing exchange and force the endpoints to downgrade the key to just one octet (all eight bits of it).

Progressive JPEG
Feb 19, 2003

infernal machines posted:

but if we didn't how would the ignore list work?

Doom Mathematic
Sep 2, 2008

Isn't there a power-only USB passthrough adapter you can get which is literally called a USB condom?

Midjack
Dec 24, 2007



Doom Mathematic posted:

Isn't there a power-only USB passthrough adapter you can get which is literally called a USB condom?

yes

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Doom Mathematic posted:

Isn't there a power-only USB passthrough adapter you can get which is literally called a USB condom?

I have several

flakeloaf
Feb 26, 2003

Still better than android clock

what do they show up as in setupapi.dev.log?

evil_bunnY
Apr 2, 2003

BangersInMyKnickers posted:

teledildonics have been a running industry joke for decades but yes it is possible though to what end. there was also that chinese clothes iron someone figure out was embedded with some kind of wifi board to do nefarious things for networks in range
porno webcam streamers i guess?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/katelibc/status/1215002777203593217?s=21

if I see any of y’all at DEFCON I have some weird stuff to share about this thing I’m working with

evil_bunnY
Apr 2, 2003

Volmarias posted:

Haven't there already been a couple of talks about internet connected dildo exploits? This sounds familiar.

https://www.youtube.com/watch?v=RnxcPeemHSc

There's a whole heap of real privacy risks, on top of the normal control issues you'd usually expect.

Shame Boy
Mar 2, 2010

as someone who has also reverse-engineered that particular brand of smart buttplug protocol, yeah it's not secure at all, though it's BTLE so like unless you take it outside you're probably fine

e: oh i didn't take apart the app at all but it was really obviously poorly written so i just assumed it was insecure garbage

Midjack
Dec 24, 2007



evil_bunnY posted:

https://www.youtube.com/watch?v=RnxcPeemHSc

There's a whole heap of real privacy risks, on top of the normal control issues you'd usually expect.

that was a good talk and I’m glad i was there for it.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Shame Boy posted:

as someone who has also reverse-engineered that particular brand of smart buttplug protocol,

Lmfao

geonetix
Mar 6, 2011


Midjack posted:

that was a good talk and I’m glad i was there for it.

it was a good one to get the day started for sure

GWBBQ
Jan 2, 2005


https://twitter.com/GlitchWitch/status/1215035152923086849?s=19

lol

haunted bong
Jun 24, 2007



If they could change the admin password, it would gently caress up the hardcoded back doors that the govt/businesses/state actors would use

GWBBQ
Jan 2, 2005


forget the big stuff, imagine how much damage someone could do by changing the timing of one or two traffic lights in any major city. Manhattan would be in gridlock and the Dow would plummet and you had better believe Rudy Giuliani would have something to say about it on Twitter. LA driversprobably wouldn't even notice. Road rage in Washington DC would elevate from orange to red as drivers ran out of cigarettes to keep them calm. Mormons in Salt Lake City or Provo could even go as far as along "what the heck?" out loud! Pure chaos!

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

someone did the work i didn't want to do

also

https://twitter.com/surebet247/status/1213491827694854146

https://www.troyhunt.com/the-difficulty-of-disclosure-surebet247-and-the-streisand-effect/

The Fool
Oct 16, 2003


I saw troys tweets about this earlier today and it was hilarious

GWBBQ
Jan 2, 2005


that's why I checked replies for the first person willing to call them out and shared it here. you and malware tech gotv me following a bunch of security people in Twitter and it made my internet experience much better.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
it's a sure bet!

Adbot
ADBOT LOVES YOU

animist
Aug 28, 2018
random question. Are there any applications for SGX besides DRM and spyware

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply