Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
distortion park
Apr 25, 2011


pointsofdata posted:

Lol alternativedata.org has a list of all the different ways you can be spied on
https://alternativedata.org/data-providers/

"Real-time data on user purchases and product demand, sourced directly from Edison�s mail app."

"Detailed consumer purchasing habits from live transactional data (in-app, online and in-store). "

Etc


https://twitter.com/josephfcox/status/1226855097482661888


In yospos today, tech media ... next year.

Adbot
ADBOT LOVES YOU

chestnut santabag
Jul 3, 2006

BangersInMyKnickers posted:

lol trend micro labs just raked SEP's rear end over the coals

https://support.symantec.com/us/en/article.SYMSA1505.html

Acknowledgements
CVE-2020-5820: Z0mb1E working with Trend Micro Zero Day Initiative
CVE-2020-5821: Z0mb1E
CVE-2020-5822: Z0mb1E working with Trend Micro Zero Day Initiative
CVE-2020-5823: Z0mb1E working with Trend Micro Zero Day Initiative
CVE-2020-5824: Z0mb1E working with Trend Micro Zero Day Initiative
CVE-2020-5825: Z0mb1E working with Trend Micro Zero Day Initiative
CVE-2020-5826: Z0mb1E working with Trend Micro Zero Day Initiative
CVE-2020-5827: Z0mb1E working with Trend Micro Zero Day Initiative
CVE-2020-5828: KPC of Trend Micro Zero Day Initiative
CVE-2020-5829: KPC of Trend Micro Zero Day Initiative
CVE-2020-5830: KPC of Trend Micro Zero Day Initiative
CVE-2020-5831: KPC of Trend Micro Zero Day Initiative

Bring on the digital security arms race of them exposing one another's exploits to embarrass them.

flakeloaf
Feb 26, 2003

Still better than android clock

"rakuten harvests your identity and shopping activity" is quite the revelation

dick traceroute
Feb 24, 2010

Open the pod bay doors, Hal.
Grimey Drawer
Is that a serious post

Soricidus
Oct 21, 2010
freedom-hating statist shill

chestnut santabag posted:

Bring on the digital security arms race of them exposing one another's exploits to embarrass them.
this can only end well

whoever loses, we win

Winkle-Daddy
Mar 10, 2007

chestnut santabag posted:

Bring on the digital security arms race of them exposing one another's exploits to embarrass them.

u should follow tavis on twittere, friend

brugroffil
Nov 30, 2015


lol? https://twitter.com/gregpmiller/status/1227208399387054080

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Shaggar posted:

i would not be surprised in the least if the reps facebook hired to manage their twitter account are outsourced

at least when I was there it was all in-house, but we weren’t using a 3rd-party management service at that point afaik. I just sent copy to someone via messenger for approval and posting, or they got included in an email chain and verified with me over messenger

I’d be pretty surprised if they’ve contracted that out even now

Phone
Jul 30, 2005

親子丼をほしい。

backdoors? in my crypto???

Shame Boy
Mar 2, 2010

quote:

It describes how the United States and its allies exploited other nations’ gullibility for years, taking their money and stealing their secrets.

i like the implication that it stopped at some point

MononcQc
May 29, 2007

Seems like a bunch of employees were looking to fix weaknesses in the algorithm and kept being told no.

Curious to see how that match with ECC and the countless assertions that people just keep publishing broken curves and we just don't know.

Shame Boy
Mar 2, 2010

MononcQc posted:

Seems like a bunch of employees were looking to fix weaknesses in the algorithm and kept being told no.

Curious to see how that match with ECC and the countless assertions that people just keep publishing broken curves and we just don't know.

i mean there was that one algorithm bruce pointed out as obviously having a backdoor that got approved anyway due to NSA shenanigans making them the only party on the approval board

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

MononcQc posted:

Seems like a bunch of employees were looking to fix weaknesses in the algorithm and kept being told no.

Curious to see how that match with ECC and the countless assertions that people just keep publishing broken curves and we just don't know.

I'm not aware of similar complaints against x25519 at this point. The NIST curves can go in the garbage at this point.

Agile Vector
May 21, 2007

scrum bored



Phone posted:

backdoors? in my crypto???

its doors all the way down

Media Bloodbath
Mar 1, 2018

PIVOT TO ETERNAL SUFFERING
:hb:
I love how basically everything that's been talked about in the various tinfoil BBSes and newsgroups turned out to be true.

haveblue
Aug 15, 2005



Toilet Rascal
pretty soon we're going to discover that "reflections on trusting trust" actually happened and every compiler binary in the world is compromised

Wiggly Wayne DDS
Sep 11, 2010



Media Bloodbath posted:

I love how basically everything that's been talked about in the various tinfoil BBSes and newsgroups turned out to be true.
bit more than newsgroups when this was sourced in 95:
https://twitter.com/ScottShaneNYT/status/1227242088057565190

A Man With A Plan
Mar 29, 2010
Fallen Rib
There's a pretty big gap between "we talk or even collaborate with intel agencies" and "is literally a wholly owned subsidiary of the CIA" though

ewiley
Jul 9, 2003

More trash for the trash fire

BangersInMyKnickers posted:

I'm not aware of similar complaints against x25519 at this point. The NIST curves can go in the garbage at this point.

I mean honestly the ‘munitions’ argument that anything beyond DES should be export-controlled should tell you all you need to know about the US government and crypto. I think the NSA realized that it’s just easier to directly compromise endpoints than break crypto on the wire.

Also,

https://twitter.com/pwnallthethings/status/1227271808581324800?s=21

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
https://twitter.com/burgessct/status/1227395495561060353

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

ewiley posted:

I mean honestly the ‘munitions’ argument that anything beyond DES should be export-controlled should tell you all you need to know about the US government and crypto.

i remember when the pgp stuff was getting heated in regards to crypto as "munitions" and my dad took me to the book store to buy a copy of the pgp source code that was printed as a book (and thus protected by the first amendment) because he thought it was important to prove a point. also to pick up a copy of that quarters 2600, because for whatever reason our local bookstore carried that (i'm not entirely sure how unusual that is).

CmdrRiker
Apr 8, 2016

You dismally untalented little creep!

Is 2600 worth reading anymore? The last time I picked it up ~8 years ago I was fairly disappointed.

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
i have no idea. this was circa 1995

BlankSystemDaemon
Mar 13, 2009




CmdrRiker posted:

Is 2600 worth reading anymore? The last time I picked it up ~8 years ago I was fairly disappointed.
I assume you know about PoC||GTFO and PagedOut? They are quite good.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

CRIP EATIN BREAD posted:

i remember when the pgp stuff was getting heated in regards to crypto as "munitions" and my dad took me to the book store to buy a copy of the pgp source code that was printed as a book (and thus protected by the first amendment) because he thought it was important to prove a point. also to pick up a copy of that quarters 2600, because for whatever reason our local bookstore carried that (i'm not entirely sure how unusual that is).

Need more dads like that

haveblue
Aug 15, 2005



Toilet Rascal
pretty good parenting

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



haveblue posted:

pretty good parenting

RustyKnight
Jul 11, 2016

every day is a new horror



can somebody recommend some essentials for complete beginner, i would love to understand anything other than titles of articles that are posted here

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

haveblue posted:

pretty good parenting

Tankakern
Jul 25, 2007

haveblue posted:

pretty good parenting

flakeloaf
Feb 26, 2003

Still better than android clock

haveblue posted:

pretty good parenting

CmdrRiker
Apr 8, 2016

You dismally untalented little creep!

D. Ebdrup posted:

I assume you know about PoC||GTFO and PagedOut? They are quite good.

I did not know. Thank you for the recommendation.

RustyKnight posted:

can somebody recommend some essentials for complete beginner, i would love to understand anything other than titles of articles that are posted here

The answer to this question depends on the type of background you have. If your background is software development start with OWASP and reading security code patches for various libraries and frameworks you use. If you've mostly done that already then start reading about networking, set up and configure your own personal network, and play with networking tools like little snitch, charles proxy, and tshark. If you've already done that then perhaps buy a text book that introduces you to cryptography.

e: Oh, and people publish tons of cool security tooling that they build themselves on Github. Sometimes I'll just search for various keywords and find some really cool stuff to play with.

e: This should go without saying, but be careful when you play with a stranger's code.

CmdrRiker fucked around with this message at 19:37 on Feb 12, 2020

Midjack
Dec 24, 2007



haveblue posted:

pretty good parenting

and b&n carries 2600 on the shelf every store i’ve visited.

susan b buffering
Nov 14, 2016

didn’t 2600 recently publish the location of a bunch of ICE detention facilities? that seems pretty good

Phone
Jul 30, 2005

親子丼をほしい。

haveblue posted:

pretty good parenting

Last Chance
Dec 31, 2004

haveblue posted:

pretty good parenting

Ayin
Jan 6, 2010

Have a great day.

pointsofdata posted:

quoting a post from a closed thread is difficult posted:

Lol alternativedata.org has a list of all the different ways you can be spied on
https://alternativedata.org/data-providers/

"Real-time data on user purchases and product demand, sourced directly from Edison�s mail app."

"Detailed consumer purchasing habits from live transactional data (in-app, online and in-store). "

Etc

https://alternativedata.org/data_provider/associated-press/ posted:

Structured data for news archives, real time news, live and archived vote tabulation and a database of 140k upcoming potentially newsworthy events.

Other / main data source

2008 / Year Company Founded

1-10 / Discretionary Asset Manager Customers

Hmm, I'm pretty sure the Associated Press predates 2008 :v:

Shame Boy
Mar 2, 2010

haveblue posted:

pretty good parenting

Shame Boy
Mar 2, 2010

the latest iterm update had a fun note attached

quote:

The security model for the Python API has changed. Any process attempting to use the API that was not launched by iTerm2 will require explicit user approval.

The previous technique, which relied on inferring the job name from its command line, could be subverted.

Consequently, the UI for authorizing particular scripts has been removed.

For more information, please see https://iterm2.com/python-api-security-model

that link 404's with a cutesy 404 page :allears:

Adbot
ADBOT LOVES YOU

Media Bloodbath
Mar 1, 2018

PIVOT TO ETERNAL SUFFERING
:hb:

Shame Boy posted:

the latest iterm update had a fun note attached


that link 404's with a cutesy 404 page :allears:

that bold part sure was a bold idea.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply