Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

FatCow posted:

It's only going to get worse. The FCC wants you to be able to eventually reach 911 from basically any Internet connected device. The first testbed for non-voice based 911 is the text to 911 stuff that's rolling out now.

there are police forces that already have sms shortcodes for contacting the police

which sometimes leads to funny stories:
http://vancouver.24hrs.ca/2014/04/21/skytrain-commuter-upset-by-text-a-cop-charges

quote:

A daily transit commuter with an unlimited messaging plan was still charged 10 cents each time he used Transit Police’s new text-a-cop number — so he will no longer be reporting crimes via SMS.

Angad Bawa said he spotted someone smoking on SkyTrain last week and decided to text the 877777 number to discreetly contact Transit Police.

When he checked his bill the next day, his carrier charged him 30 cents in total for the three texts he sent.

they advertise it as a non-emergency number but suggest you use it if the train is too crowded and you cannot hit the panic button--all trains here are automated (100%) and regularly are unsupervised (and stupidly the system is likely internet-accessible, but that is a different post all together)

Adbot
ADBOT LOVES YOU

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Powercrazy posted:

It's ridiculous and dangerous for the public safety to treat literally everything as the worst case scenario. It's irresponsible and if judges/police/etc were actually culpable for their actions we would have a system in place that would solve the problem with a quickness. But WELP!

anyway sorry for the 'LF' but I really despise the american (but other countries are catching up) law enforcement environment

yeah it's ahocking that the public doesn't know what's good for them

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

OSI bean dip posted:

there are police forces that already have sms shortcodes for contacting the police

which sometimes leads to funny stories:
http://vancouver.24hrs.ca/2014/04/21/skytrain-commuter-upset-by-text-a-cop-charges


they advertise it as a non-emergency number but suggest you use it if the train is too crowded and you cannot hit the panic button--all trains here are automated (100%) and regularly are unsupervised (and stupidly the system is likely internet-accessible, but that is a different post all together)

I really really really wish that people would realize "internet-connected" is often going to end horribly

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Captain Foo posted:

I really really really wish that people would realize "internet-connected" is often going to end horribly

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Captain Foo posted:

I really really really wish that people would realize "internet-connected" is often going to end horribly

tell that to sony :lol:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i should clarify that "internet-connected" or "internet-accessible" to means to me that with or without vpn access one probably could access to the scada controls. i only say this due to cursory searches on shodan for the transit agency in question revealed a telnet and ftp server that didn't make sense for their operations. i haven't and will not dare to find out if i am right :ohdear:

if you are aware of where i live please don't quote me on this and don't dare try and be a hero

Lain Iwakura fucked around with this message at 05:21 on Dec 16, 2014

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Captain Foo posted:

I really really really wish that people would realize "internet-connected" is often going to end horribly

i want to connect my fridge to tor, bithc

neutral milf hotel
Oct 9, 2001

by Fluffdaddy
oh shi..

Rick Ross Ulbricht
Feb 3, 2010

put yourself in the shoes of a prosecutor trying to build a case against you. what evidence could they pin on you? there is nothing on your laptop for them to use, if you obscure your bitcoins propperly, there is no way for them to trace them back to me.

OSI bean dip posted:

there are police forces that already have sms shortcodes for contacting the police

which sometimes leads to funny stories:
http://vancouver.24hrs.ca/2014/04/21/skytrain-commuter-upset-by-text-a-cop-charges

quote:

None of his other text messages had charges on them — Bawa has an unlimited province-wide texting plan — and he provided a copy of his bill to 24 hours as proof.

do you have to pay extra to text people the next province over????

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Remicks posted:

do you have to pay extra to text people the next province over????

i think it depends on the carrier

i have a plan that lets me text north america-wide without issues

Nintendo Kid
Aug 4, 2011

by Smythe

Remicks posted:

do you have to pay extra to text people the next province over????

yes canada still has cell providers in 2014 that charge extra for calling or texting outside a province.

even though every major and nearly all minor us cell carriers ended "long distance" extra charges back around 1999.

ChickenOfTomorrow
Nov 11, 2012

god damn it, you've got to be kind

OSI bean dip posted:

i think it depends on the carrier

i have a plan that lets me text north america-wide without issues

text me

Nintendo Kid
Aug 4, 2011

by Smythe
a cool thing about comcast voice service is that calling canada is included in standard unlimited long distance

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

i don't have your number

i also have unlimited north america calling on the plan too. i managed to get 9 people to conference in on it before too. didn't try to go beyond that

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Nintendo Kid posted:

a cool thing about comcast voice service is that calling canada is included in standard unlimited long distance

who do you call in Canada? are they nice?

jetz0r
May 10, 2003

Tomorrow, our nation will sit on the throne of the world. This is not a figment of the imagination, but a fact. Tomorrow we will lead the world, Allah willing.



OSI bean dip posted:

i don't have your number

lies, it's probably in canary.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

jetz0r posted:

lies, it's probably in canary.

funny enough i originally planned to have phone number scraping within canary but it's too easy to have false positives

Rick Ross Ulbricht
Feb 3, 2010

put yourself in the shoes of a prosecutor trying to build a case against you. what evidence could they pin on you? there is nothing on your laptop for them to use, if you obscure your bitcoins propperly, there is no way for them to trace them back to me.
heh

http://www.businessweek.com/articles/2014-12-15/verizons-new-encrypted-calling-app-plays-nice-with-the-nsa

:nsa:

ate shit on live tv
Feb 15, 2004

by Azathoth

quote:

Seth Polansky, Cellcrypt's vice president for North America, disputes the idea that building technology to allow wiretapping is a security risk. "It's only creating a weakness for government agencies," he says. "Just because a government access option exists, it doesn't mean other companies can access it."

I too want to be a Vice President for Verizon and not understand the concept of secure two-way communication.

ate shit on live tv fucked around with this message at 07:23 on Dec 16, 2014

vOv
Feb 8, 2014

cypher, clipper, same difference really

Number19
May 14, 2003

HOCKEY OWNS
FUCK YEAH


OSI bean dip posted:

i should clarify that "internet-connected" or "internet-accessible" to means to me that with or without vpn access one probably could access to the scada controls. i only say this due to cursory searches on shodan for the transit agency in question revealed a telnet and ftp server that didn't make sense for their operations. i haven't and will not dare to find out if i am right :ohdear:

if you are aware of where i live please don't quote me on this and don't dare try and be a hero

LOADING HACKING TOOLS...

computer toucher
Jan 8, 2012

So I decided to upgrade my site's certificate, when suddenly...

Jesus christ, I'm such an idiot... I didn't have their cert installed in my browser so that's why that shows up.

Welp, I'll leave this here as a testament to the stupidity of forums poster Computer Toucher.

edit: Also I apparently can't remove attached images from posts lol.

Only registered members can see post attachments!

computer toucher fucked around with this message at 09:17 on Dec 16, 2014

cinci zoo sniper
Mar 15, 2013




computer toucher posted:

Also I apparently can't remove attached images from posts lol.
Everyone will know. :awesomelon:

EMILY BLUNTS
Jan 1, 2005

at least you didn't post a domain or username or something so there's that

Hugh G. Rectum
Mar 1, 2011

computer toucher posted:

So I decided to upgrade my site's certificate, when suddenly...

Jesus christ, I'm such an idiot... I didn't have their cert installed in my browser so that's why that shows up.

Welp, I'll leave this here as a testament to the stupidity of forums poster Computer Toucher.

edit: Also I apparently can't remove attached images from posts lol.



the only way to get rid of it is to be banned

New Zealand can eat me
Aug 29, 2008

:matters:


Need a last minute flight?




You can check in as them and change their seat.

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe
"We appreciate your loyalty, and now look forward to your next flight with us - regardless if it was actually yours or not"

Jewel
May 2, 2009

The email reply is worded as if they're talking to an old person who's never used a computer and had trouble working out what a new tab was; not someone who found a flaw that could destroy their entire business, nice.

Daman
Oct 28, 2011
The email reply is written like an automatic response because it probably is. They'd probably never have known about this if that person didn't go full disclosure. having this be lost forever in customer support robot's inbox would've been a just end

computer toucher
Jan 8, 2012

EMILY BLUNTS posted:

at least you didn't post a domain or username or something so there's that

Would you be interested in these php files that belong to a client? They're worth a few yuks, right?

Progressive JPEG
Feb 19, 2003

I LIKE TO SMOKE WEE posted:

Need a last minute flight?




You can check in as them and change their seat.

You Share, We Care

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
speaking of PBX misconfigurations, place I worked at once had something break on a patch and suddenly people could call our IVR, hit pound 9, and make outbound calls

thanks avaya

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

uncurable mlady posted:

speaking of PBX misconfigurations, place I worked at once had something break on a patch and suddenly people could call our IVR, hit pound 9, and make outbound calls

thanks avaya

hahahahahaha wow iirc you have to try fairly hard to enable that sort of behavior on an avaya system

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

OSI bean dip posted:

i should clarify that "internet-connected" or "internet-accessible" to means to me that with or without vpn access one probably could access to the scada controls. i only say this due to cursory searches on shodan for the transit agency in question revealed a telnet and ftp server that didn't make sense for their operations. i haven't and will not dare to find out if i am right :ohdear:

if you are aware of where i live please don't quote me on this and don't dare try and be a hero

internet-accessible == w/o VPN from my point of view, the whole entire point of a VPN is that it provides you a secure tunnel to inside the corp network, and if it can't do that, :rip:

Active666
Apr 3, 2009

I LIKE TO SMOKE WEE posted:

Need a last minute flight?




You can check in as them and change their seat.

Say a local guy give a talk about this and other airlines that had terrible ticket security. South West's ticket bar codes\Qr codes are unencrypted and allow all sorts of fun times.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Captain Foo posted:

internet-accessible == w/o VPN from my point of view, the whole entire point of a VPN is that it provides you a secure tunnel to inside the corp network, and if it can't do that, :rip:

your network should be segmented enough that it would be impossible to get access to anything scada-related via vpn without the use of an intermediary host

otherwise you'll end up like target where systems like point-of-sale machines are easily reachable to contractors who vpn in to make changes to hvac systems

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

OSI bean dip posted:

your network should be segmented enough that it would be impossible to get access to anything scada-related via vpn without the use of an intermediary host

otherwise you'll end up like target where systems like point-of-sale machines are easily reachable to contractors who vpn in to make changes to hvac systems

:agreed:

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Active666 posted:

Say a local guy give a talk about this and other airlines that had terrible ticket security. South West's ticket bar codes\Qr codes are unencrypted and allow all sorts of fun times.

aztec codes, and "neoreader" for ios and android can decode them

they're plaintext with a signature

Progressive JPEG
Feb 19, 2003

Cocoa Crispies posted:

aztec codes, and "neoreader" for ios and android can decode them

they're plaintext with a signature

wouldnt the signature at least avoid tampering? or do they just ignore it

Adbot
ADBOT LOVES YOU

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

uncurable mlady posted:

speaking of PBX misconfigurations, place I worked at once had something break on a patch and suddenly people could call our IVR, hit pound 9, and make outbound calls

thanks avaya

lmbo


thank you for giving me yet another reason to be thankful for being rid of our avaya system

  • Locked thread