Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
jetz0r
May 10, 2003

Tomorrow, our nation will sit on the throne of the world. This is not a figment of the imagination, but a fact. Tomorrow we will lead the world, Allah willing.



H5N1 posted:

nothing will happen because nothing ever happens after data breaches like these.

right now they're in the finger-pointing stage about who is acutually liable in a legal sense (was Anthem acting as an insurer, an agent, a healthcare facilitor?!) and then the next step is determining venue and this is based largely upon which of the dozens of Acts that may have been violated. were medical records involved? then HIPAA, bitch! SSNs? HITECH Act violation, motherfucker. If the latter, then the states get to put their fingers in this too and AGs looking to make a name for themselves (*cough* Kamela Harris *cough*) will make a big fuss and stick their noses in it and gently caress it, it's all going to take 15 years to wind it all down and will all end with 3 months of free credit monitoring for everyone wheeeeeeee

it'll be a year of free credit monitoring
smh if you haven't been chaining useless spammy free credit monitoring for the past 5 years thanks to breaches.

Adbot
ADBOT LOVES YOU

EMILY BLUNTS
Jan 1, 2005

Did they still not get the adobe password thing figured out? given all the approaches they can take and all the problems with the protection I'd have figured someone might have made progress.

fritz
Jul 26, 2003

EMILY BLUNTS posted:

is the info on this site accurate at all?, because lol

http://w3techs.com/sites/info/uniqlo.com

what am i looking @ here

AARP LARPer
Feb 19, 2005

THE DARK SIDE OF SCIENCE BREEDS A WEAPON OF WAR

Buglord

EMILY BLUNTS posted:

Did they still not get the adobe password thing figured out? given all the approaches they can take and all the problems with the protection I'd have figured someone might have made progress.

Are you talking about the breach from a year ago or so? That was the one that finally got me off my rear end and get serious about my passwords (had a CS sub that got snagged).

EMILY BLUNTS
Jan 1, 2005

fritz posted:

what am i looking @ here

quote:

PHP 4.3.9
(almost 100% of sites use a newer version)

Do Not Resuscitate posted:

Are you talking about the breach from a year ago or so? That was the one that finally got me off my rear end and get serious about my passwords (had a CS sub that got snagged).

yeah

Bloody
Mar 3, 2013


and Apache 2.0.52
(87% of sites use a newer version)

EMILY BLUNTS
Jan 1, 2005

its also suggesting vkontakte is using php 3. :eek:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

As far as anyone knows the key to decrypt the passwords is unknown and as such we are unlikely to decrypt them anytime soon

vOv
Feb 8, 2014

didn't they encrypt them with ECB using a 64-bit block size?

spankmeister
Jun 15, 2008






vOv posted:

didn't they encrypt them with ECB using a 64-bit block size?

3DES iirc

vOv
Feb 8, 2014

right yeah 3DES in ECB mode, and the hints leaked too didn't they? so you could basically play crosswords

spankmeister
Jun 15, 2008






vOv posted:

right yeah 3DES in ECB mode, and the hints leaked too didn't they? so you could basically play crosswords

that's right, and unsalted so you could just take all the ones with the same ciphertext and then one of them would have a real easy hint or just the drat password even and then you'd know all the others

EMILY BLUNTS
Jan 1, 2005

wasn't it taht they may or may not be salted, but they are not different salts, if one was used.

spankmeister
Jun 15, 2008






EMILY BLUNTS posted:

wasn't it taht they may or may not be salted, but they are not different salts, if one was used.
yeah that's true

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
isn't salting usually done with concatenation? so in ECB mode it wouldn't necessarily make much of a difference

unless they did some wacky xor thing but i'm p. sure people who use ECB 3DES aren't that smart

influx.
Dec 16, 2007

Nice pants!


7-YEAR OLD GIRL HACKS PUBLIC WI-FI IN LESS THAN 11 MINUTES

I'm the IE

spankmeister
Jun 15, 2008






stay safe hotspot ghost

Notorious b.s.d.
Jan 25, 2003

by Reene

i'm the vga port

Squinty Applebottom
Jan 1, 2013

I'm the _NSAKEY that lurks in every non free/libre operating system

Bloody
Mar 3, 2013

i'm the fact that not only can a child hack your wifi, but a female child can hack your wifi

qntm
Jun 17, 2009
infosec barbie's been a bad influence on that kid

Storysmith
Dec 31, 2006

quote:

We set the challenge to IT-savvy primary school student Betsy Davies from Dulwich in South London, who was able to hack into a public Wi-Fi hotspot after she searched and watched a video tutorial online which explained how to hack a network. It took 7-year old Betsy just 10 minutes and 54 seconds to hack into a Wi-Fi hotspot. She then set up a Rogue Access Point which is often used by cybercriminals to trigger a ‘man in the middle’ attack allowing her to ‘sniff’ traffic.


What part of this is hacking into an ap exactly, as opposed to reading the plaintext your computer shamefully serves up

Shame Boy
Mar 2, 2010

Storysmith posted:

What part of this is hacking into an ap exactly, as opposed to reading the plaintext your computer shamefully serves up

The part that lets them say it was and clickbait, obviously.

Shame Boy
Mar 2, 2010

I mean such a well-respected news outlet like hidemyass.com wouldn't just make poo poo up for attention would it???

Storysmith
Dec 31, 2006

Parallel Paraplegic posted:

I mean such a well-respected news outlet like hidemyass.com wouldn't just make poo poo up for attention would it???

especially the part where what they made up made a perfect case for the primary product hide my rear end dot com sells

computer toucher
Jan 8, 2012

Storysmith posted:

especially the part where what they made up made a perfect case for the primary product hide my rear end dot com sells

LOADING CREDIT CARD_

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

FCKGW posted:

"Now, every Visa card has a Bitcoin address" - SpendBT.com [Launching officially on Monday in Canada, live pre-release this weekend for feedback] (spendbt.com)
submitted 10 hours ago by QuickBT



[–]OhThereYouArePerry 25 points 7 hours ago
How are CC numbers handled?
Are they only used for the one transaction and then purged, or are they stored somewhere?
IIRC you can't even charge a card without the Expiry Date, so this should be pretty safe, but I'm just curious.


[–]SpendBT 11 points 4 hours ago
Hi there,
Great question! We handle the credit card number like a Bitcoin address. For SpendBT we store the number in plain text for 30 days, then truncate all records older than 30 days to the last four digits.
You cannot, under any merchant system we've ever seen, place a credit card charge with solely the number. You always need at least the expiry to match.
Just like you cannot make a Bitcoin transaction with just the public key.
When you actually are generated a QR code, the site warns "Use each QR code only once".
We may in the future allow a permanent address we monitor and top up in perpetuity, thanks for the feedback!
SpendBT Team

ChickenOfTomorrow
Nov 11, 2012

god damn it, you've got to be kind


mark karpeles told us this was how you store cc details

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

:holymoley:

Venuz Patrol
Mar 27, 2011

noooooooo

FCKGW
May 21, 2006

they've seen the error of their ways thanks to reddit, they'll have it fixed on monday probably its in the wiki

[–]bontchev 19 points 2 hours ago
"we store the number in plain text"
/facepalm
Guys, I strongly recommend that you hire a computer security expert. No, I mean, a real one. Not like those that Target, or Anthem, or... had.



[–]SpendBT 2 points 2 hours ago
I suspect by the end of this feedback weekend, and before we launch, this will be solved.
We totally understand the need for PCI Compliance, but hoped that a card number (primary account number) alone (no expiry, cvc, address, name etc etc) would render the data as valuable as a Public Key.
From the comments here, Visa is still allowing charges to go through with just a PAN and an estimated expiry
Thanks for the feedback this is what we wanted so keep it coming!
Jamie
SpendBT Team

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

holy poo poo, lol

:10bux: says they're using some awful hashing function on the raw credit card number to get the keys

Vicas
Dec 9, 2009

Sweet tricks, mom.
"we knew the numbers would get stolen if we kept them this way, but we figured that'd be fine because you also need a second set of far easier to get numbers"

Shame Boy
Mar 2, 2010

Vicas posted:

"we knew the numbers would get stolen if we kept them this way, but we figured that'd be fine because you also need a second set of far easier to get numbers"

A month and a year is exactly like a cryptographic private key, that's the first thing you learn in cryptoclass 101

Jewel
May 2, 2009

$100 says that after they add expiry date support, the entire system is going to break when your expiry changes on your card

e: $key = md5($creditnumber . $expirydate)

secure

Shame Boy
Mar 2, 2010

Jewel posted:

$100 says that after they add expiry date support, the entire system is going to break when your expiry changes on your card

e: $key = md5($creditnumber . $expirydate)

secure

The only salt a bitcoiner needs is the kind that goes on their extra-large order of fries.

minivanmegafun
Jul 27, 2004

Parallel Paraplegic posted:

The only salt a bitcoiner needs is the kind that goes on their extra-large order of fries.

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.

Vicas posted:

"we knew the numbers would get stolen if we kept them this way, but we figured that'd be fine because you also need a second set of far easier to get numbers"

*puts in credit card number and cycles through next 48 months*

suffix
Jul 27, 2013

Wheeee!

is there a way to send money to a canadian credit card with just the card number? sounds more like a scam than incompetence...
afaik square cash only works with debit cards, and they use a hack where they register the payment as a "refund"

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

  • Locked thread