Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
finally, the long national nightmare of quicktime on windows is over http://blog.trendmicro.com/urgent-call-action-uninstall-quicktime-windows-today/

Adbot
ADBOT LOVES YOU

ewiley
Jul 9, 2003

More trash for the trash fire

pr0zac posted:

@facebook it was 90% arguing with people about dumb edge cases around blocking logic and why profile pictures aren't considered private

@uber we just started the program so its tons of script kiddies running scans and letting us know we have an urgent SQLi in our joomla (we don't run joomla) but we're using hackerone so we get reputation for reporters and can block and rate limit people which should improve the signal/noise

the 5% of reports that are high quality make the programs invaluable though and large public facing companies that have the resources to start one but don't are real dumb (Apple)

I'm impressed that it's as high as 5% for useful submissions. Still sounds worth it for the company if you can keep your sec folks from suiciding..

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Carbon dioxide posted:

"agressively vegan".

you can just say "vegan"

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.

anthonypants posted:

finally, the long national nightmare of quicktime on windows is over http://blog.trendmicro.com/urgent-call-action-uninstall-quicktime-windows-today/

but how will i play EV Nova now

Winkle-Daddy
Mar 10, 2007

Cocoa Crispies posted:

you can just say "big dumb idiot who has bad opinions on life"

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
apparently if you generated enough bit.ly urls you could get access to someone's onedrive until microsoft removed the feature http://www.wired.com/2016/04/researchers-cracked-microsoft-googles-shortened-urls-spy-people/

moonshine is......
Feb 21, 2007

So apparently this is a thing https://deaddrops.com/ a friend of mine told me her techie friend is really into it. So that's fun.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

moonshine is...... posted:

So apparently this is a thing https://deaddrops.com/ a friend of mine told me her techie friend is really into it. So that's fun.
all the ones in my area are marked "broken/dead/stolen/gone"

Midjack
Dec 24, 2007



moonshine is...... posted:

So apparently this is a thing https://deaddrops.com/ a friend of mine told me her techie friend is really into it. So that's fun.

looks like a glory hole for your computer

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

moonshine is...... posted:

So apparently this is a thing https://deaddrops.com/ a friend of mine told me her techie friend is really into it. So that's fun.

I wonder if any of those are just wired directly to AC mains power.

That was a nice computer you used to have.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/webster/status/720758545688477696

flakeloaf
Feb 26, 2003

Still better than android clock

lomarf cops on computers

Storysmith
Dec 31, 2006

Carbon dioxide posted:

Goddamn, I clicked that link expecting something interesting, and instead I get a guy who can't stop talking about how he is "agressively vegan". Please don't ever link to that crap again. Seriously, I somehow kept that vid going for 6 minutes without going mad and he's still going on about that and hasn't once mentioned the supposed topic of his talk.

it's a shame you didn't get to the part immediately after that where he talks about how his animal rights activism was declared literal terrorism and his friends started getting arrested under terrorism charges and how he's been foiaing since then and the government has been lying about it

oh god a whole six minutes talking about the context behind his talk, better shitpost rather than skip ahead or deal with my criminally short attention span

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

moonshine is...... posted:

So apparently this is a thing https://deaddrops.com/ a friend of mine told me her techie friend is really into it. So that's fun.

a museum I worked at some years back did something like that. I forget how it ended up but it was popular enough

e. nice finally saw my gangtags :cheers:

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

oh my god lol

Moist von Lipwig
Oct 28, 2006

by FactsAreUseless
Tortured By Flan

ahahahahahaahhaahhahaahah

Shaggar
Apr 26, 2006

the government should not be allowed near computers

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

:lol:

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Shaggar posted:

the government should not be allowed near computers
or at least the cops who self-select for below-average intelligence

flakeloaf
Feb 26, 2003

Still better than android clock

Bhodi posted:

or at least the cops who self-select for below-average intelligence

imagine how bad it is

nope it's worse

now imagine being the designated cj because you didn't have to look at the keys while typing

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

Midjack posted:

looks like a glory hole for your computer

probably about as likely to give you a virus too

Trabisnikof
Dec 24, 2005

Midjack posted:

looks like a glory hole for your computer

one of the nearest ones to me is literally installed in a glory hole

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Trabisnikof posted:

one of the nearest ones to me is literally installed in a glory hole

noice

computer toucher
Jan 8, 2012

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

I think im missing something

e: oh god dammit there's the pass's barcode

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

pr0zac posted:

I think im missing something

e: oh god dammit there's the pass's barcode

here's the original image:



i tried to get the code to read but it's a bit too low res

apseudonym
Feb 25, 2011

anthonypants posted:

apparently if you generated enough bit.ly urls you could get access to someone's onedrive until microsoft removed the feature http://www.wired.com/2016/04/researchers-cracked-microsoft-googles-shortened-urls-spy-people/

This is from a good friend and my old PhD advisor, the paper is worth a read for the laughs.

big shtick energy
May 27, 2004


on gmail in iOS, you can't attach non-picture files to an email, you can only add them in google drive and make them viewable to anyone with the URL

pretty annoying since I didn't want to share my credit card details with the world. of course I was already attaching them to an unencrypted email but I already accepted that fuckup

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Midjack posted:

looks like a glory hole for your computer

mods namechange to 'USB Glory Hole" plz

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

DuckConference posted:

on gmail in iOS, you can't attach non-picture files to an email, you can only add them in google drive and make them viewable to anyone with the URL

if you figure out a way to figure out one of those urls without actually being given it, lmk

ErIog
Jul 11, 2001

:nsacloud:

Jabor posted:

if you figure out a way to figure out one of those urls without actually being given it, lmk

It's more that if they're sniffed then whoever sniffed it needs no other authentication to be able to view the picture. I noticed it a while ago, and I bet most hangout users don't know it behaves like that. Any picture you send over Hangouts to another user is public information. So maybe find another way to send your dick picks.

It's super weird because it's clearly a violation of the expectation of privacy. Text sent to another person isn't public. Pictures are. Google doesn't seem to let you know this. I'm surprised some consumer bureau in the EU hasn't taken them to ask over it.

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

ErIog posted:

It's more that if they're sniffed then whoever sniffed it needs no other authentication to be able to view the picture. I noticed it a while ago, and I bet most hangout users don't know it behaves like that. Any picture you send over Hangouts to another user is public information.

It's super weird because it's clearly a violation of the expectation of privacy. Text sent to another person isn't public. Pictures are.

...what?

if they can't see the text you've sent to the other person, how are they going to see the image?

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'


jfc ayy

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

quote:

Abstract
In December 2015, Juniper Networks announced that
unknown attackers had added unauthorized code to
ScreenOS, the operating system for their NetScreen VPN
routers. This code created two vulnerabilities: an authentication
bypass that enabled remote administrative access,
and a second vulnerability that allowed passive decryption
of VPN traffic. Reverse engineering of ScreenOS binaries
revealed that the first of these vulnerabilities was a conventional
back door in the SSH password checker. The
second is far more intriguing: a change to the Q parameter
used by the Dual EC pseudorandom number generator. It
is widely known [7, 33] that Dual EC has the unfortunate
property that an attacker with the ability to choose Q can,
from a small sample of the generator’s output, predict all
future outputs. In a 2013 public statement, Juniper noted
the use of Dual EC but claimed that ScreenOS included
countermeasures that neutralized this form of attack.
In this work, we report the results of a thorough independent
analysis of the ScreenOS randomness subsystem,
as well as its interaction with the IKE VPN key establishment
protocol. Due to apparent flaws in the code,
Juniper’s countermeasures against a Dual EC attack are
never executed. Moreover, by comparing sequential versions
of ScreenOS, we identify a cluster of additional
changes that were introduced concurrently with the inclusion
of Dual EC in a single 2008 release. Taken as a
whole, these changes render the ScreenOS system vulnerable
to passive exploitation by an attacker who selects
Q. We demonstrate this by installing our own parameters,
and showing that it is possible to passively decrypt
a single IKE handshake and its associated VPN traffic in
isolation without observing any other network traffic.

http://dualec.org/DualECJuniper-draft.pdf

NFX
Jun 2, 2008

Fun Shoe

DuckConference posted:

on gmail in iOS, you can't attach non-picture files to an email, you can only add them in google drive and make them viewable to anyone with the URL

pretty annoying since I didn't want to share my credit card details with the world. of course I was already attaching them to an unencrypted email but I already accepted that fuckup

i tried to do the same thing recently (e-mail a pdf from my iphone). the built in mail-app can do it, but it's not very obvious how. outlook was excellent and even looked through my inbox to find attachments to upload to nsa choose from

spankmeister
Jun 15, 2008






DuckConference posted:

on gmail in iOS, you can't attach non-picture files to an email, you can only add them in google drive and make them viewable to anyone with the URL

pretty annoying since I didn't want to share my credit card details with the world. of course I was already attaching them to an unencrypted email but I already accepted that fuckup

depending on the mail server you are sending it to, the email can actually be encrypted in transit

not something you want to rely on though

Shame Boy
Mar 2, 2010

spankmeister posted:

depending on the mail server you are sending it to, the email can actually be encrypted in transit

not something you want to rely on though

isn't google adding some icon that indicates if the mail server supports TLS or something

Shaggar
Apr 26, 2006

Bhodi posted:

or at least the cops who self-select for below-average intelligence

its not just the cops.

Shaggar
Apr 26, 2006

DuckConference posted:

on gmail in iOS, you can't attach non-picture files to an email, you can only add them in google drive and make them viewable to anyone with the URL

pretty annoying since I didn't want to share my credit card details with the world. of course I was already attaching them to an unencrypted email but I already accepted that fuckup

put them on your one drive and share them only with a specific user. anyone with the url will still have to log in and only the user you authorized will be able to access it.

Adbot
ADBOT LOVES YOU

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

Jabor posted:

...what?

if they can't see the text you've sent to the other person, how are they going to see the image?

if you send someone a pic via hangouts it actually uploads it to your Google photos account as a shared photo

  • Locked thread