Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
keseph
Oct 21, 2010

beep bawk boop bawk

hackbunny posted:

like I have a password and I need to use it both for authentication and to encrypt/verify a database. if using two key derivation functions, for their intended usage, is rolling my own protocol then I dunno what I'm supposed to do instead

Why are yoy not just:
Hash once, use as symmetric decryption key for a nonce that is itself used to decrypt the raw data. Hash second time and store as verifier if anyone might be trying this inside of a trusted service. The hashing parameters could be the same for both functions.

Adbot
ADBOT LOVES YOU

ate shit on live tv
Feb 15, 2004

by Azathoth

It's probably something like these,

https://en.wikipedia.org/wiki/TACLANE

Lots of vendors do it nowadays, but 10 year's ago you needed that. And they were often locked in tamper-proof cages.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/afreak/status/725508559580987393

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

Cocoa Crispies posted:

well it's not like anyone but the befuddled use bitcoin
they left out a colon in the title though


nice

Loving Africa Chaps
Dec 3, 2007


We had not left it yet, but when I would wake in the night, I would lie, listening, homesick for it already.

The surgeons at my hospital have decided answering pages is for proles so they bought 6 iPhones for various people around the hospital and now want us to group text patient identifiable information whenever we send for a patient.

There's no pin to unlock the screen because it gets handed over frequently at shift changes so whoever steals one first is going to have a record of everyone who went to emergency theatre from today and what operation they had.

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.

Loving Africa Chaps posted:

The surgeons at my hospital have decided answering pages is for proles so they bought 6 iPhones for various people around the hospital and now want us to group text patient identifiable information whenever we send for a patient.

There's no pin to unlock the screen because it gets handed over frequently at shift changes so whoever steals one first is going to have a record of everyone who went to emergency theatre from today and what operation they had.

this is illegal, you know

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.

Powercrazy posted:

It's probably something like these,

https://en.wikipedia.org/wiki/TACLANE

Lots of vendors do it nowadays, but 10 year's ago you needed that. And they were often locked in tamper-proof cages.

this pushes my Strong-Looking Hardware button



i think i'm either the dual redundant dual redundant power supplies, the battery, or the ZEROIZE PRESS 3X button

that or the network interface sets for PLAIN TEXT and CIPHER TEXT

Fart Cannon
Oct 12, 2008

College Slice

atomicthumbs posted:

this pushes my Strong-Looking Hardware button



i think i'm either the dual redundant dual redundant power supplies, the battery, or the ZEROIZE PRESS 3X button

that or the network interface sets for PLAIN TEXT and CIPHER TEXT

tac lanes fuckin own

Loving Africa Chaps
Dec 3, 2007


We had not left it yet, but when I would wake in the night, I would lie, listening, homesick for it already.

atomicthumbs posted:

this is illegal, you know

I've pointed this out on the departmental email including links to hscic guidance but looks like it's still going ahead!

All my nightshifts are on obstetrics from now on and a consultant holds it during the day so at least I don't have to physically touch it.

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

Loving Africa Chaps posted:

I've pointed this out on the departmental email including links to hscic guidance but looks like it's still going ahead!
lol

tell the feds so you get ~BLACKMAILED~ into 20 years of audits i guess

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

keseph posted:

Why are yoy not just:
Hash once, use as symmetric decryption key for a nonce that is itself used to decrypt the raw data.

this is exactly what I do to encrypt the storage: I derive (HKDF) a key from the master key derived (PBKDF2) from the password, and use it to decrypt+verify (AES-GCM) a random key that encrypts the storage. I forget why I'm not using the master key directly and I pass it through HKDF first, though

keseph posted:

Hash second time and store as verifier if anyone might be trying this inside of a trusted service. The hashing parameters could be the same for both functions.

isn't this what I'm doing already, too? I derive (HKDF) a separate key as a hash twice removed of the password. I will probably eventually drop everything and use the storage layer to both verify the password and detect when the user is switching between passwords... but I'm afraid the storage library doesn't have a "verify key" function yet, just "open with key, reset storage if the key is wrong"

Shame Boy
Mar 2, 2010

atomicthumbs posted:

this pushes my Strong-Looking Hardware button



i think i'm either the dual redundant dual redundant power supplies, the battery, or the ZEROIZE PRESS 3X button

that or the network interface sets for PLAIN TEXT and CIPHER TEXT

im the fill hole

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
https://isecguy.wordpress.com/2016/04/25/flaw-allowed-anyone-to-modify-take-control-over-any-as-domain/
.as domain registry ran on pre-2000 code that stored passwords as plaintext and used the domain name in base64 as the sole auth control

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
wizardhacking

computer toucher
Jan 8, 2012

spankmeister posted:

What's in the box!?

charger, warranty card, headphones, microfiber cloth, manual, your wife's head, a coupon for free download.

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
earbuds, vampire teeth, chopsticks with helper, Spider Man 3 bluray (opened)

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

atomicthumbs posted:

this pushes my Strong-Looking Hardware button



i think i'm either the dual redundant dual redundant power supplies, the battery, or the ZEROIZE PRESS 3X button

that or the network interface sets for PLAIN TEXT and CIPHER TEXT

lmao a cik, what is this, 1987

spankmeister
Jun 15, 2008






atomicthumbs posted:

this pushes my Strong-Looking Hardware button



i think i'm either the dual redundant dual redundant power supplies, the battery, or the ZEROIZE PRESS 3X button

that or the network interface sets for PLAIN TEXT and CIPHER TEXT

No red/black? pff

FlapYoJacks
Feb 12, 2009

Loving Africa Chaps posted:

I've pointed this out on the departmental email including links to hscic guidance but looks like it's still going ahead!

All my nightshifts are on obstetrics from now on and a consultant holds it during the day so at least I don't have to physically touch it.

You do realize that if you continue to do this you can also be found culpable in this illegal activity right?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Enjoy your newfound moral dilemma of doing the right thing and getting fired for "unsatisfactory performance" in a year and black balled, or dealing with the vague threat of criminal culpability from a law that has never resulted in a prosecution.

minivanmegafun
Jul 27, 2004

Malloc Voidstar posted:

https://isecguy.wordpress.com/2016/04/25/flaw-allowed-anyone-to-modify-take-control-over-any-as-domain/
.as domain registry ran on pre-2000 code that stored passwords as plaintext and used the domain name in base64 as the sole auth control

lol the first comment is someone saying they found this problem in 2008 and the registrar ignored it then

FlapYoJacks
Feb 12, 2009

Volmarias posted:

Enjoy your newfound moral dilemma of doing the right thing and getting fired for "unsatisfactory performance" in a year and black balled, or dealing with the vague threat of criminal culpability from a law that has never resulted in a prosecution.

And that's the dilemma. If know it's poo poo, and I'm not trying to act morally superior. Just giving him the heads up is all.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

minivanmegafun posted:

lol the first comment is someone saying they found this problem in 2008 and the registrar ignored it then

Well, what are you going to do? Go with another registrar for .as?

I have a .as domain, this doesn't fill me with warm fuzzies, but my options are "bear it" and "pull the domain that a bunch of your stuff is inextricably tied to."

ewiley
Jul 9, 2003

More trash for the trash fire

ratbert90 posted:

You do realize that if you continue to do this you can also be found culpable in this illegal activity right?

comedy option, report it to HHS and find out if there are any whistle-blower protections (there probably aren't)

http://www.hhs.gov/hipaa/filing-a-complaint/index.html

Now by reading this and not reporting it, you're SUPER double in trouble if something happens

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Volmarias posted:

Well, what are you going to do? Go with another registrar for .as?

I have a .as domain, this doesn't fill me with warm fuzzies, but my options are "bear it" and "pull the domain that a bunch of your stuff is inextricably tied to."

volmari.as?

Shame Boy
Mar 2, 2010

ratbert90 posted:

And that's the dilemma. If know it's poo poo, and I'm not trying to act morally superior. Just giving him the heads up is all.

"That guy knew it was wrong and didn't try to physically stop us it's his fault!!!"

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

ewiley posted:

comedy option, report it to HHS and find out if there are any whistle-blower protections (there probably aren't)

maybe not in that order

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

BeOSPOS posted:

volmari.as?

Yep. It's basically just storage and ad hoc hosting, but I still get mail relayed through there too.

ewiley
Jul 9, 2003

More trash for the trash fire
Looooool cloudflair

FlapYoJacks
Feb 12, 2009

Parallel Paraplegic posted:

"That guy knew it was wrong and didn't try to physically stop us it's his fault!!!"

More like: That guy knew it was wrong and still continued to send texts out.

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Parallel Paraplegic posted:

im the fill hole

pour your bits iin here

Shaggar
Apr 26, 2006

Loving Africa Chaps posted:

The surgeons at my hospital have decided answering pages is for proles so they bought 6 iPhones for various people around the hospital and now want us to group text patient identifiable information whenever we send for a patient.

There's no pin to unlock the screen because it gets handed over frequently at shift changes so whoever steals one first is going to have a record of everyone who went to emergency theatre from today and what operation they had.

there are a number of hipaa compliant secure text apps that you can get for them and you can stick them on ur exchange server for MDM. its not that bad and your pager system is probably ancient and terrible. We have a bunch of customers using DocbookMD and then a few who use onpage and dochalo.

also it makes more sense at that point for them to use their own phones so they don't have to transfer them around.

Shaggar
Apr 26, 2006
The hardest part about setting up docbookmd is trying to get your doctors' NPIs. they sure as poo poo don't know what they are and what you have in your credentialing system is wrong.

ewiley
Jul 9, 2003

More trash for the trash fire

ratbert90 posted:

More like: That guy knew it was wrong and still continued to send texts out.

Meh, doing thing with explicit approval from management is 99% of the time an employee's get out of jail free card. Unless you're murdering someone in a Nazi death camp, 'just following orders' is actually a valid defense. You're not personally responsible for securing your employers process, just following it consistently and correctly. They may have compensating controls on the back-end that he's unaware of.

FlapYoJacks
Feb 12, 2009

ewiley posted:

Meh, doing thing with explicit approval from management is 99% of the time an employee's get out of jail free card. Unless you're murdering someone in a Nazi death camp, 'just following orders' is actually a valid defense. You're not personally responsible for securing your employers process, just following it consistently and correctly. They may have compensating controls on the back-end that he's unaware of.

If it was me I would CYA with at least a email from management, if not a printed and signed document explicitly saying it's ok for me to do this.

Edit* I have done this twice in my career, and both times management backed off and told me to forget about doing it. Making somebody else culpable is the easiest way to get illegal activities to stop pretty quick.

Shame Boy
Mar 2, 2010

ewiley posted:

Meh, doing thing with explicit approval from management is 99% of the time an employee's get out of jail free card. Unless you're murdering someone in a Nazi death camp, 'just following orders' is actually a valid defense. You're not personally responsible for securing your employers process, just following it consistently and correctly. They may have compensating controls on the back-end that he's unaware of.

Tell that to the VW engineers who just randomly decided to cheat emissions standards completely by themselves because they're weird and quirky.

At least like, save an email or something with your boss saying "hey everyone do this dumb illegal thing it's our new policy!" in a safe place.

Shaggar
Apr 26, 2006

Volmarias posted:

Enjoy your newfound moral dilemma of doing the right thing and getting fired for "unsatisfactory performance" in a year and black balled, or dealing with the vague threat of criminal culpability from a law that has never resulted in a prosecution.

nah if he brought it up with his hospitals lawyers they'll drop a bag of poo poo on the docs so fast because they know its a terrible and pointless risk when there are easy ways to do it correctly.

FlapYoJacks
Feb 12, 2009

Shaggar posted:

nah if he brought it up with his hospitals lawyers they'll drop a bag of poo poo on the docs so fast because they know its a terrible and pointless risk when there are easy ways to do it correctly.

I forgot that hospitals have lawyers on retainer specifically for this. This is probably the correct answer, as it seems like Shaggar knows his poo poo when it comes to infosec in hospitals.


Also, this is what I imagine all hospital lawyers to be like:

https://www.youtube.com/watch?v=u1ZtaaFZDcI&hd=1

ewiley
Jul 9, 2003

More trash for the trash fire

Parallel Paraplegic posted:

Tell that to the VW engineers who just randomly decided to cheat emissions standards completely by themselves because they're weird and quirky.

At least like, save an email or something with your boss saying "hey everyone do this dumb illegal thing it's our new policy!" in a safe place.

Yeah but VW engineers legit deserve to burn in hell


against the firewall

Adbot
ADBOT LOVES YOU

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



ewiley posted:

Yeah but VW engineers legit deserve to burn in hell


against the firewall

is that one contiguous chain? it is isn't it? JFC

  • Locked thread