Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
New Zealand can eat me
Aug 29, 2008

:matters:


Can you all stop making me look good, I'm clearly the original white noise poster

jony ive aces posted:

goatseing silicon valley startups is its own reward

snipe

Adbot
ADBOT LOVES YOU

Tayter Swift
Nov 18, 2002

Pillbug
current security status: password must be between 8 and 12 characters long and must contain a special character

the only special character allowed is an exclamation mark

Shame Boy
Mar 2, 2010

Tayter Swift posted:

current security status: password must be between 8 and 12 characters long and must contain a special character

the only special character allowed is an exclamation mark

a very "special" character

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

quote:

Heuristic match to horrible posting. User loses posting privileges for 6 hours.

:nsavince:

Wiggly Wayne DDS
Sep 11, 2010



Tayter Swift posted:

current security status: password must be between 8 and 12 characters long and must contain a special character

the only special character allowed is an exclamation mark
saw a new one - uppercase letter every 8th character

Su-Su-Sudoko
Oct 25, 2007

what stands in the way becomes the way

Wiggly Wayne DDS posted:

saw a new one - uppercase letter every 8th character

how does one even come up with that

Shame Boy
Mar 2, 2010

Testiclops posted:

how does one even come up with that

seems like someone's thought process is "the more complicated the password rules are the harder it is to guess them" which i guess makes sense if you have no actual idea how passwords work

a foolish pianist
May 6, 2007

(bi)cyclic mutation

uncurable mlady posted:

https://labs.detectify.com/2016/04/28/slack-bot-token-leakage-exposing-business-critical-information/

im mostly just mad I didn't think about writing a scraper for slack api keys to rake in that sweet bounty cash

managing tokens and keys seems to a big problem for smaller orgs. someone at my job left, and when we removed his personal keys, a couple of important services that he'd used his personal keys for broke.

poo poo made for a serious scramble.

Midjack
Dec 24, 2007



a foolish pianist posted:

managing tokens and keys seems to a big problem for smaller orgs. someone at my job left, and when we removed his personal keys, a couple of important services that he'd used his personal keys for broke.

poo poo made for a serious scramble.

interesting real world example of a deadman switch

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

Captain Foo posted:

gold-medal goatse is a great phrase

something something olympic ring

ewiley
Jul 9, 2003

More trash for the trash fire

a foolish pianist posted:

managing tokens and keys seems to a big problem for smaller orgs. someone at my job left, and when we removed his personal keys, a couple of important services that he'd used his personal keys for broke.

poo poo made for a serious scramble.


At least you disabled his access, that's better than a lot of small orgs do.

ate shit on live tv
Feb 15, 2004

by Azathoth

spankmeister posted:

$45K a year is pretty good for an intern

I think that's what I pulled in when I was an intern. P-dece imo.

ate shit on live tv
Feb 15, 2004

by Azathoth

Pro as gently caress prob. A PROb if you will..

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
his new title is p dece

mod saas
May 4, 2004

Grimey Drawer

OSI bean dip posted:

his new title is p dece

on mobile/no avs what is it

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Adix posted:

on mobile/no avs what is it

Kazinsal
Dec 13, 2011
:shittypop: one of you is a fantastic bastard

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
i didn't do it but i will gladly take all the credit

Stymie
Jan 9, 2001

by LITERALLY AN ADMIN
taking credit for spending money on a forums grudge isn't the best move, frankly

but that's just me, with my dignity and all

LordSaturn
Aug 12, 2007

sadly unfunny

EDIT: oops forgot

motherfucker you're stymie

you're the eicar test pattern for no dignity

Stymie
Jan 9, 2001

by LITERALLY AN ADMIN
and yet i can confidently say i have never bought someone a red avatar, which puts me firmly in the plus column

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Stymie posted:

and yet i can confidently say i have never bought someone a red avatar, which puts me firmly in the plus column
the test results came back and your positive

grilldos
Mar 27, 2004

BUST A LOAF
IN THIS
YEAST CONFECTION
Grimey Drawer

Stymie posted:

and yet i can confidently say i have never bought someone a red avatar, which puts me firmly in the plus column

your avatar is very dope and good also

edit: it is nice that the text is red clearance

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Stymie posted:

taking credit for spending money on a forums grudge isn't the best move, frankly

but that's just me, with my dignity and all

:nsallears:

Asshole Masonanie
Oct 27, 2009

by vyelkin
that is one low bar for dignity

moonshine is......
Feb 21, 2007

https://trustfoundry.net/reverse-engineering-a-discovered-atm-skimmer/ basically it's a camera surprise surprise. But there's a cool vid of someone installing a swiper in a liquor store.

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

"someone (not naming names but she's my GF)" was possibly the most cringeworthy thing ever said in that thread

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Dex posted:

"someone (not naming names but she's my GF)" was possibly the most cringeworthy thing ever said in that thread

seriously like what was his motivation for posting that

spankmeister
Jun 15, 2008






i agree that AV is useless, all you need is combofix and tdsskiller

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

Tayter Swift posted:

current security status: password must be between 8 and 12 characters long and must contain a special character

the only special character allowed is an exclamation mark

1. Must be 12 - 16 characters long.
2. Cannot match your initial default password.
3. Must start with a letter.
4. Must contain at least one number in character positions 2 thru 7, inclusive.
5. Cannot match the employee ID.
6. Must contain at least one upper case letter.
7. Must contain at least one lower case letter.
8. Must contain at least one special character (e.g. !, @, #, $, % ) within the password.
9. Cannot be the same password the user had before.
10. Cannot match any of the previous 24 passwords used.

Su-Su-Sudoko
Oct 25, 2007

what stands in the way becomes the way

ultramiraculous posted:

10. Cannot match any of the previous 24 passwords used.

lol

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
hunter26

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

ultramiraculous posted:

10. Cannot match any of the previous 24 passwords used.

this is the ad policy at my work. im up to $LONGPASSPHRASE + "16" now

ate shit on live tv
Feb 15, 2004

by Azathoth
Season or Month + Year + ! for all your dumbass password requirement needs.

Password Manager for everything else.

suffix
Jul 27, 2013

Wheeee!

Subjunctive posted:

from someone smarter than me:

i'm seriously starting to wonder if the nsa is releasing stuff they want public through microsoft now :tinfoil:

this is the same group that was "sabotaging" the cfrg's curve standardization
they kept pushing some crap curves that no one wanted because they're slow for no benefit
most curves try to use a prime like 2x - n where n is pretty small for efficiency, but ms hosed their performance by insisting on some dumb prime picking procedure they claimed was more "rigid" that happened to give pretty large n
https://research.microsoft.com/en-us/projects/nums/

eventually curve25519 won out of course, it's well established and has great performance

so some months later (too late), they come out with a new curve which is actually faster than curve25519 at comparable security, wow, great job, that would have been a real contender 6 months ago.
(it's still not over a field like 2x - n, they used another form that is fast as well)
https://research.microsoft.com/en-us/projects/fourqlib/

and now an almost practical quantum-safe DH just when nist is starting to make noises about post-quantum crypto
it's just great work and well timed

of course this is very :tinfoil: but who doesn't love a good conspiracy theory?
and there are other unbelievable parts of the story like
- microsoft research making anything directly useful
- djb being outperformed by a team of only five people

suffix
Jul 27, 2013

Wheeee!
this is pretty interesting: https://bits-please.blogspot.com/2016/05/qsee-privilege-escalation-vulnerability.html

quote:

In this blog post we'll discover and exploit a vulnerability which will allow us to gain code execution within Qualcomm's Secure Execution Environment (QSEE).
...
communication with TrustZone exposes a large (!) attack surface - if any trustlet that can be loaded on a particular device contains a vulnerability, we can exploit it in order to gain code execution within the trusted execution environment. Moreover, since the trusted execution environment has the ability to map-in and write to all physical memory belonging to the "Normal World", it can also be used in order to infect the "Normal World" operating system's kernel without there even being a vulnerability in the kernel
...
Because of the dangers outlined above, the access to this device is restricted to the minimal set of processes that require it. A previous dive into the permissions required in order to access the driver has shown that only four processes are able to access "qseecom":
surfaceflinger (running with "system" user-ID)
drmserver (running with "drm" user-ID)
mediaserver (running with "media" user-ID)
keystore (running with "keystore" user-ID)
...
Previously, we decided to focus our research efforts on the "widevine" trustlet, which enables playback of DRM encrypted media using Widevine's DRM platform. This trustlet seems like a good candidate since it is moderately complex (~125KB) and very wide-spread (according to their website, it is available on over 2 billion devices).

list of critical applications that should be trusted with access to write anywhere in the kernel:
the media player
yeah, that thing that decodes files in a bazillion formats
files from the internet
but wait, the privileged rootkit access will be guarded by a highly trusted secure api
it's so trustable we call it a trustlet
we hired some dropouts from securom and safedisc to write it

Stymie
Jan 9, 2001

by LITERALLY AN ADMIN

Power Ambient posted:

that is one low bar for dignity

agreed, and yet folks fail to clear even that

ewiley
Jul 9, 2003

More trash for the trash fire

suffix posted:

this is pretty interesting: https://bits-please.blogspot.com/2016/05/qsee-privilege-escalation-vulnerability.html


list of critical applications that should be trusted with access to write anywhere in the kernel:
the media player
yeah, that thing that decodes files in a bazillion formats
files from the internet
but wait, the privileged rootkit access will be guarded by a highly trusted secure api
it's so trustable we call it a trustlet
we hired some dropouts from securom and safedisc to write it

What a cute little trustlet, it won't bite will it?

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



a trustlet for when you just need a lil bit of trust

Adbot
ADBOT LOVES YOU

Midjack
Dec 24, 2007



moonshine is...... posted:

https://trustfoundry.net/reverse-engineering-a-discovered-atm-skimmer/ basically it's a camera surprise surprise. But there's a cool vid of someone installing a swiper in a liquor store.

the usb interface appears similar to the ones i've pulled up so I guess it's an industry standard

he said he'd used that atm before so either he got skimmed already or there was a real shield at first. not sure there's a new skimmer at the end of the story though, likely the skimmer replaced a legit shield and the bank put a new shield back on

  • Locked thread