Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Tayter Swift
Nov 18, 2002

Pillbug
trustr

Adbot
ADBOT LOVES YOU

jetz0r
May 10, 2003

Tomorrow, our nation will sit on the throne of the world. This is not a figment of the imagination, but a fact. Tomorrow we will lead the world, Allah willing.



Midjack posted:

the usb interface appears similar to the ones i've pulled up so I guess it's an industry standard

he said he'd used that atm before so either he got skimmed already or there was a real shield at first. not sure there's a new skimmer at the end of the story though, likely the skimmer replaced a legit shield and the bank put a new shield back on
https://www.youtube.com/watch?v=XBMK7C_HwI4

but as a card skimmer

A Man With A Plan
Mar 29, 2010
Fallen Rib

there is no such thing as irony https://www.facebook.com/TrustRApp/

Shame Boy
Mar 2, 2010

woo i get to post something i heard on the local news for once

http://www.tbo.com/news/business/tampa-international-to-conduct-new-audit-after-potential-security-breach-20160502/

quote:

A consultant working in the airport’s computer system to upgrade business intelligence software in 2014 and 2015 shared his user name and password with people in foreign countries who logged into the system dozens of times from places like Mumbai and Pradesh, India, United Arab Emirates and Kashmir, India.

Those unusual log-ins ledseveral employees at the airport to voice concerns over potential security breaches. One employee sent an anonymous email to managers. They warned that consultant Gautham Sampath may have allowed those unauthorized people in foreign countries to access sensitive information, including employee Social Security numbers and a secure terrorism-related no-fly list.

Sampath told investigators the people he gave his network access to were helping him upgrade software on the system.

Lopano said that anonymous email kicked off a security audit. The Aviation Authority hired an outside security consultant to conduct the audit, but that audit was “unable to determine specifically what data may have been transferred,” the final report stated.

Lopano and other airport officials continue to say there is no evidence a breach of any sensitive information occurred. The airport is paying Vaco Risk Solutions $127,400 to conduct the new audit. It is paying business consulting firm Plante Moran $80,000 to assess its IT department.

i too dream of one day farming out all of my work to third world contractors for pennies :allears:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

OpenSSL regressed Lucky 13, meet the new padding oracle attack same as the old one: https://mta.openssl.org/pipermail/openssl-announce/2016-May/000072.html

Shaggar
Apr 26, 2006
i didn't think anyone was still using openssl.

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Midjack posted:

the usb interface appears similar to the ones i've pulled up so I guess it's an industry standard

he said he'd used that atm before so either he got skimmed already or there was a real shield at first. not sure there's a new skimmer at the end of the story though, likely the skimmer replaced a legit shield and the bank put a new shield back on
I never understood this from an aesthetic perspective; you could easily make atms that are just flat plexiglass with a slot that fits a CC exactly. Why don't they design the atms to both look futuristic and remove the ability to attach skimmers to it without people noticing? Instead they're going in the other direction, attaching increasingly large and ridiculous multi-colored shields which are indistinguishable from skimmers themselves

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

i didn't think anyone was still using openssl.
there are people using openssl on windows server, right now

Shaggar
Apr 26, 2006
hosed up if true

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

hosed up if true
agreed but i believe the libressl folks are more worried about getting a functional implementation right now than porting it everywhere

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Bhodi posted:

I never understood this from an aesthetic perspective; you could easily make atms that are just flat plexiglass with a slot that fits a CC exactly. Why don't they design the atms to both look futuristic and remove the ability to attach skimmers to it without people noticing? Instead they're going in the other direction, attaching increasingly large and ridiculous multi-colored shields which are indistinguishable from skimmers themselves

cost, durability, accessibility, repairability, etc

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Cocoa Crispies posted:

cost, durability, accessibility, repairability, etc
it smells to me more like bandaids rather than a concern incorporated into the base design, you can use the same materials, you just need to make everything flush

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

Shaggar posted:

hosed up if true

shaggar was right

ErIog
Jul 11, 2001

:nsacloud:

Bhodi posted:

it smells to me more like bandaids rather than a concern incorporated into the base design, you can use the same materials, you just need to make everything flush

How is the user supposed to know the slot is supposed to be flush? There's lots of different ATM designs all around the world, and I bet there are cases where even a bank of multiple ATM's at a bank have slightly different form factors.

This isn't a problem that can be solved with any change in physical form factor because the user has to know what the ATM should look like before they can tell if it's been modified. So you'd need to do something like showing a picture of the card slot on the screen and telling the user to check to make sure the card slot looks the same as the picture.

Solving the pin entry being recorded is a slightly harder problem, but making the plastic hardware that surrounds the input pad thinner would make it harder for someone to hollow them out to insert a camera.

ErIog fucked around with this message at 16:44 on May 3, 2016

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

anthonypants posted:

there are people using openssl on windows server, right now

I put ours behind an IIS reverse proxy because gently caress Apache/OpenSLL. schannel 4 lyfe

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

ErIog posted:

How is the user supposed to know the slot is supposed to be flush? There's lots of different ATM designs all around the world, and I bet there are cases where even a bank of multiple ATM's at a bank have slightly different form factors.
true, but I mean trying to integrate it into an overall design such that adding anything to it would look weird. It may not be possible but it might be something to try. Imagine trying to put a skimmer onto what amounts to an ipad with a slot; if it doesn't fit inside the slot people would notice it immediately

well, they would if we weren't already accustomed to weirdly shaped shields. which was my point

Shame Boy
Mar 2, 2010

I always yank at the card slot vigorously before any transaction

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Parallel Paraplegic posted:

I always yank at the card slot vigorously before any transaction
please sir, stop accosting our CC machine or we're going to have to ask to you leave target

Su-Su-Sudoko
Oct 25, 2007

what stands in the way becomes the way

Parallel Paraplegic posted:

I always yank at the card slot vigorously before any transaction

uh
text me?

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
some ATMs show a photo/diagram of what the ATM is supposed to look like on the screen, I wonder if it's a good measure

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

hackbunny posted:

some ATMs show a photo/diagram of what the ATM is supposed to look like on the screen, I wonder if it's a good measure

lol if u think

Shaggar
Apr 26, 2006

anthonypants posted:

agreed but i believe the libressl folks are more worried about getting a functional implementation right now than porting it everywhere

the correct choice is schannel

Shaggar
Apr 26, 2006

BangersInMyKnickers posted:

I put ours behind an IIS reverse proxy because gently caress Apache/OpenSLL. schannel 4 lyfe

Phone
Jul 30, 2005

親子丼をほしい。

hackbunny posted:

some ATMs show a photo/diagram of what the ATM is supposed to look like on the screen, I wonder if it's a good measure

Wiggly Wayne DDS
Sep 11, 2010



https://medium.com/@rhuber/imagemagick-is-on-fire-cve-2016-3714-379faf762247

quote:

There are multiple vulnerabilities in ImageMagick, a package commonly used by web services to process images. One of the vulnerabilities can lead to remote code execution (RCE) if you process user submitted images. The exploit for this vulnerability is being used in the wild.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

there are always vulnerabilities in ImageMagick. sandbox that poo poo for christ's sake.

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.

https://imagetragick.com/

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope
i make all my gifs with imagemagick.

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.

Wheany posted:

i make all my gifs with imagemagick.
lmao
imagemagick makes terrible gifs

Shame Boy
Mar 2, 2010

i switched to GraphicsMagick years ago and am secure in the knowledge that less people use it so i probably will not find out about security vulnerabilities and feel safe

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
imagemagick allowed me to make huge.jpg back in 2001 :unsmith:

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

imagemagick allowed me to make huge.jpg back in 2001 :unsmith:

you monster

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Parallel Paraplegic posted:

i switched to GraphicsMagick years ago and am secure in the knowledge that less people use it so i probably will not find out about security vulnerabilities and feel safe

brb running afl on graphicsmagick

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Malloc Voidstar posted:

lmao
imagemagick makes terrible gifs

fight me irl

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.

Wheany posted:

fight me irl
it has absolute garbage dithering/optimization

i use a weird workflow of imagemagick+pngquant+gifsicle to avoid that and make hq gifs
the only other thing i know that has similar quality is photoshop (it's worse)

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
I wonder if mrtg and other visualization tools still have imagemagik bundled deps

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

OSI bean dip posted:

imagemagick allowed me to make huge.jpg back in 2001 :unsmith:

you son of a bitch :unsmith:

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

i use ffmpeg to make gifs

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

this is extremely my poo poo

Adbot
ADBOT LOVES YOU

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

Parallel Paraplegic posted:

i switched to GraphicsMagick years ago and am secure in the knowledge that less people use it so i probably will not find out about security vulnerabilities and feel safe

my only open source contribution of the last like 5 years was an RCE fix in graphicsmagick that i found because i was doing

OSI bean dip posted:

brb running afl on graphicsmagick

that

  • Locked thread