Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Shame Boy
Mar 2, 2010

not at all security related really but i bought the cheap VPS plan on a cheap poo poo-tier hosting provider just to see if it's acceptable for a dinky little website project i'm doing and this guy was on the order confirmation page and i think you guys should meet him:

Adbot
ADBOT LOVES YOU

Truga
May 4, 2014
Lipstick Apathy
i'm the pee plug

spankmeister
Jun 15, 2008






flakeloaf posted:

well i don't think windows defender hasn't done this recently so it may not be a terrible idea

trigger warning that linkedin link pls

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

flakeloaf posted:

well i don't think windows defender hasn't done this recently so it may not be a terrible idea

They fixed it inside 3 days I believe through the sig update channel. It was stupid and there's still issues with the scanning/heuristic engine running under the system context so that could still come back to bite them in the rear end again but they also do things like aggressively tracking of hosts/urls distributing malware and kill the connection before any payload can come in so its not completely worthless.

flakeloaf
Feb 26, 2003

Still better than android clock

something like google's safe browsing but on things that aren't http?

i certainly wouldn't say it's worthless, but whether it's worth more or less than any other desktop av :shrug:

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://twitter.com/troyhunt/status/730034943657574409

quite the breach, if i do say so myself.

https://motherboard.vice.com/read/rosebuttboard-ip-board

quote:

Hunt obtained the data, which includes usernames, email addresses, IP addresses, and passwords hashed with the notoriously weak MD5 algorithm, along with a salt for some 107,303 accounts, and verified its authenticity.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

flakeloaf posted:

something like google's safe browsing but on things that aren't http?

i certainly wouldn't say it's worthless, but whether it's worth more or less than any other desktop av :shrug:

It's definitely hard to quantify the impact since it will kick in before any of the browser-based protections and there's bound to be overlap but it will also check any HTTP connection so if a dedicated process is trying to phone back to a known malware host it will kill the connection. the default config for every single install effectively becomes a honeypot that will feed back infection data to map malware networks which is useful

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


MD5 passwords so at least it isn't TBC's site

Sulfrasta
Dec 15, 2015

BangersInMyKnickers posted:

They fixed it inside 3 days I believe through the sig update channel. It was stupid and there's still issues with the scanning/heuristic engine running under the system context so that could still come back to bite them in the rear end again but they also do things like aggressively tracking of hosts/urls distributing malware and kill the connection before any payload can come in so its not completely worthless.

so keep eset then probably?

Shame Boy
Mar 2, 2010

Truga posted:

i'm the pee plug



judging by the file names he's called "server mannequin" which makes this even creepier

nitrogen
May 21, 2004

Oh, what's a 217°C difference between friends?

CRIP EATIN BREAD posted:

i just switched to a credit union and they enforce passwords 6-10 characters long.

altho EVERY TIME you login they ask you a different security question. all the options were poo poo that didnt apply (where did you meet your spouse) to dumb pop culture poo poo that doesnt seem to work long term (what is your favorite band, who is your favorite actor/actress).

who can justify a 6-10 character password for a loving bank.

i hope someone steals my credentials and votes for a lovely board member

That's still better than AMEX, which has CASE INSENSITIVE passwords...

flakeloaf
Feb 26, 2003

Still better than android clock

So does battle.net but at least they use 2fa

we live on a planet where it's harder to break into a warcraft account than a bank account

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
a forum focused around “extreme anal dilation and anal fisting,” according to security researcher Troy Hunt.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Sulfrasta posted:

so keep eset then probably?

or go MSE and find some other tool that will do IP/URL blacklisting I guess

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

flakeloaf posted:

So does battle.net but at least they use 2fa

we live on a planet where it's harder to break into a warcraft account than a bank account

yeah well nobody has money in their bank account

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

BangersInMyKnickers posted:

yeah well nobody has money in their bank account

:thurman:

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

pounded in the butt by their own sql injection

LordSaturn
Aug 12, 2007

sadly unfunny

Parallel Paraplegic posted:

not at all security related really but i bought the cheap VPS plan on a cheap poo poo-tier hosting provider just to see if it's acceptable for a dinky little website project i'm doing and this guy was on the order confirmation page and i think you guys should meet him:




Parallel Paraplegic posted:



judging by the file names he's called "server mannequin" which makes this even creepier

I see you've met our mascot, Pozzie the Unpatched Server

flakeloaf
Feb 26, 2003

Still better than android clock

lotta bug chasers itt

Dolomite
Jul 26, 2000
Cars & Legs


leave kirk johnson alone!!

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Chris Knight posted:

pounded in the butt by their own sql injection

:golfclap:

AllTerrineVehicle
Jan 8, 2010

I'm great at boats!

Chris Knight posted:

pounded in the butt by their own sql injection

a secfuck indeed

Haquer
Nov 15, 2009

That windswept look...

https://twitter.com/troyhunt/status/730035057960751104

https://twitter.com/troyhunt/status/730036184651431937



also

As the film ends, the camera reveals that "Rosebutt" is the trade name of the sled on which the eight-year-old Kane was playing on the day that he was taken from his home in Colorado

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://blog.cylance.com/know-the-truth-signatures-and-multi-av-scanners

quote:

Contrary to competitors, reporters and bloggers who’ve never seen, much less used, our products, we don’t use or rely on signatures or multi-AV scanners or traditional AV scanners. Period. Full stop.

Why? Because at the end of the day, we just don’t trust anyone, especially the AV industry. We have collected samples sourced from countless places to train our machine learning models ourselves and by doing so have created an insanely high efficacy rate measured countless times well above 90% and often well over 99% by volume. This is in an antivirus industry that can barely break the 50% efficacy ceiling (even with their sharing of convictions among themselves called "reputation"). In other words, we don’t need to know or for that matter, care about anyone else’s convictions.


But as it goes with the cybersecurity sewing circle sometimes, competitors will spread FUD and commonly confuse the market with HOW we do what we do. They don’t fully understand what we are doing or how we are doing it so they grasp at straws to understand it. So try to look past their unfounded claims. When you hear FUD in our industry just ask yourself, would the person perpetuating it have any motivation to spread misinformation? If so, feel free to use your ear muffs. And of course, test yourself.

Over the past two years we have shown countless times how antiquated and archaic antivirus technology truly is. We show how obfuscated and mutated live samples can easily bypass both traditional and "next-gen" AV vendors in our "Unbelievable Tour" every week. We were the only ones to demonstrate our efficacy without relying on an internet connection, without requiring any cloud uploads, and certainly without ever needing the judgment of a 30-year-old industry to tell us right from wrong, good from bad.

As for Cylance? We’re going to continue speaking the truth to protect and empower our customers and those who desperately need the protection our products provide. So don’t trust anyone. Don’t trust the "independents". Don’t trust the bloggers or the reporters. Don’t trust the vendors. Don’t trust us! Please, please, please, just trust yourself. Test for yourself. Only then will you believe.

P.S. - Oh, and if you’re evaluating endpoint protection technologies right now, you might want to re-test their detections this week (including ours) in both connected and disconnected states. Only then will the truth will be known. Want to know more about CylancePROTECT® really works? Read our Math vs. Malware white paper here.
Blog_Hdr_Thumb_World6.jpg

someone at cylance seems mad about people calling them out for their dumb tactics

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

OSI bean dip posted:

https://blog.cylance.com/know-the-truth-signatures-and-multi-av-scanners


someone at cylance seems mad about people calling them out for their dumb tactics

they are just taunting the wrath of taviso, aren't they

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Captain Foo posted:

they are just taunting the wrath of taviso, aren't they

would he even be able to get a copy of the thing with how NDA-happy they are? this "verify but don't talk to anyone about it" tactic reeks of bullshit

crusader_complex
Jun 4, 2012

OSI bean dip posted:

someone at cylance seems mad about people calling them out for their dumb tactics

reads like bitcoin bingo

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

BangersInMyKnickers posted:

would he even be able to get a copy of the thing with how NDA-happy they are? this "verify but don't talk to anyone about it" tactic reeks of bullshit

eh, should be a put up or shut up thing for them, but it won't be

Sharktopus
Aug 9, 2006

flakeloaf posted:

we live on a planet where it's harder to break into a warcraft account than a bank account

it's very clear exactly why this is imo

uninterrupted
Jun 20, 2011

OSI bean dip posted:

https://blog.cylance.com/know-the-truth-signatures-and-multi-av-scanners


someone at cylance seems mad about people calling them out for their dumb tactics

has anyone ever used the phrase FUD outside of defending a scam?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

flakeloaf posted:

well i don't think windows defender hasn't done this recently so it may not be a terrible idea
this is a giant linkedin article written by an "Enterprise Security Advisor" at symantec and the title namedrops like all of their av competitors, so the grey thread might actually listen to this one

Sulfrasta
Dec 15, 2015

quote:

"... the CMS Levin logged in to had also been retired and replaced with one that ran WordPress."

that is a strange thing to brag about.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

uninterrupted posted:

has anyone ever used the phrase FUD outside of defending a scam?

I use it to describe the pitch from every single DCS salesman I've ever met. Industrial controls is a open sewer of a tech sector

Shame Boy
Mar 2, 2010

Sulfrasta posted:

that is a strange thing to brag about.

the other day i was walking behind two guys talking about how their new company site was WordPress because it was "the best in the industry" and i just kinda burst into quiet snickering

Sharktopus
Aug 9, 2006

http://www.dailydot.com/politics/encryption-crypto-wars-police-indiana-charles-cohen-interview/

there are too many gems in this article to individually quote

but rest assured its not a zero-sum article

gonadic io
Feb 16, 2011

>>=

Sharktopus posted:

it's very clear exactly why this is imo

see how pizzas often get to you faster than an ambulance would

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug
relevant

http://fortune.com/2016/05/10/pornhub-bug-bounty-program-hackerone/

ate shit on live tv
Feb 15, 2004

by Azathoth

Ulf posted:

i was going through this yesterday and thank you for trying so that i did not have to

"what was your favorite class in high school" [dropdown of 5,000 possible answers]

5000? Lol try like 3.

What's that you forgot your password? Well lets verify your identity via 5 static questions with 3 possible answers each.

ate shit on live tv
Feb 15, 2004

by Azathoth

Malloc Voidstar posted:

a forum focused around “extreme anal dilation and anal fisting,” according to security researcher Troy Hunt.

He actually goes by Mike.

Adbot
ADBOT LOVES YOU

Sharktopus
Aug 9, 2006

gonadic io posted:

see how pizzas often get to you faster than an ambulance would

ur my new fav poster

  • Locked thread