Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
pixaal
Jan 8, 2004

All ice cream is now for all beings, no matter how many legs.


EAT THE EGGS RICOLA posted:

Cryptolocker yourself but have the bitcoin wallet address be one that you control and see if they'll pay.

That might actually be breaking the law, one you are getting 2 scammers to scam each other, the other you are scamming a scammer and stealing stolen money.

Adbot
ADBOT LOVES YOU

Arsten
Feb 18, 2003

pixaal posted:

That might actually be breaking the law, one you are getting 2 scammers to scam each other, the other you are scamming a scammer and stealing stolen money.

Yes, but who is going to report it?

"Hello, police? We were trying to steal this guy's information and we paid for a cryptolocker unlock and it turns out he crypto'ed this himself and scammed us into paying a bitcoin! Can you have him arrested?"
"Sure. We'll be right over to....take a statement."

EAT THE EGGS RICOLA
May 29, 2008

It's for sure illegal but:

1) they're never going to realize what you did
2) See Arsten's post.

Edit: Actually I wonder if it would be illegal at all. "Oh yeah I have a cryptolocker thing on my computer and don't have the bitcoin to unlock it" is certainly not a lie in any way.

EAT THE EGGS RICOLA fucked around with this message at 14:36 on Jun 2, 2016

BaseballPCHiker
Jan 16, 2006

demonicon posted:

Totally not pissing me off:

My current job requires a 90 minute commute (on good days) and this just wasn't doable anymore after 2 years. Especially because since I am in a new relationship I am not able to move to my job location anymore. So what I did was looking for a new job with a lot less commute. Signed a new contract last week on tuesday for a job with a 20 minute commute and 10% more pay, starting at 1/9.

So I had a few days left to give my notice. According to my contract the notice period is 3 months (I live in Germany). So I went to the office signed notice in hand and was about to go to my manager, when our director called me to his office. With a grave face he told me that there was a necessary restructuring underway and that my department was likely being made redundant. He offered me a severance package and said that if I agreed to not being fired but instead signed a mutual agreement to leave that they would release me today and pay me until 1/9.

I signed immediately and went out with a wtf face that lasted for a few days. I think I am still wearing it today trying to understand the fact that I was paid a lot of money to accept a paid vacation for 3 months to leave a company that I wanted to leave anyway.

I don't think anyone has ever been more glad to be fired...

That sounds amazing. I think about all of things I could get done and learn with even just a month off. Congratulations you're living the dream.

A former company I worked for did this. The writing was on the wall and I got out early. A friend who stayed behind got 6 months severance pay, gave him enough time to study and get a few new certs and then find an even better job.

Bigass Moth
Mar 6, 2004

I joined the #RXT REVOLUTION.
:boom:
he knows...
Guy just called returning the call of the person I replaced who left two months ago to complain about his iPhone not syncing the calendar. I explained that I manage the voip system and he should contact apple and he got pissed. Sorry you forgot your password dude.

Sirotan
Oct 17, 2006

Sirotan is a seal.




We all know its true.

pixaal
Jan 8, 2004

All ice cream is now for all beings, no matter how many legs.


Sirotan posted:



We all know its true.

I thought it was +1 per ASCII value, what encoding method is this and what are the 5 missing numbers between each letter for?

DigitalMocking
Jun 8, 2010

Wine is constant proof that God loves us and loves to see us happy.
Benjamin Franklin

Daylen Drazzi posted:

I'm waiting for the dick-punch that invariably comes when too many good things happen to me all at once.

Mods, pls revert and do the needful.

More poo poo that pisses you off: Waiting for the dick-punch.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

pixaal posted:

I thought it was +1 per ASCII value, what encoding method is this and what are the 5 missing numbers between each letter for?
It's A=1,B=2... and then multiplied by six? Except they hosed up and made Y=160 and Z=166 instead of 150 and 156.

Sirotan
Oct 17, 2006

Sirotan is a seal.


pixaal posted:

I thought it was +1 per ASCII value, what encoding method is this and what are the 5 missing numbers between each letter for?

That's exactly what the computers wanted you to ask!! :spooky:

xzzy
Mar 5, 2009

You're asking for logic from numerologists, that was where you went wrong.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
The on call guy tonight is taking the day off. Nobody stepped up to volunteer to take his shift, so numbers were drawn. I won the on call lotto and also have outstanding plans that have been in place for a couple weeks for this evening. I love my luck sometimes. Here's to hoping nobody calls in cause the response time isn't going to be very flattering. gently caress.

kensei
Dec 27, 2007

He has come home, where he belongs. The Ancient Mariner returns to lead his first team to glory, forever and ever. Amen!


Vendors and returns piss me off. Honestly, that's all that needs to be said.

xzzy
Mar 5, 2009

That's kind of bullshit you got no one in your group willing to fall on that grenade, even it's for consideration on a future conflict.

It's super easy to get time off where I'm at, even if you're on call. Because we all like each other and get along.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Yeah but what can you do. The guys all get along great, so don't know why nobody took this one before it went to a lotto. Hell I would have volunteered for it if I didn't have previous engagements. I'm just bringing my laptop and work phone out with me and if anyone calls they can deal with my suboptimal response time; but it's better than no response at all.

porktree
Mar 23, 2002

You just fucked with the wrong Mexican.

Sirotan posted:



We all know its true.

This also works with Kissinger - who is still not dead!

stevewm
May 10, 2005
Teamviewer can lie about it all they want, they have definitely been breached. The reports keep pouring in: https://www.reddit.com/r/teamviewer/

A few IT colleagues I pointed out the breach to also discovered unauthorized logins to their account, even with two factor turned on!

Inspector_666
Oct 7, 2003

benny with the good hair

stevewm posted:

Teamviewer can lie about it all they want, they have definitely been breached. The reports keep pouring in: https://www.reddit.com/r/teamviewer/

A few IT colleagues I pointed out the breach to also discovered unauthorized logins to their account, even with two factor turned on!

Godammit what the hell am I gonna use to remotely support my parents now.

Thanks Ants
May 21, 2004

#essereFerrari


They are handling this issue so loving badly.

Siochain
May 24, 2005

"can they get rid of any humans who are fans of shitheads like Kanye West, 50 Cent, or any other piece of crap "artist" who thinks they're all that?

And also get rid of anyone who has posted retarded shit on the internet."


Inspector_666 posted:

Godammit what the hell am I gonna use to remotely support my parents now.

Same boat here. No clue what to use now :/

Inspector_666
Oct 7, 2003

benny with the good hair

Thanks Ants posted:

They are handling this issue so loving badly.

I don't understand how the attackers are sidestepping 2FA.

stevewm
May 10, 2005
Whats worse is that some people are seeing connections as far back as the end of March in their logs.

BaseballPCHiker
Jan 16, 2006

Siochain posted:

Same boat here. No clue what to use now :/

This really sucks. It's bad enough for me just using it to help out my family and friends with the occasional issue, I can't imagine how awful this will turn out to be for commercial users.

I can't think of any good alternative either.

xzzy
Mar 5, 2009

VNC. It's free and has no issues whatsoever! :buddy:

(chrome remote desktop is pretty cool too, for personal use at least)

Thanks Ants
May 21, 2004

#essereFerrari


I tried Chrome Remote Desktop but it had issues with UAC prompts

stevewm
May 10, 2005
I would hate to be the person behind their Twitter account right now: https://twitter.com/TeamViewer_help/with_replies

BaseballPCHiker
Jan 16, 2006

xzzy posted:

VNC. It's free and has no issues whatsoever! :buddy:

(chrome remote desktop is pretty cool too, for personal use at least)

Doesnt VNC send everything unencrypted though, like you'd have to setup ssh tunnels between hosts to be on a secure connection?

Deformed Church
May 12, 2012

5'5", IQ 81


stevewm posted:

I would hate to be the person behind their Twitter account right now: https://twitter.com/TeamViewer_help/with_replies

Poor Julia.

xzzy
Mar 5, 2009

BaseballPCHiker posted:

Doesnt VNC send everything unencrypted though, like you'd have to setup ssh tunnels between hosts to be on a secure connection?

Yes, VNC is actually pretty terrible. Its only strength is it runs on everything.

Slack3r
Feb 20, 2004
I'm not too sold on the "TeamViewer was compromised" thing yet.. I was freaking out yesterday when they were down as I maintain 110 remote systems for our company. Seems that TV doesn't really randomize the default passwords and they are somewhat guessable or brute-forceable. Thinking that with the HUGE install base of TV, and the default security, it's easy to gain access.

If you pay for TV, you can define policies for all settings to push out instantly. I have since shoved strict whitelists, 2FA, disabled random password login and changed all passwords to crazy generated ones.

Setting account passwords and locking the workstation goes a long way also.

Update:

Login to the teamviewer management console website here: https://login.teamviewer.com/nav/home

Then in the upper right corner click on your username and edit profile, then click on "Active Logins", for me it lists every device and location in the last year that accessed my account.

Slack3r fucked around with this message at 22:10 on Jun 2, 2016

MC Fruit Stripe
Nov 26, 2002

around and around we go
It's almost a philosophical question - if you use the bare minimum security an application which provides access to your PC offers, is that application still responsible for a breach?

I would like to see tangible evidence of a breach on 2FA.

FlapYoJacks
Feb 12, 2009
My dev board has the sound soc and camera on the same i2c bus. Thanks guys!

Thanks Ants
May 21, 2004

#essereFerrari


One of our customers has brought in a third party security firm to audit them, which I don't have a problem with. But they appear to have just run a scan and decided everything it flagged is an issue. Internal-only configuration page for an appliance? Not using a valid SSL cert signed by a CA, write it down! This sort of approach would prefer a non-HTTPS admin interface which sounds backwards.

Proteus Jones
Feb 28, 2013



Thanks Ants posted:

One of our customers has brought in a third party security firm to audit them, which I don't have a problem with. But they appear to have just run a scan and decided everything it flagged is an issue. Internal-only configuration page for an appliance? Not using a valid SSL cert signed by a CA, write it down! This sort of approach would prefer a non-HTTPS admin interface which sounds backwards.

If you only need the certificate to set up encrypted communication and don't care about authenticating the legitimacy of the service you're connecting to (which is typical for internal systems), then who cares.

A lot of these fly-by-night "security" companies basically use scanning software with default settings and their "customized reports" are simply a PDF of the results generated by the scan. If it's an overall assessment of your security profile, any team worth its salt will take time to understand your environment and what your needs are from a security perspective.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
:ssj:

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

BaseballPCHiker posted:

Doesnt VNC send everything unencrypted though, like you'd have to setup ssh tunnels between hosts to be on a secure connection?

Plain old VNC does, but there are various pairs of clients and servers that have extended the VNC protocol to include encryption, and not bad encryption at that. RealVNC and UltraVNC both offer this.

FlapYoJacks
Feb 12, 2009

flosofl posted:

If you only need the certificate to set up encrypted communication and don't care about authenticating the legitimacy of the service you're connecting to (which is typical for internal systems), then who cares.

A lot of these fly-by-night "security" companies basically use scanning software with default settings and their "customized reports" are simply a PDF of the results generated by the scan. If it's an overall assessment of your security profile, any team worth its salt will take time to understand your environment and what your needs are from a security perspective.

No, the security team is right and they should have a internal CA to Auth against.

Thanks Ants
May 21, 2004

#essereFerrari


Probably wasn't clear enough in the post - their issue with the cert was that it didn't come from a public provider, not that it was specifically self-signed. As in they want to see a valid Verisign or whatever certificate on the device for a domain that doesn't exist in public DNS.

Thanks Ants fucked around with this message at 00:24 on Jun 3, 2016

FlapYoJacks
Feb 12, 2009

Thanks Ants posted:

Probably wasn't clear enough in the post - their issue with the cert was that it didn't come from a public provider, not that it was specifically self-signed. As in they want to see a valid Verisign or whatever certificate on the device for a domain that doesn't exist in public DNS.

Oh, then yeah, that's utter Bullshit.

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


I had the discussion with the testing people and they were happy if I turned HTTPS off on the device so people had to use HTTP because then it wouldn't give a cert error :downs:. I have advised this customer not to work with them any more.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply