Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
still glad i paid for 1password

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

anthonypants posted:

still glad i paid for 1password

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

COACHS SPORT BAR posted:

I'm the oddly disjointed 5 paragraphs of explanation about why this isn't a problem, followed by "OK fine we're using signatures and https now".
it would not be a problem if everyone magically knew in advance to get it from sourceforge

he claims https is used for version checking but keepass.info still does not support https. i cbf looking into the source or w/e, but is the version checking now from a different domain, the same domain but somehow done in a bad but almost okay way with cert pinning or whatever, or from the same domain and not actually validating the lovely cert it serves? place your bets!

more importantly (since falsely reporting a new version isn't really an issue on its own), when it thinks there is a new version, has it been fixed to take you straight to sourceforge, or is it still going to the easily hijackable keepass.info like i assume he still wants it to because he apparently serves ads? vote now on your phones!

Heresiarch
Oct 6, 2005

Literature is not exhaustible, for the sufficient and simple reason that no single book is. A book is not an isolated being: it is a relationship, an axis of innumerable relationships.
i can sort of understand the belief that it wasn't a critical problem because there's no auto-update feature, so all you can mitm is a fake "there's a new version" message, possibly wasting somebody's time while they go to download the new version and discover that they've been pranked

the "we can't do it because of advertising revenue" response was the really loving bizarre and unsettling part. if they'd said "we're aware but because there's no auto-update this is a low-priority issue" then i imagine the response wouldn't have been nearly as strong

Westie
May 30, 2013



Baboon Simulator
one of my VMs got infected and brought into botnet somehow, anyone interested in files?

Heresiarch
Oct 6, 2005

Literature is not exhaustible, for the sufficient and simple reason that no single book is. A book is not an isolated being: it is a relationship, an axis of innumerable relationships.

Westie posted:

one of my VMs got infected and brought into botnet somehow, anyone interested in files?

mods please ban for :filez:

Westie
May 30, 2013



Baboon Simulator
:(

Westie
May 30, 2013



Baboon Simulator
on the plus side only one VM was infected out of 10! which, is, well, a bonus

Wiggly Wayne DDS
Sep 11, 2010



Westie posted:

one of my VMs got infected and brought into botnet somehow, anyone interested in files?
well which one then

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i'm considering dropping keepass in favour of 1password or just outright writing my own keepass clone that uses its file format

Wiggly Wayne DDS
Sep 11, 2010



have you got your backer tiers sorted out before you go live?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Wiggly Wayne DDS posted:

have you got your backer tiers sorted out before you go live?

$1 - you can poo poo on my kickstarter
$10 - you can find out my phone number
$100 - you can find out where i live
$1000 - you can spend the night at my house
$10000 - you can have the source code

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:

i'm considering dropping keepass in favour of 1password or just outright writing my own keepass clone that uses its file format
1password has a wifi sync that uses bonjour and can also sync to the icloud keychain which is pretty slick imho

Westie
May 30, 2013



Baboon Simulator

Wiggly Wayne DDS posted:

well which one then

not too sure, i'll put it on virus total to see what shows, however, looking at the output of `ps faux` it looks like it's an exploit on ajenti

i thought i had uninstalled that a loving decade ago

flakeloaf
Feb 26, 2003

Still better than android clock

i'll pledge a dollar to start the unfounded slanderous character assassination

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

anthonypants posted:

still glad i paid for 1password

faxlore
Sep 24, 2014

a blue star tattoo for you!

is 1password better than lastpass?

Wiggly Wayne DDS
Sep 11, 2010



faxlore posted:

is 1password better than lastpass?
yes?

i can poo poo on lastpass in detail again if you really want

faxlore
Sep 24, 2014

a blue star tattoo for you!

You can link me to a previous post, if you don't want to type it/copy paste it again.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Wiggly Wayne DDS posted:

breaches and vulnerabilities over years with no sign of change (up to dismissing public third party audits)

anthonypants posted:

also they're owned by logmein now, the company that bought hamachi back in the day

Wiggly Wayne DDS
Sep 11, 2010



faxlore posted:

You can link me to a previous post, if you don't want to type it/copy paste it again.
there was an argument over here that covered a lot of the details, otherwise

burning swine
May 26, 2004



jony ive aces posted:

he claims https is used for version checking but keepass.info still does not support https. i cbf looking into the source or w/e, but is the version checking now from a different domain, the same domain but somehow done in a bad but almost okay way with cert pinning or whatever, or from the same domain and not actually validating the lovely cert it serves? place your bets!

2.34 has not actually been released yet, but I'm going to have a look at the source as soon as it's available. I wouldn't be shocked if he's just hard-coding reliance on his lovely cert but we'll see

vanilla slimfast
Dec 6, 2006

If anyone needs me, I'll be in the Angry Dome



1password is worth it

Shame Boy
Mar 2, 2010

so part of my company's audit or PCI compliance thing or something involves "at least two" developers being certified in "security best practices" for coding. being the only person who actually gives a gently caress i have been tasked with choosing which cert me and a couple other devs get. this seems super suspicious, i don't know why they aren't just saying "get one of these certs" and left it so open-ended, but whatever. what's the official yossec recommendation for quote "security for code" certifications?

Winkle-Daddy
Mar 10, 2007
As someone who is not a coder, I'd take a look at the contributors to the OWASP Secure Coding Practices and asking what they have seen as most beneficial (e.g. where are they lifting their best material from) then go from there.

long-ass nips Diane
Dec 13, 2010

Breathe.

https://twitter.com/deray/status/741355856420319233

https://twitter.com/deray/status/741358452895801344


Social engineering wins again

wyoak
Feb 14, 2005

a glass case of emotion

Fallen Rib
Changing the SIM on an active account seems like one of those things that should be required to be done in-store

Daman
Oct 28, 2011
yeah, how does that work? did they just read them an IMSI? wtf

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

verizon are a bunch of idiots and my coworker had a similar thing happen to him three times in a week over the phone even after he requested they put a fraud alert on his account the first time. they are terrible.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Daman posted:

yeah, how does that work? did they just read them an IMSI? wtf
yeah you call up their activation line and tell them you bought a new phone

vOv
Feb 8, 2014

wyoak posted:

Changing the SIM on an active account seems like one of those things that should be required to be done in-store

i read a story (might've been posted in here) by someone who got their phone number stolen by someone who just walked in with a fake ID

Inspector_666
Oct 7, 2003

benny with the good hair

wyoak posted:

Changing the SIM on an active account seems like one of those things that should be required to be done in-store

AT&T has repeatedly cut off service for the wrong phone when somebody in my family uses an upgrade.

Maluco Marinero
Jan 18, 2001

Damn that's a
fine elephant.

OSI bean dip posted:

i'm considering dropping keepass in favour of 1password or just outright writing my own keepass clone that uses its file format

why is there no talk of keepassx in this discussion? or is it just as bad or some such?

Jewel
May 2, 2009

:sigh:

https://www.infoq.com/news/2016/06/visual-cpp-telemetry

quote:

Reviewing Microsoft's Automatic Insertion of Telemetry into C++ Binaries

Recently Reddit user "sammiesdog" posted claims that Visual Studio's C++ compiler was automatically adding function calls to Microsoft's telemetry services. The screenshot accompanying their post showed how a simple 5 line CPP file produced an assembly language file that included a function call titled “telemetry_main_invoke_trigger”.



...

In the meantime, users who have a copy of VS2015 Update 2 and wish to turn off the telemetry functionality currently being compiled into their code should add “notelemetry.obj” to their linker command line. (This fix was confirmed by Carroll.)

compuserved
Mar 20, 2006

Nap Ghost

:holymoley:

DrPossum
May 15, 2004

i am not a surgeon

no no it's just to log events in case you *wanted* microsoft to help you fix broke dick poo poo

and telemetry is just, like, a name, man

Phone
Jul 30, 2005

親子丼をほしい。
1password is now $65 for just a license now, right? $65 and i get to use it on my windows box, mbpr, etc?

If so, I'm going to just go with 1password vs keep rear end

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Phone posted:

1password is now $65 for just a license now, right?

coupon code MacPowerUsers gets it down to $52

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
another 10bux for pro features on ios or android but they're mostly unnecessary

Adbot
ADBOT LOVES YOU

ohgodwhat
Aug 6, 2005

So what's the proper way to share a 1pass dB across windows and Mac? I am now computer illiterate but it seemed like more work than it should be.

  • Locked thread