Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
thehustler
Apr 17, 2004

I am very curious about this little crescendo
so much for keep your software up to date. checkmate fringe quasi-InfoSec wannabe community

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/SecSnakeOil/status/743573300333273092

looks like we may have a round 2 on veiltower

burning swine
May 26, 2004



thehustler posted:

so much for keep your software up to date. checkmate fringe quasi-InfoSec wannabe community

Keep rear end 1.x still works fine and if that's needs suiting then keep on rocking

however the MITM vuln in the keep rear end 2 update check has been resolved satisfactorily. It still directs you to go download from sourceforge over http, but it does the same thing for 1.x, so, welp

check your sigs

edit: oh hey he finally kicked the download links over to HTTPS, woop

Proteus Jones
Feb 28, 2013




Refresh my memory. Was Veiltower the bullshit AP? The one with the antennas that didn't have enough planar offset and the PCB that wouldn't fit into the case?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

flosofl posted:

Refresh my memory. Was Veiltower the bullshit AP? The one with the antennas that didn't have enough planar offset and the PCB that wouldn't fit into the case?
https://www.kickstarter.com/projects/veiltower/veiltower-where-connected-and-protected-converge/

also here's osi's writeup https://securitysnakeoil.org/2015/10/06/veiltower-a-misleading-plastic-jungle-of-deception/

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

flosofl posted:

Refresh my memory. Was Veiltower the bullshit AP? The one with the antennas that didn't have enough planar offset and the PCB that wouldn't fit into the case?

it was the wastebasket with the antennas that weren't connected to anything

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
this was posted a few days ago:

https://www.youtube.com/watch?v=3yveswNUouo

also found this:
https://www.kickstarter.com/projects/1500620457/innovote-secure-mobile-voting-for-america?ref=newest

:woop:

FlapYoJacks
Feb 12, 2009

Oh god, whenever I hear the term "100%" secure I instantly file their product into the scam compartment in my brain.

ErIog
Jul 11, 2001

:nsacloud:
No freaky-deekies here!

https://www.youtube.com/watch?v=3yveswNUouo&t=129s

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

quote:

Our technology uses the same cryptographic breakthroughs that enable the bitcoin economy — the blockchain. You can learn more in our whitepaper.

:negative:

DrPossum
May 15, 2004

i am not a surgeon



that's all i saw

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

DrPossum posted:



that's all i saw

I was kind of curious what David Cross was getting up to!

mod saas
May 4, 2004

Grimey Drawer

DrPossum posted:



that's all i saw

is keeping your waste bin atop your desk instead of underneath a silicon valley fashion thing?

DrPossum
May 15, 2004

i am not a surgeon

Adix posted:

is keeping your waste bin atop your desk instead of underneath a silicon valley fashion thing?

when your business is manufacturing expensive waste bins, probably

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Adix posted:

is keeping your waste bin atop your desk instead of underneath a silicon valley fashion thing?

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

thehustler posted:

so much for keep your software up to date. checkmate fringe quasi-InfoSec wannabe community
yeah i'm on version 2 but until this latest 2.34 one hadn't updated since 2.27 or something from whenever i last set up this computer, there tends not to be anything critical in them


COACHS SPORT BAR posted:

edit: oh hey he finally kicked the download links over to HTTPS, woop
it's still showing as http for me lol. are you sure you're not just seeing https everywhere correcting it?

anyway as i already discovered the main sourceforge domains support https but the actual download mirrors don't :downs:

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


DrPossum posted:



that's all i saw

who buys one eames chair in white much less four of them

black leather and rosewood or nothing you loving philistines

spankmeister
Jun 15, 2008






Volmarias posted:

I was kind of curious what David Cross was getting up to!

was gonna post this, it's uncanny

ewiley
Jul 9, 2003

More trash for the trash fire

So am I supposed to carry my trashcan with me to every Starbucks I go in to? Otherwise how does having 802,1x help when I'm not associated with the thing?

DrPossum
May 15, 2004

i am not a surgeon
what if the hackers get their own trash can WAP and take it to starbucks? how hosed would we be?

ewiley
Jul 9, 2003

More trash for the trash fire

DrPossum posted:

what if the hackers get their own trash can WAP and take it to starbucks? how hosed would we be?

InfoSec: it's trashcans all the way down

Moist von Lipwig
Oct 28, 2006

by FactsAreUseless
Tortured By Flan

pr0zac posted:

my friend and now boss and also sometimes SA poster wrote a good article on bug bounties

https://medium.com/@collingreene/bug-bounty-5-years-in-c95cda604365#.983irqp9r

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

ewiley posted:

InfoSec: it's trashcans all the way down

spankmeister
Jun 15, 2008






posting in the infosec trashcan

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug


without any chance of fraud? hmm.

https://twitter.com/WeldPond/status/743755637000024065

https://twitter.com/matthew_d_green/status/743756987695955970

uh oh

https://blog.ethereum.org/2016/06/17/critical-update-re-dao-vulnerability/

quote:

An attack has been found and exploited in the DAO, and the attacker is currently in the process of draining the ether contained in the DAO into a child DAO. The attack is a recursive calling vulnerability, where an attacker called the “split” function, and then calls the split function recursively inside of the split, thereby collecting ether many times over in a single transaction.

The leaked ether is in a child DAO at https://etherchain.org/account/0x304a554a310c7e546dfe434669c62820b7d83490; even if no action is taken, the attacker will not be able to withdraw any ether at least for another ~27 days (the creation window for the child DAO). This is an issue that affects the DAO specifically
the DAO is a giant slush fund account i think? i dunno but

ayyy lmao

Bhodi fucked around with this message at 14:03 on Jun 17, 2016

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

anyone putting money into ethereum / bitcoin / whatever gets what they deserve

Jewel
May 2, 2009

i hadnt even heard the word 'ethereum' before and i can see why

all of your money has now disappeared into the 'ether' you idiots

spankmeister
Jun 15, 2008






the RCE is coming from inside the blockchain

Shame Boy
Mar 2, 2010


oh good i started paying attention to the bitcoin world again at just the right time :allears:

ewiley
Jul 9, 2003

More trash for the trash fire

They're all gonna get forked hard in the rear end soon

Pretty much this sums up ETH:

https://twitter.com/random_eddie/status/743753139874979841

FlapYoJacks
Feb 12, 2009
Security Fuckup Megathread - v12.1.3 - Imagine that your dollar bills were written in Javascript.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

ratbert90 posted:

Security Fuckup Megathread - v12.1.3 - Imagine that your dollar bills were written in Javascript.

nah

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
http://www.maria-johnsen.com/million-dollar-blog/multilingual-seo/should-multilingual-websites-use-https-by-default

this is all sorts of incorrect

https://twitter.com/iMariaJohnsen/status/743818598959947776

she isn't getting the best responses on twitter

apseudonym
Feb 25, 2011


What the gently caress did I just read

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

apseudonym posted:

What the gently caress did I just read

someone who needs to know their place on giving advice

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

spankmeister posted:

was gonna post this, it's uncanny

crisis kickstarter actor

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

apseudonym posted:

What the gently caress did I just read

digital marketing poo poo is almost entirely based on misunderstanding and magical thinking

SEO in 2016 means catering to delusional small business owners that didn't get the memo about SEO people all being incompetent or malicious clowndicks that are an enemy of multiple fortune 50 companies

what you just read is par for the course

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

apseudonym posted:

What the gently caress did I just read
Hyperpolyglot Entrepreneur #SEO #DigitalMarketing #influencer,Public Speaker,Programmer, soical media expert & Author.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

I assume from the lack of question mark in the blog title that there wasn't an answer

Adbot
ADBOT LOVES YOU

moonshine is......
Feb 21, 2007


I like how his ad contradicts itself. Hackers just drive up and use evilAP because your device will connect to the strongest network. Here's my poo poo, it's got a bunch of bs in it, it's somehow immune to evilAP.

  • Locked thread