Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
FlapYoJacks
Feb 12, 2009

Dex posted:

distributed denial of society

Adbot
ADBOT LOVES YOU

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Jabor posted:

im the 3840 bits of entropy in the negotiated key that they just throw away immediately

not much choice there, all schemes based on classic DH have to do something like that. it's just typically done in a way more careful fashion than just "sha256 I guess lol". zrtp for example generates the key (and salt/iv!) like this:

srtpkeyi = KDF(s0, "Initiator SRTP master key", KDF_Context, negotiated AES key length)
srtpsalti = KDF(s0, "Initiator SRTP master salt", KDF_Context, 112)
srtpkeyr = KDF(s0, "Responder SRTP master key", KDF_Context, negotiated AES key length)
srtpsaltr = KDF(s0, "Responder SRTP master salt", KDF_Context, 112)

(upstream and downstream use separate keys)

where the KDF function is:

KDF(KI, Label, Context, L) = HMAC(KI, i || Label || 0x00 || Context || L)

(you can see a lovely halfassed attempt at a similar KDF in that diagram)

and s0 (the shared secret) and kdf_context (the nonce) are:

s0 = hash(0x01 || DHResult || "ZRTP-HMAC-KDF" || ZIDi || ZIDr || total_hash || ...)
KDF_Context = (ZIDi || ZIDr || total_hash)

where dhresult is the shared secret negotiated through diffie-hellman, zidi and zidr are the unique identifiers of the two peers, and total_hash is a hash of the concatenation of all key agreement protocol messages exchanged (which includes the diffie-hellman challenges and tons of other things). I omitted the auxiliary secrets that can be mixed in the calculation of s0, but yes even more stuff could go in there

all of these are nist and fips constructions, nothing was improvised or just made up

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

Dex posted:

distributed denial of society

moooooooooooooooooooooooooooooooooooooooooooooods

Winkle-Daddy
Mar 10, 2007

Dex posted:

distributed denial of society

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Dex posted:

distributed denial of society

Shame Boy
Mar 2, 2010

so i just found a scrap of paper with someone's username/password on it in the stairwell of the parking garage

it's on investment bank letterhead

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Strongly consider not touching the poop

qntm
Jun 17, 2009
shred it

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

ate all the Oreos posted:

so i just found a scrap of paper with someone's username/password on it in the stairwell of the parking garage

it's on investment bank letterhead

take a scan and tweet it at the bank

Shame Boy
Mar 2, 2010

Volmarias posted:

Strongly consider not touching the poop

yeah to be clear i'm not going to do anything with this at all, i think i know where this thing came from (it's in my building) so I'm gonna run down there and go "hey uh you might want this maybe keep better track of that stuff next time," otherwise I'll just drop it in the shredder

just postin' bout it cuz lol banks

Wiggly Wayne DDS
Sep 11, 2010



nice read on some internal nsa whistleblowing over the security of ecdh in 2010: https://www.schneier.com/blog/archives/2016/11/whistleblower_i.html
gotta go to the comments for a link to the actual report

A Man With A Plan
Mar 29, 2010
Fallen Rib

Wiggly Wayne DDS posted:

nice read on some internal nsa whistleblowing over the security of ecdh in 2010: https://www.schneier.com/blog/archives/2016/11/whistleblower_i.html
gotta go to the comments for a link to the actual report

lol @ the redacted chunk, followed by " To ensure Suite B's integrity, ECDH would never be employed alone. ln order to provide the necessary level of information assurance, ECDH must be incorporated with the other Suite B component algorithms and approved implementation protocols"

Wiggly Wayne DDS
Sep 11, 2010



yeah there's a weird amount of telling leftovers amidst the redacted parts

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

Dex posted:

distributed denial of society

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
"smart" devices actually dumb as gently caress, redux:

http://www.theregister.co.uk/2016/11/09/finns_chilling_as_ddos_knocks_out_building_control_system/

Zamujasa
Oct 27, 2010



Bread Liar

quote:

That sent the remote systems into an endless cycle of rebooting in an attempt to reconnect, leaving the residents with no central heating and cold showers.

guess everything froze up

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
sophos is able to identify that a batch file and a shortcut are "virus/malware" but is not smart enough to determine how these files are able to reappear after sophos quarantines/deletes them. thanks sophos

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

anthonypants posted:

[av vendor] is able to identify that [anything] are "virus/malware" but is not smart enough to determine how these files are able to reappear after [av vendor] quarantines/deletes them. thanks [av vendor]

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

Zamujasa posted:

guess everything froze up

*groan*

Shame Boy
Mar 2, 2010

lame new thread title, i voted for

Dex posted:

distributed denial of society

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

ate all the Oreos posted:

lame new thread title, i voted for

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

ate all the Oreos posted:

lame new thread title, i voted for

a majority of people did in fact, but that's not how the voting is decided

Midjack
Dec 24, 2007



ate all the Oreos posted:

yeah to be clear i'm not going to do anything with this at all, i think i know where this thing came from (it's in my building) so I'm gonna run down there and go "hey uh you might want this maybe keep better track of that stuff next time," otherwise I'll just drop it in the shredder

just postin' bout it cuz lol banks

just destroy it. if you give it back to them you open yourself to having to prove you didn't log into it if there's any irregularities AT ALL in that account in the preceding six months plus however long it is before they change the password

Proteus Jones
Feb 28, 2013



Jabor posted:

a majority of people did in fact, but that's not how the voting is decided

And since it's never been decided popularly, this is a surprise, how?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

flosofl posted:

And since it's never been decided popularly, this is a surprise, how?
whoosh

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Zamujasa posted:

guess everything froze up

:golfclap:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
yes but this time it's happening to me, personally!

Proteus Jones
Feb 28, 2013




Jesus, I can't read.

Phone
Jul 30, 2005

親子丼をほしい。
minecraft.gov

the official minecraft server of the department of cyber and cool tweens

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

"it was mirai"

Yes, I'm sure it took a Tb/s attack to knock two apartment buildings of some rando management company off the Internet

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope
Okay, so according to finnish communications regulatory authority it was not mirai, and somehow through a game of telephone it changed to "it was mirai"

Wiggly Wayne DDS
Sep 11, 2010



Wheany posted:

Okay, so according to finnish communications regulatory authority it was not mirai, and somehow through a game of telephone it changed to "it was mirai"
if it's the same story that floated around a few days ago (it probably is) then they couldn't contact the nameservers, so the telephone could have been "it wasn't mirai directly"

suffix
Jul 27, 2013

Wheeee!

hackbunny posted:



why would you come up with poo poo like this in a world where ZRTP and SRTP exist, christ, where to even start

the weakest kdf ever
babby's first hkdf
mixing twofish and aes because you never know, nsa backdoors and poo poo
counter mode as a stream cipher
non-authenticated encryption

I'm a mere bs of cs and I literally could design a better algorithm

counter mode is a good stream cipher, e.g. aes-gcm is counter mode + authentication
the authentication is important though

Truga
May 4, 2014
Lipstick Apathy
https://twitter.com/jiveassbaloney/status/796082968087367680
https://twitter.com/jiveassbaloney/status/796086586748309504

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

suffix posted:

counter mode is a good stream cipher, e.g. aes-gcm is counter mode + authentication
the authentication is important though

yes, you're right, I misremembered

bicycle
Oct 23, 2013
The http://blacknurse.dk/ thing mentioned a couple pages back has been revealed and is a ping flood

hobbesmaster
Jan 28, 2008


those voting machines must've had an int overflow

Cybernetic Vermin
Apr 18, 2005

loving jackass should get a night in jail to learn to differentiate between a joke and wasting government resources and undermining (stupid, granted) peoples faith in the democratic process

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope
that heating issue once again proves that internet of poo poo :airquote:smart:airquote: devices should fall back to "dumb" mode and not shut down when they're offline.

live tweeting the toasting progress of your bread should be a value add and not considered a critical function of the device.

Adbot
ADBOT LOVES YOU

Truga
May 4, 2014
Lipstick Apathy

Cybernetic Vermin posted:

loving jackass should get a night in jail to learn to differentiate between a joke and wasting government resources and undermining (stupid, granted) peoples faith in the democratic process

if the FBI can't understand bogus php code and usb sticks can't fukc with voting, they deserve everything they get

  • Locked thread