Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Segmentation Fault
Jun 7, 2012
Security Fuckup Megathread - v13.1 - $10 for SA's customer CC info

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Segmentation Fault posted:

Security Fuckup Megathread - v13.1 - $10 for SA's customer CC info

i got one better

Segmentation Fault
Jun 7, 2012

OSI bean dip posted:

i got one better

:lol:

ate shit on live tv
Feb 15, 2004

by Azathoth

OSI bean dip posted:

i got one better

:discourse:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i have proof

Wiggly Wayne DDS
Sep 11, 2010



OSI bean dip posted:

i have proof


good work radium

WrenP-Complete
Jul 27, 2012

Tiny Brontosaurus cool and good. <3

Winkle-Daddy
Mar 10, 2007

zen death robot posted:

that drive is way too new

thats the one that has the location of this one:



e: it's no longer as new as in that picture.

Wiggly Wayne DDS
Sep 11, 2010



moving the conversation from Bad With Money:

cc data is sent to sa's store then ??? processing happens and a payment processor is involved in some manner



yes yes old terrible implementation from years ago but it isn't doing any favours towards allegations of cc misused

Tesseraction
Apr 5, 2009

Once on the SA servers it's saved to /tmp/Wiggly Wayne DDS.details until the folder is cleared out at midnight.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Tesseraction posted:

Once on the SA servers it's saved to /tmp/Wiggly Wayne DDS.details until the folder is cleared out at midnight.

also pls never ever use the term "military grade" thx

Wiggly Wayne DDS
Sep 11, 2010



Tesseraction posted:

Once on the SA servers it's saved to /tmp/Wiggly Wayne DDS.details until the folder is cleared out at midnight.
unfortunately there was a big server crash at 00:00 one day so at 23:59 radium made the time change to 00:01 the next day and paused for two minutes

Tesseraction
Apr 5, 2009

OSI bean dip posted:

also pls never ever use the term "military grade" thx

you mean you aren't awed by AES256?

Wiggly Wayne DDS
Sep 11, 2010



the point is that we can only go on your word given the setup zdr, any allegation of misconduct can't be conclusively cleared given the fundamentally flawed system to begin with

there's better ways to implement this in 2017 but whether that's in your hands is another matter

30 TO 50 FERAL HOG
Mar 2, 2005



im sorry i refuse to believe anything but it being piped to an old line printer and lowtax sitting next to it with a dialup credit card machine furiously typing numbers in

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

zen death robot posted:

make things less secure

live a little

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

zen death robot posted:

I don't know enough about webdev to fix the lovely way the cookie info is handled. That's why lowtax got an actual webdev guy to recode things, but if anyone can point me to some resouces I'll do what I can to fix that poo poo too.

just use Stripe?

Wiggly Wayne DDS
Sep 11, 2010



zen death robot posted:

I don't know enough about webdev to fix the lovely way the cookie info is handled. That's why lowtax got an actual webdev guy to recode things, but if anyone can point me to some resouces I'll do what I can to fix that poo poo too.
i mean a basic approach would be to ensure sa never handled cc data in the first place

this is why i mentioned the payment processor handling a pubkey to the client to handle in the other thread, keep as far away from passing over data you should never be looking at or modifying in the first place. that way no one can make up stories that are technically implausible

Wiggly Wayne DDS
Sep 11, 2010



oaky let's start again you know how oauth fundamentally works? imagine that but instead of user credentials it's credit card details

really this should be your payment processor who has this all ready to go and you should be on a legacy system to be EoLed

30 TO 50 FERAL HOG
Mar 2, 2005



just use paypal

necrotic
Aug 2, 2005
I owe my brother big time for this!

Subjunctive posted:

just use Stripe?

i imagine the codebase makes this more than a "just"

Trabisnikof
Dec 24, 2005

Maybe if you get the block chain involved somehow that'll help

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

zen death robot posted:

Here's the rub. While I might be able to do it, I do not feel comfortable in doing so because that's not my area of expertise. That's why Lowtax has someone else working on site code. I don't know what all he is doing I can only explain how things currently are, but no radium code will be kept around in the long term. If I put my stamp on the code then I feel as if I'm accepting responsibility with all that goes with it, and I'm not comfortable with that. I have my areas of expertise and handling payment transactions across is not that area. I will describe how it's currently done though and do what I am comfortable with to make things better.

seems reasonable. prepare for war.

Wiggly Wayne DDS
Sep 11, 2010



making you understand the issue isn't quite the same as pressing you to change a system you aren't comfortable with touching

on that note turns out the payment provider sa uses does support sane methods of handling cc data http://developer.authorize.net/api/reference/features/acceptjs.html

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
how are the sa gift certificates generated?

if you care not to divulge, can you tell us if they're generated in an idiotic manner?

is "kjs500" used as a seed anywhere in the code or have you seen it anywhere else?

necrotic
Aug 2, 2005
I owe my brother big time for this!
love you zdr keep up the good work

jre
Sep 2, 2011

To the cloud ?




:eyepop: well that escalated quickly

zen death robot posted:

Here's the rub. While I might be able to do it, I do not feel comfortable in doing so because that's not my area of expertise.

Absolutely the correct answer.

Wiggly Wayne DDS
Sep 11, 2010



i don't have anything more to add other than "here's the problem that gives vague complaints a level of validity and what could be done to stop it", sure as hell don't expect you to resolve it as a first priority

Wiggly Wayne DDS
Sep 11, 2010



how many indefinitely valid 'test' certs are active, and may i borrow one

Wiggly Wayne DDS
Sep 11, 2010



much like the store going opensource i didn't hear no so will patiently check my inbox

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

zen death robot posted:

ugh you're gonna make me dig into radium code so i can remember how this poo poo works, hang on

no don't :ohdear:

that is not dead which can eternal lie

Tayter Swift
Nov 18, 2002

Pillbug
it's kinda amazing that sa has gone as long as it has without getting completely owned in some fashion

Tayter Swift
Nov 18, 2002

Pillbug
Or maybe it does on a weekly basis and I never listen

Wiggly Wayne DDS
Sep 11, 2010



someone was dumb enough to use heartbleed

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Tayter Swift posted:

it's kinda amazing that sa has gone as long as it has without getting completely owned in some fashion

SA has been owned. There's a username and password dump floating about from 2004/2005

Wiggly Wayne DDS posted:

someone was dumb enough to use heartbleed

Not a big deal though!

Tayter Swift
Nov 18, 2002

Pillbug

OSI bean dip posted:

SA has been owned. There's a username and password dump floating about from 2004/2005

that was twelve years ago

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Tayter Swift posted:

that was twelve years ago

that may be but you didn't specify a time frame either

also search has had stored xss issues as of last year

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

zen death robot posted:

look the NRC is gonna come down on my rear end if i expose the public to that much radium

lmao

raminasi
Jan 25, 2005

a last drink with no ice

zen death robot posted:

I even fixed all the idiotic word-based SQL passwords

first read this as a winword.exe-based authentication system, thanks radium

Adbot
ADBOT LOVES YOU

Midjack
Dec 24, 2007



zen death robot posted:

look the NRC is gonna come down on my rear end if i expose the public to that much radium

:laffo:

  • Locked thread