Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
spankmeister
Jun 15, 2008






It's a very effective distraction, true or not, from his very real conflicts of interest.

Adbot
ADBOT LOVES YOU

spankmeister
Jun 15, 2008






pr0zac posted:

Sorry, I'm on phone waiting for my wife's car to be fixed thus lack of details.

http://www.theverge.com/2017/1/11/14237136/trump-leak-telegram-security-cracked-russia-encryption

Thanks.

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

anthonypants posted:

everything in those highlighted printouts is bullshit

This claim is just as unsupported and rejecting everything completely outright makes you just as much of a gullible idiot as anyone taking them as gospel.

Asshole Masonanie
Oct 27, 2009

by vyelkin

pr0zac posted:

This claim is just as unsupported and rejecting everything completely outright makes you just as much of a gullible idiot as anyone taking them as gospel.

yeah i feel so gullible not believing a word of anything, silly stupid me

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

pr0zac posted:

This claim is just as unsupported and rejecting everything completely outright makes you just as much of a gullible idiot as anyone taking them as gospel.
well YOUR claim is also unsupported therefore YOU are also just as much the gullible idiot. check mate

Wiggly Wayne DDS
Sep 11, 2010



anthonypants posted:

well YOUR claim is also unsupported therefore YOU are also just as much the gullible idiot. check mate
piss mate

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

anthonypants posted:

every single one of the claims made against trump is completely unverifiable, and buzzfeed believes that journalism means publishing every claim so that the american people can figure out what's real and what's not by themselves. everything in those highlighted printouts is bullshit, and you would be a humongous gullible idiot for taking any of those claims seriously.

counterpoint: trump is mama's little pissboy and loves to drinkos the peepee

M_Gargantua
Oct 16, 2006

STOMP'N ON INTO THE POWERLINES

Exciting Lemon
also: "Hacking Defense" is now in trumps limited vocabulary as if this were some sort of ball game

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

fishmech
Jul 16, 2006

by VideoGames
Salad Prong
trump loves piss lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
gonna be a cold four years talking about secfucks without being able to mention us policy ever

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

anthonypants posted:

gonna be a cold four years talking about secfucks without being able to mention us policy ever

this is the security fuckup thread; not the journalism integrity one

if you want to talk about how much buzzfeed and vox suck, go make a new thread


e:

here you go:
https://forums.somethingawful.com/showthread.php?threadid=3804977

Lain Iwakura fucked around with this message at 18:43 on Jan 11, 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:

this is the security fuckup thread; not the journalism integrity one

if you want to talk about how much buzzfeed and vox suck, go make a new thread
iirc the last time you got upset we were discussing the credulity of present-day spy agencies

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

anthonypants posted:

every single one of the claims made against trump is completely unverifiable, and buzzfeed believes that journalism means publishing every claim so that the american people can figure out what's real and what's not by themselves. everything in those highlighted printouts is bullshit, and you would be a humongous gullible idiot for taking any of those claims seriously.

https://twitter.com/KenJennings/status/818977092016611328

Wiggly Wayne DDS
Sep 11, 2010



OSI bean dip posted:

this is the security fuckup thread; not the journalism integrity one

if you want to talk about how much buzzfeed and vox suck, go make a new thread


e:

here you go:
https://forums.somethingawful.com/showthread.php?threadid=3804977
limiting convo to the applicable security parts of the unverified leak and pissss is a high priority of the thread imo

qntm
Jun 17, 2009

ken jennings is my hero

Number19
May 14, 2003

HOCKEY OWNS
FUCK YEAH


yossec: who's a good ssl cert vendor in 2017? let's encrypt won't work for this. I've had a recommendation for alphassl but i want to see who else is decent these days. i need a wildcard cert for part of the project.

Shaggar
Apr 26, 2006
godaddy

spankmeister
Jun 15, 2008






Wildcart certs are indicative of bad design hth

darkforce898
Sep 11, 2007

spankmeister posted:

Wildcart certs are indicative of bad design hth

How would you go about issuing valid certificates on hundreds of devices that change their public IP address daily?

We create a domain name that we update to the correct IP when it changes.

Not accusing, just wondering.

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

darkforce898 posted:

How would you go about issuing valid certificates on hundreds of devices that change their public IP address daily?

We create a domain name that we update to the correct IP when it changes.

Not accusing, just wondering.

It's not clear to me what part of this needs a wildcard cert.

Number19
May 14, 2003

HOCKEY OWNS
FUCK YEAH


spankmeister posted:

Wildcart certs are indicative of bad design hth

agreed but until the design is fixed I have to put a new certificate in place

Shame Boy
Mar 2, 2010

Shinku ABOOKEN posted:

i don't know any company that backs up workstations lol

mine does

or well they tell us to, and once the IT intern walked around to see if we had time machine enabled!

a year ago

jre
Sep 2, 2011

To the cloud ?



Number19 posted:

yossec: who's a good ssl cert vendor in 2017? let's encrypt won't work for this. I've had a recommendation for alphassl but i want to see who else is decent these days. i need a wildcard cert for part of the project.

Go to name cheap and pick the vendor of your choice


edit: They only do comodo now, arse.

jre fucked around with this message at 20:22 on Jan 11, 2017

Shame Boy
Mar 2, 2010

fishmech posted:

counterpoint: trump is mama's little pissboy and loves to drinkos the peepee

emptyquoting fishmech

Segmentation Fault
Jun 7, 2012
this thread hasnt been alive a month lets not get it killed please :(

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

fishmech posted:

counterpoint: trump is mama's little pissboy and loves to drinkos the peepee

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Number19 posted:

yossec: who's a good ssl cert vendor in 2017? let's encrypt won't work for this. I've had a recommendation for alphassl but i want to see who else is decent these days. i need a wildcard cert for part of the project.

everybody seems to be moving away from wildcard certs and the CAs are trying to push everything over to multi-domain and just swapping out with a new one with more SANs jammed on it. Any particular reason for using a wildcard over multi-domain?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

darkforce898 posted:

How would you go about issuing valid certificates on hundreds of devices that change their public IP address daily?

We create a domain name that we update to the correct IP when it changes.

Not accusing, just wondering.

without knowing more about the details of the hardware in question I might throw up a dnssec server in the dmz, get client certs deployed on the end devices when they go out in the field, and then use the cert based auth against dns server to handle automagically getting the IPs updated. alternatively, some kind of agent on the endpoint that does a similar job and can handle applying new certs if they ever need to be replaced. either way, the key to this is getting certs deployed on to all the endpoints to use as an auth mechanism.

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe
http://www.chicagotribune.com/lifestyles/health/ct-cybersecurity-flaw-in-heart-devices-20170111-story.html

Shame Boy
Mar 2, 2010


quote:

"Your average patient isn't going to be targeted by assassins," said Matthew Green

i assume in this case you'd actually need to access the specific transmitter etc but i guarantee that some time in the near future there will be a life-critical device that will allow some 15 year old who just discovered what a metasploit is to kill someone and you bet your rear end they will do it

Number19
May 14, 2003

HOCKEY OWNS
FUCK YEAH


BangersInMyKnickers posted:

everybody seems to be moving away from wildcard certs and the CAs are trying to push everything over to multi-domain and just swapping out with a new one with more SANs jammed on it. Any particular reason for using a wildcard over multi-domain?

it's the requirement given to me more or less. i'm just on the procurement end of this one. i have pushed back with a "you don't need this" and it looks like i might win so that's good

Wiggly Wayne DDS
Sep 11, 2010



ate all the Oreos posted:

i assume in this case you'd actually need to access the specific transmitter etc but i guarantee that some time in the near future there will be a life-critical device that will allow some 15 year old who just discovered what a metasploit is to kill someone and you bet your rear end they will do it
no this was detailed yesterday and i didn't bother to mention it here (read the full thread)

https://twitter.com/matthew_d_green/status/818818410947682304

in other juniper news: https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10753&actp=search

Proteus Jones
Feb 28, 2013




Hahahaha

Loving Africa Chaps
Dec 3, 2007


We had not left it yet, but when I would wake in the night, I would lie, listening, homesick for it already.

Wiggly Wayne DDS posted:

no this was detailed yesterday and i didn't bother to mention it here (read the full thread)

https://twitter.com/matthew_d_green/status/818818410947682304

in other juniper news: https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10753&actp=search

I've been talking to the cardiologists at work about this. St Jude have been round grovelling to them recently because of battery issues but no one knew about all this

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal
to be honest, after the whole thing with the note 7 i'm not sure i like hearing about vague "battery issues" relating to medical devices any more than i like hearing about them being an open kill switch for your heart

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

Deep Dish Fuckfest posted:

to be honest, after the whole thing with the note 7 i'm not sure i like hearing about vague "battery issues" relating to medical devices any more than i like hearing about them being an open kill switch for your heart

medical devices are some of the most deeply, troublingly flawed pieces of computer you will ever encounter. companies go to extreme lengths to define the domain the device covers just so to avoid fda regulation (which, lol if that still even exists in 2 years) and will always do the bare minimum required by the loosest interpretation of the regs then fight it out in court. they don't give a poo poo at all about the patient's safety at all because they have the patient over a barrel (you need the device or you die).

Segmentation Fault
Jun 7, 2012

LeftistMuslimObama posted:

medical devices are some of the most deeply, troublingly flawed pieces of computer you will ever encounter. companies go to extreme lengths to define the domain the device covers just so to avoid fda regulation (which, lol if that still even exists in 2 years) and will always do the bare minimum required by the loosest interpretation of the regs then fight it out in court. they don't give a poo poo at all about the patient's safety at all because they have the patient over a barrel (you need the device or you die).

but see medicine benefits from the free market because

Shame Boy
Mar 2, 2010

i think it's funny that cuba has advanced cancer treatments because surprise when there's not an overriding profit motive to spend $20bn developing and marketing the next big dick pill you actually get useful poo poo done

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


anthonypants posted:

every single one of the claims made against trump is completely unverifiable, and buzzfeed believes that journalism means publishing every claim so that the american people can figure out what's real and what's not by themselves.

buzzfeed published a story about the fact that an intelligence report contained those allegations, and explicitly said they couldn't verify the claims themselves. it's like writing a story "trump appointee claims climate change a hoax".


e: whoops new page

  • Locked thread