Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

anthonypants posted:

i saw theo de raadt's talk on pledge() and what they're trying to accomplish sounds really cool

https://www.youtube.com/watch?v=F_7S1eqKsFk

Yeah, this is a really good talk and Theo owns. Theowns.

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

quote:

Hello,

It has come to our attention that in 2013 there was an undetected breach of the RedFlagDeals.com user database. The contents of this breach were posted online on Monday, January 9th 2017. No personal information was obtained in this breach, only RedFlagDeals usernames and encrypted passwords.

As a matter of best practice, we regularly conduct security testing of our sites to minimize the chance of this type of leak reoccurring. As a precautionary measure, we have logged all affected users out of the RedFlagDeals system and are implementing a mandatory password reset. We encourage affected users to take the time to reset their password, when prompted, by clicking 'Forgot your password?' and following the subsequent steps. It is also important to change your password on any sites where the same password may have been used.

We apologize for any inconvenience this may cause you. Please email support if you have any further questions.

RedFlagDeals.com

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
openbsd wrote it's own httpd so that's pretty cool

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/andryou/status/818946765684670468

spankmeister
Jun 15, 2008






Rooney McNibnug posted:

Yeah, this is a really good talk and Theo owns. Theowns.

Theo is annoying

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

spankmeister posted:

Theo is annoying

i threw an egg at his house once

spankmeister
Jun 15, 2008






OSI bean dip posted:

i threw an egg at his house once

I reported a vulnerability in openssh once


it went as well as you would expect

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/Viss/status/819685780247298048
https://twitter.com/Viss/status/819686452002861056

hobbesmaster
Jan 28, 2008


hope he likes gitmo

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/sarahjeong/status/819710944095809536

ErIog
Jul 11, 2001

:nsacloud:

Thanks Ants posted:

has anyone got any pointers on what to look for when hiring a firm/consultant to do penetration testing? it seems there's a ton of charlatans in the industry.

im currently looking at ones that publish their own research and show up at cons rather than simply blogging about things, but would be interested to hear about how this is usually approached.

Here's a non-exhaustive list of things I would ask:
1. What they bring to the table other than pointing a bunch of off-the-shelf tools at servers.
2. If they have options for physical consultation/testing(even if you don't need it)
3. How much face time you will be able to get with an actual infosec wizard person in charge of your penetration testing (as opposed to "account representatives.")
4. If you can get a timeline along with a quote.

Be wary of vague salesman speak that exposes the fact that their company does nothing like if they say dumb poo poo like, "we work so quickly we don't think providing a timeline will really be necessary!" without knowing anything about your infrastructure.

Just think of all the ways you'd run a charlatan security company on the cheap and ask questions that would expose that charade.

Segmentation Fault
Jun 7, 2012

get brain fuckler'd

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Malcolm XML posted:

pledge and friends should be a compiler pass tbh

it's usefult o have it not be one, because even p-langers would benefit from it

Truga
May 4, 2014
Lipstick Apathy
trump's obercybergrandpa

mod saas
May 4, 2004

Grimey Drawer

ErIog posted:

charlatan security

dont infringe my trademarks tia

brand engager
Mar 23, 2011


Why did whoever got the data sit on it for a few years?

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
it gets better

https://twitter.com/ErrataRob/status/819740885504192512

https://twitter.com/ErrataRob/status/819741399465816064

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice
are there any non poo poo consumer wifi routers?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
i got a tp-link ac3200 and it's needs-suiting, do you care about custom firmware or anything here's his first tweet in that thread: https://twitter.com/ErrataRob/status/819738590116716544

Pile Of Garbage
May 28, 2007



A Pinball Wizard posted:

are there any non poo poo consumer wifi routers?

it's more SMB than consumer but i've got a cisco rv130w and it's been pretty solid (i mainly got it for the SSID-to-VLAN mapping). however i'm running it in AP-mode with routing disabled so i guess this isn't really helpful is it

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
https://www.theguardian.com/technology/2017/jan/13/whatsapp-backdoor-allows-snooping-on-encrypted-messages

quote:

WhatsApp’s end-to-end encryption relies on the generation of unique security keys, using the acclaimed Signal protocol, developed by Open Whisper Systems, that are traded and verified between users to guarantee communications are secure and cannot be intercepted by a middleman. However, WhatsApp has the ability to force the generation of new encryption keys for offline users, unbeknown to the sender and recipient of the messages, and to make the sender re-encrypt messages with new keys and send them again for any messages that have not been marked as delivered.

The recipient is not made aware of this change in encryption, while the sender is only notified if they have opted-in to encryption warnings in settings, and only after the messages have been re-sent. This re-encryption and rebroadcasting effectively allows WhatsApp to intercept and read users’ messages.

quote:

Boelter said: “[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which users might not notice. Using the retransmission vulnerability, the WhatsApp server can then later get a transcript of the whole conversation, not just a single message.”

Here's the 2016 blog post which this article is based on.

if I'm understanding correctly, the problem boils down to whatsapp automatically resending undelivered messages without first asking for user-input if the recipient's key has changed (like Signal does).

further, whatsapp doesn't warn you of a changed key by default, you have to enable the warning (probably to prevent confused users from freaking out whenever someone changes their phone or reinstalls the app).

the only thing that I think the article gets wrong, or at least misrepresents, is that whatsapp is supposedly re-encoding messages that have already been delivered to the server. those messages are encrypted, you can't decrypt them without the recipient's key, which Whatsapp supposedly doesn't have. ie: if my phone is offline, or if I've cleared my chat history, whatsapp would theoretically be unable to re-encrypt the message and re-send it.

in theory, the only way would be for the sender's app to re-send the messages with the new encryption key, right? so on whatsapp's side this would be easily solvable by adding a second switch that says "ask before resending messages if recipient's key has changed?", to which Whatsapp has responded:

quote:

"[...] We were previously aware of the issue and might change it in the future, but for now it's not something we're actively working on changing.[...]"

ofc there's also the question of if you can actually trust an unaudited closed-source app but that's moot, really

edit: for what it's worth, there's precedent of Facebook literally going "we really can't decrypt these messages, even if we wanted", while a Brazilian judge was threatening to throw it's Latin America CEO in jail for contempt in a murder case.

dpkg chopra fucked around with this message at 15:32 on Jan 13, 2017

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug
gonna just quote myself on twitter here then go rock climbing instead of arguing cause the people who want to assume facebook is mustache twirlingly evil will never be convinced otherwise

https://twitter.com/pr0zac/status/819917881899155456

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

A Pinball Wizard posted:

are there any non poo poo consumer wifi routers?

just get a dedicated wifi access point and connect it to a decent router

Shame Boy
Mar 2, 2010

last night i had a dream that i clicked a random link in this thread and it zero-day'd my browser and changed my user avatar to pepe the frog and started automatically making a bunch of bad posts and i couldn't close the browser

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

A Pinball Wizard posted:

are there any non poo poo consumer wifi routers?

get a NETGEAR AC1750

fritz
Jul 26, 2003

ate all the Oreos posted:

last night i had a dream that i clicked a random link in this thread and it zero-day'd my browser and changed my user avatar to pepe the frog and started automatically making a bunch of bad posts and i couldn't close the browser

that was no dream (check ur post history)

fins
May 31, 2011

Floss Finder
Shadowbrokers taking their toys and going home:
https://onlyzero.net/theshadowbrokers.bit/post/messagefinale/

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

fins posted:

Shadowbrokers taking their toys and going home:
https://onlyzero.net/theshadowbrokers.bit/post/messagefinale/

quote:

So long, farewell peoples. TheShadowBrokers is going dark, making exit. Continuing is being much risk and bullshit, not many bitcoins. TheShadowBrokers is deleting accounts and moving on so don’t be trying communications. Despite theories, it always being about bitcoins for TheShadowBrokers. Free dumps and bullshit political talk was being for marketing attention. There being no bitcoins in free dumps and giveaways. You are being disappointed? Nobody is being more disappointed than TheShadowBrokers. But TheShadowBrokers is leaving door open. You having TheShadowBrokers public bitcoin address 19BY2XCgbDe6WtTVbTyzM9eR3LYr6VitWK TheShadowBrokers offer is still being good, no expiration. If TheShadowBrokers receiving 10,000 btc in bitcoin address then coming out of hiding and dumping password for Linux + Windows. Before go, TheShadowBrokers dropped Equation Group Windows Warez onto system with Kaspersky security product. 58 files popped Kaspersky alert for equationdrug.generic and equationdrug.k TheShadowBrokers is giving you popped files and including corresponding LP files. Password is FuckTheWorld Is being final gently caress you, you should have been believing TheShadowBrokers.

lol so whiny

flakeloaf
Feb 26, 2003

Still better than android clock

OSI bean dip posted:

lol so whiny

wait, what group posted that message

i didn't catch their name

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

ate all the Oreos posted:

last night i had a dream that i clicked a random link in this thread and it zero-day'd my browser and changed my user avatar to pepe the frog and started automatically making a bunch of bad posts and i couldn't close the browser

quoting this so once i quit my job and have freetime again i can go ahead and implement it

apseudonym
Feb 25, 2011

pr0zac posted:

gonna just quote myself on twitter here then go rock climbing instead of arguing cause the people who want to assume facebook is mustache twirlingly evil will never be convinced otherwise

https://twitter.com/pr0zac/status/819917881899155456

The security community is dumb and people running around shouting "WhatsApp can't read your messages even if they want to" was dumb and primed this freakout. People thinking it's a backdoor and not an obvious feature (omg I switched phones and didn't get your messages :() are just silly.

End to end doesn't mean you don't have to trust the people building your messaging app, but it seems like a lot of people missed that.

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

apseudonym posted:

The security community is dumb and people running around shouting "WhatsApp can't read your messages even if they want to" was dumb and primed this freakout. People thinking it's a backdoor and not an obvious feature (omg I switched phones and didn't get your messages :() are just silly.

End to end doesn't mean you don't have to trust the people building your messaging app, but it seems like a lot of people missed that.

yeah basically only very few sec people get that the only way to make encryption and privacy protections universal is to make them useable by regular people, sometimes this means trading off perfect security to a degree in favor of usability in order to make adoption possible and advance the norm

this isn't a backdoor, its automating key exchange and verification because normal people don't understand what that is and wouldn't use it as a result, doing this means one billion people now have access to 90% of the benefit of e2e encryption, calling it a malicious backdoor is counter-productive to improving security for everyone

the even more ridiculous paranoia version of this is people who refuse to use Signal because it integrates Google Play services to send notifications (not the messages)

so much for my not talking about this more!

Shame Boy
Mar 2, 2010

pr0zac posted:

the even more ridiculous paranoia version of this is people who refuse to use Signal because it integrates Google Play services to send notifications (not the messages)

are you talking about my dumb friend that i brought up in this thread before or do you also know someone who's that dumb

Wiggly Wayne DDS
Sep 11, 2010



it is not an uncommon opinion among dumb people in security

Segmentation Fault
Jun 7, 2012
I'd like to think that you two have the same dumb friend

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

ate all the Oreos posted:

are you talking about my dumb friend that i brought up in this thread before or do you also know someone who's that dumb

go read the hn comments for the guardian whatsapp article, its filled with these idiots

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

pr0zac posted:

yeah basically only very few sec people get that the only way to make encryption and privacy protections universal is to make them useable by regular people, sometimes this means trading off perfect security to a degree in favor of usability in order to make adoption possible and advance the norm

this isn't a backdoor, its automating key exchange and verification because normal people don't understand what that is and wouldn't use it as a result, doing this means one billion people now have access to 90% of the benefit of e2e encryption, calling it a malicious backdoor is counter-productive to improving security for everyone

the even more ridiculous paranoia version of this is people who refuse to use Signal because it integrates Google Play services to send notifications (not the messages)

so much for my not talking about this more!

i posted an example in my op but fwiw pretty much everyone i've talked to in law enforcement has told me that they are basically hosed w/r/t reading whatsapp messages unless they have access to the phone itself (ie: access to the app), and i've read quite a few articles touting it as the messaging app of choice when it comes to encryption, right below Signal, so you're definitely above most everything else when it comes to public perception.

i still think a setting that asks you to reverify a contact before resending messages when the key has changed, would pretty much fix this problem. it doesn't have to be on by default, like with signal

apseudonym
Feb 25, 2011

Ah yes, the good ol' "I don't trust my OS but somehow don't think Im completely hosed"

Wiggly Wayne DDS
Sep 11, 2010



Ur Getting Fatter posted:

i still think a setting that asks you to reverify a contact before resending messages when the key has changed, would pretty much fix this problem. it doesn't have to be on by default, like with signal
it already exists

Adbot
ADBOT LOVES YOU

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

Wiggly Wayne DDS posted:

it already exists

??

  • Locked thread