Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Truga posted:

Well, yeah, but now it's also legal. Until now there was that safe harbour replacement thing: http://fortune.com/2016/02/02/looks-like-data-will-keep-flowing-from-the-eu-to-the-u-s-after-all/

So how is this the same as it's been then?

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
here's some anecdotes about av:
https://news.ycombinator.com/item?id=13489100

quote:

Except AV started out like how Carbon or Cylance did (lean, effective, buzzworthy, etc) and other popular applications started out. It was decades of feature creep, poor competition, out of control pricing, etc that killed the AV industry.

quote:

Windows 8/10 with the MS built-in protection or Linux + clamav
Sometimes I used CClenaer and/or Spybot to deal with something really nasty, but the MS stuff really does a good job (Someone checked if the hell is frozen now ?)

quote:

I have 150 ish machines on eset across a few different clients, obviously my experience with it has been very good over the years in all aspects. Eset don't offer the biggest margins but I stick with them because it doesn't cause support issues and I can count the number of infected eset machines I've had to deal with on one hand.

quote:

I have the impression that the AV business is some kind of mixture of scam and mafia.

quote:

Who writes all these viruses ?
I mean, I've experimented with assembler when I was a teenager and I may have developed some kind of program which could replicate itself.. but I highly doubt today's viruses are written by teenagers...
Who and why do people write viruses ? Is this a thing at all or are all the viruses written by the Antivirus makers themselves ?
More 'threats' is good news for the A/V makers so why not have a separate department which develops them ?
I wouldn't be surprised at all, given that much crazier things are happening in this world..
Can anyone confirm or disprove this ?

quote:

If you need AV, consider F-secure. They do quality products and take security seriously.

quote:

Defender has the nasty habit of aggressively scanning new games I download off Steam. There are two occasions where it'll do it:
- While it's downloading it seems to scan each chunk. I have a gigabit connection, with defender off I can download at nearly full speed. With it on I can download at about 1MB/s.
- While the game loads a level. For example, the intro level to the new Deus Ex took over 10 minutes to load the first time. At that point I disabled defender entirely and just promised myself I would be careful. Naive, I know, but at least I can play my video games.

quote:

In principle, I agree with the article.
Personally, on Win7 I use a combination of 3 things:
- MSSE - TinyWall as a lightweight firewall - heavily modified HOSTS file
Never had malware/virus problems and sometimes I do visit shady webistes or download quirky software.

quote:

Any relevant information about Avast? I'm using their free version for 10 years and don't have any major complains.

quote:

While many AV companies are really bad, AV per say is still an extra layer of security. Telling people to remove a layer of security is bad advice. There's a problem though and if I knew how to solve it I'd be rich!

quote:

Most people forget the malware on hacked website. Browsers won't give you a warning. (OK. Chrome will show you a RED screen but not for all) They need not hack into your system. But they collected your login info, credit card. I even want to install one on my MacOS.
MS AV still too slow at the moment. In Windows 10, you could turn on Defender to run both AV at the same time.

:allears:

spankmeister
Jun 15, 2008






Security Fuckup Megathread - v13.2 - Naive, I know, but at least I can play my video games.

Haquer
Nov 15, 2009

That windswept look...
Naive, I know, but at least I can play my video games.

Truga
May 4, 2014
Lipstick Apathy

Subjunctive posted:

So how is this the same as it's been then?
difference is, now it's legal for nsa to read my mail
it's the same since i'm pretty sure they'd do it if they wanted to do it

in other words:

flakeloaf posted:

to the extent that the law can be flexed, for compelling reasons like "because we can" and "gently caress you"

also, this fuels my paranoia nicely, and it feels good.

my antivirus anecdote is that windows defender runs in the background automatically and users don't know it's av since it's windows and thus don't complain about av slowing their pc. probably might as well not exist, but it satisfies the antivirus requirement some people give so i'll take it

e: oh, i also run clamav on mail gateways for the same reason and get a few mails every year about it catching this or that 10 year old infected .doc or troyan

Shaggar
Apr 26, 2006
my antivirus anecdote is sometimes it catches and quarantines ancient Trojans that people download on work machines that would have successfully run otherwise.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Truga posted:

difference is, now it's legal for nsa to read my mail
it's the same since i'm pretty sure they'd do it if they wanted to do it

this isn't about the NSA. this is about agencies being able to publish that personal data, send to other agencies, share with private contractors. the privacy policy on a government service serves the same function as on a private service.

Truga
May 4, 2014
Lipstick Apathy
oh, that's even worse then

Shaggar
Apr 26, 2006
lol. like you had any recourse against the government when it was "illegal"

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

lol. like you had any recourse against the government when it was "illegal"
shaggar is right

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
pls do not d&d this thread

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

anthonypants posted:

gonna be a cold four years talking about secfucks without being able to mention us policy ever

spankmeister
Jun 15, 2008






OSI bean dip posted:

pls do not d&d this thread

it's not d&d it's just alternative secfucks

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal
Security Fuckup Megathread - v13.2 - I've experimented with assembler when I was a teenager

triple sulk
Sep 17, 2014



McGlockenshire
Dec 16, 2005

GOLLOCKS!
e: ^^^ drat you

OSI bean dip posted:

pls do not d&d this thread

yeah but on the other hand
https://twitter.com/azalben/status/824664543091707905

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer


(sorry, OSI)

flakeloaf
Feb 26, 2003

Still better than android clock

poop touching is bad especially when it's elected official poop but what do you want to bet his "secret questions" have "truthful answers"

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
Security Fuckup Megathread - v13.2 - DON'T HACK THE PRESIDENT YOU FUCKS!

Wiggly Wayne DDS
Sep 11, 2010



infernal machines posted:

Security Fuckup Megathread - v13.2 - DON'T HACK THE PRESIDENT YOU FUCKS!
https://twitter.com/Nash076/status/824656400320253959

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
brb - going to announce we've just signed the legislation to make antigua illegal, the bombing begins in five minutes

Shame Boy
Mar 2, 2010


god dammit it's press secretary at gmail dot com isn't it

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal
what does your heart tell you

Shame Boy
Mar 2, 2010

Deep Dish Fuckfest posted:

what does your heart tell you

that it has too many letters, actually, but "PressSec2017" fits

Shaggar
Apr 26, 2006
pretty sure the asterisks are the same count for all addresses to prevent disclosing length so presssec or presssecretary would both work

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
the asterisks correlate to the missing letters so it can't be presssecretary

e:fb

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

Shaggar posted:

pretty sure the asterisks are the same count for all addresses to prevent disclosing length so presssec or presssecretary would both work

they're not, they correlate exactly

Shame Boy
Mar 2, 2010

Shaggar posted:

pretty sure the asterisks are the same count for all addresses to prevent disclosing length so presssec or presssecretary would both work

the @potus screenshot a few posts up has more asterisks so lol no

Shaggar
Apr 26, 2006
lol twitter is junk.

Wiggly Wayne DDS
Sep 11, 2010



check the replies for how it handles subdomains

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
pressy.spice@gmail.com

Diva Cupcake
Aug 15, 2005

CNN ran this a few days ago.

http://money.cnn.com/2017/01/24/technology/trump-white-house-twitter-security/index.html

quote:

WauchulaGhost says he found the likely email associated with Melania Trump's handle within twenty minutes. He said the email associated with Vice President Mike Pence was easy to guess once you saw the redacted version: vi***************@gmail.com, which WauchulaGhost pieced together as vicepresident2017@gmail.com. It has since been changed, but the president and first lady's email addresses remain the same. (And the VP account still doesn't have the extra layer of security.)

ClassActionFursuit
Mar 15, 2006


its cute that you think the trump administration will last four years and also laughable that you think the following administration will change these policies

the thing about surveillance policies is every government believes they are the only ones moral enough to have such power so no one ever walks them back

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

LastInLine posted:

its cute that you think the trump administration will last four years and also laughable that you think the following administration will change these policies

the thing about surveillance policies is every government believes they are the only ones moral enough to have such power so no one ever walks them back

shut the gently caress up and go post in d&d

Wiggly Wayne DDS
Sep 11, 2010



at least keep it security related

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
if you want to talk about how trump is loving up his opsec or whatever, sure

if you want to talk about how trump won't last four years, go post in d&d

if either of these two points are unclear then don't post at all

flakeloaf
Feb 26, 2003

Still better than android clock

trumpet winsockpuppet

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
http://metro.co.uk/2017/01/26/white-house-press-secretary-tweeted-his-own-password-so-everyone-feels-very-safe-6408492/

We're safe everyone. Everything is fine.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
are people assuming that's a password or did someone actually verify that. because people butt-dial on twitter all the time

Adbot
ADBOT LOVES YOU

power botton
Nov 2, 2011

sometimes people make mistakes when copying things out of their passwords.txt is that really so hard to believe?

  • Locked thread