Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
cinci zoo sniper
Mar 15, 2013




http://www.redmondpie.com/firm-that-helped-fbi-break-into-san-bernardino-iphone-gets-hacked-tools-leaked-online/ #whoa

Adbot
ADBOT LOVES YOU

ErIog
Jul 11, 2001

:nsacloud:

cheese-cube posted:

i'm a big proponent of surface area limitation taken to the extreme which includes not installing bullshit software on servers and such.

I also subscribe to this, and inherited an environment where 100+ servers have full desktop environments installed. Rip me.

Thankfully I have free will to improve the gently caress out of this poo poo and it soothes my tism so hard.

ErIog fucked around with this message at 14:02 on Feb 4, 2017

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

cheese-cube posted:

for actualy content, xpost from the cisco thread:


lmao

at six months to crack that password it's almost better to just rebuild

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/PrissSoares_/status/827579332080050181

Truga
May 4, 2014
Lipstick Apathy
your operating system is printing owned sheets.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
nothing but receipts:
https://twitter.com/lmaostack

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

The printernet of poo poo

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Volmarias posted:

The printernet of poo poo

Shame Boy
Mar 2, 2010


everyone likes a meme

Proteus Jones
Feb 28, 2013




quote:

For the love of God, please close this port, skid

Shame Boy
Mar 2, 2010



hacked
hacked
lol just,
kidding

duTrieux.
Oct 9, 2003

chaotic good as gently caress

Agile Vector
May 21, 2007

scrum bored



duTrieux. posted:

chaotic good as gently caress

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice
https://twitter.com/HPSupport/status/827963612606119938

Agile Vector
May 21, 2007

scrum bored



lp0 botnet on fire

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
pc bot letter? what the gently caress does that mean?

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

this is good

minivanmegafun
Jul 27, 2004

I'm gonna take a wild shot in the dark here but any receipt printer spewing that out is proooooobably not in a PCI compliant configuration

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
since when did a receipt printer need to be pci compliant

minivanmegafun
Jul 27, 2004

anthonypants posted:

since when did a receipt printer need to be pci compliant

when it's connected to a point of sale system, as most receipt printers are?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
so when you see an obfuscated credit card number on a receipt, you think it's the printer's job to translate numbers to asterisks?

Proteus Jones
Feb 28, 2013



minivanmegafun posted:

when it's connected to a point of sale system, as most receipt printers are?

I have never seen a receipt printer come up as a PCI audit point.

Are you confusing them with portable POS devices with integrated receipt printers maybe?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
if a printer has to be pci compliant then so does the display on the pos system

in any pci compliant report i've read, printers have never come up

Storysmith
Dec 31, 2006

anthonypants posted:

since when did a receipt printer need to be pci compliant

if a receipt printer has a way to talk to it over the public internet do you really believe the pos terminal itself does not

minivanmegafun
Jul 27, 2004

you could argue that the pos terminal's network is segmented/isolated properly and the printer's is not, but, uh, we're talking about the people who setup networks in hundreds of small businesses as quickly as they can and that's a lot of faith to put in them

Proteus Jones
Feb 28, 2013



Storysmith posted:

if a receipt printer has a way to talk to it over the public internet do you really believe the pos terminal itself does not

Still missing the point of there is no such thing as a "PCI compliant configuration" for a printer. It's just not a thing.

minivanmegafun
Jul 27, 2004

flosofl posted:

Still missing the point of there is no such thing as a "PCI compliant configuration" for a printer. It's just not a thing.

i was talking about the POS installation as a whole, not just the printer itself

I mean sure a single receipt printer living somewhere not near a register has no requirements

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Storysmith posted:

if a receipt printer has a way to talk to it over the public internet do you really believe the pos terminal itself does not
it's very likely, because these are just dumb printers with like port 9100 or whatever open. opening up that port to the world is probably the easiest way for the pos system to be able to talk to it, because whoever installed it was also a pos

minivanmegafun posted:

i was talking about the POS installation as a whole, not just the printer itself

I mean sure a single receipt printer living somewhere not near a register has no requirements
you should check out the twitter that was linked a few posts up then because it's actually a guy who's owned pos printers, specifically, and not pos installations as a whole as you seem to believe

Luigi Thirty
Apr 30, 2006

Emergency confection port.

your printer is broadcasting an IP address /!\

Proteus Jones
Feb 28, 2013



anthonypants posted:

it's very likely, because these are just dumb printers with like port 9100 or whatever open. opening up that port to the world is probably the easiest way for the pos system to be able to talk to it, because whoever installed it was also a pos
you should check out the twitter that was linked a few posts up then because it's actually a guy who's owned pos printers, specifically, and not pos installations as a whole as you seem to believe

I haven't dealt with printers directly in almost 20 years, but I see "port 9100" and I felt a chill run down my spine. Those loving HP JetDirect cards.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
let's just all agree that all printers suck

minivanmegafun
Jul 27, 2004

anthonypants posted:


you should check out the twitter that was linked a few posts up then because it's actually a guy who's owned pos printers, specifically, and not pos installations as a whole as you seem to believe

there seem to be some register jockeys bemused about their printers spewing weird ascii art so I think some real POS installs might actually be effected!

https://mobile.twitter.com/faithers99/status/827920542007037955?ref_src=twsrc%5Etfw

spankmeister
Jun 15, 2008






At least this guy prints out harmless messages instead of weev and his nazi propaganda.

spankmeister fucked around with this message at 12:59 on Feb 5, 2017

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

spankmeister posted:

At least this guy prints out harmless messages instead of weev and his nazi propaganda.

:agreed:

"Fix your poo poo lmao" is probably one of the best possible outcomes here.

Phone
Jul 30, 2005

親子丼をほしい。

this is the weirdest, and most effective, STEM outreach for women I've seen

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
lol. a us judge just nuked the global market for cloud services from us based companies

turns out having local data centers can't save you from the us drinking your data through a straw. looks like ms built those fancy new canadian data centers for nothing

infernal machines fucked around with this message at 17:34 on Feb 5, 2017

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

infernal machines posted:

lol. a us judge just nuked the global market for cloud services from us based companies

turns out having local data centers can't save you from the us drinking your data through a straw.

lol as if they're not going to do it anyway no matter where you're located, if they can get the flimsiest reason to care about you. especially if you do your alternate hosting in any of the explicit spying ally countries of the us.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
the point is that previous ruling was the only reason patriated data centers mattered. if you have a legal requirement to store data domestically, you had the option of using local data centers even if they were being managed by an american company, because at least legally speaking the us couldn't just subpoena all your data across national boundaries.

ms specifically built a bunch of canadian DCs so that they could bid on a shared services contract for the federal government. whoops, that's out the window now.

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

infernal machines posted:

the point is that previous ruling was the only reason patriated data centers mattered. if you have a legal requirement to store data domestically, you had the option of using local data centers even if they were being managed by an american company, because at least legally speaking the us couldn't just subpoena all your data across national boundaries.

ms specifically built a bunch of canadian DCs so that they could bid on a shared services contract for the federal government. whoops, that's out the window now.
there was a lot of hand-wringing and discussion @ SAP when I still worked there, specifically with supporting HANA and some other products sold to the german government. contract required everything to be local, including all support staff, and no data was supposed to cross borders. This played havoc with a modern-day IT support infrastructure, where we had centralized management (in the USA!) for a dozen DCs around the world, plus tier-1 in bangalore, etc. It got ugly and gradually escalated upwards and legal got involved and finally we ended up making an exception for the germans while simultaneously vowing never to enter into another contract like it.

i'm sure the groaning will start because it's still deployed (but not managed!) by american staff and that access tunnel potentially means the feds will have legal avenues to grab data

Adbot
ADBOT LOVES YOU

geonetix
Mar 6, 2011


The Germans (and French, sometimes) are hella strict on data transfer, and they do investigate if there's any connection to anything non-local whenever news like this pops, or someone feels like it. Ever since the safe harbor/privacy shield fiasco the Germans have been on companies like mad dogs about those things as well, issuing plenty of fines, but mostly poking around hoping its all still "secure"

Best advice? Got big German clients? Make sure you're doing what you've said you were doing ;-).

  • Locked thread