Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

fishmech posted:

It's pretty weird how mad you are where other people's ui elements are located

? no mad, just kinda perplexed that someone is angry that they can't sacrifice their security in exchange for trivial ui changes anymore.

Adbot
ADBOT LOVES YOU

Cybernetic Vermin
Apr 18, 2005

cheese-cube posted:

NPAPI support : firefox :: register_globals : PHP

don't think this is about npapi support, but rather the extensions based on the xul/xpcom framework, basically the same customization level that turned the same base application into both firefox and thunderbird with just different xml/javascript tossed in

going to webextensions, same relatively weaksauce thing that chrome and edge uses. no doubt way safer and easier to maintain, but the possiblities are also certainly not as many

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

cheese-cube posted:

NPAPI support : firefox :: register_globals : PHP


ah but was it 100 x 512GB flash drives on one day or one 512GB flash drive per day for 100 days?

can you even get 512GB flash drives idk

microsd cards are the densest, let's assume he's using 128GB, 256 is too new

50TB/128GB =390.625

a microsd card is 1mm so that 39cm or 15.4in

if you can get 2 stacks side by side thats 7.7in up your butt

cinci zoo sniper
Mar 15, 2013




that twitter account :eyepop:

Pile Of Garbage
May 28, 2007



Cybernetic Vermin posted:

don't think this is about npapi support, but rather the extensions based on the xul/xpcom framework, basically the same customization level that turned the same base application into both firefox and thunderbird with just different xml/javascript tossed in

going to webextensions, same relatively weaksauce thing that chrome and edge uses. no doubt way safer and easier to maintain, but the possiblities are also certainly not as many

so there's an API which has the same functionality as NPAPI but is less of a dumpster-fire sec wise compared to NPAPI?

Truga
May 4, 2014
Lipstick Apathy

cheese-cube posted:

NPAPI support : firefox :: register_globals : PHP

nobody is bothered by NPAPI being gone, it's never worked in 64bit firefox anyway

people are bothered with the webextensions framework being a shitshow, though at least they seem to be working hard on extending it finally

hopefully they'll have most of the functionality down by the time they force xul off for everyone

e;fb

and no, it's nothing like npapi at all.

Pile Of Garbage
May 28, 2007



ah i see. thanks for the info.

everyone pls ignore my posts, im wrong again!

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Cybernetic Vermin posted:

don't think this is about npapi support, but rather the extensions based on the xul/xpcom framework, basically the same customization level that turned the same base application into both firefox and thunderbird with just different xml/javascript tossed in

going to webextensions, same relatively weaksauce thing that chrome and edge uses. no doubt way safer and easier to maintain, but the possiblities are also certainly not as many

gently caress xul/xpcom extensions. yes, they can do anything. they can completely rewrite the functionality of the application. it's a really bad way of doing things, and xul so bad that it's bad even for legit use

nothing against xpcom and xpconnect though. love those guys

Truga
May 4, 2014
Lipstick Apathy
yeah, I'm not going to defend xul in any way because it's a gigantic mess, and i purposefully avoided writing poo poo in it even though i've used firefox since the first beta releases. writing applications with xml ughhhh

but webextensions right now can't replace quite a bit of things xul extensions do for firefox. webextensions is very good though and mozilla has been working hard on extending it to the point where it'll hopefully do most of the things xul does now. there's some things that won't ever be possible I'm sure, but I don't know any extensions that would need more than webextensions is theoretically capable of providing

plus, it's more secure, since it runs inside the browser sandbox afaik. if you install a malicious firefox extension it probably can do some real damage right now

Midjack
Dec 24, 2007



Perplx posted:

microsd cards are the densest, let's assume he's using 128GB, 256 is too new

50TB/128GB =390.625

a microsd card is 1mm so that 39cm or 15.4in

if you can get 2 stacks side by side thats 7.7in up your butt

it's physically possible

Shame Boy
Mar 2, 2010

a bunch has gotta be text files full of repetitive log data so it probably compresses down to something more manageable anyway

Pile Of Garbage
May 28, 2007



i'd aay we're back at option one: the contractor was just given a fuckton of data which was then placed on a network outside of the NSA. if we use occams razor then for once"1000 thumb(drives) in the butt" is less realistic.

power botton
Nov 2, 2011

not mutually exclusive. how was the contractor given this data? maybe through butt drives

power botton
Nov 2, 2011

we just don't have enough information to rule out butt data at this point

Truga
May 4, 2014
Lipstick Apathy
gonna be a lot of bits when that condom ruptures

power botton
Nov 2, 2011

with all the leaked Snowden docs it was proved the NSA even has a term for this: AnEx (Anal Exfiltration)

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

power botton posted:

maybe through butt drives

universal serial butt

Truga
May 4, 2014
Lipstick Apathy

Meat Beat Agent posted:

universal serial butt

spankmeister
Jun 15, 2008






Meat Beat Agent posted:

universal serial butt

FlapYoJacks
Feb 12, 2009

Meat Beat Agent posted:

universal serial butt

Pile Of Garbage
May 28, 2007



Meat Beat Agent posted:

universal serial butt

Pile Of Garbage
May 28, 2007



i asked my colleague who worked at raytheon / DSIA "DID THE NSA EVER IMPLEMENT A BUTT TRANSFER PROTOCOL FOR CONTRACTORS?" and he says "It was one of their more successful implementations" case closed

Shaggar
Apr 26, 2006

lol. steam is so bad ever since they moved to slowkit.

Pile Of Garbage
May 28, 2007



i'm inclined to say "lol if your 'app' is just a browser backed by a bunch of websites" but isn't that the folly of everything these days?

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

cheese-cube posted:

NPAPI support : firefox :: register_globals : PHP


npapi support is already dropped in 64 bit firefox for everything but flash, also, extensions arent implemented through the npapi

Pile Of Garbage
May 28, 2007



yeah i know that now. i'm an idiot

DrPossum
May 15, 2004

i am not a surgeon
Here's my sec gently caress for the year. Had an employee leave us a few months ago who was doing work at a national lab. Guess he thought the best way to handle chain of custody for his computer my group owns was to leave it in an unused cube in a public space and write a username/password on a whiteboard next to it (which gives full access to the lab's network) and "This is DrPossum's computer now" (I'm not even his supervisor or have anything to do with ownership)

I learned of this by email from a rando grad student at the lab asking if he could use it.

DrPossum fucked around with this message at 17:30 on Feb 7, 2017

Wiggly Wayne DDS
Sep 11, 2010



well could he use it?

DrPossum
May 15, 2004

i am not a surgeon

Wiggly Wayne DDS posted:

well could he use it?

Holy poo poo i'm so livid right now. Everyone involved with this did not pay attention to the required idiot baby computer security training to work there and my loving name is one a loving whitebaord with it

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



oh wow lol

Pile Of Garbage
May 28, 2007



DrPossum posted:

Here's my sec gently caress for the year. Had an employee leave us a few months ago who was doing work at a national lab. Guess he thought the best way to handle chain of custody for his computer my group owns was to leave it in an unused cube in a public space and write a username/password on a whiteboard next to it (which gives full access to the lab's network) and "This is DrPossum's computer now" (I'm not even his supervisor or have anything to do with ownership)

I learned of this by email from a rando grad student at the lab asking if he could use it.

yeah same but it's a drilling drig and the laptop belongs to the senior drilling supervisor and he leaves it unlocked all the time and the offices well there aren't really any locked offices on a rig and often they're unoccupied and there's no CCTV and he has passwords for his laptop, personal laptop, FB and personal e-mail on post-its around the desk. also there's an unsecured network on the vessel for wired and wireless acess with no 802.1x on the wired and just PSK for wireless (codes written on whiteboard in SDSV office).sure that net doesn't touch client network and has service-provider break-out to the internet instead of hitting the MPLS but lol there's some very "loose" ACLs on the ASA in front of the VSAT and you could quite easily traverse back to shore.

also it's the same poo poo in the geo office

and the completions office.

i forgot what my point was but lol there's no sec offshore

edit: lol i forgot there's a port in the medic's office that has port sec disabled because it needs some life-saving device plugged-in but lol if you want to hook up just un-plug the super life saving device no one cares.

Pile Of Garbage fucked around with this message at 17:50 on Feb 7, 2017

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
any port in a packet storm

Pile Of Garbage
May 28, 2007



it's the scariest loving thing because i'm watching off-shore gas processing facilities going into production with equally lax configuration on them. they're being commissioned in korea and the company has gone hard on lowest $ tender which means they've ended up with poo poo and we're just made to produce punch-lists of poo poo which is hosed and may or may not get fixed.

makes me sick to my stomach thinking i could be responsible if a system goes to piss and the onshore plant goes boom or something equally disastrous. i didn't build these systems i just tried to force people to make them not shite and do things properly (because if you're not prepared to do something properly then you shouldn't loving do it) :(

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Chris Knight posted:

any port in a packet storm

Proteus Jones
Feb 28, 2013



power botton posted:

with all the leaked Snowden docs it was proved the NSA even has a term for this: AnEx (Anal Exfiltration)

Brb, adding AnEx testing to the contract with our pentest (lol) team.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
local provincial party shows off how it is getting hacked

https://twitter.com/Emile_BC/status/828788950806384640

Pile Of Garbage
May 28, 2007



they might have an open git repo idk

edit: nothing to see there, they're just screencapping logs from WP. also their WP install is patched to latest and they have a competent host.

Pile Of Garbage fucked around with this message at 19:00 on Feb 7, 2017

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
gocardless, direct debit charging -as-a-service company, got burglarised

Only registered members can see post attachments!

Storysmith
Dec 31, 2006

Rufus Ping posted:

gocardless, direct debit charging -as-a-service company, got burglarised



password protected is not encrypted

whoops

Adbot
ADBOT LOVES YOU

Midjack
Dec 24, 2007



Meat Beat Agent posted:

universal serial butt

Chris Knight posted:

any port in a packet storm

  • Locked thread