Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
I regret that post and I acknowledged in the thread it was wrong of me

Adbot
ADBOT LOVES YOU

Stymie
Jan 9, 2001

by LITERALLY AN ADMIN

OSI bean dip posted:

I regret that post and I acknowledged in the thread it was wrong of me

just that post?

how magnanimous of you

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

I regret that post and I acknowledged in the thread it was wrong of me

Cool, can we go back to laughing at sec fucks and not have to wade through you quoting your own dick waving posts from else where in the forums ?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

jre posted:

Cool, can we go back to laughing at sec fucks and not have to wade through you quoting your own dick waving posts from else where in the forums ?

how about we both agree to not derail the thread further with either?

SpaceClown
Feb 13, 2016

by FactsAreUseless
YOSPOS# no shut jre

Wiggly Wayne DDS
Sep 11, 2010



SpaceClown posted:

YOSPOS# no shut jre
same

cinci zoo sniper
Mar 15, 2013




ack

vodkat
Jun 30, 2012



cannot legally be sold as vodka

jre posted:

Cool, can we go back to laughing at sec fucks and not have to wade through you quoting your own dick waving posts from else where in the forums ?

but i enjoy waving my dick :(

anyway have a secfuck https://www.theregister.co.uk/2017/02/21/us_dhs_computer_access_down/ 🤔

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
as a computer janitor they probably just didn't change their password

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

Have an unanswered tweet I sent out to Ticketmaster last year:

https://twitter.com/Migishu/status/797946928893816832

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
I just went back, while it's "Powered by Ticketmaster", it looks like it's only for the Place Des Arts in Montreal. Maybe they're the ones that are creating the password rules?

Either way, I was able to create an account with a 1 character password.

I'm going to sent a tweet out to them.

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
Triple SLAM

https://twitter.com/Migishu/status/834567858285854721

apseudonym
Feb 25, 2011


I would have accepted "most Security Experts suck rear end at building real things" as a response instead of "OMG NSA".

Midjack
Dec 24, 2007




Hello, Yospos Bitch

apseudonym posted:

I would have accepted "most Security Experts suck rear end at building real things" as a response instead of "OMG NSA".

eripsa is loving insane

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

Wiggly Wayne DDS posted:

if the security experts are the ones installing nsa backdoors, then who are the ones detecting them?

who pentests the pentesters?

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

Finally recovered from RSA. The security bubble is in some serious decline y'all.

1) The free shwag was lovely this year. No free shirts or other poo poo.
2) Want any of the cool poo poo, time to sit through a 20-30 minute sales presentations
2) The parties were garbage. One of the 'hottest' parties gave you two free drink tickets.
3) There were also way less parties than previous years

Dare I say, IT Security might be in decline

Also, as a white person..............

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

Ur Getting Fatter posted:

who pentests the pentesters?

i like to penetrate pentesters

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Migishu posted:

I just went back, while it's "Powered by Ticketmaster", it looks like it's only for the Place Des Arts in Montreal. Maybe they're the ones that are creating the password rules?

Either way, I was able to create an account with a 1 character password.

I'm going to sent a tweet out to them.

see my previous post about the TIFF scenario, also done through ticketmaster, also with the ability to create 1 character passwords :/

spankmeister
Jun 15, 2008






Optimus_Rhyme posted:

Finally recovered from RSA. The security bubble is in some serious decline y'all.

1) The free shwag was lovely this year. No free shirts or other poo poo.
2) Want any of the cool poo poo, time to sit through a 20-30 minute sales presentations
2) The parties were garbage. One of the 'hottest' parties gave you two free drink tickets.
3) There were also way less parties than previous years

Dare I say, IT Security might be in decline

Also, as a white person..............

When going to a rapid7 all expenses paid party in some vegas club I remember thinking "This is the high water mark of the security bubble. I will think back to this moment in a few years when the bubble has popped and think about how ridiculous this all was."

bicycle
Oct 23, 2013
just go to congress and bring a bottle of booze and share it and have fun and pick up some free stickers and buy a tor t shirt or w.e and pretend youre a hacker or speak to smart people who arent actually trying to hire you or sell you poo poo and have fun and give a gently caress about the culture and avoid ioerror supporters and stop expecting the industry to give you tons of free drinks just for showing up and just provide the kicking rad party yourself hth

spankmeister
Jun 15, 2008






The web sight is getting rekt but SHA-1 is now officially completely broken:

https://www.shattered.io/



e: a mirror I guess http://shattered.it/

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

spankmeister posted:

The web sight is getting rekt but SHA-1 is now officially completely broken:

https://www.shattered.io/



e: a mirror I guess http://shattered.it/

:rip:

cinci zoo sniper
Mar 15, 2013




Shame Boy
Mar 2, 2010

Sapozhnik posted:

i don't know much about docker but i'm still convinced it's bad

let's have a complex god process that runs as root managing everything and it also has some sort of http interface, what could possibly go wrong

The http interface is off by default at least

Diva Cupcake
Aug 15, 2005

spankmeister posted:

The web sight is getting rekt but SHA-1 is now officially completely broken:

https://www.shattered.io/



e: a mirror I guess http://shattered.it/
Here's the Google blog post...

https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

ate all the Oreos posted:

The http interface is off by default at least

doesn't VMWare have an available HTTP interface too? or do they use a custom protocol (not really better, imo)

what should they use for control if not http? make admins ssh in and command-line for every operation?

Shame Boy
Mar 2, 2010

Subjunctive posted:

what should they use for control if not http? make admins ssh in and command-line for every operation?

yes, obviously. also my good man have you installed gentoo

James Baud
May 24, 2015

by LITERALLY AN ADMIN

"Today, 10 years after of SHA-1 was first introduced" ........... Odd place to make a mistake like that, and I don't mean the extra word/typo.

Shaggar
Apr 26, 2006

Subjunctive posted:

doesn't VMWare have an available HTTP interface too? or do they use a custom protocol (not really better, imo)

what should they use for control if not http? make admins ssh in and command-line for every operation?

I think the problem is more that its configured incorrectly out of the box so its disabled with the intent that you configure it properly before enabling rather than deploying misconfigured by default.

VMWare creates a bunch of bad defaults for its http server and its a huge pain in the dick to setup correctly even when using something like vsphere, but VMware is different since its infrastructure and docker is an application.

power botton
Nov 2, 2011

James Baud posted:

"Today, 10 years after of SHA-1 was first introduced" ........... Odd place to make a mistake like that, and I don't mean the extra word/typo.

lmao there really are 10 types of people in this world

Wiggly Wayne DDS
Sep 11, 2010



cool we need more companies funding attacks on this scale

hobbesmaster
Jan 28, 2008

Shaggar posted:

I think the problem is more that its configured incorrectly out of the box so its disabled with the intent that you configure it properly before enabling rather than deploying misconfigured by default.

VMWare creates a bunch of bad defaults for its http server and its a huge pain in the dick to setup correctly even when using something like vsphere, but VMware is different since its infrastructure and docker is an application.

i work for a company with an iot gateway that by default blocks all incoming connections on whatever the wan interface is detected as

guess what the number one question for the gateways is

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

hobbesmaster posted:

i work for a company with an iot gateway that by default blocks all incoming connections on whatever the wan interface is detected as

guess what the number one question for the gateways is

it's not a question but i bet the number one ticket filed is "it dont work"

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
what does 110gpu/year processing mean in real world dollars?

i imagine it varies because legit actors will pay for cloud processing which is probably more expensive but more efficient, while criminals/APTs will use botnet computing which is cheaper but less efficient?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
a year now will be a month in few years

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

OSI bean dip posted:

a year now will be a month in few years

also, the thrust of their post was "sha-1 is now worthless against an attacker with large resources." the unspoken implication being that sha-1 is not safe against state-level actors and you should stop using it unless you want russia and china sonying the poo poo out of you.

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
https://twitter.com/rafalwilinski/status/834772410125733888

cinci zoo sniper
Mar 15, 2013




:stonklol:

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

lol

Adbot
ADBOT LOVES YOU

coffeetable
Feb 5, 2006

TELL ME AGAIN HOW GREAT BRITAIN WOULD BE IF IT WAS RULED BY THE MERCILESS JACKBOOT OF PRINCE CHARLES

YES I DO TALK TO PLANTS ACTUALLY

Ur Getting Fatter posted:

what does 110gpu/year processing mean in real world dollars?
~$50k on AWS spot GPU instances i think.

anyone who wanted to do this on an industrial scale would follow bitcoin's lead and design ASICs to do the hashing. that gets you a >thousand fold speed up over a GPU, for a similar per-unit cost.

  • Locked thread