Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
jre
Sep 2, 2011

To the cloud ?




I think you're being trolled.

Adbot
ADBOT LOVES YOU

AggressivelyStupid
Jan 9, 2012


why

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
so the ex-kaspersky guy got fingered for treason by a well connected business man who is also allegedly involved in cyber crime

Hollow Talk
Feb 2, 2014

ate all the Oreos posted:

shorter, smaller passwords are less conspicuous and harder for hackers to see

hunter2

Does adding a \ in front count as salting?

Hollow Talk fucked around with this message at 23:22 on Feb 27, 2017

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

jre posted:

I think you're being trolled.

it's hard to tell really

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

it's hard to tell really

:smith:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
while walking to the office today, i found this:



http://fobclone.wixsite.com/fobclone

i'm the lack of access control

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
burglary as a service

also, just a low rent clone of the unfortunately named fobcouver.ca

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

that is pretty unfortunate

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
I would buy a consolidator for fobs from aliexpress instantly

like, this http://www.wexinc.com/wex-corporate/the-rise-of-the-all-in-one-card-consolidator/ but for fobs, even if it was just HID or something i have four of the loving things

yoloer420
May 19, 2006

Bhodi posted:

I would buy a consolidator for fobs from aliexpress instantly

like, this http://www.wexinc.com/wex-corporate/the-rise-of-the-all-in-one-card-consolidator/ but for fobs, even if it was just HID or something i have four of the loving things

There was a Kickstarter for one, all the reviews reported that it didn't work.

A Man With A Plan
Mar 29, 2010
Fallen Rib

OSI bean dip posted:

it's hard to tell really

He's been posting super dumb opinions about everything all over the forums so he's either a troll or the dumbest motherfucker alive

jre
Sep 2, 2011

To the cloud ?



sarehu posted:

It's very easy to test my hypothesis. Take my 8 characters-and-less passwords on websites I use (they go down to 6), count how many times my accounts have been lost from the password being hacked, and compare the results with your however-long passwords that make you feel secure.

I've never lost any account to somebody brute forcing my password over the wire. Or from anybody getting the password database and cracking it offline. That would be doable, but there's minimal harm that could be done on any service for which that could be accomplished.
:suicide:

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'


Wat 😥😥

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

A Man With A Plan posted:

He's been posting super dumb opinions about everything all over the forums so he's either a troll or the dumbest motherfucker alive

sarehu posted:

Also, at a startup it's a good idea to know your employment law poo poo, because they won't. For example the place I worked at didn't know that CA law requires paying out accrued vacation time when the employee leaves, and when I started they accidentally the whole health insurance for all the employees. Also a goon hacked the HR contractor's website and found out how much money I made.

Thanks Ants
May 21, 2004

#essereFerrari


re: access fobs, a bunch of the systems work by just reading the serial number off the 125khz token which is shamefully bad. i think the hid systems are actually able to interrogate the card bt they cost more than some apartment developer is going to pay.

also fob + pin pad readers should be more common than they are.

the card standard in use matters less if you can just smash the reader off the wall and deliver the data straight to the controller, though: http://blog.opensecurityresearch.com/2012/12/hacking-wiegand-serial-protocol.html

Thanks Ants fucked around with this message at 01:07 on Feb 28, 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lmao

Midjack
Dec 24, 2007



Thanks Ants posted:

re: access fobs, a bunch of the systems work by just reading the serial number off the 125khz token which is shamefully bad. i think the hid systems are actually able to interrogate the card bt they cost more than some apartment developer is going to pay.

also fob + pin pad readers should be more common than they are.

the card standard in use matters less if you can just smash the reader off the wall and deliver the data straight to the controller, though: http://blog.opensecurityresearch.com/2012/12/hacking-wiegand-serial-protocol.html

not really, most LF systems just read the number off the fob. there are a ton of custom formats running around but the LF systems don't typically have enough sophistication on the credentials to do any sort of authentication

newer HF stuff can get fancy as you describe

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

jre posted:

While claiming a 3 month average is taking the piss a bit, they are correct that the speed with which they fixed this and deployed to massive infra is impressive.

idk i deployed Facebook once. is everything in that blog post not standard?

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



A Man With A Plan posted:

He's been posting super dumb opinions about everything all over the forums so he's either a troll or the dumbest motherfucker alive

make sure to ask him why there aren't more women in software development

just not here because I'm sure OSI doesn't want the thread poo poo up with :biotruths:

a witch
Jan 12, 2017

i need help to not become a security fuckup :ohdear:

I want to encrypt traffic between some digital ocean servers. I am too stupid to set up a CA to use stunnel, is spiped ok?

the only consequence of messing up is that people could cheat at online pictionary, but I'd still like to try to do this properly.

Raere
Dec 13, 2007

a witch posted:

i need help to not become a security fuckup :ohdear:

I want to encrypt traffic between some digital ocean servers. I am too stupid to set up a CA to use stunnel, is spiped ok?

the only consequence of messing up is that people could cheat at online pictionary, but I'd still like to try to do this properly.

you can manually encrypt data by XORing the data as many times as you want bits of key strength. for example, if you XOR a packet 128 times it will be as strong as aes 128

Pile Of Garbage
May 28, 2007



i'd setup an IPsec tunnel between the two servers

Absurd Alhazred
Mar 27, 2010

by Athanatos

Raere posted:

you can manually encrypt data by XORing the data as many times as you want bits of key strength. for example, if you XOR a packet 128 times it will be as strong as aes 128

Pfft, that's for amateurs. Have you heard of ROT13? Try ROT19! They'll never expect that!

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

a witch posted:

I am too stupid to set up a CA to use stunnel, is spiped ok?


cheese-cube posted:

i'd setup an IPsec tunnel between the two servers

thats cruel cheese cube.

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE

Midjack posted:

not really, most LF systems just read the number off the fob. there are a ton of custom formats running around but the LF systems don't typically have enough sophistication on the credentials to do any sort of authentication

newer HF stuff can get fancy as you describe

HID will do cooler stuff the more money you get them

that being said if you get ahold of one of the earlier iCLASS readers it is possible to dump out the standard private key, which is used in most installations (you can specify your own key for added security but it's wayyyyyyyyyyyy more expensive. If you hold a HID key up to a reader and it doesn't beep, they've got their own. If it does decode, you can clone a card that has access)

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

a witch posted:

i need help to not become a security fuckup :ohdear:

I want to encrypt traffic between some digital ocean servers. I am too stupid to set up a CA to use stunnel, is spiped ok?

the only consequence of messing up is that people could cheat at online pictionary, but I'd still like to try to do this properly.

spiped is fine but there might be better options depending on what kind of traffic it is

cfssl is handy for setting up a CA and issuing certs but the documentation is crap. you may potentially be able to use letsencrypt certs with stunnel

you may also wish to consider openvpn which is fairly straightforward to set up

Rufus Ping fucked around with this message at 05:57 on Feb 28, 2017

Shame Boy
Mar 2, 2010

Thanks Ants posted:

re: access fobs, a bunch of the systems work by just reading the serial number off the 125khz token which is shamefully bad. i think the hid systems are actually able to interrogate the card bt they cost more than some apartment developer is going to pay.

also fob + pin pad readers should be more common than they are.

the card standard in use matters less if you can just smash the reader off the wall and deliver the data straight to the controller, though: http://blog.opensecurityresearch.com/2012/12/hacking-wiegand-serial-protocol.html

reminder that you can just spray some of that canned duster through a crack in the door to trigger the heat sensor on the other side to think someone's leaving

i have done that a few times when I forgot my card at work since i happened to carry a little can of air at the time :v:

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
or slip a receipt under the door.

but yeah, why did you carry a can of compressed air?

Shame Boy
Mar 2, 2010

infernal machines posted:

or slip a receipt under the door.

but yeah, why did you carry a can of compressed air?

... because i wanted to try to open the door with it, then i forgot to take it out of my bag for a few weeks :shobon:

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
that's very sneakers of you

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://bugs.chromium.org/p/chromium/issues/detail?id=694593

Pile Of Garbage
May 28, 2007




i'm probably dumb but does that only affect proxysg os v6.5 or is it v6.5 and later. we're actually in the process of trying to upgrade our pair of blue coats, one is on 6.6 but the other is on 6.5 so lol

cinci zoo sniper
Mar 15, 2013




Absurd Alhazred posted:

Pfft, that's for amateurs. Have you heard of ROT13? Try ROT19! They'll never expect that!
i mean, you dont even need to invent your own cryptoROT or something. get your data, rot13 it, make rot13 of your data your actual data, and store it plain text, so the hackers who find it rot13 into human readable garbage and are left with empty hands :smug:

flakeloaf
Feb 26, 2003

Still better than android clock


quote:

We're waiting on a response from Blue Coat. They were made aware of TLS 1.3 several months ago, but evidently did not test their software per our instructions.

lol?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cheese-cube posted:

i'm probably dumb but does that only affect proxysg os v6.5 or is it v6.5 and later. we're actually in the process of trying to upgrade our pair of blue coats, one is on 6.6 but the other is on 6.5 so lol

quote:

Note these issues are always bugs in the middlebox products. TLS version negotiation is backwards compatible, so a correctly-implemented TLS-terminating proxy should not require changes to work in a TLS-1.3-capable ecosystem. It can simply speak TLS 1.2 at both client <-> proxy and proxy <-> server TLS connections. That these products broke is an indication of defects in their TLS implementations.

hobbesmaster
Jan 28, 2008

Jimmy Carter posted:

HID will do cooler stuff the more money you get them

that being said if you get ahold of one of the earlier iCLASS readers it is possible to dump out the standard private key, which is used in most installations (you can specify your own key for added security but it's wayyyyyyyyyyyy more expensive. If you hold a HID key up to a reader and it doesn't beep, they've got their own. If it does decode, you can clone a card that has access)

i interviewed at hid, i asked a bunch of security questions that got answers like "uhhh, would you be interested in working on that?"

(it was mostly for the printers and I was really not interested in doing that )

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
oops

https://twitter.com/matthew_d_green/status/836552317138788353

Hollow Talk
Feb 2, 2014

Rufus Ping posted:

you may also wish to consider openvpn which is fairly straightforward to set up

This is good advice. OpenVPN comes with easyCA, which serves as a wrapper around openSSL and makes the whole CA creation really straightforward. Depending on keysizes, you might have to edit a pregenerated config file, but it handles everything from CA -> Server Certificate -> Client Certificate(s).

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lol

  • Locked thread