Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Wiggly Wayne DDS
Sep 11, 2010



that wasn't the fun one they found tbh: https://team-sik.org/sik-2016-024/

then again these were all disclosed and fixed months ago

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i'll use lastpass because it works for me :colbert:

https://www.hackread.com/vbulletin-forums-hacked-data-leaked/

when is nilbog going to be done?

burning swine
May 26, 2004



OSI bean dip posted:

when is nilbog going to be done?

a week, two tops

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

COACHS SPORT BAR posted:

a week, two tops

oh okay. glad that erlang code is coming along

Proteus Jones
Feb 28, 2013




Shut up Professor Green!

https://twitter.com/matthew_d_green/status/836594951702052864

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.


too early to tell if it's a secfuck, but amazon broke the internet

geonetix
Mar 6, 2011


It's a fine display of dependency on the shittiest region AWS has to offer. I hope a lot of people learned valuable lessons tonight.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

geonetix posted:

It's a fine display of dependency on the shittiest region AWS has to offer. I hope a lot of people learned valuable lessons tonight.
https://twitter.com/me_irl/status/836669812583485440

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.



lol at the guy that thinks it's no big deal because theyd have root so could 'get the data anyway'.

if only there were some way of storing the data such that it couldn't be read even if you had the file...

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/Pinboard/status/836665328583135232

ayyyyyyy

cinci zoo sniper
Mar 15, 2013




taviso dm'd bezos about unencrypted data on s3, they are now bulk-encrypting everything xd

Hollow Talk
Feb 2, 2014

infernal machines posted:



too early to tell if it's a secfuck, but amazon broke the internet

alternative uptime

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
beff jezos

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
https://twitter.com/mathowie/status/836659635159379969

:smithcloud:

cinci zoo sniper
Mar 15, 2013





lorf

Celexi
Nov 25, 2006

Slava Ukraini!

NICE!

Thanks Ants
May 21, 2004

#essereFerrari


spankmeister
Jun 15, 2008






Hollow Talk posted:

This is good advice. OpenVPN comes with easyCA, which serves as a wrapper around openSSL and makes the whole CA creation really straightforward. Depending on keysizes, you might have to edit a pregenerated config file, but it handles everything from CA -> Server Certificate -> Client Certificate(s).

easyrsa has had terrible defaults for years, don't use it without changing the keysize to at least 2k

Hollow Talk
Feb 2, 2014

spankmeister posted:

easyrsa has had terrible defaults for years, don't use it without changing the keysize to at least 2k

easy-rsa vars posted:

# Increase this to 2048 if you
# are paranoid. This will slow
# down TLS negotiation performance
# as well as the one-time DH parms
# generation process.

:v:

But yeah, that's what I meant. Change the keysize to 4096 or so, add your own entries for KEY_Name/KEY_COUNTRY etc. and it becomes a useful little tool.

Truga
May 4, 2014
Lipstick Apathy
Yeah openvpn is arguably the best vpn and I'll probably start using it at work despite it needing extra software on windows/macos, because holy poo poo the built-in solution for ikev2 on macos is a piece of flaming garbage. Not that the windows one is much better.

But the easyrsa defaults are garbage, definitely change that poo poo.

spankmeister
Jun 15, 2008






WireGuard is the new hotness btw.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Hollow Talk posted:

:v:

But yeah, that's what I meant. Change the keysize to 4096 or so, add your own entries for KEY_Name/KEY_COUNTRY etc. and it becomes a useful little tool.

Lol how many ms of overhead does this add in reality

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

BangersInMyKnickers posted:

Lol how many ms of overhead does this add in reality

4096 bit keys take like 1s to generate, since it has to find a big probably-prime number

Truga
May 4, 2014
Lipstick Apathy

spankmeister posted:

WireGuard is the new hotness btw.

a vpn that runs as a kernel module? plus, their centos rpms are you of date? i'm not jumping on this train just yet.

spankmeister
Jun 15, 2008






Cocoa Crispies posted:

4096 bit keys take like 1s to generate, since it has to find a big probably-prime number

DH parameters take significantly longer but it's a one time thing anyway.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
is there anything particularly wrong with microsoft's sstp vpn?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

infernal machines posted:

is there anything particularly wrong with microsoft's sstp vpn?

it's IP-over-TCP, which can lead to meltdown if you don't have ample excess bandwidth

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Subjunctive posted:

it's IP-over-TCP, which can lead to meltdown if you don't have ample excess bandwidth

is there a microsoft protocol that doesn't have excessive overhead?

Truga
May 4, 2014
Lipstick Apathy
their /dev/null implementation

because it doesn't exist

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

OSI bean dip posted:

is there a microsoft protocol that doesn't have excessive overhead?

does CIFS? what is it?

spankmeister
Jun 15, 2008






Subjunctive posted:

does CIFS? what is it?

SMB is pretty chatty as far as file sharing protocols go.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Truga posted:

a vpn that runs as a kernel module? plus, their centos rpms are you of date? i'm not jumping on this train just yet.
their goal is to mainline it into the kernel, literally https://www.wireguard.io/roadmap/

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

geonetix posted:

It's a fine display of dependency on the shittiest region AWS has to offer. I hope a lot of people learned valuable lessons tonight.

yeah, use azure :v:

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Truga posted:

Yeah openvpn is arguably the best vpn and I'll probably start using it at work despite it needing extra software on windows/macos, because holy poo poo the built-in solution for ikev2 on macos is a piece of flaming garbage. Not that the windows one is much better.

But the easyrsa defaults are garbage, definitely change that poo poo.

openvpn is the best, clients for everything, including ios, the good mac client is viscosity

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!


i physically rofl'd irl

bobfather
Sep 20, 2001

I will analyze your nervous system for beer money

Cocoa Crispies posted:

openvpn is the best, clients for everything, including ios, the good mac client is viscosity

Tunnelblick for MacOS is free and has never let me down in any capacity. Does Viscosity do something it doesn't, save for cost $9?

Star War Sex Parrot
Oct 2, 2003

I am currently using Cisco AnyConnect Secure Mobility Client

ErIog
Jul 11, 2001

:nsacloud:

bobfather posted:

Tunnelblick for MacOS is free and has never let me down in any capacity. Does Viscosity do something it doesn't, save for cost $9?

Tunnelblick is free and never stops spamming you about loving updates. Subtly, It's one of the most annoying pieces of software I have ever used even if it does do a passable job of allowing me to juggle VPN configs from the OS X menu bar.

It does update itself (unlike Filezilla), but it's still real weird since it feels to me like it should be very stable by this point. I kind of don't want the thing in charge of my VPN creds to be on some weird daily release track.

tldr: TunnelBlick is HeartBleeding edge software

minivanmegafun
Jul 27, 2004

ErIog posted:


tldr: TunnelBlick is HeartBleeding edge software

well seeing that almost all of the updates are to push new builds of OpenSSL you're more correct than you realize

Adbot
ADBOT LOVES YOU

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug
<3 openvpn, my home router is running multiple instances, with/without redirecting all traffic over the tunnel, and on alternative ports like udp 53 and tcp 443 (though yeah tcp/ip over tcp isnt great but if everything else is blocked from some location then its better than nothing)

  • Locked thread