Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Salt Fish
Sep 11, 2003

Cybernetic Crumb
Look, if they didn't send the last few packets somewhere they would just build up inside the doorbell until it was full.

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Truga posted:

the s in iot stands for security

Proteus Jones
Feb 28, 2013



quote:

[–]akesh45 [-1] 4 points 19 hours ago
I should add dahua, hikvison, etc are huge companies.... your concern is valid however unless theyre truly stupid, i have doubts such a backdoor exists. It would kill alot of business for years. Then again.... sony got hacked multiple times so i cant say its not valid.

HAIL eSATA-n
Apr 7, 2007


Salt Fish posted:

Look, if they didn't send the last few packets somewhere they would just build up inside the doorbell until it was full.

in middle-school gym class i was yelled at for not walking during a cooldown and the gym teacher said "where do you think all that blood is going to go? hmm?"

Proteus Jones
Feb 28, 2013



I just managed to bully a client cert out of the help desk for my VPN app. They were going to call me on my "on-file" contact number with the passphrase to unlock the key for import. No worries guys, I managed to get it in one guess: CompanyName123

Gonna have some interesting conversations on Monday.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Truga posted:

the s in iot stands for security

redleader
Aug 18, 2005

Engage according to operational parameters

Truga posted:

the s in iot stands for security

vOv
Feb 8, 2014

Truga posted:

the s in iot stands for security

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Truga posted:

the s in iot stands for security

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Truga posted:

the s in iot stands for security

mods

LordSaturn
Aug 12, 2007

sadly unfunny

Truga posted:

the s in iot stands for security

spankmeister
Jun 15, 2008






Truga posted:

the s in iot stands for security

new thread title pls

Pile Of Garbage
May 28, 2007



Truga posted:

the s in iot stands for security

spankmeister posted:

new thread title pls

mods plzz

Thanks Ants
May 21, 2004

#essereFerrari


spankmeister posted:

new thread title pls

jre
Sep 2, 2011

To the cloud ?



Truga posted:

the s in iot stands for security

Pile Of Garbage
May 28, 2007



flosofl posted:

I just managed to bully a client cert out of the help desk for my VPN app. They were going to call me on my "on-file" contact number with the passphrase to unlock the key for import. No worries guys, I managed to get it in one guess: CompanyName123

Gonna have some interesting conversations on Monday.

yeah, with HR whilst being sacked for violating corpsec policy!

cinci zoo sniper
Mar 15, 2013




Truga posted:

the s in iot stands for security

spankmeister posted:

new thread title pls

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet



Truga posted:

the s in iot stands for security

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Truga posted:

the s in iot stands for security

Security Fuckup Megathread - v13.3 - the s in iot stands for security

also:

quote:

On January 6, 2017, Butte Highland Mining Company changed the focus of the business by acquiring all of the ownership interests of InterLok Key Management, Inc., a Texas corporation engaged in the business of developing and licensing its patented key based encryption methods. To better reflect the new business, the name was changed to Ironclad Encryption Corporation. Ironclad Encryption Corporation focuses on providing global freedom to execute electronic transmissions and store electronic data absent the oppressive intrusion of cyber-terrorism that causes destruction and loss. The company offers cyber security encryption so advanced, it operates without performance degradation or significant band-width usage. To learn more about Ironclad Encryption Corporation, please visit http://ironcladencryption.com.

this seems vaguely familiar

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
patent filed in 1997

https://www.google.com/patents/US6157722

WrenP-Complete
Jul 27, 2012

Truga posted:

the s in iot stands for security

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender


there is no way a headline like that would work now

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Truga posted:

the s in iot stands for security

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

OSI bean dip posted:

this seems vaguely familiar

iron clad, rock solid

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

fart touching

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Truga posted:

the s in iot stands for security

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Also those guys chaos dunked on Matt

Shame Boy
Mar 2, 2010

oh hey the thread changed titles between reloads thanks mods :3:

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

OSI bean dip posted:

Security Fuckup Megathread - v13.3 - the s in iot stands for security

also:


this seems vaguely familiar

i'm the "in the news" section that isn't coverage of the company but coverage of other companies getting hacked

also they all 404, which is also me

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


I read writeups about malware doing this kind of thing for C2 signaling years ago. Not exactly a new behavior though uncommon

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Truga posted:

the s in iot stands for security

lol

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

abraham linkedin posted:

i'm the "in the news" section that isn't coverage of the company but coverage of other companies getting hacked

also they all 404, which is also me

Versimilitude

LordSaturn
Aug 12, 2007

sadly unfunny

OSI bean dip posted:

Security Fuckup Megathread - v13.3 - the s in iot stands for security

also:


this seems vaguely familiar

didn't one of the hucksters from your column have a shell company named that?

EDIT: column lol what am I eighty, I mean your blog

Applebees
Jul 23, 2013

yospos

LordSaturn posted:

didn't one of the hucksters from your column have a shell company named that?

EDIT: column lol what am I eighty, I mean your blog

I think it was a web journal actually

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

LordSaturn posted:

didn't one of the hucksters from your column have a shell company named that?

EDIT: column lol what am I eighty, I mean your blog

lol

yeah. it really is just uncanny. they're different people as far as i can see. sitting on this for now

wolrah
May 8, 2006
what?

BangersInMyKnickers posted:

I read writeups about malware doing this kind of thing for C2 signaling years ago. Not exactly a new behavior though uncommon

I'm pretty sure I've seen a full IP-over-DNS solution implemented a while back as a way to bypass certain captive portals.

Shame Boy
Mar 2, 2010

wolrah posted:

I'm pretty sure I've seen a full IP-over-DNS solution implemented a while back as a way to bypass certain captive portals.

it's built in to DD-WRT

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i've had a lot of success just binding sshd to dns tcp

Westie
May 30, 2013



Baboon Simulator
why do all AV providers feel the need to install MitM certs onto machines nowadays anyway

Adbot
ADBOT LOVES YOU

ErIog
Jul 11, 2001

:nsacloud:

Westie posted:

why do all AV providers feel the need to install MitM certs onto machines nowadays anyway

The misguided notion that you're going to do a better job checking certs than the cert system itself. It does make retarded kind of sense, but it also always ends up with them doing a far weaker implementation. They're not 100% wrong. If they were to do a good job and provide an extra layer in the cert chain then on a long enought timeline they could provde value. They're never going to do that, though. The impulse is understandable. The execution is unconscionable.

  • Locked thread