Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Jewel
May 2, 2009

oh my God don't do this poo poo in your username handling, or really, any fields on a consumer website or product

https://twitter.com/0xabad1dea/status/842410941119643648/photo/1

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

Jewel posted:

oh my God don't do this poo poo in your username handling, or really, any fields on a consumer website or product

https://twitter.com/0xabad1dea/status/842410941119643648/photo/1

nicely donetendo

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
dynamically-typed languages own

spankmeister
Jun 15, 2008






anthonypants posted:

dynamically-typed languages own

but unironically

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
jesus christ http://www.citypages.com/news/edina-police-ask-for-whole-citys-google-searches-and-a-judge-says-yes/416319633

PIZZA.BAT
Nov 12, 2016


:cheers:



i don't think that's unreasonable seeing as they're getting a warrant

PIZZA.BAT
Nov 12, 2016


:cheers:


lol @ thinking that will give them anything resembling worthwhile information though

flakeloaf
Feb 26, 2003

Still better than android clock

if their theory is that someone got the photos they used in an ID fraud by doing a GIS for "douglas j.f. jingleheimer schmidt" then yeah, i can see the list of everyone who searched that name being useful but how on earth would you prove that's the search term that brought you there

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Rex-Goliath posted:

i don't think that's unreasonable seeing as they're getting a warrant

that the warrant was granted is precisely the problem

Shame Boy
Mar 2, 2010

i'm the request for MAC addresses

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

extra laughs if the guy's last name is "adams" or some other famous douglas

Truga
May 4, 2014
Lipstick Apathy

Jewel posted:

oh my God don't do this poo poo in your username handling, or really, any fields on a consumer website or product

https://twitter.com/0xabad1dea/status/842410941119643648/photo/1

her name is a computer killing word

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
spotted at my local supermarket: scalable network infrastructure

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Ur Getting Fatter posted:

spotted at my local supermarket: scalable network infrastructure



yeah, those are all networked so they don't have to be individually programmed with product codes/prices

the control software is a dumpster fire and generally there is absolutely no access control whatsoever

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

infernal machines posted:

yeah, those are all networked so they don't have to be individually programmed with product codes/prices

the control software is a dumpster fire and generally there is absolutely no access control whatsoever

doesn't matter because the bar codes they print out are very predictable and have no controls on 'em either

part of the last handful of digits is the price

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
i honestly just wanted to make that dumb joke

edit: remote produce execution

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Cocoa Crispies posted:

doesn't matter because the bar codes they print out are very predictable and have no controls on 'em either

part of the last handful of digits is the price

if it weren't for the fact that they run off a z80 they'd probably be primo botnet targets

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

Ur Getting Fatter posted:

i honestly just wanted to make that dumb joke

edit: remote produce execution

ive been waiting for that dumb sailor moon game to get ppls phones hacked so i could say "moonlight privilege escalation" but it never comes :(

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

ate poo poo on live tv posted:

Civil Forfeiture is hosed up and shouldn't be applauded in anyway.

two wrongs make a right lisa

pseudorandom name
May 6, 2007

Cocoa Crispies posted:

doesn't matter because the bar codes they print out are very predictable and have no controls on 'em either

part of the last handful of digits is the price

only for products that have variable weights

EndlessRagdoll
May 20, 2016

Rufus Ping posted:

that the warrant was granted is precisely the problem

yeah this poo poo is insane. i can't believe the judge was just okay with requesting a whole town's google history. gonna be fun when they realize it is a ton of poo poo to dig through

EndlessRagdoll
May 20, 2016

use duck duck go if you're committing wire fraud

flakeloaf
Feb 26, 2003

Still better than android clock

EndlessRagdoll posted:

yeah this poo poo is insane. i can't believe the judge was just okay with requesting a whole town's google history. gonna be fun when they realize it is a ton of poo poo to dig through

all they're going to get is the pii of anyone who searched that specific term

lol for when they receive a blank cd

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

EndlessRagdoll posted:

i really need to delete my lastpass account

don't stop there lol

but yeah same. wtf lastpass

PIZZA.BAT
Nov 12, 2016


:cheers:


EndlessRagdoll posted:

use duck duck go if you're committing wire fraud

or at least a proxy lol

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

pseudorandom name posted:

only for products that have variable weights

well yeah, hence the grocery scale that needs products loaded so they can print appropriately priced labels

pseudorandom name
May 6, 2007

oh, I thought that was a checkout scale. suddenly your point makes a whole lot more sense.

xPanda
Feb 6, 2003

Was that me or the door?
wouldn't that lastpass vulnerability taviso just showed off be negated by turning off autofill?

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



anthonypants posted:

putty 0.68 came out last month and it's finally got support for 25519 curves :toot:

2 something something 1 9 you say?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

xPanda posted:

wouldn't that lastpass vulnerability taviso just showed off be negated by turning off autofill?

here's a question: why are they using regex that way?

xPanda
Feb 6, 2003

Was that me or the door?

OSI bean dip posted:

here's a question: why are they using regex that way?

i really have no idea, i don't understand much of whats going on in that screenshot

hifi
Jul 25, 2012

i don't know how lastpass works but it looks like it's trying to create a input element that lastpass recognizes as a password field and then it types in the password, so a regex makes sense there

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

xPanda posted:

wouldn't that lastpass vulnerability taviso just showed off be negated by turning off autofill?
wouldn't that lastpass vulnerability taviso just showed off be negated by not using lastpass?

hifi posted:

i don't know how lastpass works but it looks like it's trying to create a input element that lastpass recognizes as a password field and then it types in the password, so a regex makes sense there
lmao

hifi
Jul 25, 2012

sorry i mean makes sense in the sense of, "how do we solve this problem". it's probably something i would do although i don't have to write enterprise grade password software

i wonder how google does it

vOv
Feb 8, 2014

the problem isn't how lastpass is detecting password fields. the problem is that the attack worked despite the fact that travis's exploit page was on a completely different domain.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

hifi posted:

sorry i mean makes sense in the sense of, "how do we solve this problem". it's probably something i would do although i don't have to write enterprise grade password software

i wonder how google does it
you'd think if you're going to automate putting a password into a field, maybe you should remember what the name of the password field is, so you don't put the password into any available text-entry field

hifi
Jul 25, 2012

it's in an iframe though

vOv
Feb 8, 2014

hifi posted:

it's in an iframe though

yeah and you can't gently caress with other domains' iframes.

password fields don't have any special protection from JS, you can still get at their contents with .value(), so there has to be something else going on here.

apseudonym
Feb 25, 2011

https://www.us-cert.gov/ncas/alerts/TA17-075A

Even the US government knows that MiTMs are poo poo, what a world.

Adbot
ADBOT LOVES YOU

xPanda
Feb 6, 2003

Was that me or the door?

anthonypants posted:

wouldn't that lastpass vulnerability taviso just showed off be negated by not using lastpass?

well yes, but i was looking for something more technical than flippant

  • Locked thread