Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Jabor
Jul 16, 2010

#1 Loser at SpaceChem
the vulnerability isn't "tricking" lastpass into auto-filling something - it'll autofill anything that looks like a password, that's the whole point.

the vulnerability is tricking lastpass into thinking bankofamerica.evil.com is a good place to autofill your bank password

Adbot
ADBOT LOVES YOU

xPanda
Feb 6, 2003

Was that me or the door?
if that's the case, then this is a further nail in the coffin of lastpass' autofill feature, rather than something abhorrently new. not saying lastpass isn't a dumpster fire, nor that they should be trusted to be doing things correctly without evidence, but this seems to be another variation of something taviso demonstrated a few months ago

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

xPanda posted:

if that's the case, then this is a further nail in the coffin of lastpass' autofill feature, rather than something abhorrently new.
look who's being flippant now

moron izzard
Nov 17, 2006

Grimey Drawer
Is there a reason they are a version behind between whats on addons.mozilla.org and what you get if you download directly from the website.

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
at this point pretty much the only way to get any actual outrage would be to exploit a bunch of smart TVs that have microphones so that they record a bunch of audio and then put it up on pirate bay.

gently caress, the largest employer in the US got hacked and nothing really happened other than 9/11 mayor getting made chief of cyber.

ErIog
Jul 11, 2001

:nsacloud:

A Yolo Wizard posted:

Is there a reason they are a version behind between whats on addons.mozilla.org and what you get if you download directly from the website.

I have a friend who does addon development for Firefox and he's always complaining about the approval queue for new versions for the official addons site. I mean LastPass probably forgot to submit a new version, but some of the blame for some of the lag that might exist might also go to Mozilla.

Wiggly Wayne DDS
Sep 11, 2010



i'm glad so many people are rushing to defend lastpass given their spotless security history

pseudorandom name
May 6, 2007

welp, if I wanted to be a career rapist, I now know who I'd want to be my Ph.D advisor

vOv
Feb 8, 2014

pseudorandom name posted:

welp, if I wanted to be a career rapist, I now know who I'd want to be my Ph.D advisor

uh what

pseudorandom name
May 6, 2007

just more Jacob Appelbaum stuff, this time implicating djb as a facilitator

Loving Africa Chaps
Dec 3, 2007


We had not left it yet, but when I would wake in the night, I would lie, listening, homesick for it already.

vOv posted:

uh what

https://twitter.com/hdevalence/status/842526511915786240

ohgodwhat
Aug 6, 2005

Why the gently caress are those people so lovely? Why would anyone cover for such an awful awful person?

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

quote:

On the last day of the Japan trip, I returned to the AirBNB and stayed upstairs by myself, in an attempt to take some time alone before I would have to be stuck with Jacob for the 16-hour trip back to Europe. Jacob came upstairs with a bottle of irritant eye drops, supposedly containing menthol, and pushed me to let him put them in my eyes. I said no, three times, before deciding that, because Jacob thrives on provoking negative reactions from others, it would be best to “go along to get along” until I would no longer have to deal with him. My right eye, into which Jacob placed an irritant eye drop, has never really felt the same since then; for months afterward it was continually slightly irritated, often watering, and I would get headaches localized to my right temple.

wtf

people need to stop rolling over for fuckers like this

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
i guess that's blaming the victim but i mean everyone involved in this loving fiasco, covering for him or minimizing for him

gently caress

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Cold on a Cob posted:

wtf

people need to stop rolling over for fuckers like this

rethink this

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Cold on a Cob posted:

i guess that's blaming the victim

I GUESS

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
yeah i phrased that poorly, my anger should be aimed solely at the jacob and the people that covered for him

Suspicious
Apr 30, 2005
You know he's the villain, because he's got shifty eyes.
and what is so precious about this jacob that he must be protected at all costs

flakeloaf
Feb 26, 2003

Still better than android clock

Cold on a Cob posted:

wtf

people need to stop rolling over for fuckers like this

i don't care what kind of special flower you are, there's no story that'll end with "and then i let him put some mystery irritant in my loving eye"

AggressivelyStupid
Jan 9, 2012

Bernstein is a wild rear end in a top hat jesus loving christ

flakeloaf
Feb 26, 2003

Still better than android clock

quote:

In the taxi to the airport and on the airplane, Jacob continued his inappropriate, boundary-violating behaviour, loudly describing to me (and the entire airplane) how at a previous job (at Kink.com) he had “hosed a woman with a converted Sawzall”, before asking “have you ever seen a woman squirt?”, and adding “This is not a work conversation, by the way” as if that were some kind of magical incantation that would make his behaviour appropriate.

you know that experiment they did where they raised monkeys with robots to see how hosed up their concept of a social structure would be?



this one?

convince me jacob is not the product of a similar experiment with a child raised entirely by the internet in the absence of any meaningful opposition from a parental figure

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
This is the first time I've heard of that monkey experiment and holy poo poo that's disturbing as gently caress

I will not convince you otherwise

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


flakeloaf posted:

you know that experiment they did where they raised monkeys with robots to see how hosed up their concept of a social structure would be?



this one?

convince me jacob is not the product of a similar experiment with a child raised entirely by the internet in the absence of any meaningful opposition from a parental figure

lmao at 'this is not a work conversation by the way' like you can add nsfw tags irl or something

Shame Boy
Mar 2, 2010

Migishu posted:

This is the first time I've heard of that monkey experiment and holy poo poo that's disturbing as gently caress

I will not convince you otherwise

they made fun of it on MST3k, crow's mother was shown to be one of those wire mesh nipple robots

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice
in lighter news:

https://nakedsecurity.sophos.com/2017/03/16/switch-console-flaw-leaves-nintendo-looking-flat-footed/

flakeloaf
Feb 26, 2003

Still better than android clock

quote:

It might actually be the first time in history that people could get their hands on a console hack more easily than on the console itself.

moron izzard
Nov 17, 2006

Grimey Drawer

They've removed almost all data management tools from the switch, compared to the wii and wii u (beyond "delete this" and "delete this but leave a link on my main screen in case I want to download it again"). All saves are internal memory only. You can't move games from the internal storage to the sd card directly, and you can't choose where to download a game if you have the sd card inserted.

But there is no save or game file manipulation needed to hack the wii u (also a browser based exploit), and they'll probably gently caress that up with the switch as well.

Shame Boy
Mar 2, 2010

quote:

We recently updated the password security on the Synergy website (symless.com/synergy). This means you'll need to visit our site and set a new password. Use the "Forgot Your Password?" link on the login page.

https://symless.com/password/reset
We previously had a roll-your-own PHP website that I wrote back in 2009 when I started working on Synergy. Poor Dan, our new web developer, had to struggle along with my old code for the last few months, almost going insane in the process.

Yesterday, he completed his masterpiece: a lean rewrite of the entire website using Laravel, which now loads 2.4 times faster on average. The security professionals out there will be glad to know that we now use bcrypt hashing for password storage.

what did you use before now, guys :ohdear:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

quote:

The security professionals out there will be glad to know that we now use bcrypt hashing for password storage.

nice jab there

Truga
May 4, 2014
Lipstick Apathy
wait, synergy costs money now?

:rip:

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

flakeloaf posted:

you know that experiment they did where they raised monkeys with robots to see how hosed up their concept of a social structure would be?



this one?

convince me jacob is not the product of a similar experiment with a child raised entirely by the internet in the absence of any meaningful opposition from a parental figure

that kink.com story. that site sure loves to constantly pitch themselves as progressive women loving folks but they sure do seem to hire rapists at an extraordinary clip.

Shame Boy
Mar 2, 2010

Truga posted:

wait, synergy costs money now?

:rip:

he sent out an email a while ago saying that he put a ton of effort into it and only like 0.001% of all users donated so "it's going to cost money now"

i happened to be one of the suckers that donated before it cost money so i get access to the premium version of everything he makes for life :smug:

Pile Of Garbage
May 28, 2007



just gony drop this here

https://twitter.com/faultywarrior/status/842687723408412673

AggressivelyStupid
Jan 9, 2012

On a scale of 1 to 10 how bad is storing SSNs in plaintext? I'm asking for a friend.

E: along with pretty much every other piece of PII

Truga
May 4, 2014
Lipstick Apathy
tbh, synergy is still on github, so it's not a big deal, people will just compile it. but that is lovely of people not donating anything.

i generally donate to projects i use often and can't contribute to in some way otherwise, especially big productivity enhancers like synergy.


titanic also never sank before

e:

AggressivelyStupid posted:

On a scale of 1 to 10 how bad is storing SSNs in plaintext? I'm asking for a friend.

E: along with pretty much every other piece of PII

the correct way to handle personal information is to use your govt api to only get information when you need it, and then discard it. let it be their problem. you can probably do better than them, but you still don't want to be liable for poo poo imo.

Truga fucked around with this message at 16:41 on Mar 17, 2017

spankmeister
Jun 15, 2008






AggressivelyStupid posted:

On a scale of 1 to 10 how bad is storing SSNs in plaintext? I'm asking for a friend.

E: along with pretty much every other piece of PII

You need to store them either with reversible encryption, or if you hash them, you can very easily enumerate the entire keyspace of all SSN's with any kind of hashing algorithm, there's only like what, a billion different possible SSN's?

Shame Boy
Mar 2, 2010

@bigendiansmalls is a great name

flakeloaf
Feb 26, 2003

Still better than android clock

pii at rest will soon be in motion

AggressivelyStupid
Jan 9, 2012

For clarification, I'm not the one storing them. If it were up to me I'd not touch that poo poo because I don't want to get owned and have it be my fault for being a big dumb idiot.

I'm just looking at my own unencrypted ssn right now and am kinda annoyed but resigned to the fact that I already am owned

Adbot
ADBOT LOVES YOU

burning swine
May 26, 2004



Truga posted:

wait, synergy costs money now?

:rip:

I was pretty annoyed by this, they started charging right at the same time that they completely broke synergy on linux. They broke their poo poo then began charging to update to a working version

arch even created a package with this description:

code:
aur/synergy-1.6 1.6.3-1 (11) (0.53)
    Synergy upstream 1.6 branch. 1.7.x is very unstable on Linux.

  • Locked thread