Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Carbon dioxide
Oct 9, 2012

https://www.youtube.com/watch?v=glZnkpIDWSE

Adbot
ADBOT LOVES YOU

vOv
Feb 8, 2014


it's bothering me more than it should that it doesn't play the 'full' song

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

hackbunny posted:

eeeh that's arguable imo but this:

https://twitter.com/faultywarrior/status/842569756360302593

is not. omg don't use encrypted filesystems as archives, it's a bad bad idea. it's bad crypto! disk encryption is, frankly, a hack: the cipher modes are poorly studied compared to stuff like cbc, and the encryption isn't authenticated (or at least I've never seen an authenticating implementation). never do this

XTS and CBC diffuser modes at least made some attempt to improve this situation so it isn't as bad as it was a few years ago but still not great. validation has too much overhead, gotta run fast and dirty

Shame Boy
Mar 2, 2010

BangersInMyKnickers posted:

XTS and CBC diffuser modes at least made some attempt to improve this situation so it isn't as bad as it was a few years ago but still not great. validation has too much overhead, gotta run fast and dirty

??? XTS was around when i was first setting up FDE for funsies back in highschool like 10 years ago, was that different somehow?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

the standard was accepted in 07 but it takes years before anyone major jumps on new FDE crypto, only starting to go mainstream now. all the major players wanted to give it time to sit and get beat up, seems "ok" at this point

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
whoa phishers are getting tricksy
https://twitter.com/techhelplistcom/status/843832482390855681

Shame Boy
Mar 2, 2010

BangersInMyKnickers posted:

the standard was accepted in 07 but it takes years before anyone major jumps on new FDE crypto, only starting to go mainstream now. all the major players wanted to give it time to sit and get beat up, seems "ok" at this point

well okay, i just seem to remember it was recommended by all the tutorials even back then (like 2008-2009-2010 ish) but then again these were linux turbodorks so not exactly representative of the industry I guess

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
er... bitlocker?

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
I'm the HTML Encryption

Shame Boy
Mar 2, 2010

infernal machines posted:

er... bitlocker?

are you talking to me? no i was using LUKS because turbodork as I mentioned

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i was responding to the notion that fde isn't implemented anywhere

tpm secured bitlocker has been a commercially available product since 2007

burning swine
May 26, 2004



infernal machines posted:

er... bitlocker?

annual reminder that bitlocker was significantly weakened after windows 7 with the removal of the diffuser


:nsa:

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

The diffuser was removed because it wasn't FIPS compliant or compatible with hardware accelerators and the increasing prevalence of SSDs means substantial bottlenecks and large CPU overhead on high performance storage. AES-XTS was in the works to be the default cipher mode and solved those problems and is now the default for all fixed disks and optional for removable. MS made a mistake releasing a non-standard crypto mode and pulling it was the correct thing to do.

cinci zoo sniper
Mar 15, 2013




:rip: cisco

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

lol is the vulnerability really based on a malformed telnet command?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BeOSPOS posted:

lol is the vulnerability really based on a malformed telnet command?
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmp

cinci zoo sniper
Mar 15, 2013




BeOSPOS posted:

lol is the vulnerability really based on a malformed telnet command?

yea

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmp

e: beaten like a router

Wiggly Wayne DDS
Sep 11, 2010



hey that looks familiar
oh right

spankmeister
Jun 15, 2008






transport input all


because it Just Works

cinci zoo sniper
Mar 15, 2013




Wiggly Wayne DDS posted:

hey that looks familiar

oh right
look, no one is trying to steal your precious internet points

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Wiggly Wayne DDS posted:

hey that looks familiar

oh right
weird

spankmeister
Jun 15, 2008






it's a glitch in teh matrix

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

cinci zoo sniper posted:

look, no one is trying to steal your precious internet points

actually, i am

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

commandeer 318 models of cisco gear with this ONE WEIRD TRICK

network engineers HATE THIS!

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
it's a shame too he was the best starbase commander

spankmeister
Jun 15, 2008






The Cisco has completed his task.

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

spankmeister posted:

The Cisco has completed his task.

If that's the case, then why do you live here? [link-exploit]

beepsandboops
Jan 28, 2014
A random utility company filed a Firefox bug report b/c they do logins over HTTP:

[link removed]

beepsandboops fucked around with this message at 03:31 on Mar 21, 2017

Shame Boy
Mar 2, 2010

beepsandboops posted:

A random utility company filed a Firefox bug report b/c they do logins over HTTP:

https://bugzilla.mozilla.org/show_bug.cgi?id=1348902



i'm the website called "Oil and Gas International" that the reporter refers to as "my website" as if they're the only one who works on it or owns it

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

beepsandboops posted:

A random utility company filed a Firefox bug report b/c they do logins over HTTP:

https://bugzilla.mozilla.org/show_bug.cgi?id=1348902



it's run by some former oil industry guy who retired in 2011

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
bless u tavis
https://twitter.com/taviso/status/843965519371812864

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

did somebody deface his site yet

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

:munch:

spit on my clit
Jul 19, 2015

by Cyrano4747
Does this guy just get paid to find vulnerabilities like this? poo poo, sounds like he just does it for fun

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

ate all the Oreos posted:

i'm the website called "Oil and Gas International" that the reporter refers to as "my website" as if they're the only one who works on it or owns it

im the fact when when you try to log into the site it says the users table doesnt exist....................

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



aww the bug report is private

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

spit on my clit posted:

Does this guy just get paid to find vulnerabilities like this? poo poo, sounds like he just does it for fun

yeah his job is to just find broken poo poo for google

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

hes basically an internet superhero

but real

Doom Mathematic
Sep 2, 2008
He's a bounty hunter. It's not immediately obvious from the lack of cool full-body power armour.

Adbot
ADBOT LOVES YOU

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


ate all the Oreos posted:

i'm the website called "Oil and Gas International" that the reporter refers to as "my website" as if they're the only one who works on it or owns it

don't link this right now, thanks!

Somebody fucked around with this message at 02:23 on Mar 21, 2017

  • Locked thread