Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
surebet
Jan 10, 2013

avatar
specialist


pseudorandom name posted:

interferes with your Right To Repair

also prevents TouchID MITM attacks

apples and oranges, imho

my expectations of repair-ability of a miniaturized consumer product versus a massive piece of industrial equipment worth more than a house is different

plus my security requirements would be higher on a device that i carry out in public

i would like to be able to repair my phone, but i would poo poo a kidney if i was stuck with a drm'ed critical piece of farm infrastructure

between john deer's bullshit and the horrible contracts doled out by food conglomerates it's a wonder farmers even bother anymore

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

surebet posted:

my expectations of repair-ability of a miniaturized consumer product versus a massive piece of industrial equipment worth more than a house is different

sounds like you've been brainwashed by modern capitalism into just accepting $800 devices as disposable friend

Bulgakov
Mar 8, 2009


рукописи не горят

ate all the Oreos posted:

sounds like you've been brainwashed by modern capitalism into just accepting $800 devices as disposable friend

its a dumb fellow idiot that I've accepted as being a willing accomplice to my day to day existence

iphone wants subdermal finger prints compared to lazier finger scanners


what does this mean for my love life???????

surebet
Jan 10, 2013

avatar
specialist


ate all the Oreos posted:

sounds like you've been brainwashed by modern capitalism into just accepting $800 devices as disposable friend

nah, i cycled through every part for my previous phone at least once and i make my purchase decisions partly based on repair friendliness

electronics manufacturers are flaming shitbags for making their stuff hard to repair (apple is especially guilty here), but i can understand it to a point with space saving & miniaturization

actual industrial equipment should have some lockouts to prevent randoms from poking at everything, but there's no scenario in which i think it's acceptable to both force users to rely exclusively on you and then also refuse any liability

Truga
May 4, 2014
Lipstick Apathy
https://twitter.com/taviso/status/844313307632754688

just disable autofill guys :smugbert:

how the gently caress does this even happen, what the poo poo are they doing with their plugin jfc

xPanda
Feb 6, 2003

Was that me or the door?

Truga posted:

https://twitter.com/taviso/status/844313307632754688

just disable autofill guys :smugbert:

how the gently caress does this even happen, what the poo poo are they doing with their plugin jfc

yeah, the mind boggles

surebet
Jan 10, 2013

avatar
specialist


i'm sure it's not that simple, but why isn't lastpass checking the domain/url of the page it's on before barfing out creds?

Truga
May 4, 2014
Lipstick Apathy
last few times it was regex fuckups or similar, but considering this time poo poo goes straight past autofill, i have no loving idea what's going in anymore.

Maximum Leader
Dec 5, 2014
they obviously hired the adobe flash guys to make their password plugin

Pile Of Garbage
May 28, 2007



taviso has found another one. this is getting to be beyond a joke:

https://twitter.com/taviso/status/844312124541186048

James Baud
May 24, 2015

by LITERALLY AN ADMIN
Look at the bright side, by next week every lastpass user is that much safer against world class attackers.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



surebet posted:

nah, i cycled through every part for my previous phone at least once and i make my purchase decisions partly based on repair friendliness

electronics manufacturers are flaming shitbags for making their stuff hard to repair (apple is especially guilty here), but i can understand it to a point with space saving & miniaturization

actual industrial equipment should have some lockouts to prevent randoms from poking at everything, but there's no scenario in which i think it's acceptable to both force users to rely exclusively on you and then also refuse any liability

what the hell are you doing to your phones you maniac

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

Truga posted:

https://twitter.com/taviso/status/844313307632754688

just disable autofill guys :smugbert:

how the gently caress does this even happen, what the poo poo are they doing with their plugin jfc

they're just assuming any arbitrary connections to that domain are their their plugin, aren't they?

ultramiraculous fucked around with this message at 17:29 on Mar 22, 2017

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

more likely they're trusting some metadata that the page can manipulate but they assumed was solid

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice
I love when libertarians start lobbying for regulations

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

surebet posted:

i'm sure it's not that simple, but why isn't lastpass checking the domain/url of the page it's on before barfing out creds?

It is, at least nominally.

I'm still using LastPass (yes, I know, I'm the real secfuck here, etc), and use a credit union whose website is <cu>.com but which uses <cu>.org in an iframe to log in to their online banking for some inscrutable reason. Every time I open their webpage, LastPass screams, loudly, via modal dialog, at me that <cu>.org isn't the same site as <cu>.com and that this might be a dangerous situation. So, they're definitely checking on some level, it just sounds like it isn't particularly rigorous somehow :(

Shame Boy
Mar 2, 2010

i got a new credit card from my credit union and it finally appeared on my accounts page and



oh no i'm 2,016 years late on my payments already :ohdear:

cinci zoo sniper
Mar 15, 2013




taviso making it into ~le big league news~ with the destruction of lastpass

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Volmarias posted:


I'm still using LastPass (yes, I know, I'm the real secfuck here, etc), and use a credit union whose website is <cu>.com but which uses <cu>.org in an iframe to log in to their online banking for some inscrutable reason.
what in the ever loving gently caress

Asshole Masonanie
Oct 27, 2009

by vyelkin
i'm really mad about lastpass guys. i use windows and mac, is 1pass the right direction to move? i will probably have to buy software now, which is incredibly lame.

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
yeah i'm looking for a new one too

how bad is relying on the password manager built into chrome?

flakeloaf
Feb 26, 2003

Still better than android clock

i'd thought reluctance to rely on a browser's password manager was the whole raison d'etre driving pwms to begin with

cinci zoo sniper
Mar 15, 2013




flakeloaf posted:

i'd thought reluctance to rely on a browser's password manager was the whole raison d'etre driving pwms to begin with

there are non-browser applications, essentially

neutral milf hotel
Oct 9, 2001

by Fluffdaddy
just wait until lastpass forks chromium and bakes their pwm right into the code base :smuggo:

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

flakeloaf posted:

i'd thought reluctance to rely on a browser's password manager was the whole raison d'etre driving pwms to begin with

my original motivation was that i wanted cross-browser support with syncing. the password generation feature was a plus too. i don't need cross-browser support anymore though.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

flakeloaf posted:

i'd thought reluctance to rely on a browser's password manager was the whole raison d'etre driving pwms to begin with

no, it was usually just that browser password managers did not sync between devices on their own, and obviously did not sync to multiple browsers. additionally, browser password managers don't work so well when you need to log into other applications. they were also not encrypted/even encryptable at all originally, but that was more of a minor issue

separate password managers thus were developed to fix those shortcomings

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
it's almost enough to drive one into the apple ecosystem

if safari for windows had keychain support and wasn't a poo poo browser, it'd be a good bandaid

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
i was v sad when they gave up on safari for windows b/c i have to use windows at work

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

Cold on a Cob posted:

i was v sad when they gave up on safari for windows b/c i have to use windows at work

why would you make it worse by using safari

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
it's comforting that this is my mobile carrier

https://twitter.com/DaveManouchehri/status/844379363315474432

moron izzard
Nov 17, 2006

Grimey Drawer
I'm considering switching to dashlane for my father, but hes functionally retarded and has had to get his account recovered multiple times, because he forgot his Last Password. The only one he needs to remember. I've tried physically taping it under the desk, but he then recovered his account, changed his password, and forgot it again, without ever touching it.

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

tarsnap does this too but there's a legitimate reason

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/taviso/status/844573211278794753

one's regex on domains https://bugs.chromium.org/p/project-zero/issues/detail?id=1188 (and also from 2016 https://labs.detectify.com/2016/07/27/how-i-made-lastpass-give-me-all-your-passwords/)

one's firefox-specific https://bugs.chromium.org/p/project-zero/issues/detail?id=1217

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.

Truga posted:

last few times it was regex fuckups or similar,
good news the regex was still hosed up
lol

moron izzard
Nov 17, 2006

Grimey Drawer
Time to start mailing them dozens of used copies of the owl book

moron izzard fucked around with this message at 17:19 on Mar 22, 2017

flakeloaf
Feb 26, 2003

Still better than android clock

https://twitter.com/taviso/status/844574176165822465

gotta hand it to my kid, every time i find another tupperware container full of his poo poo he's quick to empty it out and put it in the dishwasher

burning swine
May 26, 2004



l o l

https://www.helpnetsecurity.com/2017/03/21/nest-security-cameras-stop-recording/

quote:

Google Nest’s Dropcam, Dropcam Pro, Nest Cam Outdoor and Nest Cam Indoor security cameras can be easily disabled by an attacker that’s in their Bluetooth range, a security researcher has found.

The vulnerabilities are present in the latest firmware version running on the devices (v5.2.1). They were discovered by researcher Jason Doyle last fall, and their existence responsibly disclosed to Google, but have still not been patched.

The first two flaws can be triggered and lead to a buffer overflow condition if the attacker sends to the camera a too-long Wi-Fi SSID parameter or a long encrypted password parameter, respectively.

Unfortunately, Bluetooth can’t be disabled on these cameras, so there is little users can do to minimize this particular risk.

Reported to Google: October 26, 2016
Public Disclosure: March 17, 2017
https://github.com/jasondoyle/Google-Nest-Cam-Bug-Disclosures/blob/master/README.md

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
stick the camera into a faraday cage imo

sure the camera no longer works but you're safe and that's what matters, really

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
"Nest is aware of this issue, developed a fix for it, and will roll it out to customers in the coming days."
~150 days to fix allowing random users to essentially tell your cameras to stop recording, excellent work on your security products google

Adbot
ADBOT LOVES YOU

surebet
Jan 10, 2013

avatar
specialist


Powaqoatse posted:

what the hell are you doing to your phones you maniac

i'm accident prone, and since i'm not always in an office environment means my gently caress-ups are usually around machinery or concrete floors

also up until recently i was running blackberries, and parts were hilariously cheap, like "cheaper to resurface my display rather than buy screen protectors" cheap

  • Locked thread