Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
i love my dead gay smart home

Adbot
ADBOT LOVES YOU

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

my goth gf posted:

i love my dead gay smart home

does a gay home like to be close with other homes or something? is it like a duplex?

spankmeister
Jun 15, 2008






no home-o

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

lol

obviously apartments and condos are mormon then

Midjack
Dec 24, 2007



cis autodrag posted:

does a gay home like to be close with other homes or something? is it like a duplex?

duplex is extremely codependent

cinci zoo sniper
Mar 15, 2013




"Ormandy RCE" is an actual phrase now

flakeloaf
Feb 26, 2003

Still better than android clock

cis autodrag posted:

does a gay home like to be close with other homes or something? is it like a duplex?

freehold to be you and me

Truga
May 4, 2014
Lipstick Apathy

cinci zoo sniper posted:

"Ormandy RCE" is an actual phrase now

https://twitter.com/ramriot/status/844575453226713089

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

fishmech posted:

they were also not encrypted/even encryptable at all originally,

pretty sure Mozilla supported the master password from when it first got password management, in the late 90s

Truga
May 4, 2014
Lipstick Apathy
yep, the mozilla solution is pretty ok, though i think there's some issues with syncing passwords over different devices if you have the master password set? or has that been fixed?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I haven't had a problem with it

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Truga posted:

yep, the mozilla solution is pretty ok, though i think there's some issues with syncing passwords over different devices if you have the master password set? or has that been fixed?

firefox sync will replicate the password blob to anything else that supports sync

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
our hr person got a notification that a vendor is updating the ssl cert on their website, and gave them instructions on how to install the cert. it's not self-signed, so i don't know why they wouldn't just attach the CA and intermediate certs instead. i think they might be worried about pinned certificates?

McGlockenshire
Dec 16, 2005

GOLLOCKS!

anthonypants posted:

our hr person got a notification that a vendor is updating the ssl cert on their website, and gave them instructions on how to install the cert. it's not self-signed, so i don't know why they wouldn't just attach the CA and intermediate certs instead. i think they might be worried about pinned certificates?

Are you sure it isn't a client certificate? One of our financial vendors used certificates for user authentication, and that was a real trip figuring out. Their 2013-ish instructions were for IE6 on XP.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

McGlockenshire posted:

Are you sure it isn't a client certificate? One of our financial vendors used certificates for user authentication, and that was a real trip figuring out. Their 2013-ish instructions were for IE6 on XP.
these instructions were provided in a word document sent as a link in the notification email:

quote:

Here are the steps you can use to test the URL to confirm if you will need to manually update your company’s SSL Certificate:
Search for Internet Explorer on your machine
1. Right click – choose Run as administrator
2. Click Yes
3. Paste this URL into the toolbar: https://the url is here
a. If you are able to see the follow page then you shouldn’t need to update your SSL Certificate, if you don’t see the page below, move to step b.

[image of internet explorer with the above url in it]

b. Click on the Lock
i. Click View Certificate
ii. Click Install Cert
iii. Choose Current User
iv. Click Next
v. Choose “Place all certificates in the following store”
vi. Choose the store you store your certificates in
vii. Click Next
viii. Click Finish. You should get a window that advises “The import was successful.”

anthonypants fucked around with this message at 23:06 on Mar 22, 2017

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
https://blog.lastpass.com/2017/03/important-security-updates-for-our-users.html

quote:

Based on our URL parsing process in Firefox 3.3.2, malicious websites could spoof legitimate websites and fool the LastPass add-on into providing user site credentials.

This bug was reported to our team last year and fixed at that time. However, the fix was not pushed down to our legacy Firefox 3.3.x branch; this branch has been scheduled for formal retirement in April.
are they saying they just straight up forgot to patch a vulnerability in a maintained version of their addon?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

yep.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Malloc Voidstar posted:

are they saying they just straight up forgot to patch a vulnerability in a maintained version of their addon?

what they're saying is that they have the highest quality assurance practices going and that they take the development of their application real serious

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
either forgot or didn't care about it because it was deprecated, despite telling taviso earlier this week that most people were on that version

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
http://orionbrowser.com/





Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
the cert is for http://www.evestigator.com.au/ which :magical: how did he think this was a proper site design

ohgodwhat
Aug 6, 2005

The blog is even better: http://www.evestigatorblog.com.au/

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Malloc Voidstar posted:

the cert is for http://www.evestigator.com.au/ which :magical: how did he think this was a proper site design

browse the site from tor:

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
oh man the stuff he boasts about is incredible

"This is when I got involved. When he presented his laptop to me I was able to take off the important data and remove the entire malware/virus, and even further since [the tech support scammers] were still trying to get money out of him, I decided to locate them. Via proprietary techniques, I attained the criminals IP Address, IP, Mobile device make, firmware which was in India."

"I uncovered one of the largest DDOS cyber-attacks (with this case being followed closely in the media) involving defamation of a celebrity."

"15 years ago I discovered a flaw in (one of the world's largest accounting software companies) that revealed credit card details in the hexadecimal binary of the unencrypted data file and alerted the producers of the software to the problem."

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
that mcmahon gif but with each of these pages

Malloc Voidstar posted:

the cert is for http://www.evestigator.com.au/ which :magical: how did he think this was a proper site design

OSI bean dip posted:

browse the site from tor:

ohgodwhat
Aug 6, 2005

I imagine it's like 419 scams being obvious scams intentionally so that only dumb people fall for it. This guy actually makes sure only idiots hire him so he doesn't have to do poo poo and just makes bank.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
part of me wants to do a follow up post to this i posted in haste:
https://securitysnakeoil.org/2017/03/22/shooting-fish-in-a-barrel-orion-browser/

Doom Mathematic
Sep 2, 2008

Malloc Voidstar posted:

hexadecimal binary

Wow!

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

browse the site from tor:



:allears: legit amazing

What ya gonna do, when the austrian police come from you ?

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

OSI bean dip posted:

browse the site from tor:



:five:

Suspicious
Apr 30, 2005
You know he's the villain, because he's got shifty eyes.
how can i tell if i have an illegal ip address :ohdear:

flakeloaf
Feb 26, 2003

Still better than android clock

you must erase this bios within 24 hours

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE

surebet posted:

i'm accident prone, and since i'm not always in an office environment means my gently caress-ups are usually around machinery or concrete floors

also up until recently i was running blackberries, and parts were hilariously cheap, like "cheaper to resurface my display rather than buy screen protectors" cheap

my sister acknowledged she was a dipshit with technology in general so in college her strategy was "use whatever blackberry model came out 2-3 years ago" so every 4-6 weeks she destroyed her phone and just picked up one that was being liquidated from large company fleets for like $20.

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
i'm seriously thinking at this point that storing my username/pws in google keep would be more secure than lastpass, jfc

i'm not actually going to do this

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
a bit surprised that guy isnt on the attrition charlatans page

apseudonym
Feb 25, 2011

Cold on a Cob posted:

i'm seriously thinking at this point that storing my username/pws in google keep would be more secure than lastpass, jfc

i'm not actually going to do this

This is true though so...

Shaggar
Apr 26, 2006

anthonypants posted:

these instructions were provided in a word document sent as a link in the notification email:

I don't think IE does cert pinning so they're probably worried about XP or something that might not still be getting root certificate updates. also you haven't been able to install certs that way from IE for a few years now since they started sandboxing it.

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

apseudonym posted:

This is true though so...

lol yeah

i meant i wouldn't put them in keep because then google could read them too which is still better than any loving website i visit doing it via lastpass, but still not what i want

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Rufus Ping posted:

a bit surprised that guy isnt on the attrition charlatans page
i thought about looking him up on that page but couldn't find it (it is here if you have not seen it http://attrition.org/errata/charlatan/)

  • Locked thread