Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
The Earl of ToeJam
Jan 22, 2012

quote:

The America’s JobLink (AJL) system has been affected by a security incident. Between February 23 and March 14, individual job seeker account information including names, dates of birth, and Social Security numbers may have been accessed by an unauthorized user in the AJL systems of ten states.

http://sitedev.ajla.net/pressrelease.html

in case you were curious, no, https doesn't work on the site of a company that promises

quote:

We Can Help You:

[...]

Ensure the security and integrity of your workforce data including personally identifiable information.

Adbot
ADBOT LOVES YOU

Pile Of Garbage
May 28, 2007



Suspicious posted:

how can i tell if i have an illegal ip address :ohdear:

send them to me and i will check them 4 u

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

cheese-cube posted:

send them to me and i will check them 4 u

192.168.1.1

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cheese-cube posted:

send them to me and i will check them 4 u
fe80::1034:56ff:fe78:90ab

Phoenixan
Jan 16, 2010

Just Keep Cool-idge

cheese-cube posted:

send them to me and i will check them 4 u
4.20.69.69

Pile Of Garbage
May 28, 2007



Phoenixan posted:

4.20.69.69

missed opportunity for triple-combo: 69.66.64.20

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


OSI bean dip posted:

browse the site from tor:



Security fuckup megathread: expect to get raided shortly :)

BillWh0re
Aug 6, 2001


cheese-cube posted:

send them to me and i will check them 4 u

this is literally what he does with his app, if you watch the promo video

https://play.google.com/store/apps/details?id=penetrationtest.eVestigator.com&hl=en

Shame Boy
Mar 2, 2010


this has gotta be a parody, right? i refuse to believe jon hendren didn't make this site as an addendum to http://devopsleague.com/

Wiggly Wayne DDS
Sep 11, 2010



wikileaks put out more docs, focusing on apple attacks https://wikileaks.org/vault7/darkmatter/?cia

thunderstrike attacks were being performed circa 2012, 2 years before public research https://wikileaks.org/vault7/darkmatter/document/SonicScrewdriver_1p0/page-4/#pagination

e: and an efi rootkit in 09 https://wikileaks.org/vault7/darkmatter/document/DarkSeaSkies_1_0_CONOP/page-4/#pagination

Wiggly Wayne DDS fucked around with this message at 14:54 on Mar 23, 2017

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
was cleaning out my imgur and i found this blast from the past

cinci zoo sniper
Mar 15, 2013




Cold on a Cob posted:

was cleaning out my imgur and i found this blast from the past


id like a little bit of what he had

30 TO 50 FERAL HOG
Mar 2, 2005



that was an excellent talk

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BiohazrD posted:

that was an excellent talk
too many memes iirc

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

anthonypants posted:

too many memes iirc

u gotta spend memes to make memes

Wiggly Wayne DDS
Sep 11, 2010



https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/eUAKwjihhBs
Intent to Deprecate and Remove: Trust in existing Symantec-issued Certificates
:getin:

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
SSL certs are such a loving racket.

on the other hand, if i really thought I needed to shell out $2k for a SSL cert from some company and then find out it's losing its trust i'd flip my poo poo.

apseudonym
Feb 25, 2011

CRIP EATIN BREAD posted:

SSL certs are such a loving racket.

on the other hand, if i really thought I needed to shell out $2k for a SSL cert from some company and then find out it's losing its trust i'd flip my poo poo.

EV certs do nothing compared to normal certificates. Don't buy them.

30 TO 50 FERAL HOG
Mar 2, 2005



CRIP EATIN BREAD posted:

SSL certs are such a loving racket.

on the other hand, if i really thought I needed to shell out $2k for a SSL cert from some company and then find out it's losing its trust i'd flip my poo poo.

we almost bought a cert from startcom and then went with a comodo reseller. it would have only been $350 or so, but still

CrazyLittle
Sep 11, 2001





Clapping Larry

BiohazrD posted:

we almost bought a cert from startcom and then went with a comodo reseller. it would have only been $350 or so, but still

there's always starfield too

apseudonym posted:

EV certs do nothing compared to normal certificates. Don't buy them.

but if you pay them enough money you can put your name in the padlock thingy don't you want your name in the padlock thingy?

apseudonym
Feb 25, 2011

CrazyLittle posted:

there's always starfield too


but if you pay them enough money you can put your name in the padlock thingy don't you want your name in the padlock thingy?

There's no indication users actually care

30 TO 50 FERAL HOG
Mar 2, 2005



CrazyLittle posted:

there's always starfield too

never heard of them, $8 a year is crazy. im using LE for my home certs but if i wasnt....

30 TO 50 FERAL HOG
Mar 2, 2005



apseudonym posted:

There's no indication users actually care

this is a user problem, EV is good idea because people trust the green padlock and if they see the padlock on paypa1.com they think they are okay

ErIog
Jul 11, 2001

:nsacloud:

apseudonym posted:

There's no indication users actually care

I think that's :thejoke:

Users don't know what SSL certs are at all and just look for the padlock icon (if they actually bother to even look for that).

I would also bet a ton of money that a lot of users think the padlock icon also means the site they're putting lots of personal information into can be trusted with that information.

flakeloaf
Feb 26, 2003

Still better than android clock

i'll be the padlock as favicon.ico

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
i would bet that more people look for the MCAFEE SECURE or similar logo than a padlock in the address bar. or anything else in the address bar. people do not look at the address bar.

apseudonym
Feb 25, 2011

BiohazrD posted:

this is a user problem, EV is good idea because people trust the green padlock and if they see the padlock on paypa1.com they think they are okay

Which is why we're moving toward treating http as actively insecure. It's just that tech is loving slow and you have to argue with idiots every step of the way :smithicide:

ate shit on live tv
Feb 15, 2004

by Azathoth

OSI bean dip posted:

browse the site from tor:



:ironicat:

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010

Wiggly Wayne DDS posted:

https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/eUAKwjihhBs
Intent to Deprecate and Remove: Trust in existing Symantec-issued Certificates
:getin:

I hope someone is making GBS threads a brick rn at symantec

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

apseudonym posted:

EV certs do nothing compared to normal certificates. Don't buy them.

of course not. but there's some people who think they need them. they'll be mad still, in this case.

Shame Boy
Mar 2, 2010

anthonypants posted:

i would bet that more people look for the MCAFEE SECURE or similar logo than a padlock in the address bar. or anything else in the address bar. people do not look at the address bar.

it says right under the submit button that they use industry standard high grade all american made secure sockets, good enough for me

redleader
Aug 18, 2005

Engage according to operational parameters
gently caress i love it when browsers decide to drop trust in a ca

Storysmith
Dec 31, 2006

in the off chance anyone here is on the other side of the embargo, what's the verdict on the new xen vuln (xsa-212)? how hosed are my clouds?

apseudonym
Feb 25, 2011

Storysmith posted:

in the off chance anyone here is on the other side of the embargo, what's the verdict on the new xen vuln (xsa-212)? how hosed are my clouds?

Anyone on the other side of an embargo isn't going to post about it in YOSPOS friend

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Storysmith posted:

in the off chance anyone here is on the other side of the embargo, what's the verdict on the new xen vuln (xsa-212)? how hosed are my clouds?

tthe verdict is its good

Pile Of Garbage
May 28, 2007



redleader posted:

gently caress i love it when browsers decide to drop trust in a ca

:same:

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

redleader posted:

gently caress i love it when browsers decide to drop trust in a ca

same

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

redleader posted:

gently caress i love it when browsers decide to drop trust in a ca

cinci zoo sniper
Mar 15, 2013




meanwhile on national news in latvia - "indian hackers have deleted our tile shop product database after we failed to pay 1500 euro in ransom. twice in two weeks. :qq:"

Adbot
ADBOT LOVES YOU

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
https://twitter.com/campuscodi/status/845211770490904577

whoopsie

  • Locked thread