Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Truga
May 4, 2014
Lipstick Apathy
if let's encrypt destroys paypal, it'll have achieved far more than it set out to do.

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

im the one that has fraud in the name

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

ate all the Oreos posted:

im the one that has fraud in the name

one of the ways to phish people is through an account recovery or fraud protection flow, since most haven't gone through it, and some will be spooked enough by it to not think clearly

my parents got a fake ios app subscription receipt with a very prominent "cancel and manage subscriptions" link and correctly knew it was phishing but they're def. above average

Shame Boy
Mar 2, 2010

Cocoa Crispies posted:

one of the ways to phish people is through an account recovery or fraud protection flow, since most haven't gone through it, and some will be spooked enough by it to not think clearly

my parents got a fake ios app subscription receipt with a very prominent "cancel and manage subscriptions" link and correctly knew it was phishing but they're def. above average

yeah i know i get those all the time, i just think it's funny to see "paypal-fraud-site.cz" or whatever

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
amazing

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
lmao that sounds like so much work

flakeloaf
Feb 26, 2003

Still better than android clock

Cocoa Crispies posted:

lmao that sounds like so much work

would be much easier to just put some ativan in your mouth and drink water

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
what do those kinds of people do for money?

do they think wendy's doesn't have a file on them?

if you're going freegan you might not be getting enough nutrients to run your own brain right or something

if i was using github and jenkems over tor i would probably hate life too

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
idk what the gently caress he's talking about the second I go into incognito mode YouTube serves me ads for Russian toothpaste so whatever high tech tracking they're doing is clearly poo poo

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
it's almost as if someone that goes to all that trouble to hide browsing habits that nobody cares about* is paranoid as hell and sees patterns where none exist

*unless he's a pedo or something, but i'd put odds on him being a plain old :tinfoil:

BillWh0re
Aug 6, 2001



2017 and this linux user still can't get sound in his browser

burning swine
May 26, 2004



BillWh0re posted:

2017 and this linux user still can't get sound in his browser

Truga
May 4, 2014
Lipstick Apathy
tbh that linux user doesn't get many things.

Doom Mathematic
Sep 2, 2008

Ur Getting Fatter posted:

idk what the gently caress he's talking about the second I go into incognito mode YouTube serves me ads for Russian toothpaste so whatever high tech tracking they're doing is clearly poo poo

That's what they want you to think!

Shame Boy
Mar 2, 2010

"hey you need to get on this old service that nobody remembers the password to because reasons"
"hmm ok, let me see if i can find the password somewhere or reset it... oh hey look a text file... with an unsalted MD5 in it, cool"

i love being able to just google MD5's it just makes me giggle :allears:

El Mero Mero
Oct 13, 2001

Google's tossing all of the Symantec certs

Shame Boy
Mar 2, 2010

Ur Getting Fatter posted:

idk what the gently caress he's talking about the second I go into incognito mode YouTube serves me ads for Russian toothpaste so whatever high tech tracking they're doing is clearly poo poo

but the audio could infect your sound drivers and spy on you!!!

i'm just imagining this guy is like Monk but instead of dirt he's freaking out and yelling "attack surface ATTACK SURFACE AAAA"

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


no they aren't. keep reading

quote:

In addition, we propose to require that all newly-issued certificates must have validity periods of no greater than 9 months (279 days) in order to be trusted in Google Chrome, effective Chrome 61

quote:

This proposal allows for web developers to continue to use Symantec issued certificates, but will see their validity period reduced. This ensure that web developers are aware of the risk and potential of future distrust of Symantec-issued certificates, should additional misissuance events occur, while also allowing them the flexibility to continue using such certificates should it be necessary.

Truga
May 4, 2014
Lipstick Apathy
Disgusting abuse of your power! You are punishing 30,000 websites, 99.9%+ of whom are completely legitimate, in order to exact revenge against Symantec.

LEAVE THE INNOCENT BYSTANDERS ALONE!!!!

I propose you block all *new* Symantec certificates until they go back and re-validate (AT THEIR EXPENSE) all the 30,000 websites, and revoke any that are found incorrect.

Be responsible with the power you have, and mindful of the massive collateral damage your actions cause!

You've already just destroyed wosign and startssl wreaking havoc across their entire user base: ***WE*** SUFFER when *you* attack CAs... so STOP IT!!!!

ErIog
Jul 11, 2001

:nsacloud:

Nah, it was a mistake for them to conflate transport layer security with trustiworthiness of the entity in the first place. HTTPS everywhere should be the standard. If e-commerce companies want to create a further layer on top of that to certify trustworthiness then they should do it.

apseudonym
Feb 25, 2011


Its not the CAs job to stop phishing, their job is to verify ownership.

Shaggar
Apr 26, 2006
yeah good luck getting regular people to understand encryption vs trust. especially after its been drilled into their head to look for the lock without explaining what the lock means.

El Mero Mero
Oct 13, 2001

Subjunctive posted:

no they aren't. keep reading

Yes they are:

quote:

To restore confidence and security of our users, we propose the following steps:

A reduction in the accepted validity period of newly issued Symantec-issued certificates to nine months or less, in order to minimize any impact to Google Chrome users from any further misissuances that may arise.

An incremental distrust, spanning a series of Google Chrome releases, of all currently-trusted Symantec-issued certificates, requiring they be revalidated and replaced.


Removal of recognition of the Extended Validation status of Symantec issued certificates, until such a time as the community can be assured in the policies and practices of Symantec, but no sooner than one


They'll all have to be reissued and replaced. I mean, people can still use them, but they won't be trusted.

El Mero Mero fucked around with this message at 17:25 on Mar 24, 2017

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

El Mero Mero posted:

Yes they are:


They'll all have to be reissued and replaced. I mean, people can still use them, but they won't be trusted.

ah yes, you're right, I didn't realize you just meant the current ones

pseudorandom name
May 6, 2007

so these are all in the Safe Browsing list now, right?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/Babylonian/status/845027732845084672

Truga
May 4, 2014
Lipstick Apathy
my favourite part about that thread is that one guy pointing out google has their own CA now and absolutely nobody taking the bait

there just might be hope for humanity left

flakeloaf
Feb 26, 2003

Still better than android clock


go to the sdkfjdsflsdfkl

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

Margo: What's happening?
Hal: It's replicating, eating up memory: what do I do?
The Plague: Type 'sdkfjdsflsdfk', you idiot. I'll head them off at the pass.

Shame Boy
Mar 2, 2010

Shaggar posted:

yeah good luck getting regular people to understand encryption vs trust. especially after its been drilled into their head to look for the lock without explaining what the lock means.

remember how last time you were making this dumb argument it was pretty readily disproven by actual research (Subjunctive posted I think?) showing that no, people don't give a gently caress about the lock or even look at the address bar, and then you just kinda didn't respond to that

remember that

Shaggar
Apr 26, 2006
no I don't. all I remember is people looking at the lock and thinking it means its ok

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
don't quote shaggar

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/CiscoSecurity/status/845331129523748868

100% breach detection yo

Chalks
Sep 30, 2009


Out of all the breaches we detected, we detected 100% of them.

Wiggly Wayne DDS
Sep 11, 2010



https://twitter.com/amallek/status/845337101923205120
Co-Founder/CEO of CertCenter

hrm they seem to resell only symantec certs shocking

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Wiggly Wayne DDS posted:

https://twitter.com/amallek/status/845337101923205120
Co-Founder/CEO of CertCenter

hrm they seem to resell only symantec certs shocking

https://twitter.com/amallek/status/845339483360972801

Shame Boy
Mar 2, 2010

pretend i posted that ms paint drawing of the guy pretending to be retarded until people walk away and then going "heh now they think I'm retarded :smug" because i can't find it

cinci zoo sniper
Mar 15, 2013




lmao

moonshine is......
Feb 21, 2007

Regarding the whole ISP's selling browsing history etc, I'm seeing a lot of people recommend a VPN as a solution. What keeps the ISP from just MITMing your traffic?

Adbot
ADBOT LOVES YOU

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
how would they do that to any arbitrary endpoint without you having to manually trust their certificates?

  • Locked thread