Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Cocoa Crispies posted:

even warning you that it's a non-https connection to that server is a very recent thing

https://twitter.com/internetofshit/status/847444546741047297

Adbot
ADBOT LOVES YOU

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

CrazyLittle posted:

yes because browser stores are notoriously insecure. Firefox used to store in clear text

the number 1 reason you're using randomly generated passwords and using a password manager is when a random site gets its login information leaked, all your logins everywhere are not immediately hosed.

if you have malware on your computer that can leak your browser's password database, you're already dead.

if your browser vendor's cloud sync platform gets popped, welp,

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

pseudorandom name posted:

Firefox Sync used to use strong crypto which required you to pair new devices with an existing client to do the key exchange, but users were too stupid to understand the concept and thought Sync was a backup mechanism and got mad when they lost everything when they deleted all their Firefox installs

so Mozilla changed it to just derive the key from your Sync password because we can't have nice things

i'm not too stupid to understand the concept, but i wanted to sync my bookmarks from my home computer to my work laptop and it told me to type the code that's displayed on my home computer's screen (or other way around, i don't remember). anyway it was unusable unless i remembered to specifically prepare for the sync process

vOv
Feb 8, 2014

Wheany posted:

the number 1 reason you're using randomly generated passwords and using a password manager is when a random site gets its login information leaked, all your logins everywhere are not immediately hosed.

if you have malware on your computer that can leak your browser's password database, you're already dead.

if your browser vendor's cloud sync platform gets popped, welp,

there could also just be an exploit that lets someone read arbitrary files as you but doesn't give them code execution or anything


someone post the warning ie6 displayed when you were connecting over https

Truga
May 4, 2014
Lipstick Apathy

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.
https://twitter.com/FakeUnicode/status/848836903860289536

Last Chance
Dec 31, 2004


microsoft: "WARNING! THINGS ARE OKAY. IS THAT OKAY? *CLICKS OK*"

Cybernetic Vermin
Apr 18, 2005


haha, legit a funny one, though it will not have a whole lot of impact

Shame Boy
Mar 2, 2010


I DON'T CLICK LEARN MORE

minivanmegafun
Jul 27, 2004

ate all the Oreos posted:

I DON'T CLICK LEARN MORE

learning is for nerds

Pile Of Garbage
May 28, 2007



minivanmegafun posted:

learning is for nerds

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope
Today in the secfuck thread: "if you suddenly get weird new popups in your browser, be sure to click on them"

cinci zoo sniper
Mar 15, 2013




Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

ate all the Oreos posted:

I DON'T CLICK LEARN MORE

Dylan16807
May 12, 2010

Wheany posted:

Today in the secfuck thread: "if you suddenly get weird new popups in your browser, be sure to click on them"

clicking inside a web page can't really do anything that the web page couldn't already do

Truga
May 4, 2014
Lipstick Apathy

Wheany posted:

Today in the secfuck thread: "if you suddenly get weird new popups in your browser, be sure to click on them"

i mean, i'm all for people not clicking on random popups, but how do you propose a browser implement a new feature like this?

this will all be over in a month or two and then people will know that this particular popup is by mozilla telling them the website is poo poo and people will go on with their lives

Shame Boy
Mar 2, 2010

i think the better part is the person who used google's predictive search to gauge how real something was, like i don't even think they actually hit enter on the search they just waited to see if google would suggest the thing they said and deemed it suspicious when it didn't

i mean that's clever in a really stupid way i guess?

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Dylan16807 posted:

clicking inside a web page can't really do anything that the web page couldn't already do

how can the user tell the difference between a safe thing to click and a non-safe thing?

Shaggar
Apr 26, 2006

Truga posted:

i mean, i'm all for people not clicking on random popups, but how do you propose a browser implement a new feature like this?

this will all be over in a month or two and then people will know that this particular popup is by mozilla telling them the website is poo poo and people will go on with their lives

stick it in the url field like what chome does w/ the / across the http. also the learned behavior will be "oh firefox always gives that error and nothing happens so I click ignore"

Shaggar
Apr 26, 2006

Unicode was a mistake.

flakeloaf
Feb 26, 2003

Still better than android clock

I ▯ UNICODE would still be a good t-shirt

akadajet
Sep 14, 2003


unicode sure has a ton of useless control characters

Shame Boy
Mar 2, 2010

Wheany posted:

how can the user tell the difference between a safe thing to click and a non-safe thing?

make it an actual clear OS popup window or something more closely integrated in the browser that doesn't look like it's just part of the website would be a good start, i mean it wouldn't catch the idiots who fall for those fake windows XP popup adds about YOUR COMPUTER HAS 5 MILLION VIRUSES but they're kinda beyond saving anyway

Asshole Masonanie
Oct 27, 2009

by vyelkin

Wheany posted:

wanted to sync my bookmarks from my home computer to my work laptop

use xmarks for this, but disable browser syncing of bookmarks or you may get duplicates

Shame Boy
Mar 2, 2010

or just completely block submitting passwords on non-https and watch the lols

pseudorandom name
May 6, 2007

quote:

Beau du Jour found that the Siime Eye creates a WiFi internet access point whose password, by default, is "88888888." That way, anyone in range can connect to it by guessing the simple password, as he explained in a blog post published on Monday. By looking at the code of the mobile app that comes with the dildo, the researcher also found that once on the dildo's WiFi, you can access its webserver. This has a login portal, but the user is "admin" and the password is blank.

By reverse engineering the firmware, Beau du Jour found a way to get root—hacker speak for taking full control of it—and get persistence on the device, meaning that he could connect to it even outside the range of the WiFi. At that point, it was game over for the smart camera dildo.
https://motherboard.vice.com/en_us/article/camera-dildo-svakom-siime-eye-hacked-livestream

Shame Boy
Mar 2, 2010

why does a dildo have a webserver

why does a dildo have a webserver

flakeloaf
Feb 26, 2003

Still better than android clock

a radiation source, built by the lowest bidder, inserted into the body cavity where your gonads are doesn't sound too smart even before you get stupid iot poo poo like web servers involved

pseudorandom name
May 6, 2007

ate all the Oreos posted:

why does a dildo have a webserver

why does a dildo have a webserver

how else are you going to get the images from the camera?

flakeloaf
Feb 26, 2003

Still better than android clock

pseudorandom name posted:

how else are you going to get the images from the camera?

std card

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/feldpos/status/848554527204794368

Shame Boy
Mar 2, 2010

yes heart-eye emoji i sure am enjoying that discussion

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

ate all the Oreos posted:

why does a dildo have a webserver

why does a dildo have a webserver

ever heard of penetration testing

Shame Boy
Mar 2, 2010

Meat Beat Agent posted:

ever heard of penetration testing

booooooooo

Truga
May 4, 2014
Lipstick Apathy

ate all the Oreos posted:

or just completely block submitting passwords on non-https and watch the lols

this is the correct choice tbh

it'll have worked for symantec

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet



ate all the Oreos posted:

why does a dildo have a webserver

why does a dildo have a webserver

Security Fuckup Megathread v13.4 - why does a dildo have a webserver

flakeloaf
Feb 26, 2003

Still better than android clock


two idiots having an idiot-off

Shame Boy
Mar 2, 2010

Pikavangelist posted:

Security Fuckup Megathread v13.4 - why does a dildo have a webserver

what does God a dildo need with a starship webserver?

Diva Cupcake
Aug 15, 2005

Pikavangelist posted:

Security Fuckup Megathread v13.4 - why does a dildo have a webserver

Adbot
ADBOT LOVES YOU

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

flakeloaf posted:

I ▯ UNICODE would still be a good t-shirt

I had a I � Unicode shirt a few years ago.

  • Locked thread