Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Pile Of Garbage
May 28, 2007



ate all the Oreos posted:

why does a dildo have a webserver

why does a dildo have a webserver

pseudorandom name posted:

how else are you going to get the images from the camera?


lol nice

Adbot
ADBOT LOVES YOU

surebet
Jan 10, 2013

avatar
specialist



ugh, this is going to be me next friday, my sister's clinic did an arguably good thing by allowing new clients to fill out the new patient questionnaire online (instead of having 15 minute bottlenecks at the office) but it's on a plain http wordpress site so it's sketching out people

i think i'm just going to suggest they replace that with a bunch of forms available as pdfs or something so people can fill stuff out at home, but then i'm sure people will start emailing the forms in and that's it's own issue

i guess i could add 10mb of bloat to make them un-emailable

Shaggar
Apr 26, 2006
what your sister's clinic did is a hipaa violation and should be disabled immediately

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Yeah, PDF with no real fields so they have to print it out and write on it seems like the best bet

Shaggar
Apr 26, 2006
or just setup your EHR's user portal properly and have them handle the forms there.

or just have them come 15 minutes early for their first appointment.

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
its funny reading this because i literally just had to re-up my hipaa training for the feds 10 minutes ago

Shaggar
Apr 26, 2006
is that for cms? did you sign the cms cyber pledge for security??

flakeloaf
Feb 26, 2003

Still better than android clock

Shaggar posted:

the cms cyber pledge for security??

why does this sound like a thing five puppets do at the beginning of a kids tv show

Shaggar
Apr 26, 2006
because cms is litterrall clown town

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Shaggar posted:

is that for cms? did you sign the cms cyber pledge for security??

nah, it was for another agency. i had to do fisma as well, which had a different pledge.

i love how all the agencies have different requirements for this poo poo, and also their own set of NIST modifications which almost universally make things less secure

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

minivanmegafun posted:

learning is for nerds
https://www.youtube.com/watch?v=hmUKwgHHyeU

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

ate all the Oreos posted:

why does a dildo have a webserver

why does a dildo have a webserver

has anyone said distributed denial of sex?

(aka what feminazis do to gamergaters)

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Pikavangelist posted:

Security Fuckup Megathread v13.4 - why does a dildo have a webserver

Security Fuckup Megathread v13.4 - At that point, it was game over for the smart camera dildo.

Truga
May 4, 2014
Lipstick Apathy

Volmarias posted:

Security Fuckup Megathread v13.4 - At that point, it was game over for the smart camera dildo.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Ur Getting Fatter posted:

has anyone said distributed denial of sex?

(aka what feminazis do to gamergaters)

PoC with Lysistrata for millennia

Storysmith
Dec 31, 2006

a literal sec gently caress up

also I cannot stop reading that brand name as "slime eye" which is a really crass name for a cervix

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

Volmarias posted:

Security Fuckup Megathread v13.4 - At that point, it was game over for the smart camera dildo.

Shaggar
Apr 26, 2006

Pikavangelist posted:

Security Fuckup Megathread v13.4 - why does a dildo have a webserver

I like this one a little better but either way

surebet
Jan 10, 2013

avatar
specialist


Shaggar posted:

what your sister's clinic did is a hipaa violation and should be disabled immediately

yup, done as soon as i caught wind of it

although i think it's a pipeda violation, i'm not even sure we have a hipaa-like equivalent in this province

re: having people show up 15 minutes in advance, yeah that never works, so having people show up with their stuff ready to go is really the best possible workflow

they'll eventually spring for a proper forward facing system to have people fill in their info, but for now i'm pretty sure that having a link to a 26mb pdf in the welcome email is a ghetto as all hell but compliant solution

Thanks Ants
May 21, 2004

#essereFerrari


Storysmith posted:

also I cannot stop reading that brand name as "slime eye" which is a really crass name for a cervix

freeasinbeer
Mar 26, 2015

by Fluffdaddy
or you could just wrap it up in ssl?

EMILY BLUNTS
Jan 1, 2005

Security Fuckup Megathread - v13.3 - plugins may violate privacy

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

EMILY BLUNTS posted:

Security Fuckup Megathread - v13.3 - plugins may violate privacy
we already have a name for 13.3 though

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

EMILY BLUNTS posted:

Security Fuckup Megathread - v13.3 - plugins may violate privacy

Security Fuckup Megathread - v13.69 - plugins may violate privacy

surebet
Jan 10, 2013

avatar
specialist


Punkbob posted:

or you could just wrap it up in ssl?

per the advice i got in this thread (and really, common sense) i'm not doing security related for them, including setting up a server

i'm game to throw in a recommendation here or there and help them understand concepts, but that's it

1) i'm doing this pro-bono to help my sister, but she's working in an established clinic with owners that should know better
2) lol @ the idea of taking on healthcare liability
3) i'm also a patient (gp, neurology) with a bunch of schedule ii stuff prescribed, so extra lol @ the idea of touching a network that has a computer able to issue any kind of prescriptions

that said, if you guys have suggestions of stacks they should look into, i'll gladly relay them

a witch
Jan 12, 2017

my suggestion is to never work for free.

Shaggar
Apr 26, 2006

surebet posted:

yup, done as soon as i caught wind of it

although i think it's a pipeda violation, i'm not even sure we have a hipaa-like equivalent in this province

re: having people show up 15 minutes in advance, yeah that never works, so having people show up with their stuff ready to go is really the best possible workflow

they'll eventually spring for a proper forward facing system to have people fill in their info, but for now i'm pretty sure that having a link to a 26mb pdf in the welcome email is a ghetto as all hell but compliant solution

oh idk how things work in non-America but here most providers have EHRs that provide portals for patients to do secure communication w/ the provider. you can do things like get ur medical records order rx refils securely message the doc or manage forms!! not all providers fully utilize their EHRs tho and an even smaller fraction have their patient portals configured and an even yet more tinier fraction use them effectively.

its totally possible to do it effectively w/out resorting to pdfs at all.

vodkat
Jun 30, 2012



cannot legally be sold as vodka

Shaggar posted:

Unicode was a mistake.

can someone explain to my why unicode is bad from a secfuck point of view?

surebet
Jan 10, 2013

avatar
specialist


i should mention that previous recommendations included "do you really need off brand philips hue rgb lightbulbs in the kitchen" and "why oh god why are you straight up giving wifi network credentials to randoms in the waiting room"

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

vodkat posted:

can someone explain to my why unicode is bad from a secfuck point of view?

xn--e77hhaecegybmf7bpt0a.com

because i can register that domain

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

vodkat posted:

can someone explain to my why unicode is bad from a secfuck point of view?
you quoted a post, but did you see which post it was replying to?

Shaggar
Apr 26, 2006

vodkat posted:

can someone explain to my why unicode is bad from a secfuck point of view?

well that was mostly a joke but in this case there are control codes in Unicode that lots of UIs dont show either because they are litterrally control codes and are doing some kind of formatting themselves or because they don't mean anything to the user. The problem is they do mean something to the system so the result is you can do things like in that example where you have 3 files, 2 with Unicode control characters at the end. the result is the user sees 3 identically named files since the control characters are ignored.

I guess the fix would be that if the control code has no meaning in the current language always show them. then let the user decide if they actually want them. if the language does support them then I guess the text should display differently based on the codes? idk.

tl;dr: Unicode is complex and that makes things hard where ascii is ez as gently caress

vodkat
Jun 30, 2012



cannot legally be sold as vodka

anthonypants posted:

you quoted a post, but did you see which post it was replying to?

but it seems like these fuckups would be fairly easy to head off by limiting the set of unicode characters you can use for system applications etc? or is there a more fundamental flaw in unicode itself, thats what I was really wondering

Shaggar
Apr 26, 2006
some of those characters are required for the display of certain non-English languages. that makes them worthless characters that shouldn't exist for sure, but apparently foreigners like to pretend they don't all just speak English

surebet
Jan 10, 2013

avatar
specialist


OSI bean dip posted:

xn--e77hhaecegybmf7bpt0a.com

because i can register that domain

lol god drat it



good luck getting someone to type that, but i can see the risk in clickable link form

not sure what the crossover of "people who click on links in weird emails" and "people who have a font stack capable of rendering obscure unicode" is

Shaggar
Apr 26, 2006
well I think the url would be presented as Unicode in the client so it wouldn't look fishy except for the font differences. but then you could probably find a similar font and make it all fit.

Chalks
Sep 30, 2009

vodkat posted:

but it seems like these fuckups would be fairly easy to head off by limiting the set of unicode characters you can use for system applications etc? or is there a more fundamental flaw in unicode itself, thats what I was really wondering

For example, unicode contains things like a variety of different widths of whitespace characters. I recently discovered that if you send a message containing normal spaces via Skype for Business, it will convert them to some sort of unicode space. Someone sends you a powershell snippet or a hosts file line, lol, have fun running in circles for a while until you realise what happened.

Having characters that are indistinguishable from each other is a recipe for gently caress ups, security or otherwise.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

vodkat posted:

but it seems like these fuckups would be fairly easy to head off by limiting the set of unicode characters you can use for system applications etc? or is there a more fundamental flaw in unicode itself, thats what I was really wondering
as always, the end user will always be the biggest secfuck of all

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

Chalks posted:

Having characters that are indistinguishable from each other is a recipe for gently caress ups, security or otherwise.

had to research a bug a few months back where a user was entering a records into our system and it was making GBS threads the bed. turns out "Foo(Bar)" is not the same as "Foo❲Bar❳" and VB6 is awful

Adbot
ADBOT LOVES YOU

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

surebet posted:

not sure what the crossover of "people who click on links in weird emails" and "people who have a font stack capable of rendering obscure unicode" is

uh, all you need is like windows vista and newer or os x 10.5 and newer

by current stats that's like, 90% of internet users. 92% if toss in linux users who will also have that.

  • Locked thread