Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
apseudonym
Feb 25, 2011

Ur Getting Fatter posted:

I enjoyed that post friend

also apseudonym I too would enjoy even a mildly :effort: post about janky old android security!

Its not janky :colbert:

Adbot
ADBOT LOVES YOU

jre
Sep 2, 2011

To the cloud ?



apseudonym posted:

Its not janky :colbert:

It's non existent

apseudonym
Feb 25, 2011

jre posted:

It's non existent

:allears:

jre
Sep 2, 2011

To the cloud ?




Oh have they finally fixed the problem of 99.9% of android devices never getting an update security or otherwise once they leave the factory ?
I must have missed that.

akadajet
Sep 14, 2003

jre posted:

Oh have they finally fixed the problem of 99.9% of android devices never getting an update security or otherwise once they leave the factory ?
I must have missed that.

Oh come on, they usually get at least 1 update.

cinci zoo sniper
Mar 15, 2013




cast iron oven or something https://www.pentestpartners.com/blog/iot-Aga-cast-iron-security-flaw/ i dont even

quote:

However, the mobile app communicates over plain text HTTP. The Android app explicitly disables certificate validation through use of ALLOW_ALL_HOSTNAME_VERIFIER. Even if it did offer SSL, it would thus be trivial for rogues to intercept and modify traffic.

Digging deeper, it turns out that a physical module is added to the Aga. It contains a GSM SIM, to which the customer has to subscribe to Orange/EE (at £6/month).

...

Seriously, the web app sends text messages to your cooker.

hobbesmaster
Jan 28, 2008


gsm modem module costs many times a wifi chip so the "it's cheap" reason is actually wrong. additionally, on the carrier side you can configure sims to only be allowed to communicate with certain endpoints on a private network that cannot leave hat carrier so it's actually possible for sms to be deployed somewhat securely; assuming your cell phone carrier has done its job

unfortunately that modem will stop working in the not so distant future. 2g service is already mostly gone in the us

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

hobbesmaster posted:

2g service is already mostly gone in the us

wrong, the only carriers doing 2g shutdown in the us are at&t (who will have their network completely shut by about june), and a few minor local regional carriers. there's also a few territories that were sold from cdma carriers to gsm carriers or vice versa after 3g was out, and which thus never had 2g service installed by the new carrier.

all other carriers don't plan to shut down 2g gsm/cdma until 2020.

Shame Boy
Mar 2, 2010

cinci zoo sniper posted:

I admit it, I have an Aga. Before I get a tonne of stick for energy inefficiency, I drive electric cars, have solar thermal panels and heat the house using a log boiler (that also has a Wi-Fi interface, more on that another time though).

yes, the reason people laugh at you for owning an internet-enabled turn of the century stove is because of the efficiency

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

quote:

Tekelek have a history in remote monitoring of oil storage tanks, heating systems, process control and medical devices among many things. These appear to be monitored using SMS, so I wonder where else this bizarre unauthenticated text messaging process might lead…

well that's fun

hobbesmaster
Jan 28, 2008

they could be relying on their mvno to handle all that for their other applications. this is how twilio for example makes money.





...but knowing how secure iot stuff is probably not

Bulgakov
Mar 8, 2009


рукописи не горят

its pagers all the way down

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe
not really a sec fuckup but i think corporate espionage still counts

https://www.engadget.com/2017/04/13/uber-hell-program-lyft-drivers/

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Dex posted:

remote monitoring of oil storage tanks

did you know hackers was a documentary?

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.

quote:

AGAs have recently been criticised for their high energy consumption and inefficiency.[2] A small, traditional two-oven AGA running on gas will use approximately 425 kWh per week (22,100 kWh per year; perhaps half that if switched off during the summer months). The average standard gas oven and hob uses 580 kWh during a year, only 2.62% of the AGA's consumption.

darkforce898
Sep 11, 2007

hobbesmaster posted:

they really want an LTE only network as soon as possible. of course that'll only occur after cat-m1 and nb-iot are deployed.

they're kinda ahead of their customers though. the latest hilarity was them saying that they were going to stop providing static IPv4 addressing in June. then they said "just kidding" when they realized they hadn't certified any modules for IPv6 static addresses

sprint claimed that they're keeping their cdma stuff around longer. good for selling out all the cdma radios lying around

This is happening by the way.
https://solutionslab.vzw.com/wp-content/uploads/2017/04/10736379_WP_Persistent_Prefix_IPv6_V1c_chi.pdf

I don't know enough about IPv6 to know if it is a good idea or not though.

minivanmegafun
Jul 27, 2004


it's bad but the fix was backported to the 3 branch back in February 2016, so most systems should be okay

unless you're on the rackspace cloud, though, we found out today that their stock system images that are being bootstrapped today are shipping 2 years out of date kernels :yayclod:

Midjack
Dec 24, 2007




i'm the pearl clutching about an internet of poo poo device having security problems

duTrieux.
Oct 9, 2003

Midjack posted:

i'm the pearl clutching about an internet of poo poo device having security problems

some people still have illusions to be shattered.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

atomicthumbs posted:

quote:

AGAs have recently been criticised for their high energy consumption and inefficiency.[2] A small, traditional two-oven AGA running on gas will use approximately 425 kWh per week (22,100 kWh per year; perhaps half that if switched off during the summer months). The average standard gas oven and hob uses 580 kWh during a year, only 2.62% of the AGA's consumption.
jesus christ

ohgodwhat
Aug 6, 2005

JFC they cost tens of thousands of dollars, and seemingly having them run all day is a feature? It's like loving audiophile poo poo for cooking

Edit: sorry, the great thing about the new model is that you can turn it off! Unlike normal stoves I guess? https://youtu.be/wZiNxafBZ9o

vOv
Feb 8, 2014

if you live somewhere cold then it'll probably offset your heating bill at least

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

ohgodwhat posted:

JFC they cost tens of thousands of dollars, and seemingly having them run all day is a feature? It's like loving audiophile poo poo for cooking

Edit: sorry, the great thing about the new model is that you can turn it off! Unlike normal stoves I guess? https://youtu.be/wZiNxafBZ9o

that's over seven hundred dollars a year to run at british gas rates, not counting the text messaging serving

also it's basically a half-ton radiator, you probably have to open every window in the kitchen just to stand being in the same room

akadajet
Sep 14, 2003

This is the dumbest poo poo ad I've ever seen
https://www.youtube.com/watch?v=nVXALZQ6Y6M

hobbesmaster
Jan 28, 2008

rjmccall posted:

that's over seven hundred dollars a year to run at british gas rates, not counting the text messaging serving

also it's basically a half-ton radiator, you probably have to open every window in the kitchen just to stand being in the same room

seems like it'd be useful in iceland

30 TO 50 FERAL HOG
Mar 2, 2005



this is a real product? it feels like a tim and eric skit

"here use this oven. its like a regular oven but its huge an ugly and costs 10 times as much in utilities"

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

akadajet posted:

This is the dumbest poo poo ad I've ever seen
https://www.youtube.com/watch?v=nVXALZQ6Y6M
a blind, noble prize-winning physicist

hobbesmaster
Jan 28, 2008

BiohazrD posted:

this is a real product? it feels like a tim and eric skit

"here use this oven. its like a regular oven but its huge an ugly and costs 10 times as much in utilities"

its a product unchanged* since before central air was invented

older = better right

*except to add insecure internet controls :laugh:

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE

hobbesmaster posted:

gsm modem module costs many times a wifi chip so the "it's cheap" reason is actually wrong. additionally, on the carrier side you can configure sims to only be allowed to communicate with certain endpoints on a private network that cannot leave hat carrier so it's actually possible for sms to be deployed somewhat securely; assuming your cell phone carrier has done its job

unfortunately that modem will stop working in the not so distant future. 2g service is already mostly gone in the us

https://www.aliexpress.com/store/pr...2802458477.html you can strap anything to the cell network for :10bux: now

hobbesmaster
Jan 28, 2008

Jimmy Carter posted:

https://www.aliexpress.com/store/pr...2802458477.html you can strap anything to the cell network for :10bux: now

if you lie to the carrier about what device it is, maybe. you need a certified device to get on their network

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

hobbesmaster posted:

if you lie to the carrier about what device it is, maybe. you need a certified device to get on their network

Uh.

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.

hobbesmaster posted:

if you lie to the carrier about what device it is, maybe. you need a certified device to get on their network

for sprint or verizon, sure

this is GSM

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



hobbesmaster posted:

seems like it'd be useful in iceland

i thought iceland had pretty much free geothermal heating but i guess it costs between 500 and 1400 eur per year depending where you live

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

ohgodwhat posted:

JFC they cost tens of thousands of dollars, and seemingly having them run all day is a feature? It's like loving audiophile poo poo for cooking

Edit: sorry, the great thing about the new model is that you can turn it off! Unlike normal stoves I guess? https://youtu.be/wZiNxafBZ9o

I'm shocked that a british home appliance is inefficient, poorly thought out, and expensive to boot.

BattleMaster
Aug 14, 2000

i'm actually kind of angry that such an ostentatious display of conspicuous consumption exists as a stove that burns gas 24/7 and needs its own cell phone plan and is controlled by text messages

Truga
May 4, 2014
Lipstick Apathy

Cocoa Crispies posted:

I'm shocked that a british home appliance is inefficient, poorly thought out, and expensive to boot.

spankmeister
Jun 15, 2008






New shadowbrokers dump

https://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation

This time with Windows exploits (7, 2008R2) and the Swift archive has a list of targets that were hacked to poo poo including router configs and network topology maps etc...

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

there's actually a reason why we had separate taps for years. the first running hot water systems (invented in britain while most of the world barely had running cold water) required a separate tap because they heated the water in the pipe directly under the sink using flue gases from the fireplace (yes, that is ridiculously dangerous and dumb) and they were the standard for 70 or so years before centralised water-heating systems started to become economical enough to replace the old systems.

even then for years there was a legal requirement to prevent hot water (which was normally fed from a cistern and so not legally drinking water) feeding back into the drinking water system, and given everyone was used to having separate taps and back-flow devices were just another thing to go wrong we kept on with the separate taps.

Diva Cupcake
Aug 15, 2005

spankmeister posted:

New shadowbrokers dump

https://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation

This time with Windows exploits (7, 2008R2) and the Swift archive has a list of targets that were hacked to poo poo including router configs and network topology maps etc...

the sec fuckup has been found.

https://twitter.com/musalbas/status/852860956396986370

Adbot
ADBOT LOVES YOU

minivanmegafun
Jul 27, 2004

I'm the progra~1 still used on an NT-lineage os

  • Locked thread