Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Adbot
ADBOT LOVES YOU

Mr. Nice!
Oct 13, 2005

c-spam cannot afford



Powaqoatse posted:

i know itd just be fun to have a piece of paper on official intelligence letterhead saying "yea this kid is a goddamned commie and probably smoked weeed"

there used to be a list of adjudication decisions online regarding clearances, but I can't seem to find it at the moment. in your example it would probably be listed as "person has deep and undisclosed ties to groups that have a stated goal of undermining the goverment. was not truthful about past drug use. clearance denied."

MononcQc
May 29, 2007

Actually-I-was-wrong-the-accused-is-not-guilty-and-as-prosecutor-I.rest

Pile Of Garbage
May 28, 2007




lmao what channel?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
#r_netsec on freenode

he has since left

pseudorandom name
May 6, 2007

Mr. Nice! posted:

there used to be a list of adjudication decisions online regarding clearances, but I can't seem to find it at the moment. in your example it would probably be listed as "person has deep and undisclosed ties to groups that have a stated goal of undermining the goverment. was not truthful about past drug use. clearance denied."

http://ogc.osd.mil/doha/industrial/2017.html

this year's crop is pretty boring so far

pseudorandom name
May 6, 2007

quote:

Applicant purchased proprietary software from a major competitor using a shell company as the purchaser without disclosing his affiliation with the real purchaser in interest. He based his concealment of his employer on his not wanting the seller to know his real employer. When later completing his security clearance application, Applicant deliberately omitted the Company B federal lawsuit from his application. Personal conduct concerns are not mitigated. Clearance is denied. CASE NO: 15-01014.h1

cinci zoo sniper
Mar 15, 2013




MononcQc posted:

Actually-I-was-wrong-the-accused-is-not-guilty-and-as-prosecutor-I.rest

not a prosecutor, but

Midjack
Dec 24, 2007




keep in mind​ too that these are just department of defense clearances, ic would have even better stuff in theirs

Wiggly Wayne DDS
Sep 11, 2010



well the bar is much lower now

pseudorandom name
May 6, 2007

quote:

Applicant credibly testified that he did not meet woman X for sex or to break the
law. He wanted information from her about his wife for his custody dispute. He does not
believe he was thinking clearly. Applicant was born without an eye socket and had a
tumor growing where his eye socket should be. Doctors removed the tumor, but it grows
back every three to four years and must be surgically removed. He testified that he
consulted his doctor and asked if the tumor could affect his brain and was told that it
could cause confusion and memory problems. Applicant believed that the brain tumor
may have had an effect on his interactions with woman X. He admitted he did not think
through the interactions with her as clearly as he should have. He had surgery to
remove the tumor on December 1, 2011, which was 36 days after he was arrested.

A Man With A Plan
Mar 29, 2010
Fallen Rib

Midjack posted:

keep in mind​ too that these are just department of defense clearances, ic would have even better stuff in theirs

About 2/3s of the ic is under the dod, including the nsa. The big ones that aren't are the cia and fbi.

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

i think you might have found an application for forum user tumor looking batty there

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe


:psyduck:

Dylan16807
May 12, 2010

spankmeister posted:

Nice way to make yourself not look like an idiot because you had a bog-standard DLL hijacking vulnerability.

I don't think there was actually a vulnerability, they were just replacing the DLL inside program files and the signing is more of a "gently caress you" than an increase in security

vOv
Feb 8, 2014

yeah it looks like it loads the dll from the same directory as the exe, so it's not a secfuck at all

Wiggly Wayne DDS
Sep 11, 2010



vOv posted:

yeah it looks like it loads the dll from the same directory as the exe, so it's not a secfuck at all
welcome to the majority of dll hijacking vulnerabilities

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
Security Fuckup Megathread - airtight hatchway, etc etc

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

:monocle: except a tumor pops out

spankmeister
Jun 15, 2008






vOv posted:

yeah it looks like it loads the dll from the same directory as the exe, so it's not a secfuck at all

actually,

Su-Su-Sudoko
Oct 25, 2007

what stands in the way becomes the way

Shaggar posted:

2 factor windows sign in is coming soon so maybe they could add that to DPAPI so you get a push notification on your phone when something wants to pull something out of DPAPI like a web credential.

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme


itym :psypop:

Proteus Jones
Feb 28, 2013



A/V continues to be the skid mark in the underwear of Info Sec.

https://arstechnica.com/information-technology/2017/04/the-mystery-of-the-malware-that-wasnt/

quote:

One of the vendors had provided a set of malware samples to test—48 files in an archive stored in the vendor's Box cloud storage account. The vendor providing those samples was Cylance, the information security company behind Protect, a "next generation" endpoint protection system built on machine learning. In testing, Protect identified all 48 of the samples as malicious, while competing products flagged most but not all of them. Curious, the engineer took a closer look at the files in question—and found that seven weren't malware at all.

FCKGW
May 21, 2006

the most aggressively stupid coworker got laid off during layoffs at work last year and now works at cylance where his official title is "wizard". I have no clue what he's doing there and I know he lied about his degree and it would be painful obvious to any hiring manager just talking to him

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

What a shocker. Cylance lying about its product?

Shame Boy
Mar 2, 2010

i just overheard our sysadmin talking about how much he loves getting targeted advertising because it's helpful and he's okay with them harvesting all his data because "it's anonymous"

Progressive JPEG
Feb 19, 2003

ate all the Oreos posted:

i just overheard our sysadmin talking about how much he loves getting targeted advertising because it's helpful and he's okay with them harvesting all his data because "it's anonymous"

He knows they're listening

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

it's an interesting fact that's often overlooked! everything in a program's directory becomes part of that program, often unintentionally. beware of running setup programs straight from your download directory!

burning swine
May 26, 2004



ate all the Oreos posted:

i just overheard our sysadmin talking about how much he loves getting targeted advertising because it's helpful and he's okay with them harvesting all his data because "it's anonymous"

lol forever at people who think like this

most that I know work for advertising companies and rationalize their own line of work like this so they can pretend that what they do isn't profoundly unethical

see also: people working for "relevant marketing" companies and insisting that what they do isn't advertising at all

ate shit on live tv
Feb 15, 2004

by Azathoth

COACHS SPORT BAR posted:

lol forever at people who think like this

most that I know work for advertising companies and rationalize their own line of work like this so they can pretend that what they do isn't profoundly unethical

see also: people working for "relevant marketing" companies and insisting that what they do isn't advertising at all

I would "lol" at them, except that their idiocy makes my life worse and some of them get elected.

Thanks Ants
May 21, 2004

#essereFerrari



less a skid mark, more a full-on brick

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

OSI bean dip posted:

What a shocker. Cylance lying about its product?

lol selling a prettier ui to a DenyAll AppLocker policy and charging money for it is kinda brilliant but yeah cylance stank like poo poo from the word go

Wild EEPROM
Jul 29, 2011


oh, my, god. Becky, look at her bitrate.
gonna make my own av program.

just gonna be something that makes a windows process that wastes a few resources doing nothing, puts something into the tray, pops up notifications twice a day saying you aren't protected or you should upgrade to the gold platinum plus package, and then when you do a manual scan, it just moves a status bar to 100% slowly.

probably less bad than the major av's

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

i don't have much opinion about av products these days. coincidentally i am no longer a teenager trying to download game cracks and porn mag scans from sketchy ftps

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

Wild EEPROM posted:

gonna make my own av program.

just gonna be something that makes a windows process that wastes a few resources doing nothing, puts something into the tray, pops up notifications twice a day saying you aren't protected or you should upgrade to the gold platinum plus package, and then when you do a manual scan, it just moves a status bar to 100% slowly.

probably less bad than the major av's

yeah uh i think the average popup ad has you beaten by a decade and a half by now

Midjack
Dec 24, 2007



Lutha Mahtin posted:

i don't have much opinion about av products these days. coincidentally i am no longer a teenager trying to download game cracks and porn mag scans from sketchy ftps

well then​ what the gently caress are you doing posting in yospos

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Wild EEPROM posted:

gonna make my own av program.

just gonna be something that makes a windows process that wastes a few resources doing nothing, puts something into the tray, pops up notifications twice a day saying you aren't protected or you should upgrade to the gold platinum plus package, and then when you do a manual scan, it just moves a status bar to 100% slowly.

probably less bad than the major av's

there's kits floating around that will basically let you sell a program that uses the windows defender/mse engine and definitions files to do the scan while letting you sell the product and take a cut of the money..

so basically you get a "real" antivirus for your idiot grandma customers that will work as well as any other, and its easier than faking it.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong
also right now delta.com loads fine over http but the connection consistently times out over https so there's clearly a security fuckup in progress

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
inline elements denied boarding

Adbot
ADBOT LOVES YOU

lord of the files
Sep 4, 2012

Thanks Ants posted:

less a skid mark, more a full-on brick

https://www.youtube.com/watch?v=swXrBKoTVv4

quote:

Cylance creates test methodology where they pack malware with Mpress or VMProtect. CylanceProtect detects every software packed with Mpress or VMProtect as malicious. I even found strings in one of their files where it mentions Mpress or VMprotect. Cylance denies this is their file, they claim it must be malware. I created this video to proof this is their file, as it is digitally signed by Cylance ...

I've been around Cylance employees touting that they are hottest poo poo on the planet about their "cutting edge AV". It's good to see that cutting edge technology has to do with just flagging the attributes that normal files have.

  • Locked thread