Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
haveblue
Aug 15, 2005



Toilet Rascal
grandfather's exe

Adbot
ADBOT LOVES YOU

burning swine
May 26, 2004



infernal machines posted:

mainframe of theseus

NICE!



lol atlassian

My company switched to hipchat a while ago, and I noticed that whenever someone sends a picture (which is frequently a screenshot of something proprietary, or at least not meant for disclosure), it ends up hosted on an s3 instance with absolutely no authentication. URL is something like s3.amazonaws.com/uploads.hipchat.com/[comany's unique ID]/[some other id]/[upload.png]

I'd been meaning to do some prodding and see if [some other id] is predictable, maybe I should take that off the back burner

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

haveblue posted:

grandfather's exe

I've only changed the language twice and the OS three times

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

infernal machines posted:

mainframe of theseus
I get this reference

haveblue posted:

grandfather's exe
I get this reference

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

COACHS SPORT BAR posted:

NICE!


lol atlassian

My company switched to hipchat a while ago, and I noticed that whenever someone sends a picture (which is frequently a screenshot of something proprietary, or at least not meant for disclosure), it ends up hosted on an s3 instance with absolutely no authentication. URL is something like s3.amazonaws.com/uploads.hipchat.com/[comany's unique ID]/[some other id]/[upload.png]

I'd been meaning to do some prodding and see if [some other id] is predictable, maybe I should take that off the back burner

just stick a UUID in there and it's basically as good as authentication over https.

necrotic
Aug 2, 2005
I owe my brother big time for this!

COACHS SPORT BAR posted:

NICE!


lol atlassian

My company switched to hipchat a while ago, and I noticed that whenever someone sends a picture (which is frequently a screenshot of something proprietary, or at least not meant for disclosure), it ends up hosted on an s3 instance with absolutely no authentication. URL is something like s3.amazonaws.com/uploads.hipchat.com/[comany's unique ID]/[some other id]/[upload.png]

I'd been meaning to do some prodding and see if [some other id] is predictable, maybe I should take that off the back burner

I found slack had this same issue and it blew my mind. I _think_ its since been fixed? e: yeah totally has

burning swine
May 26, 2004



Subjunctive posted:

just stick a UUID in there and it's basically as good as authentication over https.

It's waaaaaay too short to be a UUID

e: just compiled a list of all the urls sent to me. It's more or less on par with an imgur identifier. Meh, not as interesting as I had hoped

burning swine fucked around with this message at 19:07 on Apr 26, 2017

darthbob88
Oct 13, 2011

YOSPOS

Wheany posted:

I get this reference

I get this reference
I got these references long ago, and though they have changed over the years they are the same references.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

quote:

14:26:20 warrshrike | I need some help from you geniuses
14:27:25 warrshrike | So I had this idea for a side project
14:27:56 warrshrike | I'm thinking if a nearly totally safe messenger service is possible
14:28:14 warrshrike | Here is my rationale for it
14:29:12 warrshrike | recently, many end to end services have been known to be insecure to certain 3 letter agencies as well as criminals
14:29:27 warrshrike | this is almost always due to the OS running the sw getting breached
14:29:44 warrshrike | rather than the encryption or key app getting compromised
14:30:34 warrshrike | so what we cut the OS out of it? Make a messenger which runs directly on bare metal (say an opensource linux board) ala unikernel style

:allears:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
so like an eeprom that contains your messages, sounds cool

burning swine
May 26, 2004



Good writeup on the security dumpster fire that is SugarCRM:

http://karmainsecurity.com/tales-of-sugarcrm-security-horrors

Shaggar
Apr 26, 2006
the sugarcrm "API" is basically sql injection.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

COACHS SPORT BAR posted:

Good writeup on the security dumpster fire that is SugarCRM:

http://karmainsecurity.com/tales-of-sugarcrm-security-horrors

quote:

SugarCRM is a pretty popular Customer Relationship Management (CRM) application written in PHP code. It was born in 2004 as an open source project hosted on SourceForge, a development repository for free software.

article just ends right there

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Loaded fine for me


quote:

SugarCRM is a pretty popular Customer Relationship Management (CRM) application written in PHP code. It was born in 2004 as an open source project hosted on SourceForge, a development repository for free software. By June of the same year, the rapid success of the project allowed the original developers to found SugarCRM Inc. and raise $2 million in venture capital. A month later, on July 3, Sugar Open Source version 1.0 was released. In October 200 .........

Etc

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Volmarias posted:

Loaded fine for me


Etc

whoosh

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i get joaks

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Cocoa Crispies posted:

article just ends right there
lol

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Volmarias posted:

I've only changed the language twice and the OS three times

Only registered members can see post attachments!

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'


lol what the heck

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


https://arstechnica.com/information-technology/2017/04/picture-this-senate-staffers-id-cards-have-photo-of-smart-chip-no-security/

quote:

Moreover, in contrast to the executive branch's widespread adoption of PIV cards with a smart chip, most Senate staff ID cards have a photo of a chip printed on them, rather than a real chip.

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

if those chip pictures prove themselves to be brave and secure, one day they will become real chips

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

my brain automatically converted piv to penis in vagina

cinci zoo sniper
Mar 15, 2013




are planeforce have bug bounty program now

Phone
Jul 30, 2005

親子丼をほしい。

A Pinball Wizard posted:

my brain automatically converted piv to penis in vagina

computer fucker.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



pinball in wizard

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
http://www.antbleed.com/

quote:

Antbleed is a backdoor introduced by Bitmain into the firmware of their bitcoin mining hardware Antminer.

The firmware checks-in with a central service randomly every 1 to 11 minutes. Each check-in transmits the Antminer serial number, MAC address and IP address. Bitmain can use this check-in data to cross check against customer sales and delivery records making it personally identifiable. The remote service can then return "false" which will stop the miner from mining.

quote:

At worst, this firmware backdoor allows Bitmain to shut off a large section of the global hashrate (estimated to be at up to 70% of all mining equipment). It can also be used to directly target specific machines or customers. Standard inbound firewall rules will not protect against this because the Antminer makes outbound connections.

Even without Bitmain being malicious, the API is unauthenticated and would allow any MITM, DNS or domain hijack to shutdown Antminers globally. Additionally the domain in question DNS is hosted by Cloudflare making it trivially subjected to government orders and state control.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/SDLerner/status/857339715577663489
https://twitter.com/petertoddbtc/status/857341376245182464

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

someone should do the last bit

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

fishmech posted:

someone should do the last bit

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

fishmech posted:

someone should do the last bit
yeah i agree unironically but afaik i need an antmain miner first

MononcQc
May 29, 2007

this is actually good for bitcoin because

spankmeister
Jun 15, 2008
Probation
Can't post for 11 hours!
I lust for bitcoin death

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



fishmech posted:

someone should do the last bit

mod saas
May 4, 2004

Grimey Drawer

fishmech posted:

someone should do the last bit


quote:

The last bit was mined for the first time, half in jest, on April 20, 2140, at a time when humanity first stepped into the light.

Carbon dioxide
Oct 9, 2012

With the way bitcoins work, the amount of bitcoins mined per period of time cannot change, I think.

So if you were to kill a majority of bitcoin miners, those who are left over would suddenly get way more bitcoins way faster.

Mr. Nice!
Oct 13, 2005

c-spam cannot afford



Carbon dioxide posted:

With the way bitcoins work, the amount of bitcoins mined per period of time cannot change, I think.

So if you were to kill a majority of bitcoin miners, those who are left over would suddenly get way more bitcoins way faster.

the difficulty would balance out so that the speed would end up around the same (average 10 minutes iirc) after a short burst period, but the thing is they would lock out anyone not using the best asics if they shut off all the antminers outside of the chinese pools.

they can effectively lock out the entire rest of the bitcoin network and they only way to prevent it is to somehow patch and repair the firmware and hope there isn't more hidden backdoors or develop and deploy a par competitor with the current antminers.

china has the entire bitcoin protocol by the balls with this.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

... gently caress :cripes:

vOv
Feb 8, 2014

Carbon dioxide posted:

With the way bitcoins work, the amount of bitcoins mined per period of time cannot change, I think.

So if you were to kill a majority of bitcoin miners, those who are left over would suddenly get way more bitcoins way faster.

the difficulty adjustment isn't instant but i don't remember how often it happens, i want to say twice a month or something g

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Mr. Nice! posted:

the difficulty would balance out so that the speed would end up around the same (average 10 minutes iirc) after a short burst period, but the thing is they would lock out anyone not using the best asics if they shut off all the antminers outside of the chinese pools.


the difficulty can only change every so often (as it stands, once every 14 days if things are in good working order, as it's every 2016 blocks), and can only change up to a certain amount each time.

it could take months easily for bitcoin to adjust back to consistent 10ish minute blocks again if 70% of the mining power was immediately wiped out and stayed wiped out.

Adbot
ADBOT LOVES YOU

Gobbeldygook
May 13, 2009
Hates Native American people and tries to justify their genocides.

Put this racist on ignore immediately!

vOv posted:

the difficulty adjustment isn't instant but i don't remember how often it happens, i want to say twice a month or something g
it's adjusted every 2016 blocks, so every ~two weeks. next adjustment is 32 blocks away.

  • Locked thread