Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
redleader
Aug 18, 2005

Engage according to operational parameters
and nomx responds


nomx posted:

Number of nomx accounts that have been compromised since inception: 0

Number of Gmail accounts that have been compromised in the United States (from 2014): About 5 million to 24 million depending on source

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

necrotic posted:

we need an ssl cert for email. whats a good provider these days?
letsencrypt

anthonypants fucked around with this message at 21:49 on Apr 27, 2017

redleader
Aug 18, 2005

Engage according to operational parameters

Volmarias posted:

I'm not holding my breath.

we managed to regulate doctors, engineers, dentists. computers are too important to modern society to escape this forever, in my dumb and uninformed opinion

necrotic
Aug 2, 2005
I owe my brother big time for this!

that was our plan but they dont support s/mime email certs, only for auth.

https://community.letsencrypt.org/t/why-letsencrypt-certificates-are-not-valid-for-email/14039

edit saying we need an ssl cert was probably wrong. i dunno im bad at this stuff (and not working on it, phew)

necrotic fucked around with this message at 21:53 on Apr 27, 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
yeah if you want an s/mime or code-signing cert you'll have to go with someone else unfortunately. any of them should work, just maybe don't use one with a symantec-owned ca

necrotic
Aug 2, 2005
I owe my brother big time for this!
yeah trying to avoid them. all the cert providers have shady as gently caress websites which isn't helping.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

necrotic posted:

yeah trying to avoid them. all the cert providers have shady as gently caress websites which isn't helping.
you could always be your own ca and self-sign your certs, let your recipients deal with it

Shame Boy
Mar 2, 2010

quote:

Anyway, the main point for now was that I managed to crack the setup password, which was death

:ohdear:

Shame Boy
Mar 2, 2010

quote:

nomx is now finalizing the “Cloud in Your Attic” server that also includes an internal nomx email server, and a host of other servers that maintain users’ personal data off the clouds that are regularly attacked daily.

oh boy

Shame Boy
Mar 2, 2010

lol look at their 404 page



Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://twitter.com/sirus/status/857667903474118657

30 TO 50 FERAL HOG
Mar 2, 2005



Wait are the leds hooked straight into the rpi without a current limiting resistor? Lmao

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

BiohazrD posted:

Wait are the leds hooked straight into the rpi without a current limiting resistor? Lmao

there appears to be one under the heat shrink

hobbesmaster
Jan 28, 2008

BiohazrD posted:

Wait are the leds hooked straight into the rpi without a current limiting resistor? Lmao

you can get leds with them built in

really useful on breadboards

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

Powerful Two-Hander posted:

security fuckup megathread: /* should we even bother? */.

plz

redleader
Aug 18, 2005

Engage according to operational parameters
https://twitter.com/Scott_Helme/status/857617936902754304

AARP LARPer
Feb 19, 2005

THE DARK SIDE OF SCIENCE BREEDS A WEAPON OF WAR

Buglord
I laugh everytime I see the hot glue glopped inside of that box

Accretionist
Nov 7, 2012
I BELIEVE IN STUPID CONSPIRACY THEORIES
Fun security anecdote:

https://www.youtube.com/watch?v=geUsSYrsIVY&t=2978s

spankmeister
Jun 15, 2008






More security snake oil :mrgw:


quote:

John McAfee says his new smartphone will be 'as hack-proof as humanly possible'

McAfee said his new secure phone will be "light years ahead of the Blackphone".


http://www.ibtimes.co.uk/john-mcafee-says-his-new-smartphone-will-be-hack-proof-humanly-possible-1619003

cinci zoo sniper
Mar 15, 2013





mcafee will just sell phones with depleted batteries

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.



hope he remembers to turn geotagging off on them

flakeloaf
Feb 26, 2003

Still better than android clock

:cawg:

WAR DOGS OF SOCHI posted:

I laugh everytime I see the hot glue glopped inside of that box

reminds me of this thing

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Powerful Two-Hander posted:

hope he remembers to turn geotagging off on them

lmao

cinci zoo sniper
Mar 15, 2013




It's been awhile since hackers broke into Home Depot's servers and stole 56 million customers' credit card information back in 2014. But recently, a tipster pointed business watchdog site Consumerist to a web address under the HomeDepot.com domain. The unprotected page stored photos of various home improvement projects...and 13 Excel spreadsheets filled with customer data. All told, it had names, phone numbers, and physical and email addresses for up to 8,000 people. And all those files sat there unprotected, unencrypted and discoverable by search engines for an unknown period of time.

FAT32 SHAMER
Aug 16, 2012



i dont shop at home depot and i feel justified in that now

Phone
Jul 30, 2005

親子丼をほしい。
I probably used the self checkout at Home Depot when they got owned, but nothing has ever popped up on amex? I did get a new card, but I can't remember when...

actually maybe not because I hadn't bought a Lexus to turn into a race car

vOv

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
*cracks knuckles*

chome depot

Asshole Masonanie
Oct 27, 2009

by vyelkin

Powerful Two-Hander posted:

hope he remembers to turn geotagging off on them

:thurman:

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
https://lists.torproject.org/pipermail/tor-relays/2017-April/012217.html

Progressive JPEG
Feb 19, 2003


code:
Hi all,

Last week, we were contacted by Australian law enforcement, on behalf of
German law enforcement, about one of our relays.

It appears that some law enforcement agency had performed a guard
discovery attack on a hidden service. One of our relays was that hidden
service's guard. They requested that we provide a detailed network
capture of that guard's traffic. We refused. (We do not keep detailed
logs.) We also shut down the guard.

T
--
Tim Wilson-Brown (teor)

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
:lol:

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
countdown to legal defense kickstarter

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
http://www.theverge.com/2017/4/28/15468828/facebook-google-phishing-scam-rimasauskas

quote:

Last month, the Department of Justice charged a Lithuanian man for fraud, aggravated identity theft, and money laundering after documents revealed he scammed two major tech companies for over $100 million by masquerading as a Taiwanese electronics manufacturer. A Forbes report this week identified those two affected companies as Facebook and Google.

:allears:

flakeloaf
Feb 26, 2003

Still better than android clock

you think he'd have been caught if he'd just stopped at like, $70 million?

Sereri
Sep 30, 2008

awwwrigami

Re: manufacturing bill

Hey it's me, Jerry from HTC,
I noticed you still haven't paid us for manufacturing the Pixel phone. Please transfer $50m to the following account in Latvia (it's for tax purposes, don't worry about it)

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


the hardware interlocks are kinda stupid but ok whatever. I'm curious how they are going to detect stingrays and dropping the connection. It seems like someone else would have already tried doing that in software if it was viable/reliable

Truga
May 4, 2014
Lipstick Apathy
https://bgpmon.net/bgpstream-and-the-curious-case-of-as12389/

anyone knows what this poo poo was all about yet?
tl;dr someone set up routes so all visa and mastercard transactions went through russia yesterday.

cinci zoo sniper
Mar 15, 2013




Sereri posted:

Re: manufacturing bill

Hey it's me, Jerry from HTC,
I noticed you still haven't paid us for manufacturing the Pixel phone. Please transfer $50m to the following account in Latvia (it's for tax purposes, don't worry about it)

dude was registered as a "low capital llc" in the town i went to college in, the little russian city state of latvia. probably the most crime ridden area of the country, for economical and historical reasons

cinci zoo sniper fucked around with this message at 18:01 on Apr 28, 2017

cinci zoo sniper
Mar 15, 2013




Truga posted:

https://bgpmon.net/bgpstream-and-the-curious-case-of-as12389/

anyone knows what this poo poo was all about yet?
tl;dr someone set up routes so all visa and mastercard transactions went through russia yesterday.

https://arstechnica.com/security/2017/04/russian-controlled-telecom-hijacks-financial-services-internet-traffic/ arse technica, sorry, etc

Adbot
ADBOT LOVES YOU

MononcQc
May 29, 2007


Sounds like a variant of the Ubiquiti scam again (http://fortune.com/2015/08/10/ubiquiti-networks-email-scam-40-million/)

I'm well entertained by seeing major tech companies getting scammed like grandpa at these things.

  • Locked thread