Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
duTrieux.
Oct 9, 2003

gotta have 2fa to protect my digital hats

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




duTrieux. posted:

gotta have 2fa to protect my digital hats
dude, csgo knives used to cost up to 40k, still cost up to 15k. theres are like 50k worth sniper rifles atm. even "pleb-tier" skins for same csgo can be in hundreds of dollars (those were thousands of dollars earlier, yes)

duTrieux.
Oct 9, 2003

lol at using games in order to gamble and launder money

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

duTrieux. posted:

lol at using games in order to gamble and launder money
lol that you forgot about it

flakeloaf
Feb 26, 2003

Still better than android clock

cinci zoo sniper posted:

dude, csgo knives used to cost up to 40k, still cost up to 15k. theres are like 50k worth sniper rifles atm. even "pleb-tier" skins for same csgo can be in hundreds of dollars (those were thousands of dollars earlier, yes)

asking price isn't selling price

or is it i don't know, i'm not up on shootman economics

apseudonym
Feb 25, 2011

Ur Getting Fatter posted:

my hope is that eventually android and/or apple will put out some sort of authentication API where the phone itself is the 2FA and not a separate app.

also, just want to say that I wish iOS would let you set non-owner PINs/fingerprints with restricted access.

2FA tends to be pretty bespoke server side unfortunately, which is why I doubt there will be platform APIs anytime soon. If you've got an app on the device then 2fa is pretty easy (and even doing hard crypto binding isn't _that_ painful)

cinci zoo sniper
Mar 15, 2013




flakeloaf posted:

asking price isn't selling price

or is it i don't know, i'm not up on shootman economics

it is, there is no shortage of buyers which are very rich children

zero knowledge
Apr 27, 2008

Ur Getting Fatter posted:

my hope is that eventually android and/or apple will put out some sort of authentication API where the phone itself is the 2FA and not a separate app.

some of what you need for this already exists, in that you can put ACLs on keychain items that require/allow biometric authentication, but as others have argued you'd still have tons of work to do for full on 2FA

still, you can create a key and have reasonable confidence it's bound to a specific device/fingerprint (you can also mark individual items as non-syncable)

quote:

also, just want to say that I wish iOS would let you set non-owner PINs/fingerprints with restricted access.

this gets really hard because you need to be able to know which finger has been presented; identification vs. authentication

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

apseudonym posted:

2FA tends to be pretty bespoke server side unfortunately, which is why I doubt there will be platform APIs anytime soon. If you've got an app on the device then 2fa is pretty easy (and even doing hard crypto binding isn't _that_ painful)

i'll settle for an api call that lets the app show an authentication request on the lockscreen and then the phone lets you use touchid to approve it without actually having to go into the app. same end result.

edit: I realize that it seems like I'm bitching about a trivial problem (just unlock the phone, open the app, and approve the authentication request) but this is seriously the kind poo poo that prevents someone like my dad from using 2fa.

if you can reduce it down to one simple step, he can deal with that

dpkg chopra fucked around with this message at 19:28 on May 4, 2017

apseudonym
Feb 25, 2011

Ur Getting Fatter posted:

i'll settle for an api call that lets the app show an authentication request on the lockscreen and then the phone lets you use touchid to approve it without actually having to go into the app. same end result.

edit: I realize that it seems like I'm bitching about a trivial problem (just unlock the phone, open the app, and approve the authentication request) but this is seriously the kind poo poo that prevents someone like my dad from using 2fa.

if you can reduce it down to one simple step, he can deal with that

It's tricky because the required details vary a lot between devs.

Is it sufficient to have the app report to the server "yup authed"? Do you need to use a wrapped hw backed key with auth requirements?"


Seriously the most questions I get from devs are 2fa and crypto related and what people want varies way too much for useful platform APIs :(

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug
idk i use Duo Mobile with my university 2fa and i get a push notification on my phone, i swipe from the lock screen, use touch id to unlock the phone, and press the green checkmark button in the app, i dont know any way this could be more convenient

pressing the green checkmark button automatically authorizes the login attempt in whatever web browser on whatever machine im using, its real nice

Shame Boy
Mar 2, 2010

goddamnedtwisto posted:

i think that's an android feature and it can certainly be disabled in the security screen on stock android, but i wouldn't past an oem to reinvent the wheel in a much stupider way

it's definitely them reinventing the wheel in this case since its part of a whole dumb suite of wheel reinventing that also replaces the entire homescreen and stuff by default. I'll see if I can disable it, I seem to remember turning it off still nagged you to enable it whenever something was paired but that was like a year and a half ago

It's an LG G4 from AT&T for whoever's curious

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Cocoa Crispies posted:

it's optional and apps can't override it



which of those disables being able to force-press a lock screen notification bubble? I can't get it to happen for me


pr0zac! it's Steve!

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Subjunctive posted:

which of those disables being able to force-press a lock screen notification bubble? I can't get it to happen for me


pr0zac! it's Steve!

Steve is touching some very dangerous poop

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Steam 2fa is badly implemented because the only way I could find to log in to Steam (on my phone I think?) after updating my phone last time was to disable it

it's still disabled about a year later because meh

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Munkeymon posted:

Steam 2fa is badly implemented because the only way I could find to log in to Steam (on my phone I think?) after updating my phone last time was to disable it

it's still disabled about a year later because meh

if steam wasn't the top dealer for dumpy rear end in a top hat white guys' drug of choice they'd be sunk because valve's steam team is incredibly incompetent

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Munkeymon posted:

Steam 2fa is badly implemented because the only way I could find to log in to Steam (on my phone I think?) after updating my phone last time was to disable it

it's still disabled about a year later because meh
here is how it works: you try to log in to steam, the steam app on your phone gets a push notification (which you can choose to display on your lock screen or not) and that notification has a code that you type into the steam application on your desktop or on the webpage.

for comparison, the blizzard authentication process works a little differently: the blizzard game/webpage shows you a short (four-character?) alphanumeric string, and also sends a push notification to your phone. your phone shows you the same alphanumeric string (which you can choose to display on your lock screen or not), and asks if you want to approve the auth request, and you get a confirm/deny prompt. if you're at the lock screen, you can longpress the notification, select confirm/deny, and then you have to enter your pin or fingerprint or whatever for it to go through. i like this method and i think it's good.

power botton
Nov 2, 2011

I got duo auth on all my vaguely important machines and I don't know if its good but it stays out of my way and makes me feel secure

wolrah
May 8, 2006
what?

goddamnedtwisto posted:

i think that's an android feature and it can certainly be disabled in the security screen on stock android, but i wouldn't past an oem to reinvent the wheel in a much stupider way

It's definitely an Android thing, I have it on my AOSP Galaxy Note 4, but it also definitely prompts for the PIN/pattern/whatever if you want to add a device or modify the Smart Lock settings.

It's a reasonable tradeoff in the car for example, but I wouldn't bind it to a set of headphones or my watch.

Shame Boy
Mar 2, 2010

Captain Foo posted:

Steve is touching some very dangerous poop

"hey now the drone feed is showing my office, isn't that weird guys? let me see if I can go outside and wave to i-" *entire city block explodes*

Pile Of Garbage
May 28, 2007



secfuck: just found this GPO in our environment, it's to get bginfo.exe to run via a batch file sitting in netlogon on all the drat SAP servers

https://twitter.com/GarbageDotNet/status/860398920450494464

i guess it wasn't working for them so they said "lol gently caress it disable everything" and it started working. idiotfuckers

cinci zoo sniper
Mar 15, 2013




a new wordpress 0-day? must be another day ending with y

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

cinci zoo sniper posted:

a new wordpress 0-day? must be another day ending with y

more like wordpress 2day vuln

Captain Foo fucked around with this message at 14:16 on May 5, 2017

cinci zoo sniper
Mar 15, 2013




Captain Foo posted:

more like wordpress 2day vuln :vface:

lorf

Shame Boy
Mar 2, 2010

i was gonna post it yesterday but i read the european date backwards and thought it had happened a month ago and i was late to the party :saddowns:

Tayter Swift
Nov 18, 2002

Pillbug
the internet is cool and good

https://twitter.com/jjmacnab/status/860512321642287104

cinci zoo sniper
Mar 15, 2013




https://developer.microsoft.com/en-us/microsoft-edge/platform/issues/11896203/

"Edge displays "123456" in PDF but prints "114447""

:allears:

flakeloaf
Feb 26, 2003

Still better than android clock

wonder what'd happen if you PDF'd that page and viewed it in edge

cinci zoo sniper
Mar 15, 2013




meanwhile in the av vendor world

https://www.av-test.org/en/news/new...7077.1493914732

Shame Boy
Mar 2, 2010


all I could think of when I read "we are not a bunch of babies to be kicked around"

https://www.youtube.com/watch?v=aYK9hGcmE7c

vOv
Feb 8, 2014

https://twitter.com/whitequark/status/860549648494321666

Wiggly Wayne DDS
Sep 11, 2010



i have many questions, and unfortunately answers

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BangersInMyKnickers posted:

lmbo the only way this is possible is if he's using XP/2003 somewhere which doesn't have any AES ciphers in schannel. There's an optional KB you can install on 2003 to give it RSA_AES_CBC_SHA support. XP is poo poo out of luck and the only cipher/protocol overlap left on it is 3DES over TLS 1.0 which is why I generally still leave it on.

https://support.microsoft.com/en-us...ows-server-2003
fwiw google says that if fips mode is enabled then disabling 3des will break rdp. i do not know why fips mode would be enabled, or why it would need to be enabled.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

anthonypants posted:

fwiw google says that if fips mode is enabled then disabling 3des will break rdp. i do not know why fips mode would be enabled, or why it would need to be enabled.

fips mode is the greatest

apseudonym
Feb 25, 2011


I'm crying

NFX
Jun 2, 2008

Fun Shoe

anthonypants posted:

fwiw google says that if fips mode is enabled then disabling 3des will break rdp. i do not know why fips mode would be enabled, or why it would need to be enabled.

better the broken standard that's certified than the secure stuff that is not

geonetix
Mar 6, 2011


Cocoa Crispies posted:

fips mode is the greatest

power botton
Nov 2, 2011

A bunch of our customers love FIPS mode and last year we finally updated all our poo poo so that it would work with FIPS enabled and I have no clue what it does but its very important to the enterprise

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

Cocoa Crispies posted:

fips mode is the greatest

Adbot
ADBOT LOVES YOU

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
what's a fips

  • Locked thread