Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Malcolm XML
Aug 8, 2009

I always knew it would end like this.

Bulgogi Hoagie posted:

in other news awful dumb biometric security system turns out to be exactly that

http://www.bbc.co.uk/news/technology-39965545

Ugh its "my voice is my passport" not password get it right hsbc

HSBC is a clown shoes org so not surprised

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I met just the other day with a company that's doing high-quality voice transformations and synthesis. I look forward to their future $1.99 toy app breaking into HSBC.

Shame Boy
Mar 2, 2010

Subjunctive posted:

I met just the other day with a company that's doing high-quality voice transformations and synthesis. I look forward to their future $1.99 toy app breaking into HSBC.

it's not that one that made that awkward, possibly-fake couple clips of obama and trump is it

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

it's them, but it's newer stuff

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
guys, help, what do I do?

Jewel
May 2, 2009

https://twitter.com/willmanduffy/status/865667195577217026

logging onto apple stuff is one of the worst experiences I've had logging into anything, not sure how they make it so bad

haveblue
Aug 15, 2005



Toilet Rascal
every time I get a new iphone I clone it off a backup of my previous one

this means that the last 3 or 4 phones I've had all have the same name

the old apple login UI let you choose which device the 2fa prompt would be sent to

but it only showed device name in the list and not type

at least once I picked the wrong phone enough times to get locked out for a while

Thanks Ants
May 21, 2004

#essereFerrari


for some reason apple dont sync your list of devices you own with the list of devices you have enabled 2fa codes to be sent to, so i was sending codes to my old iphone for ages and wondering why it never worked and i had to use sms instead

surebet
Jan 10, 2013

avatar
specialist


apparently some fuckers are trying to kill wcry's kill switch:
https://www.wired.com/2017/05/wannacry-ransomware-ddos-attack/

SeaborneClink
Aug 27, 2010

MAWP... MAWP!
Why are people still publishing MalwareTechLab's name?

Still seems an incredibly lovely thing to do, to continue to propagate that information or refer to him by his actual name in reference to the research he did.

minivanmegafun
Jul 27, 2004

haveblue posted:

every time I get a new iphone I clone it off a backup of my previous one

this means that the last 3 or 4 phones I've had all have the same name

the old apple login UI let you choose which device the 2fa prompt would be sent to

this is also a problem for systems authorized to use iTunes

you have a limit of five, im maxed out, and three of them are named "James's iPhone" and I don't know which isn't used anymore

Proteus Jones
Feb 28, 2013



minivanmegafun posted:

this is also a problem for systems authorized to use iTunes

you have a limit of five, im maxed out, and three of them are named "James's iPhone" and I don't know which isn't used anymore

iOs and tvOS devices don't count to your limit of 5. It's only the iTunes app on Windows or Mac that count. I currently have two Apple TVs, two iPads, my iPhone, work computer and home laptop and I'm only using 2 of 5.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
it doesn't tell you what time the device connected last?

Proteus Jones
Feb 28, 2013



anthonypants posted:

it doesn't tell you what time the device connected last?

Actually I went into my account to check. It shows the time it was 1st associated with the account. Turns out tvOS doesn't even show up on the list, so I was wrong on that. Only iOS and computers. All devices show a "remove" button, and for iOS the most recent active iPhone and iPad the "remove" is greyed out.

Seems like it's pretty easy to ID and remove old orphan authorized devices.

minivanmegafun
Jul 27, 2004

i think the date connected and being able to remove devices ad-hoc is a newer feature. iirc you used to have to nuke everything and reauth your devices when you maxed it out

Proteus Jones
Feb 28, 2013



minivanmegafun posted:

i think the date connected and being able to remove devices ad-hoc is a newer feature. iirc you used to have to nuke everything and reauth your devices when you maxed it out

This is true, I had to do that more than once in the past.

IIRC, the limit was in place due to the licensing agreements they had with music and movie industry.

flakeloaf
Feb 26, 2003

Still better than android clock

the google play store calls them by their model number, which i thought was uselessly opaque because who knows what an sg-1727r is

but the apple version manages to be worse somehow?

Proteus Jones
Feb 28, 2013



flakeloaf posted:

the google play store calls them by their model number, which i thought was uselessly opaque because who knows what an sg-1727r is

but the apple version manages to be worse somehow?

They're all dumpster fires.

redleader
Aug 18, 2005

Engage according to operational parameters

Migishu posted:

guys, help, what do I do?


fishmech
Jul 16, 2006

by VideoGames
Salad Prong

flakeloaf posted:

the google play store calls them by their model number, which i thought was uselessly opaque because who knows what an sg-1727r is

it's the same model number that would show up in "about" in the settings at least, so there's something you can go check when you have the phone handy.

you can also manually rename the phone in that area, which will get synced to google shortly after and then instead of saying "sarnsumg butt84x" it says "my dead gay phone" or whatev

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Malcolm XML posted:

Ugh its "my voice is my passport" not password get it right hsbc

HSBC is a clown shoes org so not surprised

"my voice is my password" is what stebe said when they're introduced voice verification for macs

Malcolm XML
Aug 8, 2009

I always knew it would end like this.

Chris Knight posted:

"my voice is my password" is what stebe said when they're introduced voice verification for macs

https://m.youtube.com/watch?v=-zVgWpVXb64

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/bofa_tips/status/864131825291210757

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Migishu posted:

guys, help, what do I do?



Rewind the cassette tape.

haveblue
Aug 15, 2005



Toilet Rascal
apple actually uses 2 different kinds of multifactor auth. they first did what they called two-step verification as a hasty response to a surge in security issues. it was replaced later with proper two-factor authentication once they had time to go back and build it into every supporting device and service. the latter is much nicer and the former I think is the one I had the unidentified phone issue with

also the detailed list of phones to remove the old ones is behind a login every time for obvious reasons so once I realized I had hosed up I still had to wait to fix it

haveblue fucked around with this message at 17:16 on May 20, 2017

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



flakeloaf posted:

the google play store calls them by their model number, which i thought was uselessly opaque because who knows what an sg-1727r is

but the apple version manages to be worse somehow?

that's still more useful because you can copy and paste it into Google and get a picture of it

unless you go through phones so fast you have more than one of the same model in which case, well, you need to learn how to close your hand on an object I guess

pseudorandom name
May 6, 2007

the former two-step may even be more secure than two-factor because it used a proper recovery key instead of a "trusted" phone number

Thanks Ants
May 21, 2004

#essereFerrari


when people refer to sms as being a poor way to deliver a login pin, is this mainly because it's possible for a determined attacker to intercept the message, or because it then places security for that number in the hands of a call center worker at verizon?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Thanks Ants posted:

when people refer to sms as being a poor way to deliver a login pin, is this mainly because it's possible for a determined attacker to intercept the message, or because it then places security for that number in the hands of a call center worker at verizon?

Yes.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

haveblue posted:

the latter is much nicer and the former I think is the one I had the unidentified phone issue with

the latter is clumsy as gently caress if you have someone trying to log into an account where you aren't (like tvOS at home while you're at work). if you dismiss the pop up it invalidates the code, so you can't text it to them. you have to be on an active voice call already, or find another device.

(and then sometimes it punts back to the primary u/p dialog without an error message of any kind so :shrug: try again I guess)

Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.

also cant basically any telecom operator spoof device registrations and get all text messages forwarded through them since ss7 is such a poo poo protocol? i remember reading about that a while ago

fake edit: yep

Bulgogi Hoagie
Jun 1, 2012

We

Mr.Radar posted:

also cant basically any cell network operator spoof device registrations and get all text messages forwarded through them since ss7 is such a poo poo protocol? i remember reading about that a while ago

fake edit: yep

pretty sure the iranian govt has been doing this for a while now to track activists and such

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE

Subjunctive posted:

the latter is clumsy as gently caress if you have someone trying to log into an account where you aren't (like tvOS at home while you're at work). if you dismiss the pop up it invalidates the code, so you can't text it to them. you have to be on an active voice call already, or find another device.

(and then sometimes it punts back to the primary u/p dialog without an error message of any kind so :shrug: try again I guess)

sometimes when I'm helping people with their iCloud the GeoIP lookup gets it wrong and the person loses their poo poo for and says they're being hacked when they're sent a message going HEY A LOGIN REQUEST HAS BEEN MADE FROM <city 200 miles away> despite being told 'gonna send a confirmation message' seconds earlier.

Shifty Pony
Dec 28, 2004

Up ta somethin'


Subjunctive posted:

the latter is clumsy as gently caress if you have someone trying to log into an account where you aren't (like tvOS at home while you're at work). if you dismiss the pop up it invalidates the code, so you can't text it to them. you have to be on an active voice call already, or find another device.

(and then sometimes it punts back to the primary u/p dialog without an error message of any kind so :shrug: try again I guess)

it also is only useful if you fill your life with apple devices and those apple devices are presently functioning properly.

as I found out when the touch sensing on my iPhone shat itself and I was unable to set up a Genius Bar appointment because when I tried to log into my apple account using my desktop it sent a notification to the iPhone which I couldn't unlock to display the code.

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
https://twitter.com/MalwareTechBlog/status/865940879261003778

(supposedly The Sun is the newspaper in question)

cinci zoo sniper
Mar 15, 2013





unsurprising. when people say daily hail is the worst of the british press, they just havent opened the sun even once

haveblue
Aug 15, 2005



Toilet Rascal

Jimmy Carter posted:

sometimes when I'm helping people with their iCloud the GeoIP lookup gets it wrong and the person loses their poo poo for and says they're being hacked when they're sent a message going HEY A LOGIN REQUEST HAS BEEN MADE FROM <city 200 miles away> despite being told 'gonna send a confirmation message' seconds earlier.

happens if the login device is on a VPN too

Thanks Ants
May 21, 2004

#essereFerrari


the entire british tabloid press needs to be burnt to the ground

fisting by many
Dec 25, 2009



except the sunday sport, they can stay

they probably have the most integrity of the lot anyway

Adbot
ADBOT LOVES YOU

pseudorandom name
May 6, 2007

what's the point of printing his address?

  • Locked thread