Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Cocoa Crispies posted:

authenticating software loads on par with a fuckin' iphone 5s
authenticating loads? sounds like a job for the :cumpolice:

Adbot
ADBOT LOVES YOU

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



ratbert90 posted:

yo momma has a bunch of open back doors.

yo moma outgrew fat32

Max Facetime
Apr 18, 2009

Cocoa Crispies posted:

authenticating software loads on par with a fuckin' iphone 5s

if your iPheart dies while you're Facebooking you also die in real life

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lmfao https://twitter.com/mikeloss/status/869169958588043265

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010

Bulgogi Hoagie posted:

heathrow is having major computer problem, wouldn't be surprised if it's related to the wannacry stuff

https://twitter.com/bbcbreaking/status/868404776790306817

your run of the mill incompetence Vis-à-vis outsourcing, not testing the backups, and getting rid of senior developers.

surebet
Jan 10, 2013

avatar
specialist


a few thoughts on the whole implanted device thing:

"if they're in the same room, they could stab you, therefore"
murdering someone in a more conventional fashion leaves behind clues that are generally well known and understood by forensic investigators. the first wave of murders-by-ssh will probably be understood as device malfunctions, especially if the device doesn't freeze it's state & firmware at the time of death.

this goes double for medical infrastructure that's subject to protest like clinics providing abortion services or hospitals run by/catering to certain groups.

"companies are probably really interested in not getting blamed/sued"
if the first wave is going to be misunderstood as failure, i'm legit concerned that further fuckery will be handled in the same way that auto manufacturer handled some incidents, where some mba geniuses cost benefited recall expenditures versus lawsuits and opted to hide risks from their customers.

if companies aren't held to the highest standards right off the bat, case law and revenue models will form in a way that supports the low security status quo.

i 100% that there are more pressing & systemic issues with healthcare security, but between the boomer cohort entering geriatric care and the proliferation of implantable devices, if manufacturers & providers aren't proactive about security concerns, we're heading towards a critical mass of problems in the next decade

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

surebet posted:

i'm legit concerned that further fuckery will be handled in the same way that auto manufacturer handled some incidents, where some mba geniuses cost benefited recall expenditures versus lawsuits and opted to hide risks from their customers.

that's fight club

jre
Sep 2, 2011

To the cloud ?



Trabisnikof posted:

What part of attacking a pacemaker requires nation state level actors?

Right so to even attempt this you need

1. To know the exact model of pacemaker you victim has
2. to buy at least 1 pacemaker of the same type as your target
3. to buy the hardware needed to programme the device
4. the knowledge to reverse engineer and rewrite the firmware for this device
5. a good enough knowledge of physiology to make your changes harmful
6. have access to all of the above and be willing to kill someone

Then once you've spent $100,000 and 3 months doing all this, you need to following someone down the street a foot away with a laptop and antenna for the time it takes to update the hardware


Meanwhile script kiddies may have actually killed someone with wanna cry because a large number of surgeries had to be cancelled because records couldn't be accessed.
Windows XP: a bigger threat to your health than some mastabatory fantasy about death rays.

quote:

if the first wave
:ughh:

Doom Mathematic
Sep 2, 2008
And what if they're using Windows XP to run the pacemaker, eh?

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

jre posted:

That's an unfortunate example you chose there because it required, get this

you think I'm talking about stuxnet :cripes: sport, why don't you chuck your computer in the garbage and then yourself

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

could you, like, chill, yo

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

infernal machines posted:

they don't require signed binaries either, so it's not impossible that a compromised binary could end up on a legitimate system and affect multiple patients

we were talking about this at work the other day, but has there ever been a documented case of bad firmware implementing stringent binary signing and essentially locking the manufacturer out of further updates?

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

CommunistPancake posted:

that's fight club

https://en.wikipedia.org/wiki/Ford_Pinto#Cost-benefit_analysis.2C_the_Pinto_Memo

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Doom Mathematic posted:

And what if they're using Windows XP to run the pacemaker, eh?

Windows Embedded surely?

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
lol I was just there a couple days ago

https://twitter.com/wvualphasoldier/status/869264987843432449

gonadic io
Feb 16, 2011

>>=
Paging luigi30:
https://twitter.com/Twylo/status/864655680514342912

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i changed my username on the forums. give me something infosec-y that i can use for an avatar

cinci zoo sniper
Mar 15, 2013




Lain Iwakura posted:

i changed my username on the forums. give me something infosec-y that i can use for an avatar

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

Lain Iwakura posted:

i changed my username on the forums. give me something infosec-y that i can use for an avatar

i mean, like half the screens from serial experiments lain probably qualify as computery enough, but then youll get chain banned for anime when you post.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

cis autodrag posted:

i mean, like half the screens from serial experiments lain probably qualify as computery enough, but then youll get chain banned for anime when you post.

sounds like a plan to me

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

ultramiraculous posted:

we were talking about this at work the other day, but has there ever been a documented case of bad firmware implementing stringent binary signing and essentially locking the manufacturer out of further updates?

this actually rings a bell, but i can't remember any details.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

this is pretty good. consider it a candidate

also an anime avatar is not the end of the world in yospos

FAT32 SHAMER
Aug 16, 2012



Lain Iwakura posted:

this is pretty good. consider it a candidate

also an anime avatar is not the end of the world in yospos

See forums poster Smoka for anime insights

flakeloaf
Feb 26, 2003

Still better than android clock

Lain Iwakura posted:

i changed my username on the forums. give me something infosec-y that i can use for an avatar

i hear canpol is a good source of avatars

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
you know the drill

https://twitter.com/taviso/status/869545056239104000

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

flakeloaf posted:

i hear canpol is a good source of avatars

I don't have any compsci students to annoy though.

vOv
Feb 8, 2014

only sort of a secfuck but apparently people have been getting banned from nintendo's online 3ds stuff for having custom firmware on their 3dses even if they don't hack in multiplayer or pirate games. nobody knows for sure how nintendo's checking but there's a bunch of telemetry enabled by default which iirc includes a log of what applications are run, and so they might just be banning everyone that runs an app on a blacklist of common cfw apps like FBI (which manages custom apps, cause they're stored in .cia files :v:)

of course you're not banned from the eshop because nintendo will still happily take money from you, they're not *completely* dumb

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Lain Iwakura posted:

i changed my username on the forums. give me something infosec-y that i can use for an avatar

not very info seccy name imo

AggressivelyStupid
Jan 9, 2012

https://twitter.com/mikko/status/869539641090867200

gonadic io
Feb 16, 2011

>>=

Lain Iwakura posted:

this is pretty good. consider it a candidate

also an anime avatar is not the end of the world in yospos

yup

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i'll miss the bean dip jokes

Mad Wack
Mar 27, 2008

"The faster you use your cooldowns, the faster you can use them again"
what is illusive and why is my enterprise talking about dark web security

burning swine
May 26, 2004




Nice

A ton of my classes used blackboard when I was in college

flakeloaf
Feb 26, 2003

Still better than android clock

cool now post the moodle one

spankmeister
Jun 15, 2008







That's a classmate of mine. Nice to see his project getting some traction.

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

blackboard has been a piece of poo poo as far back as 2005 when some of my college courses used it. some super basic poo poo like being able to "review" the correct answers for a test you just started on, and viewing other students submitted work

spankmeister
Jun 15, 2008






I should point out that in this case it's the crappy implementation of Blackboard that the University of Amsterdam did that causes most of these issues, not Blackboard itself...

Phone
Jul 30, 2005

親子丼をほしい。

vOv posted:

only sort of a secfuck but apparently people have been getting banned from nintendo's online 3ds stuff for having custom firmware on their 3dses even if they don't hack in multiplayer or pirate games. nobody knows for sure how nintendo's checking but there's a bunch of telemetry enabled by default which iirc includes a log of what applications are run, and so they might just be banning everyone that runs an app on a blacklist of common cfw apps like FBI (which manages custom apps, cause they're stored in .cia files :v:)

of course you're not banned from the eshop because nintendo will still happily take money from you, they're not *completely* dumb

also since it's idiot video game people, it's impossible to get solid data out of them to figure out what exactly happened. I only say this because I'm annoyed that there are 15 articles about how just having a capture card might blacklist you ~but no one is sure exactly why or how~

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
https://stablebit.com/CloudDrive

is this a secfuck, someone linked it in a group chat i'm in

Adbot
ADBOT LOVES YOU

AggressivelyStupid
Jan 9, 2012

spankmeister posted:

I should point out that in this case it's the crappy implementation of Blackboard that the University of Amsterdam did that causes most of these issues, not Blackboard itself...

they're probably not alone in crappy blackboard implementations though

  • Locked thread