Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Shame Boy
Mar 2, 2010

Jabor posted:

if "growing your userbase" is more important than being a good custodian of people's private data, keep on keeping on i guess.

i mean we're talking about facebook here right

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Powerful Two-Hander posted:

i used a well know UK energy switching site the other day and after going through its setup stuff it created me an account on their service which weirdly required no password, turns out what they do is just link your account to your email address then when you want to login send you a one time(i assume) link with a token in it.

i cant decide if this is good or bad. its something you'd use once a year maybe and this does make signup and login easier as you don't need to remember a password, just generate a 1 time link then forget about it

slack does this as well

Shaggar
Apr 26, 2006

Subjunctive posted:

the extra step is "Open in Instagram?", and equivalent (but more terribly worded) on Android, for which the cancel rate is non-trivial in other scenarios

it's the same broken model used by every site on the web, assuming they bother to confirm at all. the failure mode here is loss of a new, low-value-to-user account. the failure mode of a more complex system is more users locking themselves out of older, high-value-to-user accounts because they didn't complete confirmation

I will pass your thoughts on to the account access team, though, so you can save the world with untried approaches!

show them a banner in the app that's like "Don't lose access to your account! confirm your email address now!" or something to encourage them to confirm it. if they don't, then gently caress 'em.

spankmeister
Jun 15, 2008






Subjunctive posted:

slack does this as well

I think it's fine because generally speaking, if you have access to someone's email, then you have access to pretty much any service linked to that email address. (barring 2FA)

Malcolm XML
Aug 8, 2009

I always knew it would end like this.
Yeah monzo bank does this since the email password is the security barrier anyway

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Chris Knight posted:

so why should someone be allowed to sign up for an account with an email that they don't own?
the account had their telephone number in it, so i think it just uses that or their facebook account (NOTE: instagram is owned by facebook) to set up the account for the first time. for some reason they added an email account to their instagram account later, but i couldn't tell you why

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

ate all the Oreos posted:

yeah sabotaging facebook from the inside through subtle manipulation of stuff like this seems like a great way to get yourself off the short list for a guillotine'in when the revolution starts

lol at your just-world assumption that there's a way off the short list for the guillotine

Midjack
Dec 24, 2007




lolling pretty hard at this

NFX
Jun 2, 2008

Fun Shoe

Jabor posted:

all you need to do is not have the confirmation link automatically log you in. if they still have the cookie from their previous visit when they click the link, fine, if they don't then ask them to log in again. there's no excuse for the emailed confirmation link giving whoever knows it full access to the account.

e: obv. you need to not do email password recovery until they've actually confirmed their email address too.

what user name do you log in with, assuming user name is email address? the old address that you forgot/no longer have access to or the new one that isn't confirmed?

but the passwordless logins like that are good, because anthonypants can just ignore the email and the idiot teenager does not go on using the app without actually confirming an email

FAT32 SHAMER
Aug 16, 2012



anthonypants posted:

some teen just did this again, but this time the account has a bunch of pictures in it. whoops

make sure to upload a pic that says "i dont know what my loving email is" afterwards

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

funny Star Wars parody posted:

make sure to upload a pic that says "i dont know what my loving email is" afterwards
nah

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

what are the recommendations for products to do account password rotation/checkout/auditing? I'm going to do LAPS for all the Windows hosts but I need to deal with all the other poo poo somehow

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

rjmccall posted:

lol at your just-world assumption that there's a way off the short list for the guillotine

there is and it's to be the one doing the guillotining

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
users are loving dumb as hell

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



more like lusers

leper khan
Dec 28, 2010
Honest to god thinks Half Life 2 is a bad game. But at least he likes Monster Hunter.
I just bought binja; does anyone know a good resource of crackmes to get better at reversing?

I have no idea what I want to do with it after I patch dark mode into unity at home.

Daman
Oct 28, 2011

leper khan posted:

I just bought binja; does anyone know a good resource of crackmes to get better at reversing?

I have no idea what I want to do with it after I patch dark mode into unity at home.

these reversing challenges have pretty much everything you'd expect from a crackme :)

https://github.com/ctfs/write-ups-2016/search?utf8=%E2%9C%93&q=reversing&type=

also this is going on right now, but it's not really 100% just pure reverse engineering in binja

LabyREnth.com

FlapYoJacks
Feb 12, 2009
Switching our product's crypto library over to libressl today. :smug:

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
https://twitter.com/troyhunt/status/875401896185483264

:madmax:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
:boom:

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

Pardon my ignorance, but is sledging password managers just insulting them, or breaking them, or something else?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Avenging_Mikon posted:

Pardon my ignorance, but is sledging password managers just insulting them, or breaking them, or something else?

I believe it's a synonym for "slagging".

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Avenging_Mikon posted:

Pardon my ignorance, but is sledging password managers just insulting them, or breaking them, or something else?
https://www.urbandictionary.com/define.php?term=Sledging

leper khan
Dec 28, 2010
Honest to god thinks Half Life 2 is a bad game. But at least he likes Monster Hunter.

leper khan posted:

I just bought binja; does anyone know a good resource of crackmes to get better at reversing?

I have no idea what I want to do with it after I patch dark mode into unity at home.

turns out doing this stuff successfully makes you feel pretty cool

suffix
Jul 27, 2013

Wheeee!
so apparently north korea did the wannacry ransomware

https://www.washingtonpost.com/worl...381c_story.html

idk seems weird - wannacry didnt really seem that different from the thousands of other ransomwares, it just happened to be really successful using a recently published exploit, and as i understand it they didn't set up proper infrastructure for the large amount of infections
its like the flappy bird of ransomware

so i kind of figure either nk must have been churning out ransomware for years and finally got lucky, or some it guy is fronting because "hacked by north korea" sounds better than "owned by 13 yo scriptkiddie because you didn't patch"

Wiggly Wayne DDS
Sep 11, 2010



they've used ransomware/wipers to obscure their attacks before, this shouldn't surprise anyone who's been paying the least bit of attention

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

suffix posted:

so apparently north korea did the wannacry ransomware

https://www.washingtonpost.com/worl...381c_story.html

idk seems weird - wannacry didnt really seem that different from the thousands of other ransomwares, it just happened to be really successful using a recently published exploit, and as i understand it they didn't set up proper infrastructure for the large amount of infections
its like the flappy bird of ransomware

so i kind of figure either nk must have been churning out ransomware for years and finally got lucky, or some it guy is fronting because "hacked by north korea" sounds better than "owned by 13 yo scriptkiddie because you didn't patch"

quote:

WannaCry was apparently an attempt to raise revenue for the regime, but analysts said the effort was flawed. Though the hackers raised $140,000 in bitcoin, a form of digital currency, so far they have not cashed it in, the analysts said. That is likely because an operational error has made the transactions easy to track, including by law enforcement.
lol

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

anthonypants posted:

suffix posted:


so apparently north korea did the wannacry ransomware

https://www.washingtonpost.com/worl...381c_story.html

idk seems weird - wannacry didnt really seem that different from the thousands of other ransomwares, it just happened to be really successful using a recently published exploit, and as i understand it they didn't set up proper infrastructure for the large amount of infections
its like the flappy bird of ransomware

so i kind of figure either nk must have been churning out ransomware for years and finally got lucky, or some it guy is fronting because "hacked by north korea" sounds better than "owned by 13 yo scriptkiddie because you didn't patch"

quote:


WannaCry was apparently an attempt to raise revenue for the regime, but analysts said the effort was flawed. Though the hackers raised $140,000 in bitcoin, a form of digital currency, so far they have not cashed it in, the analysts said. That is likely because an operational error has made the transactions easy to track, including by law enforcement.
lol


bitcoin: now also useless for crime

suffix
Jul 27, 2013

Wheeee!

Wiggly Wayne DDS posted:

they've used ransomware/wipers to obscure their attacks before, this shouldn't surprise anyone who's been paying the least bit of attention

if they want to obscure an attack why use their own custom ransomware instead of someone elses? seems a bit like obscuring a murder scene by jizzing all over it

Wiggly Wayne DDS
Sep 11, 2010



suffix posted:

if they want to obscure an attack why use their own custom ransomware instead of someone elses? seems a bit like obscuring a murder scene by jizzing all over it
it only takes change in management for the tool to change in scope

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal
i wouldn't want to be whoever has to explain to kim jong un that they're now stuck with a pile of "money" they can't do anything with

otoh i could see kim jong un being really into bitcoin so maybe it's all good

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
being virtually banned from trade worldwide, north korea makes money as a criminal enterprise. it's been documented before that two of their main exports are counterfeit dollar bills and meth. some have lamented that both products are of such high quality (they once had to bring their dollar printing standards way down to match the quality of the originals) that it's a pity north korea can't use their manufacturing excellence for legit products

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

hackbunny posted:

being virtually banned from trade worldwide, north korea makes money as a criminal enterprise. it's been documented before that two of their main exports are counterfeit dollar bills and meth. some have lamented that both products are of such high quality (they once had to bring their dollar printing standards way down to match the quality of the originals) that it's a pity north korea can't use their manufacturing excellence for legit products

while unlimited access to slave labor and unchecked control of a nation-state can make you a very effective criminal manufacturer compared to a cartel or the mafia it only puts you at the middle of the road as a state

Diva Cupcake
Aug 15, 2005

why can't they cash it out? if it's actually nk why do they give a poo poo if investigators track the transactions to nk?

spankmeister
Jun 15, 2008






I believe the NSA's assessment on this. They were right about the Sony hacks too.

And about the intended purpose:
Word on the street is that this version of wannacry wasn't ready yet, and got released by accident. Then it turned out to be a huge success and they weren't quite ready for that. (The hardcoded Bitcoin address for example meant that they had to authorize each decrypt by hand).

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Diva Cupcake posted:

why can't they cash it out? if it's actually nk why do they give a poo poo if investigators track the transactions to nk?

cant cash out in stolen amazon gift cards in north korea i guess

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Diva Cupcake posted:

why can't they cash it out? if it's actually nk why do they give a poo poo if investigators track the transactions to nk?

how would they cash out?

Bulgakov
Mar 8, 2009


рукописи не горят

I'm the bank that wants to be associated with north korea

necrotic
Aug 2, 2005
I owe my brother big time for this!

Diva Cupcake posted:

why can't they cash it out? if it's actually nk why do they give a poo poo if investigators track the transactions to nk?

Article said exchanges won't touch it because it's a know address, which removed the easiest avenue they had.

Adbot
ADBOT LOVES YOU

necrotic
Aug 2, 2005
I owe my brother big time for this!
anonymous currency of the future

  • Locked thread