Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
raspurtin
Apr 18, 2005

RISCy Business posted:

https://www.youtube.com/watch?v=wdWgvJRHA0s

this is a good (and funny) talk on pentesting, also covers pentesters and "0day"

this guy says oh-day, and he's an american who also swears alot to make himself sound important

Adbot
ADBOT LOVES YOU

Crime on a Dime
Nov 28, 2006

ate all the Oreos posted:

did anyone else notice SA was down for two hours due to a bad SSL certificate

I was at the gym lifting

Dylan16807
May 12, 2010

Rufus Ping posted:

someone probably tried to turn on strict origin cert CN validation in cloudflare

https://crt.sh/?id=168610427

I'm pretty sure the error page from cloudflare said the certificate was expired

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
fair enough. richard wont get very far with that one though

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

permanent cart and order history, look at me fancy pants swinging his big dick over here

FAT32 SHAMER
Aug 16, 2012



I like how the pentesters are popping out of the woodwork to diss a guy for calling their job a relatively large scam

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

FAT32 SHAMER posted:

I like how the pentesters are popping out of the woodwork to diss a guy for calling their job a relatively large scam
i don't know who this mister manuts thinks he is, but i bet his employer won't appreciate his tone when they find out

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

pap schmear posted:

this guy says oh-day, and he's an american who also swears alot to make himself sound important

ok but what did he say that was wrong

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
i mean the man aliased as duncan manuts

i don't think pointing out that he says oh-day and also cuss words is going to affect him in the least

FAT32 SHAMER
Aug 16, 2012



"this guy pointed out that the infosec community is hampered by the fact that normies and even techies and some infosec dudes have no idea what infosec is nor does and because of that pentesting is usually a huge loving scam performed by people who have no idea what they're doing nor why. I'm going to laugh at this dude because he's obviously an idiot that doesn't recognize how my work as a pentester has a major impact on my field"

Pile Of Garbage
May 28, 2007



BangersInMyKnickers posted:

Crypto Config Boogaloo 2017 Edition

hey sorry this was several pages ago now but i was wondering why you're prioritising DHE with GCM over ECDHE with CBC. from what i understand GCM provides better performance than CBC but not much more on the security side whilst ECDHE is an effective mitigation against logjam attacks. happy to be wrong though!

leper khan
Dec 28, 2010
Honest to god thinks Half Life 2 is a bad game. But at least he likes Monster Hunter.
I think I'm going to start using nil-day which we can all agree is wrong.

Crime on a Dime
Nov 28, 2006
it's me. 0cool

Crime on a Dime
Nov 28, 2006
everyone calls me oh cool though should I change my nick

BattleMaster
Aug 14, 2000

it had never even occurred to me that "oh day" was a possible way to say it especially when phrases like "zero hour" have existed for a long time

spankmeister
Jun 15, 2008






https://www.youtube.com/watch?v=u7ERHEJLmWc

cinci zoo sniper
Mar 15, 2013




BattleMaster posted:

it had never even occurred to me that "oh day" was a possible way to say it especially when phrases like "zero hour" have existed for a long time

its always pronounced oh hour thouhg?







ok im kidding.

Crime on a Dime
Nov 28, 2006

BattleMaster posted:

it had never even occurred to me that "oh day" was a possible way to say it especially when phrases like "zero hour" have existed for a long time

but exactly as zero cool they spell the word and don't use the numeral

flakeloaf
Feb 26, 2003

Still better than android clock

don't drink coke oh

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Lain Iwakura posted:

it's just another example of why sms 2fa is dumber than poo poo

is that seriously the thing that worries you the most in "my phone provider reassigned my phone number to someone else"

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

hackbunny posted:

is that seriously the thing that worries you the most in "my phone provider reassigned my phone number to someone else"
apparently he got his carrier to admit that someone had been trying to access his account over the phone, failed a ton, but eventually got a csr to bypass their checks

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://boringssl.googlesource.com/boringssl/+/fed35d32245ee4563691d21f55c12b4f8dac840a/crypto/fipsmodule/FIPS.md google's going to get their fork of openssl (or part of it) fips 140-2 certified

Progressive JPEG
Feb 19, 2003

Volmarias posted:

The open source nature of Android means that Google can recommend and strongly suggest, but ultimately cannot fully control what OEMs do, which is unfortunate for end users.

No, they can. Good luck selling an Android without play store or play services. Amazon tried this and failed.

Progressive JPEG
Feb 19, 2003

ate all the Oreos posted:

nope we use slack's hosting and we don't even pay for anything so it deletes all our messages within a week because we've used up our free quota lol

IIRC nothing is actually deleted, if you bought a subscription it's all still there. This is hearsay though so I could be wrong

Sereri
Sep 30, 2008

awwwrigami

Everything is still there, it just shows the last 10000 lines (over all chats including PMs)

maskenfreiheit
Dec 30, 2004
Speaking of certificate errors:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

maskenfreiheit posted:

Speaking of certificate errors:

what's firefox complaining about

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Progressive JPEG posted:

No, they can. Good luck selling an Android without play store or play services. Amazon tried this and failed.

isn't that happening for many millions of users in China?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Subjunctive posted:

isn't that happening for many millions of users in China?
lol

Vanadium
Jan 8, 2005

Ive walked past some amazon app store people a lot over the past year but I'm frankly not sure what they do, and I don't think their app works on my android phone. They watch a lot of hearthstone.

wolrah
May 8, 2006
what?

anthonypants posted:

well paypal doesn't have any other type of 2fa, are you saying people should just stop using paypal???????

The first hardware 2FA token I ever had was for PayPal. Are you saying they stopped offering this or even the smartphone-based varieties?

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Vanadium posted:

Ive walked past some amazon app store people a lot over the past year but I'm frankly not sure what they do, and I don't think their app works on my android phone. They watch a lot of hearthstone.

firetv / fire tablets i guess

because people buying the cheap-rear end tablets are going to go ham for appstore coins

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

wolrah posted:

The first hardware 2FA token I ever had was for PayPal. Are you saying they stopped offering this or even the smartphone-based varieties?
he says in his blogpost that paypal only supports 2fa over sms, and agrees that sms 2fa is garbage

Dylan16807
May 12, 2010
paypal's 2fa options are a disaster of UI

https://itunsecurity.wordpress.com/2013/08/07/paypal-how-to-not-implement-2-factor-authentication/

apparently there's also a way to use standard TOTP but you have to trick it with fake serial numbers or something

Progressive JPEG
Feb 19, 2003

I have facebook 2fa enabled with totp/gauth. They still send me sms codes and the sms codes still work. Afaict there's no way to just have totp 2fa.

Progressive JPEG
Feb 19, 2003

I mean I only use fb like twice a year so whatever but lol

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Progressive JPEG posted:

I have facebook 2fa enabled with totp/gauth. They still send me sms codes and the sms codes still work. Afaict there's no way to just have totp 2fa.

Facebook also supports u2f which is kingshit

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

you can remove your number from Settings -> Mobile, I believe.

Progressive JPEG
Feb 19, 2003

I'm on phone so I can't see the ui, but last I checked in the 2fa config settings, it has a grayed out filled in checkbox for sms 2fa saying that it's required

Adbot
ADBOT LOVES YOU

Progressive JPEG
Feb 19, 2003

Cocoa Crispies posted:

Facebook also supports u2f which is kingshit

I'll use it if Firefox ever supports it

  • Locked thread