Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
fritz
Jul 26, 2003

are brits supposed to say zedro day or something

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


you can disable facebook sms

bicycle
Oct 23, 2013

fritz posted:

are brits supposed to say zedro day or something

naught day

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe
let's just call it zero tolerance day and be done with this terrible derail

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Thanks Ants posted:

you can disable facebook sms



huh mine has the disable button but when i click it:

Only registered members can see post attachments!

fisting by many
Dec 25, 2009



yeah not being able to disable sms bugs me

hopefully facebook can just tell what country i'm in, if anyone can do it it's them

Thanks Ants
May 21, 2004

#essereFerrari


Rufus Ping posted:

huh mine has the disable button but when i click it:



:iiam:

maskenfreiheit
Dec 30, 2004
why would you jump through hoops to set up nonshitty 2 factor on fb when u can just delete account

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



wish you would delete your SA account

maskenfreiheit
Dec 30, 2004

Powaqoatse posted:

wish you would delete your SA account

Shaggar
Apr 26, 2006

cinci zoo sniper posted:

i mean, how different is it from loosing phone with sms 2fa, or do your carriers restore stolen numbers?

you just get a new phone and the same account w/ same number. the old phone/sim are deactivated. the reason SMS is so common for 2fa is because the user doesn't have to manage their own key recovery when their 2fa mechanism is lost. For example:

anthonypants posted:

just use the gauth recovery code when you set up gauth on your new phone

like how is this even a question


doesnt work for most users who are just going to pass right by the recovery key section during setup because all they see is a list of numbers and letters that they don't understand.

cinci zoo sniper
Mar 15, 2013




guys has anyone seen the op, by the way.i think we may have killed her :ohdear:

Shaggar posted:

you just get a new phone and the same account w/ same number. the old phone/sim are deactivated. the reason SMS is so common for 2fa is because the user doesn't have to manage their own key recovery when their 2fa mechanism is lost. For example
i get that for contract numbers, yes. here that would gently caress up considerable portion of population, and i imagine it is similar in other poorer countries

Shaggar
Apr 26, 2006
oh yeah then you'd be hosed. same as if you didn't copy down your recovery keys for a non-sms 2fa. altho depending on the account they probably have a way to remove the 2fa which is an easier target than your SMS was in the first place.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

oh yeah then you'd be hosed. same as if you didn't copy down your recovery keys for a non-sms 2fa. altho depending on the account they probably have a way to remove the 2fa which is an easier target than your SMS was in the first place.
yeah you just ask nicely

Chalks posted:

My phone broke so I emailed the company and asked them to turn off 2fa and they did it no questions asked. lol

Shame Boy
Mar 2, 2010

FAT32 SHAMER posted:

I like how the pentesters are popping out of the woodwork to diss a guy for calling their job a relatively large scam

we hired some company to regularly pentest our software and they still haven't found the myriad of really incredibly obvious problems, i assume because all they're doing is running some toolkit that looks for known vulns in software that is not the software my company specifically makes

but hey we get to say we're pentested when companies ask!!

Progressive JPEG
Feb 19, 2003

Rufus Ping posted:

huh mine has the disable button but when i click it:



yep this is what i get too

Shame Boy
Mar 2, 2010

what i'm saying is they're less than worthless, they're actively harmful because they convey a level of safety that's not there at all

cinci zoo sniper
Mar 15, 2013




Shaggar posted:

oh yeah then you'd be hosed. same as if you didn't copy down your recovery keys for a non-sms 2fa. altho depending on the account they probably have a way to remove the 2fa which is an easier target than your SMS was in the first place.
the removable 2fa is double-edged sword. with google you are hosed, with steam you can email your id and unfuck the account, but then you can also be identity-theft owned

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

communism bitch posted:

Y'all sound so depressed and cynical about every method of protecting user data like login credentials. If 2fa using my phone isn't going to keep my neopets account safe what is?

Depression and cynicism are requirements to be in infosec

SMS 2fa is better than no 2fa, but it's not as good as other options and has some glaring weaknesses and security folks also generally like to hate on anything that's not perfect so

Ed: also anyone gonna be in vegas this year? I'm skipping defcon prob but will be down for bsides and then at least til Friday for a work thing

spankmeister
Jun 15, 2008






I'm not going this year :(

jre
Sep 2, 2011

To the cloud ?



pr0zac posted:

SMS 2fa is better than no 2fa, but it's not as good as other options and has some glaring weaknesses and security folks also generally like to hate on anything that's not perfect so

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

I'm not going this year :(

may your kapsalons be especially tasty

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



am I the only one who keeps the old phone and sets up the 2fa app on old and new at the same time in order to have a backup?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Munkeymon posted:

am I the only one who keeps the old phone and sets up the 2fa app on old and new at the same time in order to have a backup?
statistically no, but you are doing a dumb thing

Progressive JPEG
Feb 19, 2003

just write all your 2fa codes in a notebook

000000
000001
000002
...
999997
999998
999999

Progressive JPEG
Feb 19, 2003

get facebook to mail you a new one time pad every couple months

(actually this wouldn't be a bad idea given presumed lower likelihood of mail getting snooped)

maskenfreiheit
Dec 30, 2004
instead of facebook try face to face book

[dad laugh]

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



anthonypants posted:

statistically no, but you are doing a dumb thing

feels safer than printing off the lockout code and keeping that around - at least the old phone is encrypted and password protected

Shame Boy
Mar 2, 2010

Munkeymon posted:

feels safer than printing off the lockout code and keeping that around - at least the old phone is encrypted and password protected

serious question: is your threat model "someone could break into my house and steal a piece of paper and then use it to post terrible things to my facebook account"

maskenfreiheit
Dec 30, 2004

ate all the Oreos posted:

serious question: is your threat model "someone could break into my house and steal a piece of paper and then use it to post terrible things to my facebook account"



i'm a privacy fundementalist, models want nothing to do with me

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



ate all the Oreos posted:

serious question: is your threat model "someone could break into my house and steal a piece of paper and then use it to post terrible things to my facebook account"

burglary does happen but mainly I'd like to not have to punch in a fifty character alphanumeric code and leaving an old phone in a drawer is a way to get out of that hopefully

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


i had to use an internet cafe today to do some work bullshit while on holiday and 1) holy poo poo internet cafes still exist 2) they give you local admin which was handy because i had to install java to get our garbage remote access software working*

the guy next to me was trying to open some random file type and asked the staff about installing something and they went 'it's not a virus right?' and just did it


*recently upgraded to use a java desktop app that has to be manually set up to point to the java exe and so breaks on every java version update because environment variables are hard

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Powerful Two-Hander posted:

i had to use an internet cafe today to do some work bullshit while on holiday and 1) holy poo poo internet cafes still exist 2) they give you local admin which was handy because i had to install java to get our garbage remote access software working*

the guy next to me was trying to open some random file type and asked the staff about installing something and they went 'it's not a virus right?' and just did it


*recently upgraded to use a java desktop app that has to be manually set up to point to the java exe and so breaks on every java version update because environment variables are hard

lmao if your remote access software isn't vpn client + rdesktop/ssh

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


RISCy Business posted:

lmao if your remote access software isn't vpn client + rdesktop/ssh

it uses the java app to launch a regular rdp session i don't even know what the gently caress

edit: i guess the java app creates the vpn tunnel and they did it that way so that it could be used on macs as well. no idea what the inevitable linux users are supposed to do.

Powerful Two-Hander fucked around with this message at 05:03 on Jul 10, 2017

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Powerful Two-Hander posted:

it uses the java app to launch a regular rdp session i don't even know what the gently caress

edit: i guess the java app creates the vpn tunnel and they did it that way so that it could be used on macs as well. no idea what the inevitable linux users are supposed to do.

the most portable setup is a vpn client and your remote desktop client of choice

namaste

FAT32 SHAMER
Aug 16, 2012



Powerful Two-Hander posted:

i had to use an internet cafe today to do some work bullshit while on holiday and 1) holy poo poo internet cafes still exist 2) they give you local admin which was handy because i had to install java to get our garbage remote access software working*

the guy next to me was trying to open some random file type and asked the staff about installing something and they went 'it's not a virus right?' and just did it


*recently upgraded to use a java desktop app that has to be manually set up to point to the java exe and so breaks on every java version update because environment variables are hard

android studio loving does this and I had to write documentation to walk clients through how to handle this when setting up their android automation thing I wrote for them :argh:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Powerful Two-Hander posted:

i had to use an internet cafe today to do some work bullshit while on holiday and 1) holy poo poo internet cafes still exist 2) they give you local admin which was handy because i had to install java to get our garbage remote access software working*

the guy next to me was trying to open some random file type and asked the staff about installing something and they went 'it's not a virus right?' and just did it


*recently upgraded to use a java desktop app that has to be manually set up to point to the java exe and so breaks on every java version update because environment variables are hard

you used a public computer to connect to work resources?

FAT32 SHAMER
Aug 16, 2012



the secfuck is coming from inside the thread

vOv
Feb 8, 2014

Lain Iwakura posted:

you used a public computer to connect to work resources?

Adbot
ADBOT LOVES YOU

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

perhaps revenge for having to work on holiday

  • Locked thread