Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
if anyone happens to know how to deal with vpns on grey market ASAs, please let me know

is it just as simple as setting it up on the device and then connecting with something that isn't anyconnect, or is there more nuance?

Adbot
ADBOT LOVES YOU

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

spankmeister posted:

Thanks. Nothing in particular, just wanted to know your reasoning.

Some of the curves are unsafe according to djb et al: https://safecurves.cr.yp.to/

But I don't know enough about ecc to really understand the implications of "unsafe" curves.

That's a good resource and there's still a lot of motion in the ECC space. Since Windows is currently limited to NIST and 25519 (who uses brainpool really?). You have to make the tradeoff between a more accepted NIST curve with a larger key space (521 or 384) vs a newer, better formed 256-bit curve like 25519. MS included 25519 because of that and I expect future releases will expand the curve support but things are still shaking out of that whole discussion.

http://csrc.nist.gov/groups/ST/toolkit/documents/dss/NISTReCur.pdf

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
i dunno if it'll help but it can't possibly hurt- from the device i'm buying:

code:
ciscoasa# sh ver

Cisco Adaptive Security Appliance Software Version 9.1(7)12
Device Manager Version 7.7(1)

Compiled on Thu 14-Jun-12 11:20 by builders
System image file is "disk0:/asa917-12-k8
Config file at boot was "startup-config"

ciscoasa up 2 mins 23 secs

Hardware:   ASA5510, 1024 MB RAM, CPU Pentium 4 Celeron 1600 MHz
Internal ATA Compact Flash, 256MB
BIOS Flash M50FW080 @ 0xfff00000, 1024KB

Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)
                             Boot microcode   : CN1000-MC-BOOT-2.00
                             SSL/IKE microcode: CNLite-MC-SSLm-PLUS-2.03
                             IPSec microcode  : CNlite-MC-IPSECm-MAIN-2.06
                             Number of accelerators: 1

 0: Ext: Ethernet0/0         : address is 001f.caf0.30b4, irq 9
 1: Ext: Ethernet0/1         : address is 001f.caf0.30b5, irq 9
 2: Ext: Ethernet0/2         : address is 001f.caf0.30b6, irq 9
 3: Ext: Ethernet0/3         : address is 001f.caf0.30b7, irq 9
 4: Ext: Management0/0       : address is 001f.caf0.30b3, irq 11
 5: Int: Not used            : irq 11
 6: Int: Not used            : irq 5

Licensed features for this platform:
Maximum Physical Interfaces       : Unlimited      perpetual
Maximum VLANs                     : 100            perpetual
Inside Hosts                      : Unlimited      perpetual
Failover                          : Active/Active  perpetual
VPN-DES                           : Enabled        perpetual
VPN-3DES-AES                      : Enabled        perpetual
Security Contexts                 : 2              perpetual
GTP/GPRS                          : Disabled       perpetual
Other VPN Peers                   : 250            perpetual
Total VPN Peers                   : 250            perpetual
Shared License                    : Disabled       perpetual
AnyConnect for Mobile             : Disabled       perpetual
AnyConnect for Cisco VPN Phone    : Disabled       perpetual
Advanced Endpoint Assessment      : Disabled       perpetual
UC Phone Proxy Sessions           : 2              perpetual
Total UC Proxy Sessions           : 2              perpetual
Botnet Traffic Filter             : Disabled       perpetual
Intercompany Media Engine         : Disabled       perpetual

This platform has an ASA 5510 Security Plus license.

Shaggar
Apr 26, 2006

anthonypants posted:

if we use asas is there a good alternative to anyconnect or should we be using anyconnect

anyconnect enforces policies that other clients may not (ex: split tunneling). the biggest thing is keeping it all up to date.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

anyconnect enforces policies that other clients may not (ex: split tunneling). the biggest thing is keeping it all up to date.
we are currently using Cisco Systems VPN Client v5, i am extremely aware that we need an up-to-date client. but anyconnect licenses cost money, and this vpn client is free :qq:

Wrath of the Bitch King
May 11, 2005

Research confirms that black is a color like silver is a color, and that beyond black is clarity.
Too bad the OpenVPN client is garbage for the average user to use. Is it even worth using from a security perspective or are there problems with it?

Shaggar
Apr 26, 2006
the ASAs support multiple protocols so 3rd party clients can be used by design, so if its not a compliance requirement that you enforce certain things then don't worry about it.

a bigger problem is that asa doesn't support anything beyond tls 1.0 afaik

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Wrath of the Bitch King posted:

Too bad the OpenVPN client is garbage for the average user to use. Is it even worth using from a security perspective or are there problems with it?
it's not an ikev2 client

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

BattleMaster posted:

reminds me of like 15 years ago and using IE and getting sketchy activex controls with long names saying they're totally cool and safe and begging to be installed

not unlike vampires trying to convince you to invite them in

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/og_tjg/status/884756210267893761

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

https://mobile.twitter.com/voretaq7/status/884913799333105664

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).


:discourse:

BattleMaster
Aug 14, 2000

hackbunny posted:

not unlike vampires trying to convince you to invite them in

lol

fishmech
Jul 16, 2006

by VideoGames
Salad Prong
Plug this Web key into the USB drive on your computer.

what is with this copy

30 TO 50 FERAL HOG
Mar 2, 2005



RISCy Business posted:

i dunno if it'll help but it can't possibly hurt- from the device i'm buying:

code:
ciscoasa# sh ver

Cisco Adaptive Security Appliance Software Version 9.1(7)12
Device Manager Version 7.7(1)

Compiled on Thu 14-Jun-12 11:20 by builders
System image file is "disk0:/asa917-12-k8
Config file at boot was "startup-config"

ciscoasa up 2 mins 23 secs

Hardware:   ASA5510, 1024 MB RAM, CPU Pentium 4 Celeron 1600 MHz
Internal ATA Compact Flash, 256MB
BIOS Flash M50FW080 @ 0xfff00000, 1024KB

Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)
                             Boot microcode   : CN1000-MC-BOOT-2.00
                             SSL/IKE microcode: CNLite-MC-SSLm-PLUS-2.03
                             IPSec microcode  : CNlite-MC-IPSECm-MAIN-2.06
                             Number of accelerators: 1

 0: Ext: Ethernet0/0         : address is 001f.caf0.30b4, irq 9
 1: Ext: Ethernet0/1         : address is 001f.caf0.30b5, irq 9
 2: Ext: Ethernet0/2         : address is 001f.caf0.30b6, irq 9
 3: Ext: Ethernet0/3         : address is 001f.caf0.30b7, irq 9
 4: Ext: Management0/0       : address is 001f.caf0.30b3, irq 11
 5: Int: Not used            : irq 11
 6: Int: Not used            : irq 5

Licensed features for this platform:
Maximum Physical Interfaces       : Unlimited      perpetual
Maximum VLANs                     : 100            perpetual
Inside Hosts                      : Unlimited      perpetual
Failover                          : Active/Active  perpetual
VPN-DES                           : Enabled        perpetual
VPN-3DES-AES                      : Enabled        perpetual
Security Contexts                 : 2              perpetual
GTP/GPRS                          : Disabled       perpetual
Other VPN Peers                   : 250            perpetual
Total VPN Peers                   : 250            perpetual
Shared License                    : Disabled       perpetual
AnyConnect for Mobile             : Disabled       perpetual
AnyConnect for Cisco VPN Phone    : Disabled       perpetual
Advanced Endpoint Assessment      : Disabled       perpetual
UC Phone Proxy Sessions           : 2              perpetual
Total UC Proxy Sessions           : 2              perpetual
Botnet Traffic Filter             : Disabled       perpetual
Intercompany Media Engine         : Disabled       perpetual

This platform has an ASA 5510 Security Plus license.

if 3des is enabled you're good. id do

code:
en
config t
show activation-key
and save your key for later use

the pro move however is to take your asa and throw it in the trash, its a piece of garbage. they're slow as gently caress (max vpn throughput is something like 100mbps theoretical but you'll never get that close). the ASDM is a loving steaming turd, but its the best way to update the firmware when theres an inevitable critical security vulnerability

you can use the console, but of course you're stuck using TFTP for uploading firmware on the inside interface and it takes loving forever if theres even marginal latency on the line. you can use standard HTTP or FTP but it has to be accessible on the internet because you can't do

code:
copy [url]http://10.0.0.1/asa-999-k8.bin;interface=inside[/url]
and again, you have to do this manually per device

i guess this isn't an issue if you have one or two of these, but if you have a lot of them in the field it sucks

pro move:

get a sophos firewall image (Free for home use), spin up a VM, and get a used RED10 or RED15

30 TO 50 FERAL HOG fucked around with this message at 01:31 on Jul 12, 2017

post hole digger
Mar 21, 2011


jesus christ

FAT32 SHAMER
Aug 16, 2012



technology will be the undoing of humanity and I am glad of it

James Baud
May 24, 2015

by LITERALLY AN ADMIN
That one possibly does the same, but the federal Liberal Party of Canada (current government) sent a "pretends to be a keyboard and makes your computer do stuff" USB stick to all their donors a couple years back. I was skeptical of it from the start but finally plugged it in a couple years later when looking for a USB drive in a hurry since I had nothing else. Was mightily unimpressed even though I knew it was risky, but at least the target web page it launched was a 404 by then.

Shame Boy
Mar 2, 2010

fishmech posted:

Plug this Web key into the USB drive on your computer.

what is with this copy

it's your key to your healthcare benefits what else would you call it!!!

Pile Of Garbage
May 28, 2007



just got this lovely e-mail from symantec today:



we've got a wildcard cert issued by geotrust before that june 1st date and it's used in lots and lots of places. :rip: us i guess.

Shame Boy
Mar 2, 2010


trying to get the wife to hang this on the wall at work thanks

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

fishmech posted:

Plug this Web key into the USB drive on your computer.

what is with this copy

Any person that would actually plug this in is the kind of person who would call it a "web key"

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

cheese-cube posted:

we've got a wildcard cert issued by geotrust before that june 1st date and it's used in lots and lots of places. :rip: us i guess.

RIP you as much as if it expired, which shouldn't be that big a deal to handle.

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice
A couple years ago at work I found a box of usb toys that were left over from an industry show, it was an easy button type thing you plugged into your computer and if you pressed it it would take you to our support site

we started plugging them into each other's computers and hiding them under the adjacent cube and pressing them at random times until one day they all mysteriously disappeared

they took down that site about 6 months after the conference they were handed out in, as if to give customers a preview of the kind of lack of communication and foresight they could expect from us

ate shit on live tv
Feb 15, 2004

by Azathoth
Idea: POTUS declares all health insurance companies terrorists and arrests their entire board of directors and all company officers. Then directs all insurance claims to be paid in full in the interim. Viola! Single payer, becomes de facto, and NHS happens after the interim disruption.

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
my girlfriend just started as IT person #1 at an office of like 60 and they are apparently freaking out that they don't 'have a firewall' yet

what should she tell them to buy other than 'whatever is being advertising at the airport'

Shame Boy
Mar 2, 2010

Jimmy Carter posted:

my girlfriend just started as IT person #1 at an office of like 60 and they are apparently freaking out that they don't 'have a firewall' yet

what should she tell them to buy other than 'whatever is being advertising at the airport'

#1 as in best or #1 as in the first actual IT person at the whole company ever

post hole digger
Mar 21, 2011

James Baud posted:

That one possibly does the same, but the federal Liberal Party of Canada (current government) sent a "pretends to be a keyboard and makes your computer do stuff" USB stick to all their donors a couple years back. I was skeptical of it from the start but finally plugged it in a couple years later when looking for a USB drive in a hurry since I had nothing else. Was mightily unimpressed even though I knew it was risky, but at least the target web page it launched was a 404 by then.

lol they basically mailed people rubber duckys bad rear end

Greatbacon
Apr 9, 2012

by Pragmatica
I visited my folks today and my pops showed me his new electric toothbrush (recommended by his dentist) that has a bluetooth connection to an "app" that can send brushing data to his hygienist.

So today I got to explain the IoT and malware botnets to my boomer parents and the simultaneous looks of horror and confusion they gave me were great.

"Imagine 4 million cars on a highway on ramp; DDOS works the same way."

El Mero Mero
Oct 13, 2001

Jimmy Carter posted:

my girlfriend just started as IT person #1 at an office of like 60 and they are apparently freaking out that they don't 'have a firewall' yet

what should she tell them to buy other than 'whatever is being advertising at the airport'

she should :sever: asap

geonetix
Mar 6, 2011


Jimmy Carter posted:

my girlfriend just started as IT person #1 at an office of like 60 and they are apparently freaking out that they don't 'have a firewall' yet

what should she tell them to buy other than 'whatever is being advertising at the airport'

a few posts back somebody foolishly got an old asa they may want to part with

surebet
Jan 10, 2013

avatar
specialist



How the Calibri font could take down Pakistan’s prime minister
Microsoft’s default font is at the centre of an ongoing corruption investigation



Microsoft’s Calibri is a fairly innocuous font, used by default on countless numbers of Word, Excel and Powerpoint documents. The inoffensive lettering could soon topple Pakistan’s prime minister, however, after being placed at the heart of a corruption investigation.

Pakistan’s supreme court is currently deliberating a case against Nawaz Sharif, the head of the country’s government. As Al Jazeera reports, a Joint Investigative Team (JIT) encompassing police, military officials and financial regulators has been gathering evidence about the prime minister’s family’s assets.

This follows a judgment by investigators that there were "significant gap[s]" in Sharif's family's ability to explain their assets and means of income. The investigation stems from the 2016 Panama Paper leak, which named three of Sharif's children as beneficiaries of offshore companies. Sharif’s political opponents claim that his properties in London were obtained through corrupt means.

Okay, so where does Calibri come in? Well, to prove her father’s innocence, Sharif’s daughter Maryam Nawaz Sharif has produced a document – allegedly from 2006 – which claims to show certain declarations of income.

The JIT report, however, notes that the documents are written in Calibri, which was not made commercially available by Microsoft until 2007. The investigators say this means that the declarations are therefore incorrectly dated, and were likely created at some later point in time.

https://twitter.com/frooq/status/884494782306889730
The investigation is ongoing, so it’s too soon to tell if a misused font is enough to undermine Sharif’s case, but it certainly isn’t going to do the precariously placed politician any favours. Still, at least it wasn’t Comic Sans.

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe
And in related news the People's Republic of China is seeking damages from Microsoft (MSFT) for appropriating their flag's color scheme for the "hot dog stand" theme.

wolffenstein
Aug 2, 2002
 
Pork Pro
RE: Disabling Facebook's SMS 2FA, per their support article

quote:

Keep in mind: You can use as many authentication methods as you'd like, but you need to have at least text message (SMS) codes turned on, or at least both a security key and Code Generator turned on.
lol

leper khan
Dec 28, 2010
Honest to god thinks Half Life 2 is a bad game. But at least he likes Monster Hunter.

surebet posted:

How the Calibri font could take down Pakistan’s prime minister
Microsoft’s default font is at the centre of an ongoing corruption investigation



Microsoft’s Calibri is a fairly innocuous font, used by default on countless numbers of Word, Excel and Powerpoint documents. The inoffensive lettering could soon topple Pakistan’s prime minister, however, after being placed at the heart of a corruption investigation.

Pakistan’s supreme court is currently deliberating a case against Nawaz Sharif, the head of the country’s government. As Al Jazeera reports, a Joint Investigative Team (JIT) encompassing police, military officials and financial regulators has been gathering evidence about the prime minister’s family’s assets.

This follows a judgment by investigators that there were "significant gap[s]" in Sharif's family's ability to explain their assets and means of income. The investigation stems from the 2016 Panama Paper leak, which named three of Sharif's children as beneficiaries of offshore companies. Sharif’s political opponents claim that his properties in London were obtained through corrupt means.

Okay, so where does Calibri come in? Well, to prove her father’s innocence, Sharif’s daughter Maryam Nawaz Sharif has produced a document – allegedly from 2006 – which claims to show certain declarations of income.

The JIT report, however, notes that the documents are written in Calibri, which was not made commercially available by Microsoft until 2007. The investigators say this means that the declarations are therefore incorrectly dated, and were likely created at some later point in time.

https://twitter.com/frooq/status/884494782306889730
The investigation is ongoing, so it’s too soon to tell if a misused font is enough to undermine Sharif’s case, but it certainly isn’t going to do the precariously placed politician any favours. Still, at least it wasn’t Comic Sans.

comic sans has been around since 1994 though. and lots of people use it for things they shouldn't (anything)

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

surebet posted:

How the Calibri font could take down Pakistan’s prime minister
Microsoft’s default font is at the centre of an ongoing corruption investigation



Microsoft’s Calibri is a fairly innocuous font, used by default on countless numbers of Word, Excel and Powerpoint documents. The inoffensive lettering could soon topple Pakistan’s prime minister, however, after being placed at the heart of a corruption investigation.

Pakistan’s supreme court is currently deliberating a case against Nawaz Sharif, the head of the country’s government. As Al Jazeera reports, a Joint Investigative Team (JIT) encompassing police, military officials and financial regulators has been gathering evidence about the prime minister’s family’s assets.

This follows a judgment by investigators that there were "significant gap[s]" in Sharif's family's ability to explain their assets and means of income. The investigation stems from the 2016 Panama Paper leak, which named three of Sharif's children as beneficiaries of offshore companies. Sharif’s political opponents claim that his properties in London were obtained through corrupt means.

Okay, so where does Calibri come in? Well, to prove her father’s innocence, Sharif’s daughter Maryam Nawaz Sharif has produced a document – allegedly from 2006 – which claims to show certain declarations of income.

The JIT report, however, notes that the documents are written in Calibri, which was not made commercially available by Microsoft until 2007. The investigators say this means that the declarations are therefore incorrectly dated, and were likely created at some later point in time.

https://twitter.com/frooq/status/884494782306889730
The investigation is ongoing, so it’s too soon to tell if a misused font is enough to undermine Sharif’s case, but it certainly isn’t going to do the precariously placed politician any favours. Still, at least it wasn’t Comic Sans.

Microsoft should change the default font on Word every year just to gently caress with really dumb forgers.

Mr SuperAwesome
Apr 6, 2011

im from the bad post police, and i'm afraid i have bad news
pretend they were using the beta. should work as a defence

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

surebet posted:

How the Calibri font could take down Pakistan’s prime minister
Microsoft’s default font is at the centre of an ongoing corruption investigation



Microsoft’s Calibri is a fairly innocuous font, used by default on countless numbers of Word, Excel and Powerpoint documents. The inoffensive lettering could soon topple Pakistan’s prime minister, however, after being placed at the heart of a corruption investigation.

Pakistan’s supreme court is currently deliberating a case against Nawaz Sharif, the head of the country’s government. As Al Jazeera reports, a Joint Investigative Team (JIT) encompassing police, military officials and financial regulators has been gathering evidence about the prime minister’s family’s assets.

This follows a judgment by investigators that there were "significant gap[s]" in Sharif's family's ability to explain their assets and means of income. The investigation stems from the 2016 Panama Paper leak, which named three of Sharif's children as beneficiaries of offshore companies. Sharif’s political opponents claim that his properties in London were obtained through corrupt means.

Okay, so where does Calibri come in? Well, to prove her father’s innocence, Sharif’s daughter Maryam Nawaz Sharif has produced a document – allegedly from 2006 – which claims to show certain declarations of income.

The JIT report, however, notes that the documents are written in Calibri, which was not made commercially available by Microsoft until 2007. The investigators say this means that the declarations are therefore incorrectly dated, and were likely created at some later point in time.

https://twitter.com/frooq/status/884494782306889730
The investigation is ongoing, so it’s too soon to tell if a misused font is enough to undermine Sharif’s case, but it certainly isn’t going to do the precariously placed politician any favours. Still, at least it wasn’t Comic Sans.

:haw: Well I tried to use the original document, but word told me that it was too old so it converted it to a new one, I'm not sure I'm not good at computers

:doink: Neither am I, that sounds plausible. Case dismissed!

Seriously though, I love that there's always some new way for Microsoft's font handling to screw people over.

30 TO 50 FERAL HOG
Mar 2, 2005



cheese-cube posted:

wildcard cert...used in lots and lots of places

sounds like your own fault

Adbot
ADBOT LOVES YOU

Phone
Jul 30, 2005

親子丼をほしい。

Volmarias posted:

:haw: Well I tried to use the original document, but word told me that it was too old so it converted it to a new one, I'm not sure I'm not good at computers

:doink: Neither am I, that sounds plausible. Case dismissed!

Seriously though, I love that there's always some new way for Microsoft's font handling to screw people over.

is this an "oh day"?

  • Locked thread