Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
cinci zoo sniper
Mar 15, 2013




someone should send the founder of defcon to the australian government to reason about banning end to end encryption

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




also ismartalarm :allears:

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


Feed Me A Stray Cat

flakeloaf
Feb 26, 2003

Still better than android clock

atm load letter

Diva Cupcake
Aug 15, 2005

TavisAlert

https://twitter.com/taviso/status/886989476202926080

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

https://twitter.com/taviso/status/886989661049995264

e: lol

quote:

I pinged mozilla security team to let them know that they may need to prioritize an upcoming addon review (Mozilla manually approve all addons).

I don't know how webex works in IE and Edge, but dealing with Microsoft is such a huge pain that I'm just going to plead ignorance and let them figure it out themselves.

anthonypants fucked around with this message at 17:48 on Jul 17, 2017

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

cinci zoo sniper posted:

government

reason

encryption

Found the fatal flaw in your argument.

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
https://www.upguard.com/breaches/cloud-leak-dow-jones

dow jwned

Shaggar
Apr 26, 2006

in ie/edge it would be updated the next time its used.

Sharktopus
Aug 9, 2006

im the 500 variations of a dead guy's name still on the watchlist

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

the mall was so secure that Securutron could not go on living

https://twitter.com/bilalfarooqui/status/887025375754166272

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

BangersInMyKnickers posted:

the mall was so secure that Securutron could not go on living

https://twitter.com/bilalfarooqui/status/887025375754166272

Rick and Morty season 3 gonna be sick as hell.

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

BangersInMyKnickers posted:

the mall was so secure that Securutron could not go on living

https://twitter.com/bilalfarooqui/status/887025375754166272

what's the possibility of the robot's batteries discharging into the water and shocking/electrocuting whoever went in to try and haul it out

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
how bad are the infosec books currently in the humble bundle https://www.humblebundle.com/books/cybersecurity-wiley

hobbesmaster
Jan 28, 2008


so does Microsoft have a "ten loving years" policy?

ate shit on live tv
Feb 15, 2004

by Azathoth

Farmer Crack-rear end posted:

what's the possibility of the robot's batteries discharging into the water and shocking/electrocuting whoever went in to try and haul it out

zero. It would short between the terminal's then either be shut off by the batteries power management, or be fully discharged and inert.

Sharktopus
Aug 9, 2006

anthonypants posted:

how bad are the infosec books currently in the humble bundle https://www.humblebundle.com/books/cybersecurity-wiley

the schneier crypto textbooks are very good

looks like crypto engineering is the newer version of practical crypto and $15 for it and applied crypto is a steal

Schadenboner
Aug 15, 2011

by Shine

BangersInMyKnickers posted:

the mall was so secure that Securutron could not go on living

https://twitter.com/bilalfarooqui/status/887025375754166272

MARVIN, NO! WHY?

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Sharktopus posted:

the schneier crypto textbooks are very good

looks like crypto engineering is the newer version of practical crypto and $15 for it and applied crypto is a steal

otoh applied crypto and crypto engineering are ancient and you should probably just use NaCL

Sharktopus
Aug 9, 2006

Cocoa Crispies posted:

otoh applied crypto and crypto engineering are ancient and you should probably just use NaCL

yeah learning is for chumps

Wiggly Wayne DDS
Sep 11, 2010



anthonypants posted:

how bad are the infosec books currently in the humble bundle https://www.humblebundle.com/books/cybersecurity-wiley
top of the line books 5 years ago, but great for learning. there's some trash in there but as random ref material a pretty strong pack

Shalhavet
Dec 10, 2010

This post is terrible
Doctor Rope
anyone got a phone number for an msi sysadmin?

Number19
May 14, 2003

HOCKEY OWNS
FUCK YEAH


Daman
Oct 28, 2011
so say someone recently got a job doing internal code security auditing. they're reviewing one feature, and their "Senior" coworker is meant to be reviewing another feature. they're adjacent on the org chart.

co-worker's output only seems to be "design flaws." the coworker has even taken a brief look at the feature they aren't tasked with and spotted what they think is a big design flaw and worthy of meetings etc etc. of course it's framed like the coworker was just being helpful with getting the person up to speed on how things go during reviews. new person thinks the design flaw isn't really a big deal because it doesn't affect confidentiality integrity or availability, it only disables the non-critical feature temporarily.

new person suspects a lot of memory corruption bugs in several areas of their feature. confirming would require debugging, and simple fuzzing due to the complexity of the code being too great to be certain from code review alone. memory corruption in this situation would allow RCE.

coworker likes to repeatedly say how code review is enough and debugging/fuzzing would take too much time. however, other than design flaws they're never filing anything more than very simple+obvious memory corruption bugs.

is coworker a useless charlatan or just skirting along doing the bare minimum? are they trying to drag the new person down to their level? how can you even CYA with them trying to inject themselves into your project like that. he really wants the new person to spend time trying to fix the design related to his bug instead of find bugs that actually matter. his poo poo would take 2wks out of the 3wks allotted.

I'm probably unreasonably angry about this, I guess using the new person to make you look good is common. job security fuckup

Computer Serf
May 14, 2005
Buglord

Daman posted:

so say someone recently got a job doing internal code security auditing. they're reviewing one feature, and their "Senior" coworker is meant to be reviewing another feature. they're adjacent on the org chart.

co-worker's output only seems to be "design flaws." the coworker has even taken a brief look at the feature they aren't tasked with and spotted what they think is a big design flaw and worthy of meetings etc etc. of course it's framed like the coworker was just being helpful with getting the person up to speed on how things go during reviews. new person thinks the design flaw isn't really a big deal because it doesn't affect confidentiality integrity or availability, it only disables the non-critical feature temporarily.

new person suspects a lot of memory corruption bugs in several areas of their feature. confirming would require debugging, and simple fuzzing due to the complexity of the code being too great to be certain from code review alone. memory corruption in this situation would allow RCE.

coworker likes to repeatedly say how code review is enough and debugging/fuzzing would take too much time. however, other than design flaws they're never filing anything more than very simple+obvious memory corruption bugs.

is coworker a useless charlatan or just skirting along doing the bare minimum? are they trying to drag the new person down to their level? how can you even CYA with them trying to inject themselves into your project like that. he really wants the new person to spend time trying to fix the design related to his bug instead of find bugs that actually matter. his poo poo would take 2wks out of the 3wks allotted.

I'm probably unreasonably angry about this, I guess using the new person to make you look good is common. job security fuckup

if you wanna be worthy of your superior coworker/boss in infosec you need to capture their flag by logging into their email and sending out company wide messages disclosing the details of how "my butt is full of poopoo and it feels so good" etcetera

cinci zoo sniper
Mar 15, 2013




https://i.imgur.com/NSmFQgg.gifv

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

choosing your favorite color is such a bullshit security question, you can try all 16,7 million choices in seconds :rolleyes:

besides 2/3 will just choose black anyway :rolleyes::rolleyes:

bobfather
Sep 20, 2001

I will analyze your nervous system for beer money
I was really hoping "what security question did you choose" picked twice would pop up a third drop down box.

cinci zoo sniper
Mar 15, 2013




I was really hoping "what security question did you choose" picked twice would pop up a third drop down box.

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

bobfather posted:

I was really hoping "what security question did you choose" picked twice would pop up a third drop down box.


bobfather posted:

I was really hoping "what security question did you choose" picked twice would pop up a third drop down box.

?

Mr SuperAwesome
Apr 6, 2011

im from the bad post police, and i'm afraid i have bad news

Rectus
Apr 27, 2008


needs 32 bits per channel unbounded floating point input imo

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Rectus posted:

needs 32 bits per channel unbounded floating point input imo

yeah, without hdr there's a simple rainbow table attack

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Subjunctive posted:

yeah, without hdr there's a simple rainbow table attack

boo!

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

Subjunctive posted:

yeah, without hdr there's a simple rainbow table attack

:ughh:

mod saas
May 4, 2004

Grimey Drawer

secfuck coming from inside the thread?

Subjunctive posted:

yeah, without hdr there's a simple rainbow table attack

:confuoot:

spit on my clit
Jul 19, 2015

by Cyrano4747
A page late, but

Shaggar
Apr 26, 2006

Daman posted:

so say someone recently got a job doing internal code security auditing. they're reviewing one feature, and their "Senior" coworker is meant to be reviewing another feature. they're adjacent on the org chart.

co-worker's output only seems to be "design flaws." the coworker has even taken a brief look at the feature they aren't tasked with and spotted what they think is a big design flaw and worthy of meetings etc etc. of course it's framed like the coworker was just being helpful with getting the person up to speed on how things go during reviews. new person thinks the design flaw isn't really a big deal because it doesn't affect confidentiality integrity or availability, it only disables the non-critical feature temporarily.

new person suspects a lot of memory corruption bugs in several areas of their feature. confirming would require debugging, and simple fuzzing due to the complexity of the code being too great to be certain from code review alone. memory corruption in this situation would allow RCE.

coworker likes to repeatedly say how code review is enough and debugging/fuzzing would take too much time. however, other than design flaws they're never filing anything more than very simple+obvious memory corruption bugs.

is coworker a useless charlatan or just skirting along doing the bare minimum? are they trying to drag the new person down to their level? how can you even CYA with them trying to inject themselves into your project like that. he really wants the new person to spend time trying to fix the design related to his bug instead of find bugs that actually matter. his poo poo would take 2wks out of the 3wks allotted.

I'm probably unreasonably angry about this, I guess using the new person to make you look good is common. job security fuckup

they're probably just trying to do the bare minimum while other poo poo has to get done. if you want clarity, consult w/ ur legal department or review existing policies.

ate shit on live tv
Feb 15, 2004

by Azathoth

I wsih what is your password was a more common security question, since security questions are trash.

Adbot
ADBOT LOVES YOU

akadajet
Sep 14, 2003

ate poo poo on live tv posted:

I wsih what is your password was a more common security question, since security questions are trash.

I like password hints, personally.

  • Locked thread