Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
mod saas
May 4, 2004

Grimey Drawer

JewKiller 3000 posted:

i leave my desktop unlocked sometimes. nobody has ever touched it, because they're all deathly afraid of pissing me off. this is the way things should be

so you work with jews

Adbot
ADBOT LOVES YOU

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

mrmcd posted:

Stolen from the bitcoin thread:



I don't know how to copy posts with quotes on mobile so go there and thank the original guy who dug up this hn post

https://news.ycombinator.com/item?id=14691212

lmao at all the idiots rushing to discredit op because WELL YOU SHOULD NEVER USE FLOATING POINT FOR MONEY SO

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

A Pinball Wizard posted:

https://news.ycombinator.com/item?id=14691212

lmao at all the idiots rushing to discredit op because WELL YOU SHOULD NEVER USE FLOATING POINT FOR MONEY SO

I mean you shouldn't but that's like yelling "hahaha loser we sanitized our water! The sewer never goes into the tap because we have no sewer!" while the whole world burns down with fireborne aids virus and you're hording needle chairs.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


There were a few chaos computing club videos were they talked about the risks of things like network and intel ME chips executing arbitrary code internally and being forever in a compromised state because there is no reliable way to guarantee its been reverted/restored to a known good state. It's lovely stuff.

Shame Boy
Mar 2, 2010

mrmcd posted:

I mean you shouldn't but that's like yelling "hahaha loser we sanitized our water! The sewer never goes into the tap because we have no sewer!" while the whole world burns down with fireborne aids virus and you're hording needle chairs.

if there's one thing bitcoiners definitely never ever do and definitely don't have a long and hilarious history loving up it's floating point numbers representing currency

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



mrmcd posted:

Stolen from the bitcoin thread:



I don't know how to copy posts with quotes on mobile so go there and thank the original guy who dug up this hn post

don't use floating points for money.

rest is :wow: tho

e lol

Shifty Pony
Dec 28, 2004

Up ta somethin'


Powaqoatse posted:

don't use floating points for money.

rest is :wow: tho

e lol

pretty much my reaction as well. completely omitting the ability to use floats means someone had a moment of insight into the inevitability of some *coiner using them in a dumb way if they were present. it's like realizing that kids will be in the kitchen and taking away everything sharper than a silicone spatula.

or, given the shitshow of the rest of the language... someone hosed up in a way that for once turned out to be good.

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

Shifty Pony posted:

it's like realizing that kids will be in the kitchen and taking away everything sharper than a silicone spatula.

then telling them to peel a 10lb bag of potatoes

also the spatula is made of silly putty instead of silicone

surebet
Jan 10, 2013

avatar
specialist


any defcon streams expected this year? i'd love to watch a few talks, i hope i don't have to wait months for them to show up on youtube

Truga
May 4, 2014
Lipstick Apathy
https://twitter.com/EmiratesNBD/status/886863729547149312

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I smell lanmanager hashes

FlapYoJacks
Feb 12, 2009
It's a huge red flag to me when a website has a limit on maximum password length.

They should be hashed and salted correct? Then all of the entered passwords should be the same god drat length in your database.

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug
otoh something like a 1KB or 4KB password limit seems reasonable to keep people from posting 10GB data as their password and DoSing your systems with huge amounts of data to hash

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

ratbert90 posted:

It's a huge red flag to me when a website has a limit on maximum password length.

They should be hashed and salted correct? Then all of the entered passwords should be the same god drat length in your database.

Yes. There's basically no reason for it (aside from sanity​ checks like not accepting 25gb of data as a password) unless you hosed up real bad. I mean you could still be hashing and salting correctly and also limit length, but that 'best case scenario' just shows you have no idea what you're doing.

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

My last job, when I got there, stored passwords for a trading system, where people would login over the internet and do millions of dollars in transactions, as cleartext in a sql database. After I yelled at them for a year about how dumb and bad this was, they finally relented and changed it to... unsalted md5.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


i set a 20 character complex password for online banking and when i logged in it said "please enter characters 4, 10, 17" :suicide:

cinci zoo sniper
Mar 15, 2013




hackers can turn your segway into a bomb

spankmeister
Jun 15, 2008






So after some speculation it turns out Alphabay was indeed taken down by the feds.
A lot of users fled to Hansa market.

Which was under control of Dutch police during that time. And they disabled all encryption so they could read all messages and have a full dump of user data.




Very slick operation imo.

spankmeister
Jun 15, 2008






https://www.politie.nl/en/news/2017/july/20/underground-hansa-market-taken-over-and-shut-down.html

quote:

Nederland - As part of an extensive international investigation, the Netherlands Police and the Public Prosecution Service have dismantled, seized control of, and shut down one of the biggest illegal market places on the internet today. It is Hansa Market, currently the most popular dark market in the ‘anonymous’ part of the internet, the so-called darknet.

Workaday Wizard
Oct 23, 2009

by Pragmatica

spankmeister posted:

So after some speculation it turns out Alphabay was indeed taken down by the feds.
A lot of users fled to Hansa market.

Which was under control of Dutch police during that time. And they disabled all encryption so they could read all messages and have a full dump of user data.




Very slick operation imo.

:kiss:

Truga
May 4, 2014
Lipstick Apathy

spankmeister posted:

So after some speculation it turns out Alphabay was indeed taken down by the feds.
A lot of users fled to Hansa market.

Which was under control of Dutch police during that time. And they disabled all encryption so they could read all messages and have a full dump of user data.




Very slick operation imo.

nice!

Mr SuperAwesome
Apr 6, 2011

im from the bad post police, and i'm afraid i have bad news

Powerful Two-Hander posted:

i set a 20 character complex password for online banking and when i logged in it said "please enter characters 4, 10, 17" :suicide:

what's wrong with this? it stops you getting owned by keyloggers which is a legit threat (esp for your average joe)

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://twitter.com/zackwhittaker/status/888041129526079488

Pimp_Alex_91

ThePeavstenator
Dec 18, 2012

:burger::burger::burger::burger::burger:

Establish the Buns

:burger::burger::burger::burger::burger:

Mr SuperAwesome posted:

what's wrong with this? it stops you getting owned by keyloggers which is a legit threat (esp for your average joe)

the fact that they can check individual characters in your password means that they've stored the plaintext password

Mr SuperAwesome
Apr 6, 2011

im from the bad post police, and i'm afraid i have bad news
oh yeah welp

(well unless they precompute each possible 3-character combination of your password and hash + salt that individually but lol thats not likely at all)

Wiggly Wayne DDS
Sep 11, 2010



okay this gets better: https://blog.hboeck.de/archives/888-How-I-tricked-Symantec-with-a-Fake-Private-Key.html

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
https://twitter.com/abdilo__/status/888054760166703104

Diva Cupcake
Aug 15, 2005

dumb people run darknet markets because there's lots of money in it.



until you get caught and kill yourself.

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
the gently caress is alphabay?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Migishu posted:

the gently caress is alphabay?
it's an online marketplace for drugs, like silk road was

FCKGW
May 21, 2006

FCKGW
May 21, 2006

https://twitter.com/pwnallthethings/status/888060321365209088

Shifty Pony
Dec 28, 2004

Up ta somethin'


edit: dammit

slickest part imo:

https://twitter.com/pwnallthethings/status/888060321365209088

crash the server with the arresting swat team ready to go and then send them in when you see him log in to reboot it so you know his personal system isn't powered down and encrypted.

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

lmbo

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

cinci zoo sniper posted:

hackers can turn your segway into a bomb

Diva Cupcake
Aug 15, 2005

passwordsformyillegaldrugmarket.txt

cinci zoo sniper
Mar 15, 2013





https://www.ioactive.com/pdfs/IOActive-Security-Advisory-Ninebot-Segway-miniPRO_Final.pdf

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lol http://money.cnn.com/2017/07/19/technology/fish-tank-hack-darktrace/index.html

spankmeister
Jun 15, 2008






Here's the Krebs article on the whole Alphabay/ Hansa thing

https://krebsonsecurity.com/2017/07/after-alphabays-demise-customers-flocked-to-dark-market-run-by-dutch-police/

Adbot
ADBOT LOVES YOU

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
https://twitter.com/dyn___/status/888057949821784064

  • Locked thread