Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

stalking my friends eh? :P

Adbot
ADBOT LOVES YOU

Shaggar
Apr 26, 2006

Trabisnikof posted:

pretty great timeline considering game devs

2017-07-21: I revisited the issue and found an exploit vector, issue reported.
14 hours later: I’m informed the issue has been patched and the patch will be included in the next release.
2017-07-25: Patch released, I confirmed the vulnerability has been fixed. The

the factorio devs are constantly working on it and posting updates about changes and stuff. its pretty cool.

FCKGW
May 21, 2006

https://twitter.com/mikko/status/890369297863909378

(co-founder of BTC-e exchange was arrested for money laundering today)

Carbon dioxide
Oct 9, 2012

vOv posted:

yeah their dev blog makes them seem like some of the most competent game devs ever, especially consider that it started off like a $20k kickstarter

So they're better than the binding of isaac devs.

https://twitter.com/tyronerodriguez/status/667441957644468230

crazysim
May 23, 2004
I AM SOOOOO GAY
the lead Factorio dev has a background from making enterprise .NET software.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
the binding of isaac devs couldn't be bothered to include controller support in the original pc port for years, and told people to use joy2key instead

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
there's a windows bug bounty program now https://blogs.technet.microsoft.com/msrc/2017/07/26/announcing-the-windows-bounty-program/

Workaday Wizard
Oct 23, 2009

by Pragmatica

anthonypants posted:

the binding of isaac devs couldn't be bothered to include controller support in the original pc port for years, and told people to use joy2key instead

iirc flash didnt support it

pseudorandom name
May 6, 2007

iirc Flash crashed half the time when they tried to open the Binding of Isaac project because it was so big

spankmeister
Jun 15, 2008






https://twitter.com/BleepinComputer/status/890459256360767489

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



nice opsec lol

cinci zoo sniper
Mar 15, 2013




lmao

Maximum Leader
Dec 5, 2014

FCKGW posted:

https://twitter.com/mikko/status/890369297863909378

(co-founder of BTC-e exchange was arrested for money laundering today)

this is great news for me because for some reason I decided to keep my fraction of a bitcoin on this sketchy Russian piece of poo poo site which seems to be closed now

Shifty Pony
Dec 28, 2004

Up ta somethin'



burying the lede:

quote:

The second method of operation spotted by the Dark Web community involves so-called "locktime" files that were downloaded from the Hansa Market before Dutch authorities shut it down on July 20.

Under normal circumstances a locktime file is a simple log of a vendor's market transaction, containing details about the sold product, the buyer, the time of the sale, the price, and Hansa's signature. The files are used as authentication by vendors to request the release of Bitcoin funds after a sale's conclusion, or if the market was down due to technical reasons.

According to people familiar with Hansa's inner workings who shared their knowledge with Bleeping Computer, Hansa locktime files were usually just a simple text file.

Before the market went down, these locktime files were replaced with Excel files that contained a hidden image. When the vendor opened the file to view transaction details, the image would load on the vendor's computer.

This image was hosted on the Hansa Market, and once loaded, the server would log the user's IP address. If the user didn't use a VPN, proxy, or funneled all OS-level traffic through Tor, the Hansa server would log his real IP address.

Even if the Hansa Market went down, some vendors might still have the files laying around their computers. After Hansa went down, vendors most certainly opened the files looking into ways to retrieve any funds still locked in Hansa's accounts.

I wonder if the image URL was unique so they could tie IP addresses to usernames.

yoloer420
May 19, 2006

Maximum Leader posted:

this is great news for me because for some reason I decided to keep my fraction of a bitcoin on this sketchy Russian piece of poo poo site which seems to be closed now

Suck it.

.... I left my "pocket change" in gox. 7btc, my gox coins would have been worth a lot now.

Mr SuperAwesome
Apr 6, 2011

im from the bad post police, and i'm afraid i have bad news

Shifty Pony posted:

burying the lede:


I wonder if the image URL was unique so they could tie IP addresses to usernames.

lomarf, owned

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

https://blogs.windows.com/windowsex...zIgTr7LgxF1Y.97

Since I am sure its been posted before, Microsoft is EOLing EMET next year. They plan on building the features in to the OS with the Application Guard toolkit as part of Defender which is good, having to inject the emet.dll in to each process you want to configure was necessary but sketchy and I'm glad they have something native now. Manageability is a bit of a clusterfuck where SEHOP options seem to be controlled by some bullshit bitmask value you define through a GPO, and if you manage SEHOP through GPO then you also have to do DEP there or it will override App Guard. I'm going off what I can see on the preview screenshots and the documentation and it looks like they're missing stuff that should be managed centrally through AppGuard same as it was in EMET. A number of the process-based mitigations are now gone and replaced by an opt-in only control flow guard mitigation which is loving stupid considering this is a company that prides itself on maintaining backwards compatibility for legacy software. Good luck getting devs to compile with the right flags for once, Microsoft. gently caress you your poo poo is garbage.

Shame Boy
Mar 2, 2010

yoloer420 posted:

Suck it.

.... I left my "pocket change" in gox. 7btc, my gox coins would have been worth a lot now.

don't worry you would have lost them a different way long before now

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

yeah, that's how I console myself about the ones I mined back when people did it on CPUs

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BangersInMyKnickers posted:

https://blogs.windows.com/windowsex...zIgTr7LgxF1Y.97

Since I am sure its been posted before, Microsoft is EOLing EMET next year. They plan on building the features in to the OS with the Application Guard toolkit as part of Defender which is good, having to inject the emet.dll in to each process you want to configure was necessary but sketchy and I'm glad they have something native now. Manageability is a bit of a clusterfuck where SEHOP options seem to be controlled by some bullshit bitmask value you define through a GPO, and if you manage SEHOP through GPO then you also have to do DEP there or it will override App Guard. I'm going off what I can see on the preview screenshots and the documentation and it looks like they're missing stuff that should be managed centrally through AppGuard same as it was in EMET. A number of the process-based mitigations are now gone and replaced by an opt-in only control flow guard mitigation which is loving stupid considering this is a company that prides itself on maintaining backwards compatibility for legacy software. Good luck getting devs to compile with the right flags for once, Microsoft. gently caress you your poo poo is garbage.
Please avoid doing a PC reset via Settings > Update & security > Recovery and choosing “Remove everything”. This may put your device into a reboot loop.

cinci zoo sniper
Mar 15, 2013




https://www.youtube.com/watch?v=ANllOmgJH9Y

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/kaepora/status/890640307729047552

glass houses, etc

fivehead
Jul 11, 2017

Americans Need Cash Now
NYTimes: Wells Fargo Accidentally Releases Trove of Data on Wealthy Clients

quote:

When a lawyer for Gary Sinderbrand, a former Wells Fargo employee, subpoenaed the bank as part of a defamation lawsuit against a bank employee, he and Mr. Sinderbrand expected to receive a selection of emails and documents related to the case. But what landed in Mr. Sinderbrand’s hands on July 8 went far beyond what his lawyer had asked for: Wells Fargo had turned over — by accident, according to the bank’s lawyer — a vast trove of confidential information about tens of thousands of the bank’s wealthiest clients. The 1.4 gigabytes of files that Wells Fargo’s lawyer sent included copious spreadsheets with customers’ names and Social Security numbers, paired with financial details like the size of their investment portfolios and the fees the bank charged them. Most are customers of Wells Fargo Advisors, the arm of the bank that caters to high-net-worth investors. By Mr. Sinderbrand’s estimate, he has financial information for at least 50,000 individual customers.

They will probably face no consequence and probably cant quantify the loss internally

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


lmao they probably have to pay by the mb for that to be processed as well

Shaggar
Apr 26, 2006

fivehead posted:

NYTimes: Wells Fargo Accidentally Releases Trove of Data on Wealthy Clients


They will probably face no consequence and probably cant quantify the loss internally

lol. how is it even possible to get that information out of their system?

James Baud
May 24, 2015

by LITERALLY AN ADMIN

Shaggar posted:

lol. how is it even possible to get that information out of their system?

Indiscriminate digital copy of emails in whatever time period in response to discovery request, attachments intact.

Shaggar
Apr 26, 2006
yuck

duTrieux.
Oct 9, 2003


this is going to keep happening until companies of all type face financial and legal penalties for hilariously bad security

post hole digger
Mar 21, 2011

duTrieux. posted:

this is going to keep happening until companies of all type face financial and legal penalties for hilariously bad security

yea i think it will keep happening forever too

Mr SuperAwesome
Apr 6, 2011

im from the bad post police, and i'm afraid i have bad news
guns are p dumb

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


James Baud posted:

Indiscriminate digital copy of emails in whatever time period in response to discovery request, attachments intact.

welcome to working with law firms, hence:

Powerful Two-Hander posted:

lmao they probably have to pay by the mb for that to be processed as well



one of our legal team asked me today if i knew who could help him burn all his personal emails to a disc as he was leaving the company, i said "uhhhh no way am i touching that, but maybe go talk to that guy over there"

probably should have reported him to info security to see them try to out legal a lawyer

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

my email was subpoenaed by Microsoft once and I greatly enjoyed the idea of someone being paid by the hour to sift through my complaints about cafeteria food and weekend movie plans

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


there is an EU law coming in called GDPR that includes right to be forgotten and stuff and it is going to gently caress. poo poo. up. because good luck finding which of your 100 old rear end hosed up document stores with 800Pb of data has my personal information in it when i vindictively pull that on you when i leave.


edit: gently caress this just reminded me that legal used to .pst peoples entire mailboxes and dump them on a shared drive when they left lol

fishmech
Jul 16, 2006

by VideoGames
Salad Prong
lol right to be forgotten more like incentive to have people spitefully rehost everything possible

Shaggar
Apr 26, 2006

Powerful Two-Hander posted:

there is an EU law coming in called GDPR that includes right to be forgotten and stuff and it is going to gently caress. poo poo. up. because good luck finding which of your 100 old rear end hosed up document stores with 800Pb of data has my personal information in it when i vindictively pull that on you when i leave.


edit: gently caress this just reminded me that legal used to .pst peoples entire mailboxes and dump them on a shared drive when they left lol

"Our acceptable use policy does not allow for personal use of company resources, therefore any content related to you in our system is company property. "

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

Shaggar posted:

"Our acceptable use policy does not allow for personal use of company resources, therefore any content related to you in our system is company property. "

"Your company property is not allowed to reference me. Please provide me with proof you've removed my contact information from all your systems."

cinci zoo sniper
Mar 15, 2013




Shaggar posted:

"Our acceptable use policy does not allow for personal use of company resources, therefore any content related to you in our system is company property. "
*in european comission voice* that'll be just a few billions for time being, sir

thebigcow
Jan 3, 2001

Bully!
How would that work with things like payroll records where I have to keep them for years?

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


thebigcow posted:

How would that work with things like payroll records where I have to keep them for years?

nobody knows!

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




thebigcow posted:

How would that work with things like payroll records where I have to keep them for years?
it wouldn't, because it's not "delete all data, ever", it's "render publicly available irrelevant information inaccessible to 3rd parties"

  • Locked thread