Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Shaggar
Apr 26, 2006

lol that owns

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

is there any VPN provider that's not secretly horrible

like I don't mean "suggest me which vpn provider you like!!!" I mean are any of them capable of actually proving they're not horrible in some meaningful way

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

ate all the Oreos posted:

is there any VPN provider that's not secretly horrible

like I don't mean "suggest me which vpn provider you like!!!" I mean are any of them capable of actually proving they're not horrible in some meaningful way

they're all differently horrible and personal VPNs are just a race to the bottom when they're not self hosted nerd poo poo

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ate all the Oreos posted:

is there any VPN provider that's not secretly horrible

like I don't mean "suggest me which vpn provider you like!!!" I mean are any of them capable of actually proving they're not horrible in some meaningful way
algo, which you set up yourself, on a vps you trust

post hole digger
Mar 21, 2011

anthonypants posted:

algo, which you set up yourself, on a vps you trust

Shame Boy
Mar 2, 2010

anthonypants posted:

algo, which you set up yourself, on a vps you trust

ok sure, but that just kicks the can down the road to "which VPS do I trust"

post hole digger
Mar 21, 2011

ate all the Oreos posted:

ok sure, but that just kicks the can down the road to "which VPS do I trust"

id say standard vps options most people would be considering (aws, digitalocean, etc) are more reputable than any vpn option.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

ate all the Oreos posted:

ok sure, but that just kicks the can down the road to "which VPS do I trust"

yeah and you have to either do some threat modeling or just be a small mostly un-sketchy fish on AWS light sail or digital ocean or something

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Cocoa Crispies posted:

yeah and you have to either do some threat modeling or just be a small mostly un-sketchy fish on AWS light sail or digital ocean or something
pretty much

Carbon dioxide
Oct 9, 2012

According to the logs at work someone tried to "hack" the company website by setting a randomly generated id stored in a cookie to "file///etc/passwd".

I can't even think of any setup in which that would actually do anything. What the hell.

Shame Boy
Mar 2, 2010

Carbon dioxide posted:

According to the logs at work someone tried to "hack" the company website by setting a randomly generated id stored in a cookie to "file///etc/passwd".

I can't even think of any setup in which that would actually do anything. What the hell.

i love looking at the things bots try, it's always some bizarre poo poo like that that makes me think "wait did that actually work on some server at some point what the gently caress"

e: well not always, most of the time it's boring poo poo, but whatever i don't remember those so it's always to me dammit

Shame Boy fucked around with this message at 18:23 on Aug 11, 2017

Diva Cupcake
Aug 15, 2005

probably just someone loving around manually with BurpSuite?

maskenfreiheit
Dec 30, 2004

ate all the Oreos posted:

is there any VPN provider that's not secretly horrible

like I don't mean "suggest me which vpn provider you like!!!" I mean are any of them capable of actually proving they're not horrible in some meaningful way

i rolled my own algo server and host it on digital ocean... i'm guessing that's reasonably private?

edit: or you can go full wikileaks and just do everything on tor

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

the Onavo stuff was always bullshit. didn't even proxy correctly, so they kept breaking on the actual FB apps

Wiggly Wayne DDS
Sep 11, 2010



the transcript for malwaretech's august 4th proceeding is up: https://www.documentcloud.org/documents/3923335-USA-v-Marcus-Hutchins-August-4-2017-Hearing.html

there's a bunch of absurd parts in there, but crucially the prosecution's claiming there's another co-defendant at large conveniently excusing why kronos is still getting updates

also the tale has now evolved to sold software that later became the malware

post hole digger
Mar 21, 2011

Wiggly Wayne DDS posted:

also the tale has now evolved to sold software that later became the malware

imagine the manufacturer of a physical weapon being punished for the same...

ThePeavstenator
Dec 18, 2012

:burger::burger::burger::burger::burger:

Establish the Buns

:burger::burger::burger::burger::burger:

Wiggly Wayne DDS posted:

the transcript for malwaretech's august 4th proceeding is up: https://www.documentcloud.org/documents/3923335-USA-v-Marcus-Hutchins-August-4-2017-Hearing.html

there's a bunch of absurd parts in there, but crucially the prosecution's claiming there's another co-defendant at large conveniently excusing why kronos is still getting updates

also the tale has now evolved to sold software that later became the malware

I could've walked to the courthouse he had an appearance in on Tuesday morning. If he's got any more dates coming up I might try to go and see it.

Wiggly Wayne DDS
Sep 11, 2010



ThePeavstenator posted:

I could've walked to the courthouse he had an appearance in on Tuesday morning. If he's got any more dates coming up I might try to go and see it.
if you're free monday and there's room:

http://www.wied.uscourts.gov/court-hearings-calendar posted:

08/14/2017
10:00AM
Magistrate Judge Duffin
2017-cr-124-2: USA v. Hutchins
Courtroom 242, 517 E Wisconsin Ave., Milwaukee, WI 53202
Arraignment
might get a plea at that stage

ThePeavstenator
Dec 18, 2012

:burger::burger::burger::burger::burger:

Establish the Buns

:burger::burger::burger::burger::burger:

Wiggly Wayne DDS posted:

if you're free monday and there's room:

might get a plea at that stage

Nah I'm not gonna take off work for it until the more juicy parts happen if they even happen.

power botton
Nov 2, 2011

is it gonna go full Aaron whats his gently caress and kill heself or will he rise like a 700 pound phoenix Kim Dotcom style

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

my bitter bi rival posted:

imagine the manufacturer of a physical weapon being punished for the same...

Sounds like they're loving with him and want something.

hobbesmaster
Jan 28, 2008

Wiggly Wayne DDS posted:

the transcript for malwaretech's august 4th proceeding is up: https://www.documentcloud.org/documents/3923335-USA-v-Marcus-Hutchins-August-4-2017-Hearing.html

there's a bunch of absurd parts in there, but crucially the prosecution's claiming there's another co-defendant at large conveniently excusing why kronos is still getting updates

also the tale has now evolved to sold software that later became the malware

it's apparently illegal for an alien on a non immigrant visa to take possession of a firearm?

that explains the prosecutions strange obsession with pointing out he fired a gun but :wtc:

FAT32 SHAMER
Aug 16, 2012



hobbesmaster posted:

it's apparently illegal for an alien on a non immigrant visa to take possession of a firearm?

that explains the prosecutions strange obsession with pointing out he fired a gun but :wtc:

this is probably one of the first times in history that has been applied against a white man lmao

Midjack
Dec 24, 2007



hobbesmaster posted:

it's apparently illegal for an alien on a non immigrant visa to take possession of a firearm?

that explains the prosecutions strange obsession with pointing out he fired a gun but :wtc:

bet those rental ranges in vegas are worried

hobbesmaster
Jan 28, 2008

FAT32 SHAMER posted:

this is probably one of the first times in history that has been applied against a white man lmao

well at least the judge agreed with the defense that it doesn't matter since there were ads in the airport for it and he showed his real passport

Wild EEPROM
Jul 29, 2011


oh, my, god. Becky, look at her bitrate.

Bulgakov
Mar 8, 2009


рукописи не горят


hes no feynman

ate shit on live tv
Feb 15, 2004

by Azathoth

FAT32 SHAMER posted:

this is probably one of the first times in history that has been applied against a white man lmao

Nah, before the 1960's firearms law applied to all political dissidents, not just white dudes. It wasn't until the Dems got scared of black people with guns that gun-control got racist.

fritz
Jul 26, 2003

ate poo poo on live tv posted:

Nah, before the 1960's firearms law applied to all political dissidents, not just white dudes. It wasn't until the Dems got scared of black people with guns that gun-control got racist.

noted democrat ronald reagan

Pile Of Garbage
May 28, 2007



stoopidmunkey posted:

Sec fuckup I just became privy to: Our ticket tracking software has an asset management component. The vendor requires a service account that can ssh into a server and needs sudo access. All their tools it runs can get the same data over snmp, but they want ssh access (hard-coded password) and sudo. They say it's safe if you restrict the account in /etc/sudoers

Service Now is garbage.

is that a requirement from the vendor or from servicenow? we use servicenow and it seems p good compared to other ticketing software on the front-end at least.

however now that i think on it there are some extremely janky bits on the back-end. we need to pull user satisfaction survey results in bulk for monthly reporting and the only way they could do that is with the special snow ODBC driver which is so garbage that the server it is installed on has to be rebooted daily because it just completely dies in the rear end after X number of hours.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


stoopidmunkey posted:

Sec fuckup I just became privy to: Our ticket tracking software has an asset management component. The vendor requires a service account that can ssh into a server and needs sudo access. All their tools it runs can get the same data over snmp, but they want ssh access (hard-coded password) and sudo. They say it's safe if you restrict the account in /etc/sudoers

Service Now is garbage.

this might explain why our enormous service now instance doesn't do asset management despite it being sold as a service catalog management platform!

i proudly never close or update any ticket assigned to me because it's a waste of time and does nothing but produce meaningless metrics.

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://www.bleepingcomputer.com/news/hardware/botched-firmware-update-bricks-hundreds-of-smart-door-locks/

quote:

On Tuesday, August 8, smart locks manufacturer LockState botched an over-the-air firmware update for its WiFi enabled smart locks, causing the devices to lose connectivity to the vendor's servers and the ability to open doors for its users.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Don't stop I'm so close

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.



loving vendor lock in

stallman was right

coffeetable
Feb 5, 2006

TELL ME AGAIN HOW GREAT BRITAIN WOULD BE IF IT WAS RULED BY THE MERCILESS JACKBOOT OF PRINCE CHARLES

YES I DO TALK TO PLANTS ACTUALLY

Powerful Two-Hander posted:

Security Fuckup Megathread - v14.0 - vendor lock in

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

coffeetable posted:

Security Fuckup Megathread - v14.0 - vendor lock out
:cmon:

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Powerful Two-Hander posted:

loving vendor lock in

stallman was right

1987: what is that stallman guy going on about, it's not like a computer company is going to ever control some actual important part of my life

2017: *family burns to death inside of their malfunctioning smart house*

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


yep

Xenoveritas
May 9, 2010
Dinosaur Gum
So it turns out that Firefox has decided that they want to do "staged rollouts" of their updates, slowly letting more and more people access them over several weeks.

Problem: this includes security updates.

Firefox won't let me install Firefox 55 despite the fact that it fixes 5 critical security flaws. You can't force the update. You can't just install the latest version since it's already installed and they use a "stub installer" that downloads the rest. Your only option is to uninstall the entire thing and install from scratch, just to get security updates.

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

what

  • Locked thread