Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Carbon dioxide
Oct 9, 2012

Lutha Mahtin posted:

is this bubbling up in the blogs and twitters?? or do we have a case of yospos FIRST POST

I didn't spread it further because I am certain the yospos Actual Cecurity Experts (ACEs) will take care of it and march angrily to the twitters and grab some Mozilla devs by the neck until they fix it.

Adbot
ADBOT LOVES YOU

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Deep Dish Fuckfest posted:

heh, i remember that. although i think it was mysql, which is even more shameful

well yeah but regardless a database client should probably not have arbitrary code execution vulnerabilities regardless of if you trust the server (and if you're not using TLS with a cert infrastructure to encrypt your kink, regardless of if you trust the network)

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Look how else will I be able to dynamically patch my site at runtime? We can't have ANY downtime from bouncing the server, this is the most sure way to add content!!

maskenfreiheit
Dec 30, 2004

Carbon dioxide posted:

I didn't spread it further because I am certain the yospos Actual Cecurity Experts (ACEs) will take care of it and march angrily to the twitters and grab some Mozilla devs by the neck until they fix it.

I'm guessing there's more than a few Mozillians in YOSPOS.

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
IIRC there's one in the gray thread for Firefox

Shaggar
Apr 26, 2006

Subjunctive posted:

Linux distributors are the worst. install your browsers directly from the vendors

this but everything instead of just browsers

Shaggar
Apr 26, 2006

akadajet posted:

Always fun to see on the page of a library you're playing with.

https://node-postgres.com/announcements

edit: lol

web "developers"

Shame Boy
Mar 2, 2010

Shaggar posted:

this but everything instead of just browsers

except for the vendors that make you do that curl [url] | bash bullshit that's getting annoyingly common

akadajet
Sep 14, 2003

Shaggar posted:

web "developers"

because rce never happens for anything but web apps

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Shaggar posted:

this but everything instead of just browsers

i for one love garbage drivers from chinese firmware engineers that install directly to a new folder they create at C:\SHITCOR~ because its still 1991

wait, why am i responding to shaggar

ate all the Oreos posted:

except for the vendors that make you do that curl [url] | bash bullshit that's getting annoyingly common

for bonus points, point it an HTTPS URL but include the -k flag.

FAT32 SHAMER
Aug 16, 2012



Daman posted:

so we all know kaspersky is the best AV, but now they've really cemented the title.

new official marketing





smoka is going to be thrilled

Shaggar
Apr 26, 2006

akadajet posted:

because rce never happens for anything but web apps

its a feature of javascript that everything you do is code injection.


anatoliy pltkrvkay posted:

i for one love garbage drivers from chinese firmware engineers that install directly to a new folder they create at C:\SHITCOR~ because its still 1991

wait, why am i responding to shaggar


I'm talking about things like java or tomcat where the distro version will be broken out of the box or at the very least contain a bunch of added libs you don't want there.

nobody is installing Chinese drivers in a vm.

Shaggar fucked around with this message at 16:52 on Aug 14, 2017

FAT32 SHAMER
Aug 16, 2012



Carbon dioxide posted:

I didn't spread it further because I am certain the yospos Actual Cecurity Experts (ACEs) will take care of it and march angrily to the twitters and grab some Mozilla devs by the neck until they fix it.

doesnt subjective work for mozilla or is he with facebook, i forget

cinci zoo sniper
Mar 15, 2013




FAT32 SHAMER posted:

doesnt subjective work for mozilla or is he with facebook, i forget

subjunctive worked in facebook some time ago iirc

duTrieux.
Oct 9, 2003

Shaggar posted:

its a feature of javascript that everything you do is code injection.



lol

Wiggly Wayne DDS
Sep 11, 2010



so malwaretech update:
- plead not guilty
- the no internet access bail condition has been removed, now it's "don't touch that wannacry sinkhole" that's publicly known
- wisconsin is no longer relevant re: jurisdiction given he'll reside in LA and has CA lawyers now
- trial currently set in october, probably be moved back

Shame Boy
Mar 2, 2010

FAT32 SHAMER posted:

doesnt subjective work for mozilla or is he with facebook, i forget

he worked for Mozilla like a decade ago, then Facebook until recently

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

:wave:

Xenoveritas
May 9, 2010
Dinosaur Gum

fishmech posted:

still haven't seen any evidence that security updates are being "a/b tested" but rather just that 55 was too buggy and they're holding off until 55.0.2 is out (55.0.1 was already out)

It's less "A/B tested" and more they apparently do staged rollouts of all updates, regardless of content. And who knows if there's a 55.0.2 coming out, when I tried to find out why I was being told 54.0.1 was "up to date" by the updater despite Mozilla.org showing a huge banner saying "update your browser now!" I was told "we do staged rollouts of updates." The only reason I was even checking was because IT flagged my computer for having "vulnerable software" installed.

Dylan16807 posted:

if it's a critical security patch that got backported to 55 but not to 54, then they screwed up.

They're "critical" according to their own ranking system. Firefox 55 has a whole bunch of security updates including 5 they flagged critical and 11 marked as high. None of these were back-ported into Firefox 54, they're all listed as "fixed as of Firefox 55." It's hard to know any details beyond that because the bugs are still hidden and the CVE numbers aren't live yet. (So it's entirely possible some of the critical vulnerabilities don't even affect Firefox 54, but who knows, because they don't say. Doesn't seem likely, though.)

If they are holding back the update for a reason, then the website shouldn't be showing a huge "Update Now!" banner, and if they aren't holding it back, then the About dialog shouldn't be lying and saying you're "up to date!" when you aren't. Something is hosed up somewhere.

Dylan16807
May 12, 2010

Xenoveritas posted:

It's less "A/B tested" and more they apparently do staged rollouts of all updates, regardless of content. And who knows if there's a 55.0.2 coming out, when I tried to find out why I was being told 54.0.1 was "up to date" by the updater despite Mozilla.org showing a huge banner saying "update your browser now!" I was told "we do staged rollouts of updates." The only reason I was even checking was because IT flagged my computer for having "vulnerable software" installed.


They're "critical" according to their own ranking system. Firefox 55 has a whole bunch of security updates including 5 they flagged critical and 11 marked as high. None of these were back-ported into Firefox 54, they're all listed as "fixed as of Firefox 55." It's hard to know any details beyond that because the bugs are still hidden and the CVE numbers aren't live yet. (So it's entirely possible some of the critical vulnerabilities don't even affect Firefox 54, but who knows, because they don't say. Doesn't seem likely, though.)

If they are holding back the update for a reason, then the website shouldn't be showing a huge "Update Now!" banner, and if they aren't holding it back, then the About dialog shouldn't be lying and saying you're "up to date!" when you aren't. Something is hosed up somewhere.

yeah, sounds like the system is hosed up somewhere.

but if they decided it was appropriate to wait two months for the patch to get to the release channel, and only unhide the bug report once everyone has the fix, then a staged rollout is minor in comparison

especially when they removed an entire release channel recently, so even with the staged rollout patches get to all users faster

it's a fuckup, but not a security fuckup.

FCKGW
May 21, 2006

https://twitter.com/notdan/status/897094686506074113

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I was reading that anonymous hacked the site and turned off the registration anonymity thing and it wasn't anything GoDaddy actively did but maybe that was bullshit

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).


:bisonyes:

Doxx nazis all day everyday.

duTrieux.
Oct 9, 2003

BangersInMyKnickers posted:

I was reading that anonymous hacked the site and turned off the registration anonymity thing and it wasn't anything GoDaddy actively did but maybe that was bullshit

that was stormfront trying to save face with a false flag, i think

FCKGW
May 21, 2006

BangersInMyKnickers posted:

I was reading that anonymous hacked the site and turned off the registration anonymity thing and it wasn't anything GoDaddy actively did but maybe that was bullshit

they hosed up, the moved from godaddy to google domains and when you transfer the privacy protection gets disabled

and then your domain gets deleted anyways lol

https://twitter.com/MicahGrimes/status/897159294436683781

Diva Cupcake
Aug 15, 2005

mrmcd posted:

:bisonyes:

Doxx nazis all day everyday.
oh weev is involved. shocker.
https://twitter.com/LauraLoomer/status/897116115935133696

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BangersInMyKnickers posted:

I was reading that anonymous hacked the site and turned off the registration anonymity thing and it wasn't anything GoDaddy actively did but maybe that was bullshit
the "anonymous" "hack" was completely fabricated, they'd been told by godaddy that their site was getting shut down and wanted attention. see also: weev is involved

Phone
Jul 30, 2005

親子丼をほしい。
also don't trust anything laura loomer says, she's the moron with the dry rotted "slashed" tires from last month

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

Phone posted:

also don't trust anything laura loomer says, she's the moron with the dry rotted "slashed" tires from last month

what?

akadajet
Sep 14, 2003

https://twitter.com/thehill/status/897217289824722944

lol trump admin is asking dreamhost for records related to trump protest blogs

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
she posted a picture of an extremely old and rotten tire, like you'd find on a car at the dump, and posted on twitter that it had been slashed. it's dumb

flakeloaf
Feb 26, 2003

Still better than android clock

she also openly cheered the deaths of 2000 migrants with the hope that 2000 more might die

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
so weev, the dude who claimed that his nazi tatto was just trolling, turned out to be the admin behind the daily stormer? I'l shocked!

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ymgve posted:

so weev, the dude who claimed that his nazi tatto was just trolling, turned out to be the admin behind the daily stormer? I'l shocked!
that hasn't been a secret or anything

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


hahahaha ooooohboy you are in for a treat

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

BangersInMyKnickers posted:

hahahaha ooooohboy you are in for a treat

i saw ppl accusing a woman of not understanding tires and assumed the usual twitright misogyny but the real story is way funnier.

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

it wasn't that she didn't understand tires, it was that she expected that everyone else would believe she had her tires slashed so she could get internet nazi points

apseudonym
Feb 25, 2011

CommunistPancake posted:

it wasn't that she didn't understand tires, it was that she expected that everyone else would believe she had her tires slashed so she could get internet nazi points

No one would ever post lies for internet points

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
you really think someone would do that? just go on the internet and tell lies?

Adbot
ADBOT LOVES YOU

Mr SuperAwesome
Apr 6, 2011

im from the bad post police, and i'm afraid i have bad news


i'm the Deutsche Bahn security questions

  • Locked thread