Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Avenging_Mikon posted:

You don't put your actual password in those, you use something of the same length and characteristics.

yes, a password inspector. don't use your actual password (any of them, for anything), just one you might use.

cool, no problem, and definitely something a layperson worried about wizardsec would use in the manner in which its intended.

Adbot
ADBOT LOVES YOU

French Canadian
Feb 23, 2004

Fluffy cat sensory experience

Powaqoatse posted:

the nazi site has been cleaned up a bit since, but archive.org shows the type of poo poo they sell/sold:
https://web.archive.org/web/20160223051112/http://midgaardshop.com:80/kategori/vrigt/klistermarken

:raise:

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

infernal machines posted:

yes, a password inspector. don't use your actual password (any of them, for anything), just one you might use.

cool, no problem, and definitely something a layperson worried about wizardsec would use in the manner in which its intended.

I dunno, I found them useful to demonstrate to people the importance of complexity.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Avenging_Mikon posted:

I dunno, I found them useful to demonstrate to people the importance of complexity.

what kind of complexity? how does it work?

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang




basghetti is nice but ugh nazis

redleader
Aug 18, 2005

Engage according to operational parameters
pci dss gives fucks about exactly one thing: protecting cardholder data, and only cardholder data. you can store plaintext passwords on a sql server 2005 db with an asp.net 1.1 app running on windows server 2003 in tyool 20 loving 17 and as long as your cardholder data is 'adequately' protected you can get the big pci dss level one certificate

it is a total loving bullshit scam

incidentally, we're pci dss level one version three point oh certified

jre
Sep 2, 2011

To the cloud ?



redleader posted:

pci dss gives fucks about exactly one thing: protecting cardholder data, and only cardholder data. you can store plaintext passwords on a sql server 2005 db with an asp.net 1.1 app running on windows server 2003 in tyool 20 loving 17 and as long as your cardholder data is 'adequately' protected you can get the big pci dss level one certificate


:wrong:

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

Powaqoatse posted:

speaking of secfucks, someone hacked a nazi merch webstore and handed over their customer db to Swedish antifa

theve sent out letters saying "if you can explain why you bought nazi memorabilia, please write back so we can remove your name from the list that will be published in one week"

https://twitter.com/NiclasWestlake/status/898195585802620928

closet nazis are freaking the hell out :3:

Is there a translation of the letter somewhere?

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

infernal machines posted:

what kind of complexity? how does it work?

Short vs. Long, use of special characters, numbers, capitals. People are really dumb, and having something to show them to say "look, this simple change gives you way more protection without making your life more difficult" is useful. The thing just evaluates attack space and compares to brute force speed to get approximate time to crack.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
so a friend is having fun with sprint today

https://twitter.com/sprintcare/status/898800482663014400

https://twitter.com/sprintcare/status/898901472594636801

https://twitter.com/sprintcare/status/898912177523892224

https://twitter.com/sprintcare/status/898918538546565120

https://twitter.com/sprintcare/status/898895355609202689

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Avenging_Mikon posted:

Short vs. Long, use of special characters, numbers, capitals. People are really dumb, and having something to show them to say "look, this simple change gives you way more protection without making your life more difficult" is useful. The thing just evaluates attack space and compares to brute force speed to get approximate time to crack.

okay, so the issue is a "complex" password isn't necessarily a harder to crack password. assuming you're going for a human memorable password, you probably just want a long phrase rather than something that has a bunch of special characters in it. but also, if the thing just scores Name<birthyear> as complex* it's not very good either

*microsoft online services, i'm looking at you

My PIN is 4826
Aug 30, 2003

A Pinball Wizard posted:

Is there a translation of the letter somewhere?

dunno, but here's my liberal translation

quote:

Hello,

Your name has come to our attention because you have ordered products from the nazi website Midgård in the past. We would like to remind you that your identity is never fully protected when you are ordering nazi products over the internet. Nazi websites such as Midgård always assure their customers that their information is safe, but we always find out.

We have located all customers in in Skåne and Blekinge [two southern Swedish counties], and you are one of them. We therefore ask that you contact your local AFA branch to explain why you have ordered products from Midgård. We are planning to publish details of customers in Skåne and Blekinge,and if you don't want your details included - e.g. if you are not a nazi, or have left the nazi movement, we would like you to get in touch. Otherwise, you risk having your picture and personal information published on our website. If you do not contact us, we will assume you are a nazi and act accordingly. If we find you particularly interesting, we will contact your employer, neighbours and family directly.

Keep in mind that employers, landlords and others often Google for names, and we know from experience that our publications cause issues for nazis. When contacting us, please remember to provide a valid e-mail address, as we receive many e-mails. You can also visit our website https://www.antifa.se and use the contact form. Be prepared to answer some simple questions.

My PIN is 4826 fucked around with this message at 16:57 on Aug 19, 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

My PIN is 4826 posted:

dunno, but here's my liberal translation
owns

Midjack
Dec 24, 2007



maskenfreiheit
Dec 30, 2004

fun reverse of this story: Amex wouldn't let me create a username unless it had at least 2 #s.

gotta get dem high entropy... usernames? 🤔

tacked on my birth year like everyone else probably does 🎉

at least they let me create a complex password too

spankmeister
Jun 15, 2008






maskenfreiheit posted:

fun reverse of this story: Amex wouldn't let me create a username unless it had at least 2 #s.

gotta get dem high entropy... usernames? 🤔

tacked on my birth year like everyone else probably does 🎉

at least they let me create a complex password too

Put a 0 in front of it you might get root

duTrieux.
Oct 9, 2003

maskenfreiheit posted:

fun reverse of this story: Amex wouldn't let me create a username unless it had at least 2 #s.

gotta get dem high entropy... usernames? 🤔

tacked on my birth year like everyone else probably does 🎉

at least they let me create a complex password too

i think it's a good idea. compensates for idiot assholes who reuse username/password combos

duTrieux.
Oct 9, 2003

My PIN is 4826 posted:

dunno, but here's my liberal translation

nice, thanks!

Workaday Wizard
Oct 23, 2009

by Pragmatica

maskenfreiheit posted:

fun reverse of this story: Amex wouldn't let me create a username unless it had at least 2 #s.

gotta get dem high entropy... usernames? 🤔

tacked on my birth year like everyone else probably does 🎉

at least they let me create a complex password too

we actually got rid of predictable usernames at work because the brute force bots were getting way too good

ozymandOS
Jun 9, 2004

Shinku ABOOKEN posted:

we actually got rid of predictable usernames at work because the brute force bots were getting way too good

you should have added more entropy to the passwords rather than the usernames

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shinku ABOOKEN posted:

we actually got rid of predictable usernames at work because the brute force bots were getting way too good
lmao

akadajet
Sep 14, 2003

Shinku ABOOKEN posted:

we actually got rid of predictable usernames at work because the brute force bots were getting way too good

good job!

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

infernal machines posted:

okay, so the issue is a "complex" password isn't necessarily a harder to crack password. assuming you're going for a human memorable password, you probably just want a long phrase rather than something that has a bunch of special characters in it. but also, if the thing just scores Name<birthyear> as complex* it's not very good either

*microsoft online services, i'm looking at you

Yes, that's why I said short vs. Long. Showing someone a 20 character pass phrase is better than 8 with the gamut of characters. I'm not sure why you're so keen on making GBS threads on an educational tool.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
because a tool that says "check your password here" is a stupid tool*.

look at this website: http://www.speedypassword.com (http!!!)

do you think "Test your password below to check its strength and find out how secure it is!" suggests you should enter your actual password?

a site that offers to generate username and password pairs for you?

seriously?




*to be clear, i'm talking specifically about this password inspector website (you know, the one the tweet was about), password strength indicators in general can be useful assuming they're part of the service you're creating an account for, and properly weight things. telling someone to put their password into a random website probably isn't doing them any favours though

infernal machines fucked around with this message at 22:07 on Aug 19, 2017

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Shinku ABOOKEN posted:

we actually got rid of predictable usernames at work because the brute force bots were getting way too good

:thunk:

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

infernal machines posted:

*to be clear, i'm talking specifically about this password inspector website (you know, the one the tweet was about), password strength indicators in general can be useful assuming they're part of the service you're creating an account for, and properly weight things. telling someone to put their password into a random website probably isn't doing them any favours though

making a "password inspector" website that just displays "thanks for telling me your password, idiot" in giant letters once you press submit would probably be an effective way to teach people not to do that. hell, that might even be enough to cause them to change their now-compromised password

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

infernal machines posted:

because a tool that says "check your password here" is a stupid tool*.

look at this website: http://www.speedypassword.com (http!!!)

do you think "Test your password below to check its strength and find out how secure it is!" suggests you should enter your actual password?

a site that offers to generate username and password pairs for you?

seriously?




*to be clear, i'm talking specifically about this password inspector website (you know, the one the tweet was about), password strength indicators in general can be useful assuming they're part of the service you're creating an account for, and properly weight things. telling someone to put their password into a random website probably isn't doing them any favours though
there used to be a site at ismytwitterpasswordsecure.com and when you typed into the password field the screen turned red and called you a stupid idiot (but with nicer words)

Fergus Mac Roich
Nov 5, 2008

Soiled Meat
I think someone once posted here a sign up form that tried to log into your Twitter account with your given email and password and rejected your password if it was successful.

mdl
Jul 14, 2001

muhaha i did steal head server of Internet. If push "power" button the hole net will be shutdown. i hate all you Quake Playas!! !! !! uu!! And If i push r
tl;dr: mozilla wants to readd the Totally Not Eddy Nigg/Mossad SSL vendor to the trust rolls

https://bugzilla.mozilla.org/show_bug.cgi?id=1311832#c16

https://news.ycombinator.com/item?id=15055707 if the circlejerk ever shows it instead of a blank page, lol.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

quote:

> e.- StartCom has developed a new CMS system and website, using a new
> language, PHP, from scratch.

:discourse:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/zacaj_/status/898999055707234305

vOv
Feb 8, 2014

mdl posted:

tl;dr: mozilla wants to readd the Totally Not Eddy Nigg/Mossad SSL vendor to the trust rolls

https://bugzilla.mozilla.org/show_bug.cgi?id=1311832#c16

https://news.ycombinator.com/item?id=15055707 if the circlejerk ever shows it instead of a blank page, lol.

is that mozilla that wants to add it or is it some random gently caress

Wiggly Wayne DDS
Sep 11, 2010



i'm glad them changing management again erasing all past attempts to hide changes in management

mdl
Jul 14, 2001

muhaha i did steal head server of Internet. If push "power" button the hole net will be shutdown. i hate all you Quake Playas!! !! !! uu!! And If i push r

vOv posted:

is that mozilla that wants to add it or is it some random gently caress

our buddy iñigo works at startcom, but the original/first post in the thread is a mozilla employee stating that startcom are allowed to reapply.

also, you have to click my comments to show them now, because apparently warning the public that mozilla are imbeciles who will undermine the entire browser/CA security model is "advocacy" and therefore should not appear un-collapsed in bugzilla by default

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

vOv posted:

is that mozilla that wants to add it or is it some random gently caress

that's just someone commenting in it now that startcom has applied to be re-admitted. there's nobody from Mozilla commenting on the request.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

people are always allowed to reapply. doing otherwise would require tracking employment and private company ownership to avoid deemed reapplication. "are permitted to reapply" is boilerplate from Kathleen, not an invitation. see her other similar bugs.

(disclosure: I wrote a bunch of the CA policies, authorized removals, and was Kathleen's boss)

mdl
Jul 14, 2001

muhaha i did steal head server of Internet. If push "power" button the hole net will be shutdown. i hate all you Quake Playas!! !! !! uu!! And If i push r

Subjunctive posted:

that's just someone commenting in it now that startcom has applied to be re-admitted. there's nobody from Mozilla commenting on the request.

see the first post: https://bugzilla.mozilla.org/show_bug.cgi?id=1311832#c0

some credulous mozillan posted:

StartCom may apply for inclusion of new (replacement) root certificates[1] following Mozilla's normal root inclusion/change process[2] (minus waiting in the queue for the discussion), after they have completed all of the following action items, and shown that WoSign has no control (people or code) over StartCom.

edit: fix url

mdl fucked around with this message at 23:35 on Aug 19, 2017

mdl
Jul 14, 2001

muhaha i did steal head server of Internet. If push "power" button the hole net will be shutdown. i hate all you Quake Playas!! !! !! uu!! And If i push r

Subjunctive posted:

people are always allowed to reapply. doing otherwise would require tracking employment and private company ownership to avoid deemed reapplication. "are permitted to reapply" is boilerplate from Kathleen, not an invitation. see her other similar bugs.

if only there were databases that had this sort of information, or if any industry had the capacity to do it, such as the "information" "security" industry, which already does it. apparently this is too hard for the multi-national browser vendors

Subjunctive posted:

(disclosure: I wrote a bunch of the CA policies, authorized removals, and was Kathleen's boss)

i'm glad you're saying this in past tense. i hope it means you aren't still employed in this capacity

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

mdl posted:

if only there were databases that had this sort of information, or if any industry had the capacity to do it, such as the "information" "security" industry, which already does it. apparently this is too hard for the multi-national browser vendors

I don't know of any database of private company employees, but I'm happy to be educated.

Adbot
ADBOT LOVES YOU

mdl
Jul 14, 2001

muhaha i did steal head server of Internet. If push "power" button the hole net will be shutdown. i hate all you Quake Playas!! !! !! uu!! And If i push r

Subjunctive posted:

I don't know of any database of private company employees, but I'm happy to be educated.

have you honestly never received a background check? i'm not even talking about getting a security clearance; i mean the sort that companies often do on prospective employees.

surely the browser/ca forum is capable of vetting CAs, which, i would like to point out, account for far fewer heads total than a single CA has customers.

mdl fucked around with this message at 23:45 on Aug 19, 2017

  • Locked thread