Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
cinci zoo sniper
Mar 15, 2013




endlessmonotony posted:

Finnish Nordea banking went heavily the same direction and that's about the point I closed down my account.

:rip:

Adbot
ADBOT LOVES YOU

endlessmonotony
Nov 4, 2009

by Fritz the Horse

They went to an app login from paper one-time pads.

Me: "The same device is used for the login password and the actual online banking and it's any given smartphone?"
Clerk: "We have a very competent team and we've been assured this is perfectly secure."
Me: "I am closing my account this very instant."

Related: They rolled that update out shortly after a court ruled that a person was responsible for actions taken on their accounts even if their login info was stolen. Including, and explicitly mentioned, were loans.

I just went "nope not trusting these fucks with my money anymore".

cinci zoo sniper
Mar 15, 2013




endlessmonotony posted:

They went to an app login from paper one-time pads.

Me: "The same device is used for the login password and the actual online banking and it's any given smartphone?"
Clerk: "We have a very competent team and we've been assured this is perfectly secure."
Me: "I am closing my account this very instant."

Related: They rolled that update out shortly after a court ruled that a person was responsible for actions taken on their accounts even if their login info was stolen. Including, and explicitly mentioned, were loans.

I just went "nope not trusting these fucks with my money anymore".

haha drat, that is hosed up

Jewel
May 2, 2009

what the fuuuuck, this owns :vince:

https://twitter.com/Foone/status/910217984098017281

Wiggly Wayne DDS
Sep 11, 2010



yeah i'm not too fond of their auto-connect to skimmer and send it commands approach though. 1234 and id should be enough, sending p is overkill

Proteus Jones
Feb 28, 2013




Wow

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

endlessmonotony posted:


Related: They rolled that update out shortly after a court ruled that a person was responsible for actions taken on their accounts even if their login info was stolen. Including, and explicitly mentioned, were loans.

wtf

flakeloaf
Feb 26, 2003

Still better than android clock

Wiggly Wayne DDS posted:

yeah i'm not too fond of their auto-connect to skimmer and send it commands approach though. 1234 and id should be enough, sending p is overkill

i'm cool with the idea of remotely bricking it in theory

in practice, the moment i do that will be the moment two-crowbars-craig shows up to check on his toy

Jewel
May 2, 2009

flakeloaf posted:

i'm cool with the idea of remotely bricking it in theory

in practice, the moment i do that will be the moment two-crowbars-craig shows up to check on his toy

lol if you think most of the people using these skimmers knows anything about how they work or maybe even what bricking is in the first place though. that's why the ID/pass is unchanged

Truga
May 4, 2014
Lipstick Apathy
https://twitter.com/0x0zone/status/910118042868252672

lol

30 TO 50 FERAL HOG
Mar 2, 2005




quote:


a frame of 134 bits could be transmitted in about three
a half hours (overnight) with a bit rate of 40 bits per
hour (bph)

lol

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

If you're trying to exfiltrate a private key or some other credential then that is enough, though I bet there are much better ways of doing it and this is more theoretical wanking

Shame Boy
Mar 2, 2010

BangersInMyKnickers posted:

If you're trying to exfiltrate a private key or some other credential then that is enough, though I bet there are much better ways of doing it and this is more theoretical wanking

it's one-way though, you can only send from the A/C to the computer not the other way

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Plenty of air gapped systems sit in direct proximity of others on standard corporate lans and the supporting infrastructure for things like HVAC end up on the air gapped network because of security concerns. The point is the medium, not the details of their specific PoC

M_Gargantua
Oct 16, 2006

STOMP'N ON INTO THE POWERLINES

Exciting Lemon

emoji posted:

The ad issues thread in QCS is funny because the ads on this site are literal malware and yet people keep reporting the ads to 'help' some malicious ad network and some ad guy sometimes responds (this has been going on for years) instead of blocking the ads like a sane person.

my solution has always been to have javascript disabled by default until an allowance is added. only breaks some sites where they try to forward your browser through like four intermediary sites for cred certification or form submission.

so i randomly get redirected from sa to the first landing pad for a malicious ad redirect and am left with a white screen and an alert while it cant forward me onward, and drop that link in the thread, because i have no idea what ad it actually came from.

Shame Boy
Mar 2, 2010

BangersInMyKnickers posted:

Plenty of air gapped systems sit in direct proximity of others on standard corporate lans and the supporting infrastructure for things like HVAC end up on the air gapped network because of security concerns. The point is the medium, not the details of their specific PoC

i mean the actual paper goes into detail on other, earlier tests that used computers generating heat to talk bidirectionally so i think this paper is actually pretty much just the details of the specific PoC

i get what you're saying though

M_Gargantua
Oct 16, 2006

STOMP'N ON INTO THE POWERLINES

Exciting Lemon

ate all the Oreos posted:

i mean the actual paper goes into detail on other, earlier tests that used computers generating heat to talk bidirectionally so i think this paper is actually pretty much just the details of the specific PoC

i get what you're saying though

was there one floating around about modulating data exfiltration into cpu fan ramp up/ramp down sound?

Diva Cupcake
Aug 15, 2005

it just keeps getting better
https://twitter.com/Equifax/status/910265181976104960
https://twitter.com/thesquashSH/status/910512164938665984

cinci zoo sniper
Mar 15, 2013





ahahahahahhahaha

fins
May 31, 2011

Floss Finder

M_Gargantua posted:

was there one floating around about modulating data exfiltration into cpu fan ramp up/ramp down sound?

Yep, that was fansmitter from Mordechai Guri et al

For a reasonable comprehensive list of their hijinks look here:

https://arxiv.org/find/cs/1/au:+Guri_M/0/1/0/all/0/1

fins fucked around with this message at 16:59 on Sep 20, 2017

Jewel
May 2, 2009

I absolutely can not believe that equifax thing, holy poo poo. its been up for 24 hours too, noooo. what a nightmare

also, just saw this tweeted and lol

https://gitlab.com/gnachman/iterm2/issues/6050

cinci zoo sniper
Mar 15, 2013




Jewel posted:

I absolutely can not believe that equifax thing, holy poo poo. its been up for 24 hours too, noooo. what a nightmare

also, just saw this tweeted and lol

https://gitlab.com/gnachman/iterm2/issues/6050



Security Fuckup Megathread - v14.0b - iTerm should have not done that

Shame Boy
Mar 2, 2010

Jewel posted:

I absolutely can not believe that equifax thing, holy poo poo. its been up for 24 hours too, noooo. what a nightmare

also, just saw this tweeted and lol

https://gitlab.com/gnachman/iterm2/issues/6050



most people in the comments agree that should be removed except

quote:

DNS lookups was a feature to check whether a URL was valid before highlighting it. If you're going to send someone out of iTerm its reasonable to check that their destination will be there instead of a nice 404.

Its a feature which you may not desire for your infosec/opsec purposes, but I don't see how its broken or almost CVE worthy.

we only wanted to make sure your dns failure doesn't land you a nice 404

e: same guy

quote:

Browsers do prefetches of urls too. zomg. I'm in the minority about the severity here, but the outrage is unjustified imo.

I'm glad Philip raised the request to have it disabled by default, but the lack of personable responsibility here is what chaffs me.

lol gently caress this guy

Jewel
May 2, 2009

ate all the Oreos posted:

most people in the comments agree that should be removed except

we only wanted to make sure your dns failure doesn't land you a nice 404

you didnt show the funniest part of that message, the reaction badges

Workaday Wizard
Oct 23, 2009

by Pragmatica

this why you use subdomains. not to mention they are cheaper too.

Schadenboner
Aug 15, 2011

by Shine

cinci zoo sniper posted:

Security Fuckup Megathread - v14.0b - iTerm should have not done that

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
how is that tweet still live

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
my bank is about to roll out an improved internet banking platform. among the security improvements, I can choose to irrevocably disable my current otp key and rely on one time codes sent by sms instead

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Perplx posted:

how is that tweet still live
i'll give you three guesses

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Jewel posted:

I absolutely can not believe that equifax thing, holy poo poo. its been up for 24 hours too, noooo. what a nightmare

are they still making other tweets? it would be loving hilarious if "Tim" got fired, then Equifax realized nobody else has the Twitter password, and "Tim" isn't answering his phone for some mysterious reason

Diva Cupcake
Aug 15, 2005

the best part is that the phishing link was posted in the same thread where the legit link was.

Wiggly Wayne DDS
Sep 11, 2010



and they've been posting it since september 9th:

https://twitter.com/MadcapOcelot/status/910533555494760449

Shame Boy
Mar 2, 2010

how do they not just have their customer service support system set up to send canned approved responses when they press a button like every other one on the planet

hobbesmaster
Jan 28, 2008

[quote="“ate all the Oreos”" post="“476587095”"]
how do they not just have their customer service support system set up to send canned approved responses when they press a button like every other one on the planet
[/quote]

for the same reason they gave away everyone’s PII?

Dodoman
Feb 26, 2009



A moment of laxity
A lifetime of regret
Lipstick Apathy
apologies for interrupting the equifax chat but i have a dumb question to ask - am i in any danger if i use a bandwidth monitor like networx to track my usage?

cinci zoo sniper
Mar 15, 2013




Dodoman posted:

apologies for interrupting the equifax chat but i have a dumb question to ask - am i in any danger if i use a bandwidth monitor like networx to track my usage?

i mean, why would you? worried they sell your data?

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

rip that tweet (finally)

Shame Boy
Mar 2, 2010

hobbesmaster posted:

for the same reason they gave away everyone’s PII?

i mean "lovely security" seems like the kind of thing you can brush under the rug for not really costing money until something bad happens, not having automated / streamlined customer support strikes me as the kind of thing some middle-manager MBA would have optimized away to save 5% on labor costs years ago :shrug:

Shame Boy
Mar 2, 2010

Dodoman posted:

apologies for interrupting the equifax chat but i have a dumb question to ask - am i in any danger if i use a bandwidth monitor like networx to track my usage?

like for a single PC? there's better tools out there that are at the very least open sores and used more than that thing, though idk what OS you're talking about

Adbot
ADBOT LOVES YOU

hobbesmaster
Jan 28, 2008

equifax isn’t going to spend anything on customer service if they’re not spending money on security

i mean secure, accurate information for banks was supposed to be their entire thing right

  • Locked thread