Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Trabisnikof
Dec 24, 2005

ate all the Oreos posted:

i mean "lovely security" seems like the kind of thing you can brush under the rug for not really costing money until something bad happens, not having automated / streamlined customer support strikes me as the kind of thing some middle-manager MBA would have optimized away to save 5% on labor costs years ago :shrug:

Seeing how they repeatedly gave out the wrong link maybe they just hosed up the canned reply?

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

Trabisnikof posted:

Seeing how they repeatedly gave out the wrong link maybe they just hosed up the canned reply?

it all seems to come from "Tim" so yeah maybe lol

Shaggar
Apr 26, 2006

non-us banks don't give their customers the same protections we take for granted

Carbon dioxide
Oct 9, 2012

Shaggar posted:

non-us banks don't give their customers the same protections we take for granted

Don't US banks have a history of giving you access to everything after they ask you your mother's maiden name on the phone and you reply with some random mumbling?

Shaggar
Apr 26, 2006
probably depends on the bank but if they did you wouldn't be liable.

Carbon dioxide
Oct 9, 2012

drat, I thought the terrible way some people pronounce JWT was just a bad joke. But...

RFC 7519 posted:

The suggested pronunciation of JWT is the same as the English word "jot".

It's actually in the standard.

ate shit on live tv
Feb 15, 2004

by Azathoth

Shaggar posted:

so what you're saying is regulations are bad and we should let the market decide?

No we should make sure that the industry we are attempting to regulate has zero input whatsoever to the regulations we are applying. If that means the regulations are written in a way that makes them impossible to comply with, good, the industry get's continually fined until it goes away.

Shaggar
Apr 26, 2006
so you're saying that people who have no idea how the industry works should make rules around it?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
actually they should do detailed and in-depth industry consultations, then implement the exact opposite of whatever recommendations they were given

duTrieux.
Oct 9, 2003

the entire credit industry is hosed and has no idea what the gently caress is going on

i applied for a fancy credit card lately and was approved but can't get it because for some reason the credit agencies decided that i need to verify my identity by calling them from my parent's landline phone which i haven't used in any capacity for over a decade

LIVE AMMO COSPLAY
Feb 3, 2006

M_Gargantua posted:

my solution has always been to have javascript disabled by default until an allowance is added. only breaks some sites where they try to forward your browser through like four intermediary sites for cred certification or form submission.

so i randomly get redirected from sa to the first landing pad for a malicious ad redirect and am left with a white screen and an alert while it cant forward me onward, and drop that link in the thread, because i have no idea what ad it actually came from.

Casual browsing is surprisingly functional without javascript, though the people who want to browse the forums at work should really cough up the $5 for the noads upgrade.

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

duTrieux. posted:

the entire credit industry is hosed and has no idea what the gently caress is going on

i applied for a fancy credit card lately and was approved but can't get it because for some reason the credit agencies decided that i need to verify my identity by calling them from my parent's landline phone which i haven't used in any capacity for over a decade

just find someone with a T1/PRI and have them spoof the number for you. no big deal

Schadenboner
Aug 15, 2011

by Shine

duTrieux. posted:

the entire credit industry is hosed and has no idea what the gently caress is going on

i applied for a fancy credit card lately and was approved but can't get it because for some reason the credit agencies decided that i need to verify my identity by calling them from my parent's landline phone which i haven't used in any capacity for over a decade

Same except for I was trying to get approved to call a 1-900 number.

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl
...wait, wait, someone at a credit card company thinks Caller ID is a valid and secure method for identifying someone?? :stonk:

mod saas
May 4, 2004

Grimey Drawer

Farmer Crack-rear end posted:

just find someone with a T1/PRI and have them spoof the number for you. no big deal

dammit I was literally going to offer this for :10bux:

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://www.blackhat.com/eu-17/brie...ent-engine-8668

:nsavince:

duTrieux.
Oct 9, 2003

Farmer Crack-rear end posted:

...wait, wait, someone at a credit card company thinks Caller ID is a valid and secure method for identifying someone?? :stonk:

yes. well, partially. bsaically i'd call them and then they'd call me back

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


well that finally happened. gently caress Us.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


ME is MINIX? that is a surprising choice.

McGlockenshire
Dec 16, 2005

GOLLOCKS!
so how much worse is that going to be than all the broken IPMI implementations from like five years ago?

I mean other than ME being in consumer procs

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

that's a pretty big "other than", IMO

Raere
Dec 13, 2007

Minix? Talk about security through obscurity

Pie Colony
Dec 8, 2006
I AM SUCH A FUCKUP THAT I CAN'T EVEN POST IN AN E/N THREAD I STARTED
i'm signing up for PADI, probably the world's most well known scuba diving organization



the password i chose was "password"

ate shit on live tv
Feb 15, 2004

by Azathoth
but don't you see, it's so obvious no one will ever guess it!

Raere
Dec 13, 2007

Pie Colony posted:

i'm signing up for PADI, probably the world's most well known scuba diving organization



the password i chose was "password"

SSI is superior both in website and training program

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Pie Colony posted:

i'm signing up for PADI, probably the world's most well known scuba diving organization



the password i chose was "password"

for a second i thought it was rating your phone number

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

Raere posted:

SSI is superior both in website and training program

Trabisnikof
Dec 24, 2005

Raere posted:

SSI is superior both in website and training program

Pie Colony
Dec 8, 2006
I AM SUCH A FUCKUP THAT I CAN'T EVEN POST IN AN E/N THREAD I STARTED
it assumes both my billing and shipping addresses are the address i live at, with no way to change it, so i guess SSI it is

Shame Boy
Mar 2, 2010

infernal machines posted:

actually they should do detailed and in-depth industry consultations, then implement the exact opposite of whatever recommendations they were given

at the very least this would make stuff much more funny

endlessmonotony
Nov 4, 2009

by Fritz the Horse

They lobbied real hard to get that ruling in. Between "when your stuff is stolen" and "when you notify your bank", poo poo done on your account is your problem.

The law will probably get changed after a few horror stories but in the meantime, first you create a problem... and then you sell the answer.

spankmeister
Jun 15, 2008






Shaggar posted:

so you're saying that people who have no idea how the industry works should make rules around it?

I wish the government would regulate your posting

Wiggly Wayne DDS
Sep 11, 2010



in news absolutely no one saw coming it turns out there was a secondary payload delivered via the ccleaner backdoor: https://blog.avast.com/progress-on-ccleaner-investigation

quote:

First of all, analysis of the data from the CnC server has proven that this was an APT (Advanced Persistent Threat) programmed to deliver the 2nd stage payload to select users. Specifically, the server logs indicated 20 machines in a total of 8 organizations to which the 2nd stage payload was sent, but given that the logs were only collected for little over three days, the actual number of computers that received the 2nd stage payload was likely at least in the order of hundreds. This is a change from our previous statement, in which we said that to the best of our knowledge, the 2nd stage payload never delivered.

now if you want to know which companies were targeted ask talos: http://blog.talosintelligence.com/2017/09/ccleaner-c2-concern.html

Chumbawumba4ever97
Dec 31, 2000

by Fluffdaddy

Carbon dioxide posted:

Don't US banks have a history of giving you access to everything after they ask you your mother's maiden name on the phone and you reply with some random mumbling?

90% of the married women I know on Facebook have their maiden names before their last names (I am guessing so high school friends know who they are)

it is gonna be so easy to steal their kids' identities in ~15 years

hobbesmaster posted:

equifax isn’t going to spend anything on customer service if they’re not spending money on security

i mean secure, accurate information for banks was supposed to be their entire thing right

and their stock has been going up the past few days

lol

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

p much every time we had a security bug in the press at Netscape our stock went up. maybe there is no such thing as bad publicity

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

M_Gargantua posted:

my solution has always been to have javascript disabled by default until an allowance is added. only breaks some sites where they try to forward your browser through like four intermediary sites for cred certification or form submission.

so i randomly get redirected from sa to the first landing pad for a malicious ad redirect and am left with a white screen and an alert while it cant forward me onward, and drop that link in the thread, because i have no idea what ad it actually came from.

lmao

flakeloaf
Feb 26, 2003

Still better than android clock

from the makers of netnanny comes javajanitor

cinci zoo sniper
Mar 15, 2013




literally a secfuck - SEC got hacked

https://www.washingtonpost.com/news...m=.89f7e8ed94ac

Shame Boy
Mar 2, 2010


yeah i heard about it this morning, where NPR compared it to back to the future for some goddamn reason because they used the information for insider trading

Adbot
ADBOT LOVES YOU

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

Wiggly Wayne DDS posted:

in news absolutely no one saw coming it turns out there was a secondary payload delivered via the ccleaner backdoor: https://blog.avast.com/progress-on-ccleaner-investigation


now if you want to know which companies were targeted ask talos: http://blog.talosintelligence.com/2017/09/ccleaner-c2-concern.html


Are those internal domains?

  • Locked thread