Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Diva Cupcake
Aug 15, 2005

I'm not 100% positive as my Exchange architecture is rusty but I'm fairly certain that the ECP virtual directory is necessary for users to set their OOO messages via OWA in Exchange 2013+.

Actual administrative functionality may still be disabled.

Adbot
ADBOT LOVES YOU

CLAM DOWN
Feb 13, 2007




Diva Cupcake posted:

I'm not 100% positive as my Exchange architecture is rusty but I'm fairly certain that the ECP virtual directory is necessary for users to set their OOO messages via OWA in Exchange 2013+.

Actual administrative functionality may still be disabled.

That's fair, I never admin Exchange and haven't touched it since 2007 so wasn't sure. I just figured any admin panel accessible from the internet was a bad idea.

Dans Macabre
Apr 24, 2004


Diva Cupcake posted:

I'm not 100% positive as my Exchange architecture is rusty but I'm fairly certain that the ECP virtual directory is necessary for users to set their OOO messages via OWA in Exchange 2013+.

Actual administrative functionality may still be disabled.

End users need ECP for a bunch of things like ooo, inbox rules, retention policy settings, distro group management, signature setting, whitelist/blacklist, manage addins etc etc.

Absurd Alhazred
Mar 27, 2010

by Athanatos
If Deloitte isn't penny-stock by next week, I'm going to be very disappointed in the Invisible Hand of the Market.

Also:

Subjunctive posted:

2 Fuckup Authentication

Boris Galerkin
Dec 17, 2011

I don't understand why I can't harass people online. Seriously, somebody please explain why I shouldn't be allowed to stalk others on social media!
https://www.reddit.com/r/privacy/comments/3frjqw/psa_kaspersky_injects_remote_javascript_into_all/

quote:

its not remote its local to your machine

ff.kis.scr.kaspersky-labs.com

resolves to

127.245.107.154

which is a private non-routable address

quote:

The problem is that this could change without notice at any moment. The domain is resolved through their DNS, not locally, so the fact that it "currently" resolves to a loopback address is moot.

I checked: Even with every single bit of protection disabled - all protection entries disabled, all secure data input disabled, Firefox browser plugin disabled; the mere fact that Kaspersky is running is sufficient to inject javascript to websites.

Is this bad

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
Not really?

Unless you meant reddit, in which case, yes, reddit is very bad.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Absurd Alhazred posted:

If Deloitte isn't penny-stock by next week, I'm going to be very disappointed in the Invisible Hand of the Market.

Better prepare your pity party, the market has shown that it doesn't care about massive security breaches.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Security hurts our bottom line. Security breaches, on the other hand, only hurt the poors.

Furism
Feb 21, 2006

Live long and headbang

Cup Runneth Over posted:

Security hurts our bottom line. Security breaches, on the other hand, only hurt the poors.

Man you nailed it. I'm depressed now :smith:

CLAM DOWN
Feb 13, 2007




Cup Runneth Over posted:

Security hurts our bottom line. Security breaches, on the other hand, only hurt the poors.

Yup. Nothing will ever change, our entire industry is pointless.

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet




quote:

submitted 2 years ago

orange sky
May 7, 2007

Well, class actions can still gently caress the company's bottom line

(and result in downsizing on the lower positions, loving the poors again)

evil_bunnY
Apr 2, 2003

orange sky posted:

Well, class actions can still gently caress the company's bottom line

(and result in downsizing on the lower positions, loving the poors again)
Equifax CEO just got the boot. He's gonna get a bunch of money for loving up im sure, but i bet he would have preferred to stay. CIO left a while ago.

Of course now lobbyists will make sure class actions can never amount to anything.

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

evil_bunnY posted:


Of course now lobbyists will make sure class actions can never amount to anything.

Will? Isn't there literally a bill in the House that says "Class action can't do poo poo all" right now?

evil_bunnY
Apr 2, 2003

Avenging_Mikon posted:

Will? Isn't there literally a bill in the House that says "Class action can't do poo poo all" right now?
That's what I meant yes

orange sky
May 7, 2007

What's stopping Equifax from starting a spinoff with nothing related to their brand, transfer their managers and sell all their data to the spinoff, effectively cleaning their image?

Potato Salad
Oct 23, 2014

nobody cares


orange sky posted:

What's stopping Equifax from starting a spinoff with nothing related to their brand, transfer their managers and sell all their data to the spinoff, effectively cleaning their image?

Nothing.

Blackwater-playbook.txt

orange sky
May 7, 2007

I'd say that's gonna happen a lot in the future, when companies find out they've been hacked for the last 5 years without noticing

Evis
Feb 28, 2007
Flying Spaghetti Monster

CLAM DOWN posted:

Yup. Nothing will ever change, our entire industry is pointless.

Hey as long as the industry is redirecting money into my pocket that's okay.

Potato Salad
Oct 23, 2014

nobody cares


orange sky posted:

I'd say that's gonna happen a lot in the future, when companies find out they've been hacked for the last 5 years without noticing

That plus.every state entity.

Evis posted:

Hey as long as the industry is attributing validity and value to my empty, overworked soul that's okay.

CLAM DOWN
Feb 13, 2007




Evis posted:

Hey as long as the industry is redirecting money into my pocket that's okay.

The worst part is, I really enjoy infosec. I find it fascinating and challenging, my personal interest/passion in this field lies in cipher technologies, encryption, algorithms, the math and tech behind them. But holy hell are we ever hosed and this is a totally pointless endeavour overall tbh.

some kinda jackal
Feb 25, 2003

 
 

Potato Salad posted:

Nothing.

Blackwater-playbook.txt

Accenture.txt

Evis
Feb 28, 2007
Flying Spaghetti Monster

I feel the same way, but I don't really let it get me down. I provide a service my employers are happy with. The overall direction of industries that I think would benefit from better security is way above my pay grade.

Thermopyle
Jul 1, 2003

...the stupid are cocksure while the intelligent are full of doubt. —Bertrand Russell

Good news, you guys will have work forever until all of us software engineers switch over to TLA+ or other provable software dev techniques. Sucks that that means everyone else gets hosed. Well I guess infosec guys are people as well so you get hosed but compensated somewhat by having more work.

Furism
Feb 21, 2006

Live long and headbang

Avenging_Mikon posted:

Will? Isn't there literally a bill in the House that says "Class action can't do poo poo all" right now?

I understand that the USA are really full throttle in favor of free-market, weak state, strong companies, etc.. How does one keep thinking like this when they see what you quoted? Is anybody, anybody who doesn't have a direct stake that is, in agreement that class actions are bad, etc. ? This is a genuine question from a dirty left-wing European who cannot wrap his head around this. Send me my PM if you prefer (this not being D&D).

Potato Salad
Oct 23, 2014

nobody cares


Furism posted:

I understand that the USA are really full throttle in favor of free-market, weak state, strong companies, etc.. How does one keep thinking like this when they see what you quoted? Is anybody, anybody who doesn't have a direct stake that is, in agreement that class actions are bad, etc. ? This is a genuine question from a dirty left-wing European who cannot wrap his head around this. Send me my PM if you prefer (this not being D&D).

I think at least some small part of it is how short our memories are, and how powerfully conditioned we seem to be to give every possible benefit of the doubt to the invisible hand of money -- capitalism as something that cultivates self-policing, ethical behavior. My much more personal opinion is that we frequently conflate capitalism, patriotism, and Christianity -- so many Americans fuse those three separate things into a single lens through which they interpret the world. I'm only really comfortable living where I do because my husband is a canadian citizen with a current passport with our marriage certificate stapled inside

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Potato Salad posted:

I think at least some small part of it is how short our memories are, and how powerfully conditioned we seem to be to give every possible benefit of the doubt to the invisible hand of money -- capitalism as something that cultivates self-policing, ethical behavior. My much more personal opinion is that we frequently conflate capitalism, patriotism, and Christianity -- so many Americans fuse those three separate things into a single lens through which they interpret the world. I'm only really comfortable living where I do because my husband is a canadian citizen with a current passport with our marriage certificate stapled inside

:canada:

mewse
May 2, 2006

Where's the dating site for me to seduce American chicks with my Canadian passport Obama????????????

CLAM DOWN
Feb 13, 2007




mewse posted:

Where's the dating site for me to seduce American chicks with my Canadian passport Obama????????????

Hell, same

Potato Salad
Oct 23, 2014

nobody cares


mewse posted:

Where's the dating site for me to seduce American chicks with my Canadian passport Obama????????????

https://www.ofa.us
http://www.dsausa.org

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

:perfect:

Actual content: There's a TOR tunnel to Ireland going through a firewall at one of my clients. Happy Wednesday.

Klyith
Aug 3, 2007

GBS Pledge Week

Furism posted:

I understand that the USA are really full throttle in favor of free-market, weak state, strong companies, etc.. How does one keep thinking like this when they see what you quoted? Is anybody, anybody who doesn't have a direct stake that is, in agreement that class actions are bad, etc. ? This is a genuine question from a dirty left-wing European who cannot wrap his head around this. Send me my PM if you prefer (this not being D&D).



(pretend I edited the tv to show the Fox logo)

Moatman
Mar 21, 2014

Because the goof is all mine.

mewse posted:

Where's the dating site for me to seduce American chicks with my Canadian passport Obama????????????

I believe we call it "the entire state of Minnesota"

Harik
Sep 9, 2001

From the hard streets of Moscow
First dog to touch the stars


Plaster Town Cop
https://signal.org/blog/private-contact-discovery/

tl;dr summary: use the new intel 6xxx and 7xxx secure enclave to run the contact matching code on signal's servers to prevent them from learning your contact list. Then use remote attestation of deterministically compiled open source code to prove to the client that their query was conducted inside the secure enclave.

If I'm following right, they're using EPID to be able to anonymously sign code using the intel trusted group. You can't tell which processor did the signature, just that they're a member of the group. Ok. Group keys are cool poo poo.

From there, the chain of trust is pretty trivial - you sign the enclave package with an ephemeral key signed by the anonymous group key. That gives you a chain of trust back to intel's foundries.

Here's the rub: Signal's threat model is nation states, including 5-eyes and China. There's zero chance that they're ignoring this, and they absolutely have the group keys they need to sign an enclave but run the query outside it.

It's still a cool idea though, and it'd be useful for anything where the threat model isn't the NSA.

susan b buffering
Nov 14, 2016

Furism posted:

I understand that the USA are really full throttle in favor of free-market, weak state, strong companies, etc.. How does one keep thinking like this when they see what you quoted? Is anybody, anybody who doesn't have a direct stake that is, in agreement that class actions are bad, etc. ? This is a genuine question from a dirty left-wing European who cannot wrap his head around this. Send me my PM if you prefer (this not being D&D).

Most people in America's experience with class action suits is that they receive a letter saying they are entitled to a small part of the damages in a suit they weren't aware of previously. The damages they are entitled to usually amount to a few bucks or a coupon, so lots of people think of class action suits as "something to make lawyers money" rather than something that punishes a company for a small(or large) harm against many individuals.

The Fool
Oct 16, 2003


https://twitter.com/s7ephen/status/701488719795060736

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Absurd Alhazred
Mar 27, 2010

by Athanatos
https://twitter.com/ClickHole/status/913546418513747969

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate



Siri, remember my bank account password and social security number

What the gently caress happened to post-its for that stuff?

Adbot
ADBOT LOVES YOU

camoseven
Dec 30, 2005

RODOLPHONE RINGIN'
Anyone else going to BSides DC next weekend? It'll be my first time at any kind of tech conference, and I'm not sure what to expect.

camoseven fucked around with this message at 02:51 on Sep 29, 2017

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply