Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Shame Boy
Mar 2, 2010

im Fick.Mich.Bitte.In.Den.Arsch.DV...

e: i stand by this snipe :colbert:

Adbot
ADBOT LOVES YOU

ErIog
Jul 11, 2001

:nsacloud:

We really should have known Cosby was a predator, just look at what he did to this machine.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

ate all the Oreos posted:

im Fick.Mich.Bitte.In.Den.Arsch.DV...

e: i stand by this snipe :colbert:

its just a Bach tune

AARP LARPer
Feb 19, 2005

THE DARK SIDE OF SCIENCE BREEDS A WEAPON OF WAR

Buglord

Main Paineframe posted:

beautiful

the guy took NSA viruses home and put them on his home computer, where his antivirus detected them as potentially malicious files and sent them to the antivirus company. and since the company was Russian, the NSA couldn't just demand that the company delete it and forget it ever happened

lmao, that guy's gonna get dinged on his review!

Midjack
Dec 24, 2007



WAR DOGS OF SOCHI posted:

lmao, that guy's gonna get dinged on his review!

sadly even in places you'd think could shitcan people simply for being terminal chronic dumbshits "but but but you didn't explicitly say i couldn't do this obviously dumb thing" is an effective defense.

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


ErIog posted:

We really should have known Cosby was a predator, just look at what he did to this machine.

except its not in sleep mode...

ozymandOS
Jun 9, 2004
https://support.apple.com/en-us/HT208168

quote:

Your password might be displayed instead of your password hint if you used the Add APFS Volume command in Disk Utility to create an encrypted APFS volume, and you supplied a password hint.

lomarf

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

This never would've happened under stebe

Shaggar
Apr 26, 2006

how....

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

anthonypants posted:

the biggest risk in infosec is your self-important fuckhead users who won't report when something is wrong until months later http://www.politico.com/story/2017/10/05/john-kelly-cell-phone-compromised-243514

remember when this was predicted back in january?

akadajet
Sep 14, 2003


maybe somebody bound a control to the wrong field lol

Shaggar
Apr 26, 2006
yeah I'm just realizing they mean the volume pw so that's definitely the most likely.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

infernal machines posted:

remember when this was predicted back in january?

We assumed it would be Trump that got popped, though I assume that it's happened and Trump won't let anyone else touch his Twitter Machine so it's still live.

Shame Boy
Mar 2, 2010

Volmarias posted:

We assumed it would be Trump that got popped, though I assume that it's happened and Trump won't let anyone else touch his Twitter Machine so it's still live.

why would they hack trump he just gives them all the national secrets without even having to be asked

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

ate all the Oreos posted:

why would they hack trump he just gives them all the national secrets without even having to be asked

True

cinci zoo sniper
Mar 15, 2013




Volmarias posted:

We assumed it would be Trump that got popped, though I assume that it's happened and Trump won't let anyone else touch his Twitter Machine so it's still live.

just bait him on twitter

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
turns out letting people with security clearance byod is exactly as loving stupid as anyone with the least bit of sense assumed.

letting people with security clearance use android is just that much worse

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
To be fair, the article says that his phone was issued, so it's probably not byod.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Volmarias posted:

To be fair, the article says that his phone was issued, so it's probably not byod.

and in the image it's an iphone, so i'm 0 for 2 so far.

Fuzzy Mammal
Aug 15, 2001

Lipstick Apathy
http://www.zdnet.com/article/uber-app-can-silently-record-iphone-screens-researcher-finds/

zdnet posted:

Uber app can silently record iPhone screens, researcher finds

Uber is thought to be the only third-party app that was given access to the private, undocumented feature.

Let's just give them full r/w framebuffer access. A company as upright as uber would never make a keylogger or do anything bad with it no siree.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



infernal machines posted:

and in the image it's an iphone, so i'm 0 for 2 so far.

so is kelly!!! :xd:

sick zip everywhere
Jul 21, 2010
here's a job security hack: get in front of your leaked racist rants by suggesting your device could have been hacked within the past couple months

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Potato Salad posted:

its me, the one it guy responsible for carryig apache struts + ibm into the second decade of the 21st millennium

I'm definitely the guy at fault, pay no attention to the managers and executives who probably never approved budget requests or took security posture seriously in the headwind of user complaints

trolley problem for managers: the trolley is running over a steady stream of pennies while hurtling toward millions of people. at any point you could pour a bucket full of pennies into a coin-operated lever to make the trolley change to a track where there are no people and fewer pennies.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

sick zip everywhere posted:

here's a job security hack: get in front of your leaked racist rants by suggesting your device could have been hacked within the past couple months

nobody's doubting he's a racist, look who he works for

post hole digger
Mar 21, 2011

Midjack posted:

sadly even in places you'd think could shitcan people simply for being terminal chronic dumbshits "but but but you didn't explicitly say i couldn't do this obviously dumb thing" is an effective defense.

the old Dave Chappelle White guy defense... "I'm sorry, officer, I didn't know I couldn't do that"

Wiggly Wayne DDS
Sep 11, 2010



tor - CVE-2017-0380 - It was discovered that the Tor onion service could leak sensitive information to log files if the "SafeLogging" option is set to "0".

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

well

Wiggly Wayne DDS
Sep 11, 2010



there's more info at https://trac.torproject.org/projects/tor/ticket/23490 but who approved that summary

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



omg tor is lovely infosec?! this is a huge surprise lol

but also wow, thats bad

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
agreed

quote:

Hello!

We have found a possible problem with the code that reports an error
during the construction of an introduction point circuit. Because
of this bug, it is possible that some hidden services will sometimes
write sensitive information into their logs.

This bug can only happen when the SafeLogging option is disabled,
and SafeLogging is enabled by default. If you have not disabled
SafeLogging, then you should be fine.

We are tracking this bug as TROVE-2017-008 and as ticket #23490. It
is also CVE-2017-0380.


MITIGATION:

1. If you are not running a hidden service, then you don't need
to do anything. This bug does not affect you.

2. If you are running 0.2.5.x, this bug does not affect you: it
first appeared in 0.2.7.2-alpha. Other bugs do affect you,
though: 0.2.5.x is pretty old!

(If you are running 0.2.4, or 0.2.6, or 0.2.7, you should just
upgrade. We aren't supporting those releases.)

3. Make sure that you did not change the value of the SafeLogging
option in your configuration -- or if you did, that you set it
to "1". SafeLogging needs to be turned to "0" or "relay" for
this bug to occur.

4. If you did disable SafeLogging, re-enable it: Set it to 1, and
use a HUP signal to tell Tor to reload its configuration.

5. If you did disable SafeLogging, you should delete any old logs
that were generated with SafeLogging disabled.

(You should be regularly removing old logs anyway, as a best
security practice.)

if you're running a hidden service and planning on not going to jail for it, you problably shouldn't disable a feature called "safe logging"

hobbesmaster
Jan 28, 2008

Wiggly Wayne DDS posted:

tor - CVE-2017-0380 - It was discovered that the Tor onion service could leak sensitive information to log files if the "SafeLogging" option is set to "0".

I've also heard bad things about TLS_NULL_WITH_NULL_NULL

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
disqus was hacked http://www.zdnet.com/article/disqus-confirms-comments-tool-hacked/ in 2012

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



shame on u if u didn't block comment fields ages ago

fivehead
Jul 11, 2017

Americans Need Cash Now
If any security fuckups are going to BSides DC this weekend, I'll be there.

to find me, you need to ask everyone if they yospost and not be escorted out by security

spankmeister
Jun 15, 2008






gently caress yeah managed to get a CCC ticket in th presale

Shame Boy
Mar 2, 2010

i somehow forgot one of the important passwords i type in all the time and in trying different permutations of it i think i might have scrambled my muscle memory. i know approximately what it should be, is there a tool that will start with a string and generate every possible permutation of that string that substitutes single letters for other ones, then tries inserting characters, then does both? i could write a script i guess but this seems like the sort of thing that would exist

burning swine
May 26, 2004



ate all the Oreos posted:

i somehow forgot one of the important passwords i type in all the time and in trying different permutations of it i think i might have scrambled my muscle memory. i know approximately what it should be, is there a tool that will start with a string and generate every possible permutation of that string that substitutes single letters for other ones, then tries inserting characters, then does both? i could write a script i guess but this seems like the sort of thing that would exist

write the script

alternately, just sleep on it

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



yea sleep on it

ive forgotten passwords before but theyll come back to you if you step away and take the time (sometimes, anyway)

def dont try to bruteforce your own password, thatll probably kill your account

pseudorandom name
May 6, 2007

my Apple ID muscle memory works flawlessly on the iOS keyboard but stutters badly on a real keyboard; maybe try replicating the circumstances where you used to type it in as much as you can

Adbot
ADBOT LOVES YOU

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



i wanted to use my credit card online a couple weeks ago, it was super hard to write my number. its fully muscle memory, so i had to like step through it, typing on an imaginary numpad

did end up with the right number though, but god what a waste of time

Carthag Tuek fucked around with this message at 10:10 on Oct 8, 2017

  • Locked thread