Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Cocoa Crispies posted:

i mean 1/4 of them already did

more like 1/20 at best lmao

Adbot
ADBOT LOVES YOU

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

lol I got a Symantec platform health report back from my account rep and 70% of the "Virus Detections" in my network were from one misbehaving desktop who kept quarantining a bad .js file then detecting its own quarantine as bad and re-quarantining the file it it already had in an endless loop this product is such a clown show

Shifty Pony
Dec 28, 2004

Up ta somethin'


BangersInMyKnickers posted:

lol I got a Symantec platform health report back from my account rep and 70% of the "Virus Detections" in my network were from one misbehaving desktop who kept quarantining a bad .js file then detecting its own quarantine as bad and re-quarantining the file it it already had in an endless loop this product is such a clown show



in college I had that happen on a pc I was working on, but it spawned a new window each time it detected the file and the entire screen just filled up with them until the computer hard froze (I imagine from lack of resources).

made an awful sound too.

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
Speaking of W3C stuff, there is a spec going around to replace FIDO for phish-resistant 2-factor tokens with a superset of capabilities that include letting the OS handle these things. Looks like all the vendors are really dragging their feet which sucks because although Yubikeys are pretty rad I'd prefer to just use Touch ID

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

ratbert90 posted:

99.99999% of the people out there won't even think about "Don't be dumb" and will just go about storing poo poo in plain text.

Our architect said that he doesn't care, just store the password in plain text and i objected very strongly. We are using java, so it wasn't even a case of having to invent the wheel again, and he loving knew this

yoloer420
May 19, 2006
I got a call from a stressed IT guy today because AV had reported deleting 50k+ malware files from my staff drive. He was terrified they'd deleted one of my malware repos. As if I'd store malware on something they control.

They were all false positives, it deleted some source repos. C code is very suspicious apparently.

Truga
May 4, 2014
Lipstick Apathy

Wheany posted:

Our architect said that he doesn't care, just store the password in plain text and i objected very strongly. We are using java, so it wasn't even a case of having to invent the wheel again, and he loving knew this

i used to work at a place that hosted a few mailboxes for some of our better paying clients. passwords for the mailboxes were plaintext mysql fields. this was done not out of ignorance of the security issues with it, but because said clients kept forgetting their passwords, and also wanted their old passwords back (why? you forgot it anyway you poo poo), not new ones every time. this was a hard requirement, and the reason these clients refused to get a real provider.

when i got hired, i said we'd be better off just telling them to gently caress off to gmail, and let them argue about forgotten passwords with google, but nepotism is a powerful drug. i found a better job fairly quickly at least.

yoloer420 posted:

C code is very suspicious apparently.

http://hackertyper.net/

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

Jimmy Carter posted:

Speaking of W3C stuff, there is a spec going around to replace FIDO for phish-resistant 2-factor tokens with a superset of capabilities that include letting the OS handle these things. Looks like all the vendors are really dragging their feet which sucks because although Yubikeys are pretty rad I'd prefer to just use Touch ID

I know of at least one working implementation of FIDO in the mbp touch bar.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Wheany posted:

Our architect said that he doesn't care, just store the password in plain text and i objected very strongly. We are using java, so it wasn't even a case of having to invent the wheel again, and he loving knew this

Thunderdome him for his job.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

anthonypants posted:

when the nsa does those things it's good :911:

Nah, its bad then too, especially NSA asking for back doors and hiding bugs/developer left-in back doors.

There was a bunch of Ubiquiti stuff that had leftover development backdoors left in, and the NSA was pushing for them to be left in, despite the backdoors already being well known and documented as an issue.

Just-In-Timeberlake
Aug 18, 2003

Truga posted:

i used to work at a place that hosted a few mailboxes for some of our better paying clients. passwords for the mailboxes were plaintext mysql fields. this was done not out of ignorance of the security issues with it, but because said clients kept forgetting their passwords, and also wanted their old passwords back (why? you forgot it anyway you poo poo), not new ones every time. this was a hard requirement, and the reason these clients refused to get a real provider.


there are secure ways to do this without storing them in plain text

Shame Boy
Mar 2, 2010

i wrote a program to try a bunch of different variations of my password (and variations of the variations of the variations...) and managed to recover it after only 38,509 attempts :woop:

despite having typed that drat thing every day for the past year, i somehow managed to gently caress up the capitalization of one letter AND substitute an & in place of a ; in my brain, to the point where I didn't even consider the & to be suspicious at all. loving bizarre, i have no idea how I managed to short out my brain so bad

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
http://www.newsweek.com/north-korea-cyber-army-hacked-us-south-korea-plans-decapitate-kim-jong-un-681414

quote:

According to Rhee, the ministry still has to identify the content of about 80 percent of the 235 gigabytes of data that was stolen.

"The Ministry of National Defense has yet to find out about the content of 182 gigabytes of the total (stolen) data," the lawmaker said in a statement quoted in the South Korean news agency Yonhap.

He also said that among the stolen files were Operation Plans 5015 and 3100. The operation plans are classified to the point that South Korean lawmakers from both ruling and opposition parties protested about the superficial briefing received by defence officials when they were introduced in 2015, as reported in the local press at the time.

:catstare:

cinci zoo sniper
Mar 15, 2013





im ready to bet the secret plans are carpetbombing north korean civilians, or japanese civilians, to kill/befried best leader

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
lomarf JavaScript
https://twitter.com/aemkei/status/917094611419566081

flakeloaf
Feb 26, 2003

Still better than android clock


i want a js brainfuck interpreter for christmas

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

ate all the Oreos posted:

i wrote a program to try a bunch of different variations of my password (and variations of the variations of the variations...) and managed to recover it after only 38,509 attempts :woop:

This is actually pretty cool and good, thanks for sharing

M_Gargantua
Oct 16, 2006

STOMP'N ON INTO THE POWERLINES

Exciting Lemon

200GB of that is actually just generic power points with stupid embeded video content that has been copied to personal folders

imagine putting a 50 minute 1080p training video in a slide deck, then scaling it down to quarter resolution, then clicking through it during the presentation because nobody is paying attention anyway

high speed low brains

flakeloaf
Feb 26, 2003

Still better than android clock

M_Gargantua posted:

200GB of that is actually just generic power points with stupid embeded video content that has been copied to personal folders

i see you too have become responsible for curating user data

:suicide:

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

yeah, weirdo subsets of js aren't super fresh http://www.jsfuck.com/

moostaffa
Apr 2, 2008

People always ask me about Toad, It's fantastic. Let me tell you about Toad. I do very well with Toad. I love Toad. No one loves Toad more than me, BELIEVE ME. Toad loves me. I have the best Toad.
https://twitter.com/chesh/status/917791425210830848

https://twitter.com/chesh/status/917791692404723712

Wiggly Wayne DDS
Sep 11, 2010



win8+ dns client rce patched oct 2017: https://www.bishopfox.com/blog/2017/10/a-bug-has-no-name-multiple-heap-buffer-overflows-in-the-windows-dns-client/

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

CommieGIR posted:

Nah, its bad then too, especially NSA asking for back doors and hiding bugs/developer left-in back doors.

There was a bunch of Ubiquiti stuff that had leftover development backdoors left in, and the NSA was pushing for them to be left in, despite the backdoors already being well known and documented as an issue.
remember when the nsa would intercept shipments of cisco equipment so they could install their own backdoors or whatever

Shame Boy
Mar 2, 2010

anthonypants posted:

remember when the nsa would intercept shipments of cisco equipment so they could install their own backdoors or whatever

you make it sound like they stopped

Grassy Knowles
Apr 4, 2003

"The original Terminator was a gritty fucking AMAZING piece of sci-fi. Gritty fucking rock-hard MURDER!"

ate all the Oreos posted:

you make it sound like they stopped

why bother doing it themselves when they can get cisco to do it?

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

https://www.infineon.com/cms/en/product/promopages/tpm-update/
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV170012
https://sites.google.com/a/chromium.org/dev/chromium-os/tpm_firmware_update

quote:

A security vulnerability exists in certain Trusted Platform Module (TPM) chipsets. The vulnerability weakens key strength. It is important to note that this is a firmware vulnerability, and not a vulnerability in the operating system or a specific application. After you have installed software and/or firmware updates, you will need to re-enroll in any security services you are running to remediate those services. For more details contact the TPM manufacturer

TPM keygen is hard.

edit: enjoy resetting your tpm, everyone!

Just-In-Timeberlake
Aug 18, 2003
https://www.theverge.com/2017/10/10/16447264/prison-hacker-recycled-computer-fraud-ohio-marion-transkiy

good poo poo

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost



quote:

He said he stole the personal inmate information from an internal system called DOTS. That information was redacted, but Johnston simply viewed the code on the page.

yeah, that sounds like the quality ive seen in jms software

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


Nice.

ohgodwhat
Aug 6, 2005


quote:

 He said he stole the personal inmate information from an internal system called DOTS. That information was redacted, but Johnston simply viewed the code on the page

Lol

Edit: damnit

Tatsujin
Apr 26, 2004

:golgo:
EVERYONE EXCEPT THE HOT WOMEN
:golgo:

quote:

As the interrogation went on, the investigators pushed harder. “What’s the worst thing you’ve ever been in trouble for?” the trooper asked.

“Nothing,” Gallienne said. “I’ve never been in trouble.”

“No speeding tickets?”

“Not since I was 16.”

“You know what identity theft and fraud is?”

“Yes, I do.”

“Especially when it involves financial institutions?”

“Yes, I do. I’m sure it’s really bad.”

“And what is that? Would you say felony level?”

“Probably.”

“Okay. He’s already doing life.”

“I know.”

“You think you could do 18 months at Marysville?”

“Me? No.”

“You’re how old?”

“54.”

“Be kind of hard to do 18 months at 54 years old,” the trooper said. “Don’t you think?”

lmbo prison investigations are always such an utter hamfisted shitshow hmmmmmmmm wonder why

hobbesmaster
Jan 28, 2008

[quote="“Tatsujin”" post="“477251575”"]
lmbo prison investigations are always such an utter hamfisted shitshow hmmmmmmmm wonder why
[/quote]

unless there's a recording i wouldn't take it too literally

i guaranteed the cops mentioned that it was a serious felony though. because it is, I'm not sure what she was expecting?

Tatsujin
Apr 26, 2004

:golgo:
EVERYONE EXCEPT THE HOT WOMEN
:golgo:

hobbesmaster posted:

unless there's a recording i wouldn't take it too literally

i guaranteed the cops mentioned that it was a serious felony though. because it is, I'm not sure what she was expecting?

eh it was just a choice quote. the issue with prison investigations is that the guards/officials gently caress up everything by the time the state police and prosecutors get involved.

hobbesmaster
Jan 28, 2008

well the entire reason it got that far is that they didn't have an it department

knowing state governments they probably only had one it guy for the entire facility and paid them $30k/year

cinci zoo sniper
Mar 15, 2013




https://krausefx.com/blog/ios-privacy-stealpassword-easily-get-the-users-apple-id-password-just-by-asking

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

this is awesome

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

neat, but lol at the man with kinda bad english writing thinking that putting a period inside the quotes at the end of a sentence was incorrect and worth putting in his FAQ.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i'm pretty sure that's mostly an american style

Bulgogi Hoagie
Jun 1, 2012

We
looking up to the example set by equifax microsoft decided to also just stop bothering with their flagship product

https://twitter.com/gossithedog/status/917885384658481152

Adbot
ADBOT LOVES YOU

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Bulgogi Hoagie posted:

looking up to the example set by equifax microsoft decided to also just stop bothering with their flagship product

https://twitter.com/gossithedog/status/917885384658481152

lol they're re-creating the bug on outlook 2010

  • Locked thread