Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
cinci zoo sniper
Mar 15, 2013




Shifty Pony posted:

versions of the software on air gapped systems would hide data packets on the hand carried USB drives used to carry data/updates to or from the air gapped systems. then when that drive was attached to a system which was internet connected and also infected the data is gotten out using more traditional means.

this is not some theoretical PoC either, it has been seen in the wild :nsa:

i kinda assumed that smart people know better than to plug things into airgapped machines with production stuff directly :eng99:

Adbot
ADBOT LOVES YOU

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

cinci zoo sniper posted:

i kinda assumed that smart people know better than to plug things into airgapped machines with production stuff directly :eng99:

It's pretty much SoP for vendors doing software updates unfortunately. They think an air gap is better than a correctly configured firewall/dmz for this poo poo.

cinci zoo sniper
Mar 15, 2013




BangersInMyKnickers posted:

It's pretty much SoP for vendors doing software updates unfortunately. They think an air gap is better than a correctly configured firewall/dmz for this poo poo.

speaking of dmz, what's the tl;dr on it?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Sorry, I'm not exactly sure what you're asking there?

cinci zoo sniper
Mar 15, 2013




BangersInMyKnickers posted:

Sorry, I'm not exactly sure what you're asking there?
being just a casual thread reader, rather an infosec person of any kind, my only knowledge of dmz is seeing setting called like that in routers i had, so im wonder if theres anything more to it than what i assume to be "virtual airgap" if dmz is like demilitarised zone irl

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Basically you put anything that needs to reach outside the network (WSUS, maybe a backup server for outside replication, SCCM, a fileshare) that is in a supporting role of the internal network in the DMZ. Internal clients can reach in to the DMZ for whatever they need, but not to the internet zone directly. DMZ clients can reach out to the internet to stage content and maybe reach back in to the internal network on certain ports for some circumstances (but best to avoid/restrict that as much as possible). All traffic between zones has a default bi-direcitonal deny so you are forced to explicitly document and allow necessary traffic. This gives you logical choke points on the network that you can dump an IDS/IPS in the middle of as well as monitor traffic flows for anomalies with whatever software you have to do that work.

Truga
May 4, 2014
Lipstick Apathy
dmz is usually meant as a separate vlan/subnet where you have public servers and poo poo, and you have routing set so you can get to them, but they can't get to your network. so when someone inevitably logs into your public ftp your idiot clients need and use a zero day to escape it, they can't see other machines that might have private info no them.

e;fb

Nuclearmonkee
Jun 10, 2009


cinci zoo sniper posted:

being just a casual thread reader, rather an infosec person of any kind, my only knowledge of dmz is seeing setting called like that in routers i had, so im wonder if theres anything more to it than what i assume to be "virtual airgap" if dmz is like demilitarised zone irl

You point machine guns at the DMZ servers receiving connections from the internet and whenever they attempt to talk to servers in your internal network you light them up.

It's this basically. Can also just be one firewall.

Nuclearmonkee fucked around with this message at 19:19 on Oct 12, 2017

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

BangersInMyKnickers posted:

It's pretty much SoP for vendors doing software updates unfortunately. They think an air gap is better than a correctly configured firewall/dmz for this poo poo.

an airgap is strictly better, but if you're using physical media to move stuff in or out you now have to manage chain-of-custody for that media which is hard

cinci zoo sniper posted:

speaking of dmz, what's the tl;dr on it?

the "dmz" where like a home router just treats a given IP as a catchall? it's this in network form:

https://twitter.com/dril/status/464802196060917762

Phone
Jul 30, 2005

親子丼をほしい。

pr0zac posted:

who were the people i accused of being overly paranoid about home assistants constantly recording and sending audio to google/amazon so i can apologize?

https://www.theverge.com/2017/10/10/16456050/google-home-mini-always-recording-bug

me

I'll take an apology payment in the form of the new alexa and a bunch of smart light bulbs and like... 3 of those sweet teddy bears with the cameras inside of them

Phone fucked around with this message at 19:19 on Oct 12, 2017

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Cocoa Crispies posted:

an airgap is strictly better, but if you're using physical media to move stuff in or out you now have to manage chain-of-custody for that media which is hard


airgapping also results in total isolation so all 24/7 monitoring/alarming/everything needs to be configured and run on-site. Without extensive staffing on par of a large nuclear or government facility, this can result in blindspots that could otherwise been handle by a 3rd party NoC/SoC. I won't disagree that in its purest form air gapping is superior, but not being able to leverage outside network resources and staffing makes it lovely in practice.

cinci zoo sniper
Mar 15, 2013




BangersInMyKnickers posted:

Basically you put anything that needs to reach outside the network (WSUS, maybe a backup server for outside replication, SCCM, a fileshare) that is in a supporting role of the internal network in the DMZ. Internal clients can reach in to the DMZ for whatever they need, but not to the internet zone directly. DMZ clients can reach out to the internet to stage content and maybe reach back in to the internal network on certain ports for some circumstances (but best to avoid/restrict that as much as possible). All traffic between zones has a default bi-direcitonal deny so you are forced to explicitly document and allow necessary traffic. This gives you logical choke points on the network that you can dump an IDS/IPS in the middle of as well as monitor traffic flows for anomalies with whatever software you have to do that work.

Truga posted:

dmz is usually meant as a separate vlan/subnet where you have public servers and poo poo, and you have routing set so you can get to them, but they can't get to your network. so when someone inevitably logs into your public ftp your idiot clients need and use a zero day to escape it, they can't see other machines that might have private info no them.

e;fb

Nuclearmonkee posted:

You point machine guns at the DMZ servers receiving connections from the internet and whenever they attempt to talk to servers in your internal network you light them up.

It's this basically. Can also just be one firewall.





Cocoa Crispies posted:

an airgap is strictly better, but if you're using physical media to move stuff in or out you now have to manage chain-of-custody for that media which is hard


the "dmz" where like a home router just treats a given IP as a catchall? it's this in network form:

https://twitter.com/dril/status/464802196060917762

oh, i see. thanks!

Just-In-Timeberlake
Aug 18, 2003

Nuclearmonkee posted:

You point machine guns at the DMZ servers receiving connections from the internet and whenever they attempt to talk to servers in your internal network you light them up.


think of it this way

https://www.youtube.com/watch?v=HQDy-5IQvuU&t=10s

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet



pr0zac posted:

who were the people i accused of being overly paranoid about home assistants constantly recording and sending audio to google/amazon so i can apologize?

https://www.theverge.com/2017/10/10/16456050/google-home-mini-always-recording-bug

here's the writeup from the guy it actually happened to http://www.androidpolice.com/2017/10/10/google-nerfing-home-minis-mine-spied-everything-said-247/

supposedly it was a hardware defect that made the mini think it was randomly being touch-activated

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Pikavangelist posted:

supposedly it was a hardware defect that made the mini think it was randomly being touch-activated

a $690B company failed to build a working button

don't buy hardware from advertising companies

haveblue
Aug 15, 2005
Probation
Can't post for 4 hours!
Toilet Rascal
really stay away from capacitive buttons at all unless you really know what you're doing

sony, who has been making consumer hardware for decades, hosed it up too and some early model ps4s had a habit of ejecting discs or powering themselves off at random

wolrah
May 8, 2006
what?

Pikavangelist posted:

here's the writeup from the guy it actually happened to http://www.androidpolice.com/2017/10/10/google-nerfing-home-minis-mine-spied-everything-said-247/

supposedly it was a hardware defect that made the mini think it was randomly being touch-activated
It's confirmed to be a hardware design flaw, affecting enough units that they're permanently disabling the feature altogether rather than trying to fix or replace them.

haveblue posted:

really stay away from capacitive buttons at all unless you really know what you're doing

sony, who has been making consumer hardware for decades, hosed it up too and some early model ps4s had a habit of ejecting discs or powering themselves off at random
Agreed so much. I have never met a capacitive button where I've thought "this is better than a real button" but plenty where it's worse. My cat used to turn off my Xbox 360 S all the time by nosing the button, and my Xbox One turns itself on every few weeks.

AARP LARPer
Feb 19, 2005

THE DARK SIDE OF SCIENCE BREEDS A WEAPON OF WAR

Buglord

wolrah posted:

My cat used to turn off my Xbox 360 S all the time by nosing the button...

maybe your smart kitty just wanted you to stop and pet it?

:cabot:

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
cracking pws like nobody's business
https://twitter.com/tinkersec/status/918562485069893632

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Asshole Masonanie
Oct 27, 2009

by vyelkin

this is so sick

Thanks Ants
May 21, 2004

#essereFerrari


haveblue posted:

major updates ask for your icloud password as part of a special ui flow, that's not what's being spoofed here and it would be much harder for third party apps to fake

I can't remember the last time I've seen that l/p popup dialog, it should only appear if you try to do something involving icloud but you aren't signed in in system prefs

if i am playing music and dont have cell reception or wi-fi then ios decides that my password must be wrong and prompts me to re-enter it, the prompt looks exactly like that. ignoring it works fine and it sorts itself out again when it has a data connection.

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
oh no, what loving goober harassed someone now
https://twitter.com/sarahjeong/status/918595705966596096

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
there's this:
https://twitter.com/ggrucilla/status/918388486847131649

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
is it this guy? https://en.wikipedia.org/wiki/Morgan_Marquis-Boire

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
that's what it looks like

ThePeavstenator
Dec 18, 2012

:burger::burger::burger::burger::burger:

Establish the Buns

:burger::burger::burger::burger::burger:
sec gently caress mor elike sick gently caress

Midjack
Dec 24, 2007




if it's that guy gently caress that guy. i hadn't heard anything about sexual assault with him until now but thought he was a piece of poo poo anyway.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



ThePeavstenator posted:

sec gently caress mor elike sick gently caress

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Midjack posted:

thought he was a piece of poo poo anyway.

that's all itsec people though

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

hackbunny posted:

that's all itsec people though

hey

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
bros in itsec are garbage

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/pizzahutuk/status/918563493418295296

Midjack
Dec 24, 2007




loooooooooooooooooooooool

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Excuse me sir, this is a Pizza hut.

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

yah, it is. right there in the referer m8

LordSaturn
Aug 12, 2007

sadly unfunny

hackbunny posted:

that's all itsec people though

I may be a useless piece of genial poo poo, but I won't mess with your body

maybe I should put that on my resume, right next to how I can always pass a piss test because I'm boring

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

akadajet posted:

Not when you do major updates. From like ios 10 -> 11

Didn’t ask when I upgraded my phone or iPad.

spankmeister
Jun 15, 2008






hackbunny posted:

that's all itsec people though

oi :(

Adbot
ADBOT LOVES YOU

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Lain Iwakura posted:

bros in itsec are garbage

also all other itsec people.

and everyone who has touched a computer.

and everyone else.

hail satan.

  • Locked thread