Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Just-In-Timeberlake
Aug 18, 2003
https://arstechnica.com/information-technology/2017/10/equifax-rival-transunion-also-sends-site-visitors-to-malicious-pages/

https://twitter.com/sarahjeong/status/918604097183346688

Just-In-Timeberlake fucked around with this message at 19:37 on Oct 13, 2017

Adbot
ADBOT LOVES YOU

30 TO 50 FERAL HOG
Mar 2, 2005



https://twitter.com/infinite_scream/status/918916821436256256




Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!


isn't that tweet in reference to the "hacker" guy who raped a bunch of women and is now being memory-holed from the EFF and the other orgs he was on

Shaggar
Apr 26, 2006

security questions are the worst thing. idk if make your own security questions is better or worse. i mean then you can basically make it a custom recovery key set.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Lutha Mahtin posted:

isn't that tweet in reference to the "hacker" guy who raped a bunch of women and is now being memory-holed from the EFF and the other orgs he was on
it is also possible that there are more than two rapists in the infosec community

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
cant believe glenn greenwald replaced morgan m-b with 2 brazilian orphans

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
cjs: just had to explain to my boss that we can't just replace the ca certificate on our website, and also that sha1 is totally fine for a ca certificate

RFC2324
Jun 7, 2012

http 418

Shaggar posted:

security questions are the worst thing. idk if make your own security questions is better or worse. i mean then you can basically make it a custom recovery key set.

when I did tech support I had one guy who used the word 'pomegranate' as the answer to every secret question

seems like a good idea until you start telling everyone how smart you are for doing it

Grassy Knowles
Apr 4, 2003

"The original Terminator was a gritty fucking AMAZING piece of sci-fi. Gritty fucking rock-hard MURDER!"

RFC2324 posted:

when I did tech support I had one guy who used the word 'pomegranate' as the answer to every secret question

seems like a good idea until you start telling everyone how smart you are for doing it

Why not circumvent all secret questions by using one phrase for all of them?

How is this different from using the same passphrase everywhere?

Shame Boy
Mar 2, 2010

at my last company we set all the secret questions and secret answers by default to something that i can only assume was thought up by our alcoholic old lead dev on one of his during-work-hours drinking sprees

i won't say what it actually is because i loving guarantee they haven't done poo poo to fix it but it was some bizarre kinda-sorta-not-really sensical thing like "question: house / answer: live in"

Shame Boy
Mar 2, 2010

this was the same place that stored all the passwords as unsalted md5 in tyool 2015 (and, again, I guarantee they still do) but actually managed to make it slightly harder than trivial to reverse them, entirely by accident - the database column they were stored in was like 3 characters too short (cuz it used to be stored in plaintext and they couldn't be assed to change the table at all lol), so before inserting it they'd truncate the hash string by 3 characters. as a result you actually couldn't pull up any google results for the hash since google doesn't seem to do partial matches on long random-letter words like that. secure! :downs:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lol (it's been taken down) https://twitter.com/briankrebs/status/918910436053012480

RFC2324
Jun 7, 2012

http 418

Grassy Knowles posted:

Why not circumvent all secret questions by using one phrase for all of them?

How is this different from using the same passphrase everywhere?

better than using something that is a matter of public record like your mothers maiden name

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

anthonypants posted:

cjs: just had to explain to my boss that we can't just replace the ca certificate on our website, and also that sha1 is totally fine for a ca certificate

chaos reigns

flakeloaf
Feb 26, 2003

Still better than android clock

RFC2324 posted:

better than using something that is a matter of public record like your mothers maiden name

seriously

"so that just leaves all my mom's siblings, their kids, my uncle's kids and my dad, fantastic plan"

Main Paineframe
Oct 27, 2010

ad/analytics networks are a cancer on the web

hmm, let me just display arbitrary third-party content I didn't vet on my website, this is a good idea

RFC2324
Jun 7, 2012

http 418

flakeloaf posted:

seriously

"so that just leaves all my mom's siblings, their kids, my uncle's kids and my dad, fantastic plan"

I love that a common alternative I have seen is siblings middle name... Also a matter of public record that is pretty trivial to look up.

Thanks Ants
May 21, 2004

#essereFerrari


anthonypants posted:

cjs: just had to explain to my boss that we can't just replace the ca certificate on our website, and also that sha1 is totally fine for a ca certificate

have they asked a random tool to scan your site and are bringing you the results?

akadajet
Sep 14, 2003

Main Paineframe posted:

ad/analytics networks are a cancer on the web

ads are a cancer on society

Grassy Knowles
Apr 4, 2003

"The original Terminator was a gritty fucking AMAZING piece of sci-fi. Gritty fucking rock-hard MURDER!"

RFC2324 posted:

better than using something that is a matter of public record like your mothers maiden name

ugh, sure--but you should already be using a password manager and just create passwords for those questions.

Midjack
Dec 24, 2007



Main Paineframe posted:

ad/analytics networks are a cancer on the web

hmm, let me just display arbitrary third-party content I didn't vet on my website, this is a good idea

but check out the mad dosh you get from it

RFC2324
Jun 7, 2012

http 418

Grassy Knowles posted:

ugh, sure--but you should already be using a password manager and just create passwords for those questions.

Let me convince the general public to ignore the instructions their bank gives them in favor of using something WAY more complicated.

I'm not saying its a good practice, or that a professional who does it should be taken seriously, but for my 72 year old mom, or my school teacher sister, its better than actually giving valid answers and is a FAR easier sell(meaning its possible to get them on board with it at all)

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Thanks Ants posted:

have they asked a random tool to scan your site and are bringing you the results?
no this is from the results of a third-party external nessus report penetration test

redleader
Aug 18, 2005

Engage according to operational parameters

isn't this just the usual conversion/cart tracking garbage that literally every ecommerce site has?

Shame Boy
Mar 2, 2010

redleader posted:

isn't this just the usual conversion/cart tracking garbage that literally every ecommerce site has?

yeah it's not particularly shocking that that's happening, it's the oblivious canned reply that makes it though

surebet
Jan 10, 2013

avatar
specialist


https://twitter.com/johnofa/status/918941635387338752

quote:

On Tuesday, a South Korean lawmaker said North Korean hackers had accessed a military database and stolen top-secret files, including a plan for a decapitation strike against top leaders in Pyongyang. That followed reports that hackers working for the Russian government stole details of how the U.S. penetrates foreign computer networks and defends its own.

Midjack
Dec 24, 2007



ratbert90 posted:

Security Fuckup Megathread - v14.1 - Hello, is this a delivery order?

Nice!

Just-In-Timeberlake
Aug 18, 2003

quote:

The hacker used a variety of malware, including an internet Trojan tool known as a “China Chopper,” identified in 2012 and favored by Chinese hackers as well as cybercriminal networks and other nations. The China Chopper enables an attacker to use brute-force password guessing against login portals, then upload and download files on victim devices after gaining access.

"ok, guess this could take awhile, just gonna go make some....you've got to be kidding me"

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

ate all the Oreos posted:

yeah it's not particularly shocking that that's happening, it's the oblivious canned reply that makes it though
honestly thought it was the random social media employee's version of "Sir, this is a macdonald's drive-through" and chuckled appropriately

of course they are selling every ounce of their data they can. if the company you work for sells your salary to equifax you better believe pizza hut is selling the fact you like pineapple on pizza to someone

Bhodi fucked around with this message at 17:09 on Oct 14, 2017

Doom Mathematic
Sep 2, 2008

Bhodi posted:

honestly thought it was the random social media employee's version of "Sir, this is a macdonald's drive-through" and chuckled appropriately

So it turns out that the entirety of Twitter is, in fact, a fast food drive-through?

Hed
Mar 31, 2004

Fun Shoe
now I’m wondering if Intuit payroll or other small biz processors do that by default

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Hed posted:

now I’m wondering if Intuit payroll or other small biz processors do that by default
yeah it's a real loving mystery

fritz
Jul 26, 2003

Bhodi posted:

you better believe pizza hut is selling the fact you like pineapple on pizza to someone

hopefully interpol

Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.
do never sms 2fa: https://motherboard.vice.com/en_us/article/wjx3e4/t-mobile-website-allowed-hackers-to-access-your-account-data-with-just-your-phone-number

Haquer
Nov 15, 2009

That windswept look...

but how else will [older person here] be able to do 2fa because other forms are Too Hard so we should just let this slide

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
google authenticator can't be that hard to implement

Haquer
Nov 15, 2009

That windswept look...

anthonypants posted:

google authenticator can't be that hard to implement

but what about iphone users :rolleyes:

ohgodwhat
Aug 6, 2005


"Hey what's your response to this evidence that even my own account was affected?"

"We've found no evidence any accounts were affected"

Not confidence inspiring.

30 TO 50 FERAL HOG
Mar 2, 2005



Haquer posted:

but what about iphone users :rolleyes:

it would actually be extremely cool if apple would open their 2FA API since its integrated and has those popups

Adbot
ADBOT LOVES YOU

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Haquer posted:

but what about iphone users :rolleyes:

I have google authenticator on my iphone :confused:

  • Locked thread