Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
i guess they should accept that pull request then

Adbot
ADBOT LOVES YOU

Just-In-Timeberlake
Aug 18, 2003
what could go wrong

https://www.theregister.co.uk/2017/10/13/us_hack_back_law/?mt=1508102664099

Shaggar
Apr 26, 2006
that rules

cinci zoo sniper
Mar 15, 2013





dont be late to our conceal carry cryptominer sale!

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
if enacted this law would be a gigantic loving target on the back of the us government

Bulgogi Hoagie
Jun 1, 2012

We

anthonypants posted:

google authenticator can't be that hard to implement

tell that to twitter and facebook who will still default to sms 2fa as the most trusted method even if you use authenticator codes

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Bulgogi Hoagie posted:

tell that to twitter and facebook who will still default to sms 2fa as the most trusted method even if you use authenticator codes
yeah i can't imagine a company like twitter being actively hostile to their userbase

ohgodwhat
Aug 6, 2005

Do you think Trump uses sms 2fa for twitter?

minivanmegafun
Jul 27, 2004

Bulgogi Hoagie posted:

tell that to twitter and facebook who will still default to sms 2fa as the most trusted method even if you use authenticator codes

even google loving does. I had to set it up with SMS 2fa before I was able to flip it to OTP

Shame Boy
Mar 2, 2010

ohgodwhat posted:

Do you think Trump uses sms 2fa for twitter?

p sure trump just has someone else do all the hard "log me in" bullshit because he can't be assed

Just-In-Timeberlake
Aug 18, 2003

ate all the Oreos posted:

p sure trump just has someone else do all the hard "log me in" bullshit because he can't be assed

god i hope so that way his password is hard to guess

if it was up to him it would be trumproolzobamadroolz

ClassActionFursuit
Mar 15, 2006

minivanmegafun posted:

even google loving does. I had to set it up with SMS 2fa before I was able to flip it to OTP

twitter is worse in that you have to set it up with sms first but even after that it still sends sms no matter what which defeats the whole point

mrmcd
Feb 22, 2003
Probation
Can't post for 5 hours!
google you can delete the phone number from your account after setting up 2fa. They make you put one in to turn on 2fa because a lot of users are all "ooohh errp I just dropped my phone in the toilet and now can't access my account" but if you care enough to go back and remove the phone number after it's assumed you know what you're doing and have printed out backup codes, etc.

edit: I just checked facebook you can disable sms codes too if you dig down through the security > 2fa settings.

mrmcd fucked around with this message at 01:48 on Oct 16, 2017

Bulgogi Hoagie
Jun 1, 2012

We

mrmcd posted:

google you can delete the phone number from your account after setting up 2fa. They make you put one in to turn on 2fa because a lot of users are all "ooohh errp I just dropped my phone in the toilet and now can't access my account" but if you care enough to go back and remove the phone number after it's assumed you know what you're doing and have printed out backup codes, etc.

edit: I just checked facebook you can disable sms codes too if you dig down through the security > 2fa settings.

facebook you can only disable phone codes if you opt to use a code generator combined with U2F

e: and considering U2F is only supported by chrome natively so far it’s not a great solution really

Bulgogi Hoagie fucked around with this message at 02:05 on Oct 16, 2017

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
https://twitter.com/JGamblin/status/919606576486453249/photo/1

SmokaDustbowl
Feb 12, 2001

by vyelkin
Fun Shoe

mod saas
May 4, 2004

Grimey Drawer

idgi

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

presumably it spams deauth packets, making it rather difficult for the wireless camera to send data

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

anatoliy pltkrvkay posted:

presumably it spams deauth packets, making it rather difficult for the wireless camera to send data
that is what it does https://www.tindie.com/products/lspoplove/wifi-deauther-oled-v25-case-and-antenna/

Pardot
Jul 25, 2001




this krack thing is going to suck, isn't it? ughhhh

James Baud
May 24, 2015

by LITERALLY AN ADMIN

Pardot posted:

this krack thing is going to suck, isn't it? ughhhh

Eh, enterprises will want to patch appropriately, but only high value targets need rush and why are they using wifi and insecure protocols for things that matter?

James Baud fucked around with this message at 04:21 on Oct 16, 2017

Potato Salad
Oct 23, 2014

nobody cares



Every day, we inch closer to full corporate sovereignty.

Potato Salad
Oct 23, 2014

nobody cares


Maybe due process exists to, ya know, protect the innocent.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

anatoliy pltkrvkay posted:

presumably it spams deauth packets, making it rather difficult for the wireless camera to send data

yeah, you can be marriott starting at $30

Cocoa Crispies fucked around with this message at 04:48 on Oct 16, 2017

RFC2324
Jun 7, 2012

http 418

James Baud posted:

Eh, enterprises will want to patch appropriately, but only high value targets need rush and why are they using wifi and insecure protocols for things that matter?

WPA2 was known to be insecure prior to this?

lol at using wifi at all for anything that matters, but most places I have been everyone who mattered used a laptop, which means being on wifi at least sometimes.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
idgi

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

gently caress, crossed the streams: https://boingboing.net/2014/10/03/fcc-fines-marriott-for-jamming.html

James Baud
May 24, 2015

by LITERALLY AN ADMIN

RFC2324 posted:

WPA2 was known to be insecure prior to this?

lol at using wifi at all for anything that matters, but most places I have been everyone who mattered used a laptop, which means being on wifi at least sometimes.

By "insecure protocols", I was meaning things like credentials and other fun traffic via unencrypted pop/imap/http/etc.

EssOEss
Oct 23, 2006
128-bit approved

Oh, I bet this is exactly what was wrong with the Estonian digital identity cards, too! These are also Infineon products that probably share the majority of the codebase with their TPMs. Can't firmware patch them, though!

The FAQ is very vague but it does sound like an RNG issue. They closed the public key registry so that you could not brute force key pairs until you got a match thanks to the broken RNG.

EssOEss fucked around with this message at 05:35 on Oct 16, 2017

Proteus Jones
Feb 28, 2013




Marriott got hit with a $600,000 fine by the FCC for knocking customer's personal hotspots out of the air because they wanted to force conferences using their facilities to use their Guest connections (which they charged for) using wireless IPS. While you *can* use deauth/disassoc packets to maintain your wireless security, you have to be really, really sure what you're knocking off the air. The FCC takes a real dim view of interfering with unlicensed spectrum and can hit with up to $50K per occurrence.

It was only a matter of time. I know for a fact Marriott was advised to NOT do what they ended up doing by people who knew the minefield of using de-auth as a defensive measure.

e; poo poo. fb.

Proteus Jones fucked around with this message at 05:49 on Oct 16, 2017

Pile Of Garbage
May 28, 2007



i use WPA2-Enterprise with PEAP at home because lol why not. is that affected by this krackhole dealio or does that only affect TKIP/AES-CCMP?

Proteus Jones
Feb 28, 2013



cheese-cube posted:

i use WPA2-Enterprise with PEAP at home because lol why not. is that affected by this krackhole dealio or does that only affect TKIP/AES-CCMP?

Nope you're affected.

Also, who's calling it krackhole? I haven't seen a reference to it outside of here.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Proteus Jones posted:

Nope you're affected.

Also, who's calling it krackhole? I haven't seen a reference to it outside of here.
there was a github link with the html page it looks like they'll be using for the #branding of this latest exploit

Proteus Jones
Feb 28, 2013



anthonypants posted:

there was a github link with the html page it looks like they'll be using for the #branding of this latest exploit

Christ, this "branding of vulnerabilities" fad needs to die.

gently caress it. It's late, I'm cranky and started tilting windmills.

Pile Of Garbage
May 28, 2007



Proteus Jones posted:

Nope you're affected.

Also, who's calling it krackhole? I haven't seen a reference to it outside of here.

lol cool. was planning on buying a new WAP anyway as my current one doesn't do 802.11ac

also yeah as anthonypants pointed it out they've branded it as "KRACK" but i've decided to call it krackhole which is better

Edit: should clarify, i the KRACK hashtag and poo poo is already showing up on the tweeter

Proteus Jones posted:

Christ, this "branding of vulnerabilities" fad needs to die.

gently caress it. It's late, I'm cranky and started tilting windmills.

i made this exact same gripe in the greythread last week when drunkposting. pretty soon you'll be able to detect impending disclosure by closely watching domain registrations...

spankmeister
Jun 15, 2008






https://arstechnica.com/information-technology/2017/10/severe-flaw-in-wpa2-protocol-leaves-wi-fi-traffic-open-to-eavesdropping/

Pile Of Garbage
May 28, 2007



sooo still no advisement as to ease and practicality of such an attack?

spankmeister
Jun 15, 2008






I suspect https://www.krackattacks.com will go live within the next hour or so. It's 8:15 am in Leuven.

Pardot
Jul 25, 2001




lol in addition to the WPA2 stuff: https://twitter.com/dangoodin001/status/919798487776034817

Adbot
ADBOT LOVES YOU

Pile Of Garbage
May 28, 2007



pls don't post my keys.

also related, affordable access to protocol specs has hampered research so a lot of this poo poo has prolly (deffo) been known for ages by well-funded actors:

https://twitter.com/nikitab/status/919751347901046789

  • Locked thread