Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Luigi Thirty
Apr 30, 2006

Emergency confection port.

secfuck from 1980

I got a modem for my Atari 8-bit. in the Atari computers, the sound chip doubles as a 115200bps UART. this leads to the annoying effect of any serial i/o coming through the speakers. you get used to the speaker beeping every time a sector gets loaded from disk or whatever. good programs are supposed to mute the audio registers or at least turn them down. (the OS disk routines do not, ostensibly for debugging)

the modem only supports 300bps transfer so I called up a BBS. the phone signal came through the computer, which is pretty neat for such an old device. but then after I connected and it turned off the speaker sound, I turned the volume up on my monitor. turns out you can hear every transferred byte from the modem coming through the TV speaker as clicks of various frequencies as the audio registers are hammered with serial data :haw:

Adbot
ADBOT LOVES YOU

spankmeister
Jun 15, 2008






Oh no, better write a paper on side channel attacks

hobbesmaster
Jan 28, 2008

that’s a feature - acoustic coupler support!

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



ate all the Oreos posted:


ask me about my buttplug purchase yospos

how are you enjoying it? I mean not like details but like thumbs uuuhhh err how many stars... uh rating between one and ten?

Shame Boy
Mar 2, 2010

Munkeymon posted:

how are you enjoying it? I mean not like details but like thumbs uuuhhh err how many stars... uh rating between one and ten?

eh it's like an 8 out of 10, pretty good but i have some quibbles with some of its design choices and the $100 I paid for it is a bit much for what it boils down to

my favorite part is it has a little elongated bit that it says to point towards your back because it's where the antenna is and it gets better signal that way :downs:

suffix
Jul 27, 2013

Wheeee!

i've noticed crapware asking for it
afaict you cant turn it off, and it will keep pushing updates even when the app is closed
so i figure google are happy with apps abusing it as long as they have an excuse to log the data, "the user installed our music app, so clearly they want their activity uploaded to our servers 24/7 in order to select a fitting playlist"

bump_fn
Apr 12, 2004

two of them


i hate this so loving much

Carbon dioxide
Oct 9, 2012

bump_fn posted:



i hate this so loving much

They shouldn't be able to verify only specific characters of your password, unless their encryption is crap or non-existant.

bump_fn
Apr 12, 2004

two of them

Carbon dioxide posted:

They shouldn't be able to verify only specific characters of your password, unless their encryption is crap or non-existant.

lmao this rules, its obnoxious AND bad sec

Partycat
Oct 25, 2004

You could hash individual letters I guess

Or combinations

Midjack
Dec 24, 2007



Carbon dioxide posted:

They shouldn't be able to verify only specific characters of your password, unless their encryption is crap or non-existant.

gee, i wonder what's going on here

M_Gargantua
Oct 16, 2006

STOMP'N ON INTO THE POWERLINES

Exciting Lemon

Carbon dioxide posted:

They shouldn't be able to verify only specific characters of your password, unless their encryption is crap or non-existant.

they salt and hash each individual character and the thing as a whole :downs:

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


I don't get.. Like, is that their normal login process or what? :psyduck:

duTrieux.
Oct 9, 2003

do any websites ship their users one-time pads yet

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


duTrieux. posted:

do any websites ship their users one-time pads yet

One time shipment yes, reusable.

spankmeister
Jun 15, 2008






duTrieux. posted:

do any websites ship their users one-time pads yet

My bank used to ship TAN codes on paper before they switched to distributing them by SMS.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

duTrieux. posted:

do any websites ship their users one-time pads yet

I asked for another time pad but they told me no, you only get one.

bump_fn
Apr 12, 2004

two of them

rafikki posted:

I don't get.. Like, is that their normal login process or what? :psyduck:

yes, any time i want to log into my bank i get that

Main Paineframe
Oct 27, 2010

bump_fn posted:

yes, any time i want to log into my bank i get that

is it always the same characters, or do they ask for different ones each time

bump_fn
Apr 12, 2004

two of them

Main Paineframe posted:

is it always the same characters, or do they ask for different ones each time

diff characters but always like three or four

jammyozzy
Dec 7, 2006

Is that a challenge?

bump_fn posted:



i hate this so loving much

Hah! We share banks. I also hate this garbage, trying to work out if that character of my password is I, i, l or ¦ is tedious at best.

The phone app only asks for 3 characters of the number and foregoes the password altogether.

duTrieux.
Oct 9, 2003

somebody at that bank must have a vendetta against password managers

apseudonym
Feb 25, 2011

suffix posted:

i've noticed crapware asking for it
afaict you cant turn it off, and it will keep pushing updates even when the app is closed
so i figure google are happy with apps abusing it as long as they have an excuse to log the data, "the user installed our music app, so clearly they want their activity uploaded to our servers 24/7 in order to select a fitting playlist"

:jerkbag:

bump_fn posted:



i hate this so loving much

What a clever way to reduce the entropy of a password to almost nothing.

30 TO 50 FERAL HOG
Mar 2, 2005



jammyozzy posted:

Hah! We share banks. I also hate this garbage, trying to work out if that character of my password is I, i, l or ¦ is tedious at best.

The phone app only asks for 3 characters of the number and foregoes the password altogether.

yo name and shame

James Baud
May 24, 2015

by LITERALLY AN ADMIN
Banking world does that in the back end so that employees don't get the full password in one shot to make it harder to get back inside an account later to defraud customers ... the human risk is believed greater than the backend one, probably correctly so. One of my banks also sends an SMS otp (well, they're trying!) that you have to give the reps in person/on phone before they can get into the account. When the SMS gateway is slow, that's a good time. I should email and ask about generic TOTP support.

Re: presenting that interface to end user, though... I guess it makes it a bit harder for dridex-style malware to steal credentials in one shot, but still ew.

jammyozzy
Dec 7, 2006

Is that a challenge?

NEED MORE MILK posted:

yo name and shame

It's Santander. I know Halifax also do some similar poo poo with asking for 3 letters from a password (or at least did previously).

Wiggly Wayne DDS
Sep 11, 2010



jammyozzy posted:

It's Santander. I know Halifax also do some similar poo poo with asking for 3 letters from a password (or at least did previously).
halifax has a separate secret phrase for that, it's not based off of the account password

canis minor
May 4, 2011

jammyozzy posted:

It's Santander. I know Halifax also do some similar poo poo with asking for 3 letters from a password (or at least did previously).

Lloyds as well.

jammyozzy
Dec 7, 2006

Is that a challenge?

Wiggly Wayne DDS posted:

halifax has a separate secret phrase for that, it's not based off of the account password

Halifax: Slightly less of a secfuck than Santander

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
halifax is part of lloyds banking group, they all use the same website with different branding (as do bank of scotland)

Main Paineframe
Oct 27, 2010

James Baud posted:

Banking world does that in the back end so that employees don't get the full password in one shot to make it harder to get back inside an account later to defraud customers ... the human risk is believed greater than the backend one, probably correctly so. One of my banks also sends an SMS otp (well, they're trying!) that you have to give the reps in person/on phone before they can get into the account. When the SMS gateway is slow, that's a good time. I should email and ask about generic TOTP support.

Re: presenting that interface to end user, though... I guess it makes it a bit harder for dridex-style malware to steal credentials in one shot, but still ew.

well, I like absolutely nothing about that sentence

hobbesmaster
Jan 28, 2008

they probably also think they might be held liable for an employee stealing poo poo but not a hacker

Crust First
May 1, 2013

Wrong lads.
natwest does the same thing for online banking; seems to be a UK thing? super hate it.

cinci zoo sniper
Mar 15, 2013




what the gently caress is wrong with your idiot island

TjyvTompa
Jun 1, 2001

im gay

ThePeavstenator posted:

Isn't Peel Smart Remote super hosed for Samsung devices? I've heard that is does something like circumvent android API permissions and runs as root so it can draw ads on your screen at any time?

i'm not sure if it circumvents API permissions but it does show notifications all the time, even for stuff that is not useful just for the purpose of showing a notification, for example when you lock your phone it will show a notification that the phone is locked, it's also not possible to turn off the notifications without disabling the entire app, here's an example of how it can look: http://www.androidpolice.com/2017/03/29/peel-remote-app-upsets-users-ton-ads-lock-screen-overlays/

Chalks
Sep 30, 2009

Crust First posted:

natwest does the same thing for online banking; seems to be a UK thing? super hate it.



I get the same thing for the "verified by visa" security check password in the UK. Surely that's an international system though?

Pile Of Garbage
May 28, 2007



secfuck: my buddies twitter account got popped, now he's a sexy spambot https://twitter.com/acrocker13 :rip:

e: ok he's reclaimed control and cleaned it up

Pile Of Garbage fucked around with this message at 11:26 on Oct 30, 2017

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
edit: quote is not edit i am bad at forums.

Qtotonibudinibudet fucked around with this message at 10:01 on Oct 30, 2017

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

anatoliy pltkrvkay posted:

may his last post-spambot tweet live on in eternity. a rt of this:

https://twitter.com/heatheruu/status/922645348799021057

in not quite secfuck content news, a client of ours reported that their PCI auditor determined that they were not compliant due to lack of HPKP, and asked us how they could add it

gently caress PCI auditors.

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




Chalks posted:

I get the same thing for the "verified by visa" security check password in the UK. Surely that's an international system though?
not that i know of

  • Locked thread