Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Doom Mathematic
Sep 2, 2008

Truga posted:

"what's engine X?"

In my head I always pronounced it "en-jinx".

Adbot
ADBOT LOVES YOU

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Doom Mathematic posted:

In my head I always pronounced it "en-jinx".

it’s a hard G

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope
the n stands for tonic. the x also stands for tonic.

Shame Boy
Mar 2, 2010

Doom Mathematic posted:

In my head I always pronounced it "en-jinx".

me too but nobody understood what i was talking about so i had to conform :argh:

Truga
May 4, 2014
Lipstick Apathy
maybe if you'd called it ru-jinx, but that's kaspersky now

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Enjoin Ex

:divorce:

Workaday Wizard
Oct 23, 2009

by Pragmatica

Volmarias posted:

Enjoin Ex

:divorce:

too soon lol

fritz
Jul 26, 2003


i keep wanting the eyestalk to collapse in the manner that a tape measure would

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet




Troy Hunt's blog posted:

I’ve been speaking with the owner about SSL before I invest in becoming a member, but she’s been told by the dev of the platform (it’s a franchise system called ShopCity.com) that SSL is more about Google’s monopolizing visibility of content, and less to do with security

f^∞

Shame Boy
Mar 2, 2010

what does that even mean

like does he think chrome is the only thing capable of connecting to SSL :psyduck:

Bulgogi Hoagie
Jun 1, 2012

We
google project zero exists therefore fixing security bugs is a google monopolist plot

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
probably due to the google-symantec spat over ssl certs. they probably used a bunch of symantec ca issued certs that suddenly became untrusted and decided that was somehow google's fault

Schadenboner
Aug 15, 2011

by Shine

Keep reading. It just gets more and more :aaaaa:.

How is this PCI-compliant?

Schadenboner fucked around with this message at 17:21 on Nov 2, 2017

Phone
Jul 30, 2005

親子丼をほしい。

Schadenboner posted:

Keep reading. It just gets more and more :aaaaa:.

How is this PCI-compliant?

they got some stickers off of alibaba

Lightbulb Out
Apr 28, 2006

slack jawed yokel
is lastpass the bad one?

Proteus Jones
Feb 28, 2013



Lightbulb Out posted:

is lastpass the bad one?

Yes

wolrah
May 8, 2006
what?

infernal machines posted:

probably due to the google-symantec spat over ssl certs. they probably used a bunch of symantec ca issued certs that suddenly became untrusted and decided that was somehow google's fault
That would at least be an explanation for the stupidity, but at least looking at CT logs it looks like they experimented with Lets Encrypt about a year ago then did nothing.

https://crt.sh/?q=shopcity.com

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
is there an ecommerce platform that doesn't suck poo poo

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet



Schadenboner posted:

Keep reading. It just gets more and more :aaaaa:.

yeah, but those were different walking secfucks than the shopcambridge person

Thanks Ants
May 21, 2004

#essereFerrari


anthonypants posted:

is there an ecommerce platform that doesn't suck poo poo

magento seems alright

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:



what's wrong with lastpass, they're the best option i got since i can't bring a usb key with a keepass db on it to work or w/e

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer
Grey forum Firefox thread is advocating using insecure branch "waterfox" again because dammit the new version of Firefox broke their extension to "unfuck the ui"

Imagine being so afraid of change that you'll forgo security updates and trustworthiness of the browser you run just so you can have square tabs in the bottom of your screen.

Wiggly Wayne DDS
Sep 11, 2010



Ciaphas posted:

what's wrong with lastpass, they're the best option i got since i can't bring a usb key with a keepass db on it to work or w/e
downplaying breaches, security research, etc which all combined at the time meant all vaults were accessible by the attackers. this is without the repeated vulnerabilities allowing a site to grab any password it wants without any prompt. this is over the course of 5+ years with no visible progress in fixing the systemic issues but just fixing the public issues as they arise.

teamdest
Jul 1, 2007

Ciaphas posted:

what's wrong with lastpass, they're the best option i got since i can't bring a usb key with a keepass db on it to work or w/e

you can’t have a keepass dB but you can store your work passwords on some frequently-insecure third party site and install either their desktop client or their browser extension?

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

cis autodrag posted:

Grey forum Firefox thread is advocating using insecure branch "waterfox" again because dammit the new version of Firefox broke their extension to "unfuck the ui"

Imagine being so afraid of change that you'll forgo security updates and trustworthiness of the browser you run just so you can have square tabs in the bottom of your screen.

Waterfox isn't insecure its just lost its reason to exist when Firefox finally started issuing official 64 bit builds that didn't require alpha channel fuckery.

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

fishmech posted:

Waterfox isn't insecure its just lost its reason to exist when Firefox finally started issuing official 64 bit builds that didn't require alpha channel fuckery.

It's insecure in the sense that your trusting non Mozilla devs to always rapidly pull in security fixes and never do anything shady in their fork.

hobbesmaster
Jan 28, 2008

teamdest posted:

you can’t have a keepass dB but you can store your work passwords on some frequently-insecure third party site and install either their desktop client or their browser extension?

you can use your personal phone even if you can’t install the software

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


teamdest posted:

you can’t have a keepass dB but you can store your work passwords on some frequently-insecure third party site and install either their desktop client or their browser extension?

lol i don't put work passwords anywhere except in my head, lastpass is personal use only

and only on the internet research/goofoff machines (and i don't install the client, i just go to the website); work machines are airgapped

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


that said if lastpass is as full of holes as stated here i'll happily take recommendations for an alternative that's still internet accessible (which i'm aware inherently is a secfuck but not much other option for me atm)

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Ciaphas posted:

that said if lastpass is as full of holes as stated here i'll happily take recommendations for an alternative that's still internet accessible (which i'm aware inherently is a secfuck but not much other option for me atm)
first you're going to have to figure out what operating systems and mobile devices you use

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


just windows, i do very little on mobile that isn't phone, sms and google/email (which i remember separate from password lockers because it's so important)

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
then i'd suggest keep rear end, with the caveat that keep rear end probably has windows phone support, but since the platform is dead i wouldn't consider relying on it

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


keepass is what i was using until 10 years ago when i got my current job and had to stop keeping a usb key with the db and keepass executable on it with me

and i can't just install keepass on these machines, either, else i'd do that and keep my db on, i dunno, onedrive or something

Bulgogi Hoagie
Jun 1, 2012

We
https://twitter.com/lukasstefanko/status/926084558273044481

either pixel security is really good or no one targeted the pixel?

RFC2324
Jun 7, 2012

http 418

Ciaphas posted:

keepass is what i was using until 10 years ago when i got my current job and had to stop keeping a usb key with the db and keepass executable on it with me

and i can't just install keepass on these machines, either, else i'd do that and keep my db on, i dunno, onedrive or something

keep rear end portable doesn't need to be installed?

Schadenboner
Aug 15, 2011

by Shine

Bulgogi Hoagie posted:

https://twitter.com/lukasstefanko/status/926084558273044481

either pixel security is really good or no one targeted the pixel?

Android is literally already malware, it needs no further pwning.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Bulgogi Hoagie posted:

https://twitter.com/lukasstefanko/status/926084558273044481

either pixel security is really good or no one targeted the pixel?
no one targeted the pixel on days one or two

Dixie Cretin Seaman
Jan 22, 2008

all hat and one catte
Hot Rope Guy

Ciaphas posted:

that said if lastpass is as full of holes as stated here i'll happily take recommendations for an alternative that's still internet accessible (which i'm aware inherently is a secfuck but not much other option for me atm)

1password has a lastpass-style subscription where they host your vault (when you make your new vault your computer locally generates an authorization key that you need to enter the first time you need to authorize a new machine to download your encrypted vault. from there you use your vault password to decrypt and by default it keeps local encrypted copy of your vault in case you lose internet access). i think the non-subscription software is still sold and lets you use dropbox or icloud accounts for hosting your vault instead

chestnut santabag
Jul 3, 2006

Bulgogi Hoagie posted:

https://twitter.com/lukasstefanko/status/926084558273044481

either pixel security is really good or no one targeted the pixel?

well if the phone can't even boot then of course it's not gonna get broken into...

Adbot
ADBOT LOVES YOU

Carbon dioxide
Oct 9, 2012

The real problem with lastpass is that its firefox plugin UI is a horrible piece of poo poo.

  • Locked thread