Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
it was an issue in lots of places across the us today

Adbot
ADBOT LOVES YOU

Carbon dioxide
Oct 9, 2012

Ciaphas posted:

I like the "facebook and twitter are incestuous hitlerholes that need to be burned to the ground and salted ASAP and never ever replaced" hill myself, i'd die on that

In my experience at least half of software devs hate facebook. In society as a whole that number is a lot smaller, but still it has been growing.

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope
http://www.tomshardware.com/news/mantistek-gk2-collects-typed-keys,35850.html

MantisTek GK2 mechanical keyboard driver has a keylogger

who is MantisTek? some cheap chinese gadget manufacturer.

Truga
May 4, 2014
Lipstick Apathy
lol at that article title though. with brands like lenovo shipping bad spyware you're never safe.

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

At this point, if your network touchers haven't broken the entire internet with a bad bgp push, I'd check to make sure they're actually doing any work and not just playing dota in their cat5 lined nest all day.

ohgodwhat
Aug 6, 2005

I would rather my network touchers do that than try to do any real work

bicycle
Oct 23, 2013
https://paritytech.io/blog/security-alert.html

someone

quote:

It would seem that issue was triggered accidentally 6th Nov 2017 02:33:47 PM +UTC and subsequently a user suicided the library-turned-into-wallet, wiping out the library code which in turn rendered all multi-sig contracts unusable since their logic (any state-modifying function) was inside the library.



Issue thread: https://github.com/paritytech/parity/issues/6995

There are a large amount of previously-stuffed wallets that are a nice 0 ETH in balance right now.

Oh, and here's the guy who did it:



e: The figures floating around for impact are between $150m-270m lol

bicycle fucked around with this message at 15:21 on Nov 7, 2017

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

bicycle posted:

https://paritytech.io/blog/security-alert.html

someone




Issue thread: https://github.com/paritytech/parity/issues/6995

There are a large amount of previously-stuffed wallets that are a nice 0 ETH in balance right now.

Oh, and here's the guy who did it:


hahahahahaha

Proteus Jones
Feb 28, 2013



bicycle posted:

https://paritytech.io/blog/security-alert.html

someone




Issue thread: https://github.com/paritytech/parity/issues/6995

There are a large amount of previously-stuffed wallets that are a nice 0 ETH in balance right now.

Oh, and here's the guy who did it:



e: The figures floating around for impact are between $150m-270m lol

This is the future they want.

flakeloaf
Feb 26, 2003

Still better than android clock

no really guys cryptobucks are the future

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
BUTT










COIN

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
i'm the "added F1-security M8-contracts P0-dropeverything and removed F3-annoyance Z5-unconfirmed labels"

spankmeister
Jun 15, 2008






u-wot-M8?

Bulgogi Hoagie
Jun 1, 2012

We

bicycle posted:

https://paritytech.io/blog/security-alert.html

someone




Issue thread: https://github.com/paritytech/parity/issues/6995

There are a large amount of previously-stuffed wallets that are a nice 0 ETH in balance right now.

Oh, and here's the guy who did it:



e: The figures floating around for impact are between $150m-270m lol

nerds rapidly discover why smart contracts are not good

geonetix
Mar 6, 2011


but my special flavour of a blockchain and open contracts are the fut... no

haveblue
Aug 15, 2005



Toilet Rascal
this contract doesn't seem very smart at all!

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Truga posted:

lol at that article title though. with brands like lenovo shipping bad spyware you're never safe.

when i see lenovo i think cheap chinese crap

Truga
May 4, 2014
Lipstick Apathy
but then there's thinkpads which are passable? those are lenovo too.

post hole digger
Mar 21, 2011

Truga posted:

but then there's thinkpads which are passable? those are lenovo too.

lenovo thinkpads are bad.

Shame Boy
Mar 2, 2010

more like


































stinkpad!!!!!

Main Paineframe
Oct 27, 2010

bicycle posted:

https://paritytech.io/blog/security-alert.html

someone




Issue thread: https://github.com/paritytech/parity/issues/6995

There are a large amount of previously-stuffed wallets that are a nice 0 ETH in balance right now.

Oh, and here's the guy who did it:



e: The figures floating around for impact are between $150m-270m lol

so let me get this straight

an important library critical to some aspect of program or contract functionality was exposed to the contract system in such a way that it was possible to convert the library itself into a smart contract

this guy did that, then sent a delete command to that contract, causing the entire network to delete that library from loving everything

and it can't be undone, because the command to undo the delete depended on the library that's been deleted

CURRENCY OF THE FUTURE

bicycle
Oct 23, 2013
there are two possible things

it was a malicious attempt and the guy is pulling off the e-coin troll of the decade

or the guy accidentally rm'd $150m+ internet coins


I really can't decide which is funnier

Shame Boy
Mar 2, 2010

it's bitcoin, you know it's incompetence rather than malice

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

bicycle posted:

there are two possible things

it was a malicious attempt and the guy is pulling off the e-coin troll of the decade

or the guy accidentally rm'd $150m+ internet coins


I really can't decide which is funnier

the accident is way funnier

haveblue
Aug 15, 2005



Toilet Rascal
the accident is way funnier because it was other people's coins

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

that guy owns

Shame Boy
Mar 2, 2010

yeah i legit love this guy for being so adorably incompetent and oblivious, it's magical

like watching mr. bean accidentally set fire to a giant pile of money

post hole digger
Mar 21, 2011

post hole digger
Mar 21, 2011

Security Fuckup Megathread - v14.1 - i'm eth newbie..just learning

Workaday Wizard
Oct 23, 2009

by Pragmatica
stay safe noob ghost


i'd personally avoid any chinese or russians :tinfoil:

ate shit on live tv
Feb 15, 2004

by Azathoth

mrmcd posted:

At this point, if your network touchers haven't broken the entire internet with a bad bgp push, I'd check to make sure they're actually doing any work and not just playing dota in their cat5 lined nest all day.

We sent some BGP Communities to AT&T to accept our prefixes, but not advertise them to anyone else and so ATT did the logical thing and blackholed all traffic heading for our network by removing our prefix from their routing table. It was pretty cool.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
Security Fuckup Megathread - v14.1 - I accidentally killed it.

BattleMaster
Aug 14, 2000

'



life comes at you fast

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet



BattleMaster posted:

'



life comes at you fast

Security Fuckup Megathread - v14.2 - added P0-dropeverything and removed F3-annoyance

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
welp. a fairly high value investment firm i work for just got popped by one of those credential harvesting phishing messages, sent seemingly legitimately from another investment firm they work with, who evidently had their office 365 accounts breached some time ago and were unaware of it until now.

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

Pikavangelist posted:

Security Fuckup Megathread - v14.2 - added P0-dropeverything and removed F3-annoyance

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Pikavangelist posted:

Security Fuckup Megathread - v14.2 - added P0-dropeverything and removed F3-annoyance

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Pikavangelist posted:

Security Fuckup Megathread - v14.2 - added P0-dropeverything and removed F3-annoyance

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

infernal machines posted:

welp. a fairly high value investment firm i work for just got popped by one of those credential harvesting phishing messages, sent seemingly legitimately from another investment firm they work with, who evidently had their office 365 accounts breached some time ago and were unaware of it until now.

any additional details you can share? we love to send stories about this kind of stuff happening out as company-wide broadcasts to reinforce our "DON'T TRUST EMAIL" campaign


i understand if you can't though

Adbot
ADBOT LOVES YOU

Partycat
Oct 25, 2004

We have been having a rash of those with popped accounts at [EDU]

Only thing I noted is as they slowly roll in so far the user names being used seem to be coming in alphabetical order

  • Locked thread