Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


RISCy Business posted:

you wouldn't download a blowjob

Adbot
ADBOT LOVES YOU

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



im a fellatio bot! stop all the downloadin’

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Heavy_D posted:

yeah, as raymond would say you're already on the other side of the airtight seal

really want to see raymond's reaction to "hey someone referenced your work in response to a security issue about internet blowjobs"

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Powaqoatse posted:

im a fellatio bot! stop all the downloadin’

help fellatio bot

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl
fuckin' robots putting good honest fellatio barns out of business!

jre
Sep 2, 2011

To the cloud ?



flakeloaf posted:

so the system where a total stranger can give instructions to the robot strapped to your dick is flawed because there's an xss exploit on the site that wait can we go back to the first part again

pseudorandom name
May 6, 2007

that's funny, but the second part means you can send arbitrary USB packets to the blowjob device instead of merely sending arbitrary blowjobs using the first part

so if the device firmware is smart enough to refuse your custom squid beak blowjob, well, then you can just replace the firmware via malformed USB commands

Heresiarch
Oct 6, 2005

Literature is not exhaustible, for the sufficient and simple reason that no single book is. A book is not an isolated being: it is a relationship, an axis of innumerable relationships.
i wrote this as a joke back in feb 2015 for one of the bitcoin threads

code:
Vulnerability Summary for CVE-2032-1102

Original release date: 07/01/2032

Last revised: 07/01/2032

Source: US-CERT/FDA

Overview:
Use-after-free vulnerability in QuickGenitals Open Firmware versions 2.01.2a and higher allow for remote
denial of service attacks on all compatible hardware and remote arbitrary code execution on specific models.

A modified HNDJ server or QG-compatible jerkphone can deliver specially-crafted commands that can
override normal QGOF controls and shut down the connected hardware completely, requiring a cold restart.
Some models can have their speed and duration settings modified, and in one documented case the safety
interlocks were disabled entirely leading to physical injury.

This vulnerability is being actively exploited. Users of QGOF-compatible devices are strongly encouraged to
either avoid using their equipment until an update is available is available for their device, or to connect
only to trusted HNDJ servers and end-users.
i'm not sure how i feel about this

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Heresiarch posted:

i wrote this as a joke back in feb 2015 for one of the bitcoin threads

code:
Vulnerability Summary for CVE-2032-1102

Original release date: 07/01/2032

Last revised: 07/01/2032

Source: US-CERT/FDA

Overview:
Use-after-free vulnerability in QuickGenitals Open Firmware versions 2.01.2a and higher allow for remote
denial of service attacks on all compatible hardware and remote arbitrary code execution on specific models.

A modified HNDJ server or QG-compatible jerkphone can deliver specially-crafted commands that can
override normal QGOF controls and shut down the connected hardware completely, requiring a cold restart.
Some models can have their speed and duration settings modified, and in one documented case the safety
interlocks were disabled entirely leading to physical injury.

This vulnerability is being actively exploited. Users of QGOF-compatible devices are strongly encouraged to
either avoid using their equipment until an update is available is available for their device, or to connect
only to trusted HNDJ servers and end-users.
i'm not sure how i feel about this
and it only took us two years instead of 15!

p.s. welcome back heresiarch

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Heresiarch posted:

i wrote this as a joke back in feb 2015 for one of the bitcoin threads

code:
Vulnerability Summary for CVE-2032-1102

Original release date: 07/01/2032

Last revised: 07/01/2032

Source: US-CERT/FDA

Overview:
Use-after-free vulnerability in QuickGenitals Open Firmware versions 2.01.2a and higher allow for remote
denial of service attacks on all compatible hardware and remote arbitrary code execution on specific models.

A modified HNDJ server or QG-compatible jerkphone can deliver specially-crafted commands that can
override normal QGOF controls and shut down the connected hardware completely, requiring a cold restart.
Some models can have their speed and duration settings modified, and in one documented case the safety
interlocks were disabled entirely leading to physical injury.

This vulnerability is being actively exploited. Users of QGOF-compatible devices are strongly encouraged to
either avoid using their equipment until an update is available is available for their device, or to connect
only to trusted HNDJ servers and end-users.
i'm not sure how i feel about this

I'm rather explicitly the jerkphone

Edit:

anatoliy pltkrvkay posted:

Security Fuckup Megathread - v14.2 - Why won't you XSS me after a blowjob?

:eyepop:

Volmarias fucked around with this message at 06:16 on Nov 23, 2017

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
Security Fuckup Megathread - v14.2 - Why won't you XSS me after a blowjob?

WeedlordGoku69
Feb 12, 2015

by Cyrano4747

pseudorandom name posted:

that's funny, but the second part means you can send arbitrary USB packets to the blowjob device instead of merely sending arbitrary blowjobs using the first part

so if the device firmware is smart enough to refuse your custom squid beak blowjob, well, then you can just replace the firmware via malformed USB commands

tbh the primary application i see for this is, hacking blowjob machines to chew men's dicks off

not bite, chew

redleader
Aug 18, 2005

Engage according to operational parameters

LORD OF BOOTY posted:

tbh the primary application i see for this is, hacking blowjob machines to chew men's dicks off

not bite, chew

please don't kinkshame

fins
May 31, 2011

Floss Finder

anatoliy pltkrvkay posted:

Security Fuckup Megathread - v14.2 - Why won't you XSS me after a blowjob?

MononcQc
May 29, 2007

Fixing the security of teledildonics is a PPSPACE problem

Proteus Jones
Feb 28, 2013



anatoliy pltkrvkay posted:

Security Fuckup Megathread - v14.2 - Why won't you XSS me after a blowjob?

Zil
Jun 4, 2011

Satanically Summoned Citrus


LORD OF BOOTY posted:

tbh the primary application i see for this is, hacking blowjob machines to chew men's dicks off

not bite, chew

Sending bad bits to byte your dick

Zil fucked around with this message at 20:40 on Nov 23, 2017

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?
Unrelated to internet pocket pussies, I was wondering:

is there any reason beyond laziness that iOS apps don't use the password manager built-in, so you don't have to stay logged in, and don't need to make a "phone-type" password?

Grassy Knowles
Apr 4, 2003

"The original Terminator was a gritty fucking AMAZING piece of sci-fi. Gritty fucking rock-hard MURDER!"

Avenging_Mikon posted:

Unrelated to internet pocket pussies, I was wondering:

is there any reason beyond laziness that iOS apps don't use the password manager built-in, so you don't have to stay logged in, and don't need to make a "phone-type" password?

are you asking why they don't use the relatively new and platform-dependent password manager or why they don't have the login as a webview with a share sheet link that allows something like 1password to link in?

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
yeah, apps either don't support any sort of password management o skip straight to touch-id which is arguably less secure

apple really needs to support different touch-id levels

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

Grassy Knowles posted:

are you asking why they don't use the relatively new and platform-dependent password manager or why they don't have the login as a webview with a share sheet link that allows something like 1password to link in?

I’m asking why, on an app designed for that platform, does it not take advantage of that platform’s password store. I’m not familiar with iOS development and restrictions, this is a legit question.

Hell, the second version of the question you made is good too. I know the basics about security, so seeing how so many websites push using their custom app I don’t see why they don’t make any kind of effort to make password manager use feasible past an awkward copy and paste that doesn’t always work.

Please, effort post at me.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

MononcQc posted:

Fixing the security of teledildonics is a PPSPACE problem

minato
Jun 7, 2004

cutty cain't hang, say 7-up.
Taco Defender

Volmarias posted:

I'm rather explicitly the jerkphone
Is that what the jerkstore calls you on to say they're running out of lube?

Bulgogi Hoagie
Jun 1, 2012

We

Avenging_Mikon posted:

Unrelated to internet pocket pussies, I was wondering:

is there any reason beyond laziness that iOS apps don't use the password manager built-in, so you don't have to stay logged in, and don't need to make a "phone-type" password?

most apps i use have upgraded to integrate keychain

Bulgogi Hoagie
Jun 1, 2012

We
https://twitter.com/joernchen/status/933707416679612416

Proteus Jones
Feb 28, 2013




Uh oh.

EVGA Longoria
Dec 25, 2005

Let's go exploring!

Avenging_Mikon posted:

I’m asking why, on an app designed for that platform, does it not take advantage of that platform’s password store. I’m not familiar with iOS development and restrictions, this is a legit question.

Hell, the second version of the question you made is good too. I know the basics about security, so seeing how so many websites push using their custom app I don’t see why they don’t make any kind of effort to make password manager use feasible past an awkward copy and paste that doesn’t always work.

Please, effort post at me.

i've started seeing the key icon on the bar above the keyboard in every app password field, so i think apple might've fixed that?

still annoyed most of them don't save it that way during sign up, though

geonetix
Mar 6, 2011



Isn't that just the github issues page?

Grassy Knowles
Apr 4, 2003

"The original Terminator was a gritty fucking AMAZING piece of sci-fi. Gritty fucking rock-hard MURDER!"

Avenging_Mikon posted:

I’m asking why, on an app designed for that platform, does it not take advantage of that platform’s password store. I’m not familiar with iOS development and restrictions, this is a legit question.

Hell, the second version of the question you made is good too. I know the basics about security, so seeing how so many websites push using their custom app I don’t see why they don’t make any kind of effort to make password manager use feasible past an awkward copy and paste that doesn’t always work.

Please, effort post at me.

The extent of my personal knowledge of ios app development was exhausted in my question, I don't know the answer either--except that the iOS password store was only accessible to Safari until iOS 11, so it may require updates to apps? I do know I massively prefer the share sheet to the iCloud password manager.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

minato posted:

Is that what the jerkstore calls you on to say they're running out of lube?

Why would you get your lube from the jerk store, let alone so much and so frequently that they'd call you to give you a heads up?

A shameful lube user.

Phrosphor
Feb 25, 2007

Urbanisation

Our CSO wants me to setup NAC on every single desk and wall port in a new office. My plan of only patching the six we need (and ensuring NAC on them) is apparently not secure enough and I need to ensure that the unpatched ports are also safe..

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Phrosphor posted:

Our CSO wants me to setup NAC on every single desk and wall port in a new office. My plan of only patching the six we need (and ensuring NAC on them) is apparently not secure enough and I need to ensure that the unpatched ports are also safe..

i mean if someone has access to your switches to patch cable you're probably boned anyway, seems like a pointless exercise

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
are they just doing one of those checkbox security audit things that people with cissp's are really into

abigserve
Sep 13, 2009

this is a better avatar than what I had before
we had a security audit once and it was laughable, bikeshedding in the most purest form. We have a bunch of real architectural problems that need solving but none of those were even brought up and instead we got this hundred-point long bullet list filled with poo poo like "make sure each security domain uses different colored patch cables". yeah cheers can you define what our security domains even are?

Jewel
May 2, 2009

i dont want to thumbnail the first tweet of the thread but holy poo poo read it; pee tape is almost here https://twitter.com/RespectableLaw/status/933772881737240583

ErIog
Jul 11, 2001

:nsacloud:
They're in the middle of a security audit here at work, and it's been great. They've taken to scanning the network for VPN's and mailing the network infrastructure team when they find one with screenshots from Shodan.

Their office doesn't have any information about usage, and so every e-mail from them treats this like an intrusion.

edit: Forgot the best part. They leap-frogged the network infrastructure team to send an e-mail to end-users asking them to run a linked script as admin on every one of their Windows machines and e-mail back the results. All communication about network security usually goes through that team, and they've decided to phish their own organization instead.

ErIog fucked around with this message at 10:50 on Nov 24, 2017

Bulgogi Hoagie
Jun 1, 2012

We

Jewel posted:

i dont want to thumbnail the first tweet of the thread but holy poo poo read it; pee tape is almost here https://twitter.com/RespectableLaw/status/933772881737240583

i don’t want to ruin your day but this guy seems to be taking the piss

because it’s from kanye west’s famous

Bulgogi Hoagie fucked around with this message at 10:50 on Nov 24, 2017

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Bulgogi Hoagie posted:

i don’t want to ruin your day but this guy seems to be taking the piss

because it’s from kanye west’s famous

that said, the piss tape is definitely real

Jewel
May 2, 2009

why does everyone ruin my hopes and dreams

vv Well, he only "did the analysis", not "leaked" the original video

Jewel fucked around with this message at 12:20 on Nov 24, 2017

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Jewel posted:

why does everyone ruin my hopes and dreams
if you honestly put any faith in reddit user PickleRick_69 then you deserve worse than that

  • Locked thread