Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe
https://www.youtube.com/watch?v=DXB988kF3hI

Adbot
ADBOT LOVES YOU

hobbesmaster
Jan 28, 2008

Avenging_Mikon posted:

It just seems like the fact recording happened should be more important than what was recorded. If I went and downloaded this on Friday and had a quiet weekend alone, then Monday morning find out it’s recorded me I’m less deserving of legal protection?

then you file something that says “this application was recording without my permission during the hours of x and y during which I was in my house. recording of conversations within ones house is protected by z law as ruled on...”.

you have to specifically accuse them of something not vaguely say “this could’ve done something”. now you can do discovery and ask for all recordings from your phone as well as anything sent to their server from your phone in the future or whatever

an actual lawyer and not someone that looked at becoming one and said “gently caress that” could elaborate

hobbesmaster fucked around with this message at 22:45 on Nov 27, 2017

Wiggly Wayne DDS
Sep 11, 2010



34c3 talks, help me figure out which ones are worth prioritising https://halfnarp.events.ccc.de

spankmeister
Jun 15, 2008






Wiggly Wayne DDS posted:

34c3 talks, help me figure out which ones are worth prioritising https://halfnarp.events.ccc.de

Here's my picks:


Workaday Wizard
Oct 23, 2009

by Pragmatica
two talks on intel me already 😰

Wiggly Wayne DDS
Sep 11, 2010



spankmeister posted:

Here's my picks:



good news i have all those marked. 50 to be evaluated, although i only expect something new out of a quarter at most, half are just in-case an interesting detail appears, rest are to see what they actually want to present

Varkk
Apr 17, 2004

flakeloaf posted:

it's the self-help book, but in app form

resolving to take less poo poo and speak up in meetings is the hard part; once you've done that, what can an app do that a sticky note or a piece of string on your pen can't? just say the words and if todd talks across you, tell todd to not talk while you're speaking and keep right on truckin

gently caress you todd

The app provides actual objective measurements of how much you spoke. Of course it doesn’t give any weight to the quality of the words. We all know at least one person who drive bed on and on around in circles for 90% of any meeting.
It probably does it by uploading the full recording of your meeting to Mechanical Turk.

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

Wiggly Wayne DDS posted:

34c3 talks, help me figure out which ones are worth prioritising https://halfnarp.events.ccc.de

i hope you continue to do the write ups/recomendations for these because the ones last year were real good

Shinku ABOOKEN posted:

two talks on intel me already 😰

these

Kuvo fucked around with this message at 23:39 on Nov 27, 2017

Workaday Wizard
Oct 23, 2009

by Pragmatica

Kuvo posted:

i hope you continue to do the write ups/recomendations for these because the ones last year were real good

spankmeister
Jun 15, 2008






I'm actually going this year :woop:

Midjack
Dec 24, 2007



Kuvo posted:

i hope you continue to do the write ups/recomendations for these because the ones last year were real good

Phobeste
Apr 9, 2006

never, like, count out Touchdown Tom, man

Kuvo posted:

i hope you continue to do the write ups/recomendations for these because the ones last year were real good

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

ate all the Oreos posted:

here it is, excuse the lovely mashable link it's the first google result: http://mashable.com/2017/10/18/allai-app-speak-up-in-meetings/#B8xmWO6_DOqx

I thought nothing could top LinkedIn expecting you to willingly send all of your company's email through their servers.

I was wrong.

Kuvo posted:

i hope you continue to do the write ups/recomendations for these because the ones last year were real good

vOv
Feb 8, 2014

Avenging_Mikon posted:

It just seems like the fact recording happened should be more important than what was recorded. If I went and downloaded this on Friday and had a quiet weekend alone, then Monday morning find out it’s recorded me I’m less deserving of legal protection?

iirc some data breach related lawsuits have been thrown out because even though the plaintiff could easily show their information was exposed, they failed to show that they were harmed by it

e: yeah, here's an article, and here's one where scotus said that civil rights groups couldn't sue over a warrantless wiretapping act because they couldn't show any concrete harm

vOv fucked around with this message at 06:09 on Nov 28, 2017

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

vOv posted:

here's one where scotus said that civil rights groups couldn't sue over a warrantless wiretapping act because they couldn't show any concrete harm

That's the most galling one, because by definition there's no way you could actually prove standing outside of a major gently caress up, and then when the major gently caress up actually serendipitously lands in your lawyer's lap, the "lack of harm" of someone "just" listening to your private conversations makes it A-OK. It's the most intentionally short sighted and obsequious decision imaginable but it's ok because the defendants are brown and it would never happen to hurt real, patriotic Americans with nothing to hide.

AARP LARPer
Feb 19, 2005

THE DARK SIDE OF SCIENCE BREEDS A WEAPON OF WAR

Buglord

vOv posted:

iirc some data breach related lawsuits have been thrown out because even though the plaintiff could easily show their information was exposed, they failed to show that they were harmed by it.

Yep. You have the Supreme Court's Spokeo decision to thank for this.

flakeloaf
Feb 26, 2003

Still better than android clock

vOv posted:

iirc some data breach related lawsuits have been thrown out because even though the plaintiff could easily show their information was exposed, they failed to show that they were harmed by it

proving damages is sort of an important part of suing someone, though isn't it?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
I'm listening to your every word, watching your every move, and reading every message you send. I'm not physically harming you, I'm just stalking you. No one is getting hurt here right, so what's the problem?

flakeloaf
Feb 26, 2003

Still better than android clock

intrusion on seclusion is a tort in lots of places; i live in such a place and "but you suffered no harm" is definitely a mitigating factor in calculating damages. it's more statutory relief/punitive damage than it is an attempt to compensate you or make you whole

also that's rather different than you dropping something i asked you to hold

e: https://www.canlii.org/en/on/onca/doc/2012/2012onca32/2012onca32.html

flakeloaf fucked around with this message at 15:33 on Nov 28, 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Kuvo posted:

i hope you continue to do the write ups/recomendations for these because the ones last year were real good

geonetix
Mar 6, 2011


in theory you can be harmed by any kind of data exposed, as - this is an example given to me recently in a gdpr seminar - even the kind of music you listen to may be of influence on, for example, the interest on your mortgage. if you have to pay half a percent extra because your profile is unfavorable, you’re harmed by that information being public. harm often wrongly thought of as purely physical but lol internet and privacy

geonetix
Mar 6, 2011


also the gdpr seminar used that example because our tax service found that Bach listeners in general pay on time and correctly, so this information could be used in your advantage too of course

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://twitter.com/cglyer/status/935520759358918657

this is pretty interesting and its got me looking for more examples of data exfiltration obfuscation.

bicycle
Oct 23, 2013

Kuvo posted:

i hope you continue to do the write ups/recomendations for these because the ones last year were real good


lol i've gone the last two years and last year I went to the talks I wouldn't usually go to because I knew Wiggly would have the good recommendations to watch later

also if anyone is physically attending and would like to hang out lemme know

Just-In-Timeberlake
Aug 18, 2003
http://www.zdnet.com/article/nsa-leak-inscom-exposes-red-disk-intelligence-system/

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.



subtle

Daman
Oct 28, 2011
there's a new password manager i saw some sec people talking abouit

https://www.remembear.com/

can someone evaluate it for fuckups pls it sounds too good (also the bear art on the main page is a little weird)

Schadenboner
Aug 15, 2011

by Shine

Daman posted:

(also the bear art on the main page is a little weird)

gently caress you, you anti-ursite son of a bitch.

Schadenboner fucked around with this message at 19:34 on Nov 28, 2017

flakeloaf
Feb 26, 2003

Still better than android clock

if it's got autofill i think i know how that audit's gonna go

DONT THREAD ON ME
Oct 1, 2002

by Nyc_Tattoo
Floss Finder

Daman posted:

there's a new password manager i saw some sec people talking abouit

https://www.remembear.com/

can someone evaluate it for fuckups pls it sounds too good (also the bear art on the main page is a little weird)

it's a honeypot

Wiggly Wayne DDS
Sep 11, 2010



Daman posted:

there's a new password manager i saw some sec people talking abouit

https://www.remembear.com/

can someone evaluate it for fuckups pls it sounds too good (also the bear art on the main page is a little weird)
if you check their blog one of their two entries is a security audit in August posted Nov 21 2017: https://www.remembear.com/blog/remembear-security-audit/

they're yelling about no critical vulnerabilities found in the long security audit (25 days spread over 6 modules), but end of the day it's a password manager. the first check you'd do before bringing in outside auditors is make sure the domain detector was functional:

quote:

RMB-01-001 Mac/iOS/Android/Win: Faulty domain detection leaks passes (High)

As any password manager, RememBear is evaluates each loaded URL and matches it against stored vault items. If a user has saved a username and password combination for the URL, the application offers a possibility to automatically fill and submit the credentials. However, it was discovered that the currently deployed algorithm for URL parsing is faulty. Specifically, the algorithm attempts to detect and remove top level domains to extract the host part. This is because the current design treats subdomains in the same way as the main domain.

It can be observed that since the algorithm is removing up to two top level domains, it actually treats victim.co.uk, victim.com, victim.de and even test.victim.co.at as if they were identical. By this logic, it proposes to autofill the same user-credentials for all these domains as if they were equivalent. This behavior could trick a user into revealing their credentials, as they may end up submitting them to an attacker-controlled website.

The described behavior can be found on the Windows and Mac platforms in the Chrome extension, as well as in the vault software. Moreover, it is also present in both the mobile RememBear browser application and in the native browser. In order to solve this problem, the entire hostname should ideally be used for the process of credential storage matching. This is the simplest solution and would completely eliminate attacks against the core logic employed in the hostname matching
algorithm at present. If this approach is not feasible, it is recommended to review the domain validation process and ensure that the last two or three components of the hostname are used, making the process dependent on the received value.

To clarify, some examples on handling the matter are specified next.
  • If a domain like victim.co.uk or https://www.victim.co.uk is received, the entire three last sections of the hostname should be used, i.e. victim.co.uk.
  • If a domain like victim.com or https://www.victim.com is received, then the last two sections should be sufficient, i.e. victim.com.

Finally, if neither of these approaches can be implemented, another option would be to review the domain validation process and ensure that ccSLDs are detected properly. Although there is no complete list of ccSLDs available, a good starting point can be the public suffix list maintained by Mozilla1 . As this list is mostly maintained for browser purposes - like cookies - it requires some manual work when one seeks to extract ccSLDs, which are conversely important in a specific context of a password manager rather than generally for browsers.
beyond that it's hard to trust a security audit that nadim was involved in, and i don't recall tunnelbear having a memorable security track record. i don't know what your security model is beyond trend of the day if you're rushing to move everything to this

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

have all the fun generating those ccSLD lists. the browser eTLD ones are a joy to maintain

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE

spankmeister posted:

Here's my picks:




uhhhh you forgot the session on how 2 drift

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Daman posted:

there's a new password manager i saw some sec people talking abouit

https://www.remembear.com/

can someone evaluate it for fuckups pls it sounds too good (also the bear art on the main page is a little weird)

i think the bear is cute, and also theyre my best friend now

Bulgogi Hoagie
Jun 1, 2012

We
lol just reproduced this

https://twitter.com/lemiorhan/status/935581020774117381

Truga
May 4, 2014
Lipstick Apathy

Wiggly Wayne DDS posted:

RMB-01-001 Mac/iOS/Android/Win: Faulty domain detection leaks passes (High)

ah, the lastbear

Truga
May 4, 2014
Lipstick Apathy

Bulgogi Hoagie posted:

lol just reproduced this

who wants to bet this is a feature their support uses to help moms and dads get back into their locked computer

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
Forgotten you password ? No problem

Wiggly Wayne DDS
Sep 11, 2010



well that's an impressive bug

Adbot
ADBOT LOVES YOU

Zil
Jun 4, 2011

Satanically Summoned Citrus


Truga posted:

who wants to bet this is a feature their support uses to help moms and dads get back into their locked computer

I would kill for some kind of backdoor like this with some of my users, so yeah going to guess this is the case.

  • Locked thread