Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

oh lordy ~*dabs sweat from brow*~

Adbot
ADBOT LOVES YOU

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


dangit qbitorrent is gonna be one isn't it

if it wasn't already

LethalGeek
Nov 4, 2009

I have to come in here to say jfc because jfc apple how did you find this level of gently caress up

Wasabi the J
Jan 23, 2008

MOM WAS RIGHT
I, for one, am SHOCKED the most popular methods of pirating digital content are targeted by hackers.

VikingofRock
Aug 24, 2008





YOSPOS > Security Fuckup Megathread - v14.2 - (hurray, you're the admin now)

Proteus Jones
Feb 28, 2013



VikingofRock posted:

YOSPOS > Security Fuckup Megathread - v14.2 - (hurray, you're the admin now)

Wiggly Wayne DDS
Sep 11, 2010



so i'm hearing it doesn't have to be blank, you can set the password to whatever you want (on initial root creation) for reasons

crazysim
May 23, 2004
I AM SOOOOO GAY

VikingofRock posted:

YOSPOS > Security Fuckup Megathread - v14.2 - (hurray, you're the admin now)

bicycle
Oct 23, 2013
https://twitter.com/Viss/status/935681868845932544

@viss touching the poop like a loving idiot

Workaday Wizard
Oct 23, 2009

by Pragmatica

bicycle posted:

https://twitter.com/Viss/status/935681868845932544

@viss touching the poop like a loving idiot

mycrimes.txt

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


I guess the nsa didn't need to compel apple to put in a backdoor after all huh

VikingofRock posted:

YOSPOS > Security Fuckup Megathread - v14.2 - (hurray, you're the admin now)

go play outside Skyler
Nov 7, 2005


that apple bug made me bookmark this again.

don't disappoint me thread

karoshi
Nov 4, 2008

"Can somebody mspaint eyes on the steaming packages? TIA" yeah well fuck you too buddy, this is the best you're gonna get. Is this even "work-safe"? Let's find out!
Android to add a malware persistence layer: https://source.android.com/devices/architecture/treble

Shifty Pony
Dec 28, 2004

Up ta somethin'


Ciaphas posted:

dangit qbitorrent is gonna be one isn't it

if it wasn't already

all withers under the roving eye of Tavis.

we'll be lucky if he doesn't find some way to cause the protocol itself to trigger remote execution

flakeloaf
Feb 26, 2003

Still better than android clock

distributed denial of copyright attack

Shame Boy
Mar 2, 2010

Rahu posted:

that is a funny way to spell deluge

deluge as a split client / server if you enjoy janitoring your own poo poo a lot

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

flakeloaf posted:

distributed denial of copyright attack

Achmed Jones
Oct 16, 2004



VikingofRock posted:

YOSPOS > Security Fuckup Megathread - v14.2 - (hurray, you're the admin now)

Qwijib0
Apr 10, 2007

Who needs on-field skills when you can dance like this?

Fun Shoe
deeper dive into why the macOS bug works

https://objective-see.com/blog/blog_0x24.html

Woodchip
Mar 28, 2010
you're an admin, hurray :science:

Proteus Jones
Feb 28, 2013



Qwijib0 posted:

deeper dive into why the macOS bug works

https://objective-see.com/blog/blog_0x24.html

Well, that explains why it "resets" to NULL if you disable root again.

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

bicycle posted:

https://twitter.com/Viss/status/935681868845932544

@viss touching the poop like a loving idiot

am i reading him correctly that apple remote desktop doesn't require any authentication whatsoever to tell you what the active application is and who is logged in

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

karoshi posted:

Android to add a malware persistence layer: https://source.android.com/devices/architecture/treble

This is actually a cool and good abstraction layer, I'm not sure why you're down on it.

spankmeister
Jun 15, 2008






go play outside Skyler posted:

that apple bug made me bookmark this again.

don't disappoint me thread

Whatever you're not even my real dad

karoshi
Nov 4, 2008

"Can somebody mspaint eyes on the steaming packages? TIA" yeah well fuck you too buddy, this is the best you're gonna get. Is this even "work-safe"? Let's find out!

Volmarias posted:

This is actually a cool and good abstraction layer, I'm not sure why you're down on it.

That page contains the word (trigger warning) "vendor" 12 times. There will be multiple vendor/ODM partitions that survive a system upgrade. Those are a juicy target. "SHIP IT!" vendor implementations will make those juicy targets easy to hit.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
The current alternative is effectively zero upgrades, and no chance of OS level security updates, so I'm not sure what's realistically being lost here.

karoshi
Nov 4, 2008

"Can somebody mspaint eyes on the steaming packages? TIA" yeah well fuck you too buddy, this is the best you're gonna get. Is this even "work-safe"? Let's find out!

Volmarias posted:

The current alternative is effectively zero upgrades, and no chance of OS level security updates, so I'm not sure what's realistically being lost here.

Sir, this is the SecLOL thread, not the sensible software architecture thread.

(I agree with that POV and I think it's a great way of keeping the OS upgraded, like iOS. It also adds new and exciting malware vectors. Now your sound driver can also inject a tracking DLL into every app. It might come preinstalled by your phone manufacturer (hello lenovo) or be a 3rd-party post initial boot add-on:nsallears:.)

apseudonym
Feb 25, 2011

karoshi posted:

That page contains the word (trigger warning) "vendor" 12 times. There will be multiple vendor/ODM partitions that survive a system upgrade. Those are a juicy target. "SHIP IT!" vendor implementations will make those juicy targets easy to hit.

It's an abstraction layer for vendor code, of course it loving includes the word vendor.

It also separates out vendor code and allows us to better isolate it, it's an all around good thing.

apseudonym
Feb 25, 2011

karoshi posted:

Sir, this is the SecLOL thread, not the sensible software architecture thread.

(I agree with that POV and I think it's a great way of keeping the OS upgraded, like iOS. It also adds new and exciting malware vectors. Now your sound driver can also inject a tracking DLL into every app. It might come preinstalled by your phone manufacturer (hello lenovo) or be a 3rd-party post initial boot add-on:nsallears:.)

No, the vendor code cannot inject a tracking dll into apps.

Wiggly Wayne DDS
Sep 11, 2010



another oddity:

https://twitter.com/Viss/status/935943453615124480

Diva Cupcake
Aug 15, 2005

this is now my favorite thing

https://twitter.com/SweeneyABC/status/935942616167960576

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lol i booked a flight with american for christmas :waycool:

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



guess its fixed now

https://support.apple.com/en-us/HT208315

Workaday Wizard
Oct 23, 2009

by Pragmatica

please be real :evilbuddy:

haveblue
Aug 15, 2005



Toilet Rascal

it's fixed and apple seems to have taken the very rare step of making the update a mandatory insta-install

Condiv
May 7, 2008

Sorry to undo the effort of paying a domestic abuser $10 to own this poster, but I am going to lose my dang mind if I keep seeing multiple posters who appear to be Baloogan.

With love,
a mod


tons of posts on reddit about "well, if you have local access to the computer then you can do anything so when you think about it this is NBD" with regards to the apple root hole

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Condiv posted:

tons of posts on reddit about "well, if you have local access to the computer then you can do anything so when you think about it this is NBD" with regards to the apple root hole
https://www.youtube.com/watch?v=DOqb_UzJSUQ&hd=1

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).


Blessed are the cjs, for they alone shall save or sabotage the masters' tools.

Proteus Jones
Feb 28, 2013




omg

Adbot
ADBOT LOVES YOU

haveblue
Aug 15, 2005



Toilet Rascal

5

  • Locked thread