Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
DrPossum
May 15, 2004

i am not a surgeon

Optimus_Rhyme posted:

I was gonna reply to a link to his awesome DEFCON talk but NOOOOOPE youtube took it down

https://www.youtube.com/watch?v=PfbMZJsb1cQ&hd=1

https://archive.org/details/youtube-PfbMZJsb1cQ

Adbot
ADBOT LOVES YOU

hobbesmaster
Jan 28, 2008

SeaborneClink posted:

you forgot the part of enterprise-grade security where there's only two groups that have access, one of them is read-only with a symbol-for-char substituted password and the elevated credentials are admin:admin.

sounds accurate

Workaday Wizard
Oct 23, 2009

by Pragmatica

thanks :tipshat:

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Jewel posted:

I still don't quite get it, it's hinting at RCE in battlenet but.. what is localbattle.net? Like, that's not a registered domain and I cant find anything in the battle.net client that hosts some kind of web interface access like some programs do. And googling that url only returns that taviso tweet.

my guess is localbattle.net is a local proxy that does Something with the authenticator and they're putting a local cert trust to handle it maaaaaybe with an identical private key on every install or maybe it can be used to validate for domains it shouldn't be who knows at this point

Truga
May 4, 2014
Lipstick Apathy
my guess is it's just accessible from the network and you can send it something it'll execute

hobbesmaster
Jan 28, 2008

well that’s a given but what was the likely design goal?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

My money is on Blackberry Stupid, like not bothering to do the work to support 2FA on the backend so its shimmed in through the local proxy

FCKGW
May 21, 2006

https://twitter.com/imnoah/status/936948776119537665

Proteus Jones
Feb 28, 2013




hahahahaha

Carbon dioxide
Oct 9, 2012


Wait a minute.

Waaaait a minute.

Does archive.org have copies of all DMCA'd youtube videos? Because that would be quite a big deal.

spankmeister
Jun 15, 2008






That would own

spankmeister
Jun 15, 2008






Surely they don't have the storage needed to scrape all of youtube

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

spankmeister posted:

Surely they don't have the storage needed to scrape all of youtube

they probably only scrape certain channels

that talk isn’t on def con’s media server fwiw

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

spankmeister posted:

That would own

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Carbon dioxide posted:

Wait a minute.

Waaaait a minute.

Does archive.org have copies of all DMCA'd youtube videos? Because that would be quite a s way more llikely to have them if the big deal.

It's way more likely to have them if the link had been spread widely before the thing got taken down.

Some random video a channel with 2 videos and 3 viewers ever puts up and gets taken down probably won't be grabbed.

FCKGW
May 21, 2006

https://twitter.com/magoo/status/939227346887884800

theft of 4700 bitcoins is $75,000,000

not bad for a couple hours work

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe
i feel like there should be an asterisk whenever a news article says something like "$75,000,000 of bitcoins were stolen!" because there's no way in hell the thieves are converting all those bitcoins to hard currency in any reasonable time frame and without setting off regulatory scrutiny and/or a market crash.

flakeloaf
Feb 26, 2003

Still better than android clock

what passes for regulatory scrutiny when it comes to butts

ShinsoBEAM!
Nov 6, 2008

"Even if this body of mine is turned to dust, I will defend my country."

Kuvo posted:

i feel like there should be an asterisk whenever a news article says something like "$75,000,000 of bitcoins were stolen!" because there's no way in hell the thieves are converting all those bitcoins to hard currency in any reasonable time frame and without setting off regulatory scrutiny and/or a market crash.

well yeah they will HODL until it's at least $200,000,000 in butts

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

flakeloaf posted:

what passes for regulatory scrutiny when it comes to butts
redditors jumping around on the top of the roof of a moving train http://www.independent.co.uk/life-s...ce-8981240.html

haveblue
Aug 15, 2005



Toilet Rascal
how soon we forget the crushing tyranny of THE BITLICENSE

canis minor
May 4, 2011


The blog linked has a summary of the vulnerabilities, which are indeed... interesting

quote:

An attacker can remotely unlock any safe in this product line through specially formatted Bluetooth messages, even with no knowledge of the pin code. The phone application requires the valid pin to operate the safe, and there is a field to supply the pin code in an authorization request. However the safe does not verify the pin code, so an attacker can obtain authorization and unlock the safe using any arbitrary value as the pin code.

In other news - HP left off another keylogger: https://www.scmagazineuk.com/hidden-hp-keylogger-found-preinstalled-on-models-dating-back-to-2012/article/713242/

canis minor fucked around with this message at 21:42 on Dec 11, 2017

FlapYoJacks
Feb 12, 2009
The fact that WS2016 has SMBv1 turned on by default is so bad I can't even describe it.

SeaborneClink
Aug 27, 2010

MAWP... MAWP!
So I'm having an argument at work with someone because a system grants all users admin access by default, however you can go in set the account to have read only access. They disagree that this is a problem.

That's my head in the sand SecFuck story.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

ratbert90 posted:

The fact that WS2016 has SMBv1 turned on by default is so bad I can't even describe it.

It's on out of box but turns itself off as some period of time when it determines it isn't in use. It's still not great, but better than it initially appears

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

ratbert90 posted:

The fact that WS2016 has SMBv1 turned on by default is so bad I can't even describe it.

at least they dropped 32bit finally, 6 years after osx did

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Perplx posted:

at least they dropped 32bit finally, 6 years after osx did
windows server hasn't had 32-bit versions since ws2008

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

my current secfuck story: work laptops and computers don’t have encrypted drives, no bitlocker no nothing.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Boiled Water posted:

my current secfuck story: work laptops and computers don’t have encrypted drives, no bitlocker no nothing.

lol hope you have TPMs in them

spankmeister
Jun 15, 2008






Current secfuck status: looking at the CRC implementation in proxmark firmware.

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

BangersInMyKnickers posted:

lol hope you have TPMs in them

how would it help with bitlocker turned off?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

because its trivial to rollout after the fact so long as you have tpm. if not, good luck getting people to remember their additional password/pin

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

there’s no plan to roll it out

it’s :psyduck: all the way down

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Got local admin? Cause turn that poo poo on anyway

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

BangersInMyKnickers posted:

lol hope you have TPMs in them

do anything other than rinkydink best buy specials not come with bitlocker capable TPM these days?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I know the Lenovo yoga and I think yoga 2 shipped without one

Shaggar
Apr 26, 2006
those are rinkydink best buy specials. see also: mac book pros.

theodop
Dec 30, 2005

rock solid, heart touching

Boiled Water posted:

there’s no plan to roll it out

it’s :psyduck: all the way down

I have another layer on this.

None of our work PCs have drive encryption because they're too busy bikeshedding the solution.

Their workaround? Nobody is allowed to purchase >128GB laptop hard drives, to prevent "too much" data being lost.

The upshot is that since the last Windows update I no longer have enough space to have VS2015 and 2017 installed simultaneously and I can't procure a larger HDD to do my loving job

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

theodop posted:

I have another layer on this.

None of our work PCs have drive encryption because they're too busy bikeshedding the solution.

Their workaround? Nobody is allowed to purchase >128GB laptop hard drives, to prevent "too much" data being lost.

The upshot is that since the last Windows update I no longer have enough space to have VS2015 and 2017 installed simultaneously and I can't procure a larger HDD to do my loving job

lmao do some sh/sc posters work in your it department or something

Adbot
ADBOT LOVES YOU

theodop
Dec 30, 2005

rock solid, heart touching

Cocoa Crispies posted:

lmao do some sh/sc posters work in your it department or something

big businesses make terrible decisions

  • Locked thread