Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
spankmeister
Jun 15, 2008






someone should register the .local gTLD

Adbot
ADBOT LOVES YOU

thebigcow
Jan 3, 2001

Bully!
https://www.law360.com/cases/5a3988a7bb15e84b4f000001?article_sidebar=1

Ars is being sued over articles about that password manager in Windows.

Malcolm XML
Aug 8, 2009

I always knew it would end like this.

spankmeister posted:

someone should register the .local gTLD

can't it's reserved for mdns

Wiggly Wayne DDS
Sep 11, 2010



it is misleading to call them a cybersecurity company

e: complaint https://www.documentcloud.org/documents/4333677-Keeper-Security-Inc-v-Goodin-et-al.html

they're currently making the target on their back as large as possible going by twitter and every researcher focusing on them

e2: main point of the complaint is this insanity:

Wiggly Wayne DDS fucked around with this message at 18:58 on Dec 20, 2017

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

spankmeister posted:

someone should register the .local gTLD

i think microsoft started telling people not to use that for internal domains about 17 years ago, naturally i still see it everywhere

Shame Boy
Mar 2, 2010

infernal machines posted:

i think microsoft started telling people not to use that for internal domains about 17 years ago, naturally i still see it everywhere

it's specifically required by mDNS as part of the IETF standard so

e: actually microsoft seems real conflicted on whether you should or should not use it lol

https://en.wikipedia.org/wiki/.local

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
when i say everywhere i mean in business AD networks with name servers, i.e. places where mDNS should not be in use

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

mDNS is good and righteous in all environments

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Wiggly Wayne DDS posted:

do they notify for all potentially vulnerable configurations?
it was literally this one precise thing then a note about "by the way you might want to change the default encryption to aes "


Subjunctive posted:

is the vulnerability “your data isn’t encrypted”, or something else that is revealed by that configuration change?

no idea and it's not something I use so I have no clue why I got sent it :shrug:

idk if this is going to be a thing now but seeing as we were running unsupported. Net versions in production until recently I'm guessing someone just got really excited about it and decided to blast it at all of IT and everything else is still as disorganised as before

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


spankmeister posted:

someone should register the .local gTLD

didn't Google register .dev recently which caused some weird stuff for people using the domain for environment settings?

necrotic
Aug 2, 2005
I owe my brother big time for this!
Yup https://www.iana.org/domains/root/db/dev.html

thebigcow
Jan 3, 2001

Bully!
Is .example still reserved for documentation? You could always use companyname.example

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

thebigcow posted:

Is .example still reserved for documentation? You could always use companyname.example

yes

Varkk
Apr 17, 2004

infernal machines posted:

i think microsoft started telling people not to use that for internal domains about 17 years ago, naturally i still see it everywhere

Server essentials was still using it in at least 2012R2. In fact the build domain tool in it asked for a name, then automatically tacked .local to the end.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
server 2016 essentials does this too

microsoft is real schizophrenic about it, but their ad best practices have been relatively consistent re: don't do it

the fact that a small business product explicitly contravenes their own best practices is the least surprising thing ever, for example, every release of small business server and server essentials

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Powerful Two-Hander posted:

didn't Google register .dev recently which caused some weird stuff for people using the domain for environment settings?

and for everyone using http://pow.cx/ which defaults to .dev, since chrome requires .dev urls to be https

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
their sample text uses .test

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

infernal machines posted:

their sample text uses .test

yeah they changed a month ago, since the last time i looked

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



imo use the poop emoji for your internal tld

minato
Jun 7, 2004

cutty cain't hang, say 7-up.
Taco Defender
intranet of poo poo

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


minato posted:

intranet.poo poo

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

Powaqoatse posted:

imo use the poop emoji for your internal tld

please don't disrespect #sirpatstew like that

fe: https://www.youtube.com/watch?v=qkJYy9byRmg

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Wiggly Wayne DDS posted:

it is misleading to call them a cybersecurity company

e: complaint https://www.documentcloud.org/documents/4333677-Keeper-Security-Inc-v-Goodin-et-al.html

they're currently making the target on their back as large as possible going by twitter and every researcher focusing on them

e2: main point of the complaint is this insanity:



"Goodin knew these statements were false" lol i'd love to see their argument for that one

30 TO 50 FERAL HOG
Mar 2, 2005



infernal machines posted:

i think microsoft started telling people not to use that for internal domains about 17 years ago, naturally i still see it everywhere

yeah but they have, of course, provided no way to easily change a domain name so were gonna be using .local forever because lmao at creating a new domain and migrating stuff over

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

NEED MORE MILK posted:

yeah but they have, of course, provided no way to easily change a domain name so were gonna be using .local forever because lmao at creating a new domain and migrating stuff over

yeah, i had to modernize an old single label domain a couple years ago and welp, the process is to make a new domain

modern windows server does not like single label domain names. neither does anything else

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

cheese-cube posted:

wtf?

https://twitter.com/taviso/status/941710362717470720

apparently microsoft are bundling a vulnerable version of keeper with win10 because...?

good to know that Keeper made the same mistake as that guy in sh/sc who wrote his own password manager that runs its js in the context of the page youre trying to log into

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Farmer Crack-rear end posted:

"Goodin knew these statements were false" lol i'd love to see their argument for that one

are they suing tavis too?

Proteus Jones
Feb 28, 2013



Rufus Ping posted:

good to know that Keeper made the same mistake as that guy in sh/sc who wrote his own password manager that runs its js in the context of the page youre trying to log into

poo poo, *that* dude. I had forgotten about his helpful tool. I love that it's configuration had a setting for "7 primes" (all under 10000) and one of the defaults was the square of 11 or 12 or something.

Raere
Dec 13, 2007

Use .contoso for internal stuff

Inexplicable Humblebrag
Sep 20, 2003

dot enormous prime number that changes weekly for security purposes

spankmeister
Jun 15, 2008






01189998819991197253

Truga
May 4, 2014
Lipstick Apathy

infernal machines posted:

are they suing tavis too?

they're not gonna sue google lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/briankrebs/status/943862578740113409

i love how that error message is "SOMEONE IS HACKING YOUR GIBSON" but we all interpret it as "lol this idiot company hosed the hell up again lol"

anthonypants fucked around with this message at 16:20 on Dec 21, 2017

maskenfreiheit
Dec 30, 2004
Did anyone post this yet?

https://twitter.com/bleidl/status/943714277403357185

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
and it stuck around for six months???? https://twitter.com/bleidl/status/871527499984982016

anthonypants fucked around with this message at 16:37 on Dec 21, 2017

Maximum Leader
Dec 5, 2014
why do linux security people hate each other and also mainline devs

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

Maximum Leader posted:

why do linux security people hate each other and also mainline devs

maybe it’s linux people in general hating things, people, themselves

flakeloaf
Feb 26, 2003

Still better than android clock

Maximum Leader posted:

why do linux security people hate each other and also mainline devs

ugh this is already on the man page why are you bothering me

bob dobbs is dead
Oct 8, 2017

I love peeps
Nap Ghost

Boiled Water posted:

maybe it’s linux people in general hating things, people, themselves

practically a shaggar-level post

Adbot
ADBOT LOVES YOU

hobbesmaster
Jan 28, 2008

Maximum Leader posted:

why do linux security people hate each other and also mainline devs

linus probably saw one too many “root access allows you to run arbitrary commands” vulns and blew up at them

can’t blame him tbh, maintaining the kernel must be painful

  • Locked thread