Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/AlecMuffett/status/950699975767482370

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




Bulgogi Hoagie posted:

whatsapp is definitely more kgb secure than telegram if only because telegram doesn’t encrypt chats by default

i care much less about kgb security than i do about sharing any information with facebook

cinci zoo sniper
Mar 15, 2013




Wiggly Wayne DDS posted:

i'm the implication that telegram encryption isn't broken by said agency

how on earth were you reading my post

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.
are you an iranian, or are you a furry

Fiedler
Jun 29, 2002

I, for one, welcome our new mouse overlords.

Easy mistake to make, not verifying the password. Happens to the best of 'em.

spankmeister
Jun 15, 2008






SardonicTyrant posted:

Are there any good security-related magazines out there? I'm having a hard time keeping track of this thread the latest developments and I figure it might help.

https://risky.biz

Cybernetic Vermin
Apr 18, 2005

cinci zoo sniper posted:

i care much less about kgb security than i do about sharing any information with facebook

this a bit of a stretch to fear this though, as the content/chats themselves are encrypted, and it is a bit tinfoily to assume that facebook straight up lies about the encryption setup used, as it'd be a real pr blow when (and it likely is 'when', since the binary is there to be observed) found out

cinci zoo sniper
Mar 15, 2013




Cybernetic Vermin posted:

this a bit of a stretch to fear this though, as the content/chats themselves are encrypted, and it is a bit tinfoily to assume that facebook straight up lies about the encryption setup used, as it'd be a real pr blow when (and it likely is 'when', since the binary is there to be observed) found out

i dont think they read my chats or whatever, not do i care about security of cat pictures and video game chat specifically. i just don't like installing fb affiliated apps after ive seen some interesting "privacy" wonders on an absolutely unrelated to anything else i have throwaway instragram account, which did shamelessly recommend me all my real facebook friends straight away

McGlockenshire
Dec 16, 2005

GOLLOCKS!
teledildonic secfucks will never get old
https://twitter.com/SarahJamieLewis/status/950974881155375104

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
ios 11.2.2 includes a spectre fix

Max Facetime
Apr 18, 2009

anthonypants posted:

ios 11.2.2 includes a spectre fix

cool, I can’t wait to experience more random slowdowns because Apple can’t control what code gets executed on their platform

thanks Apple, dapple

Workaday Wizard
Oct 23, 2009

by Pragmatica

Max Facetime posted:

cool, I can’t wait to experience more random slowdowns because Apple can’t control what code gets executed on their platform

thanks Apple, dapple

i wish ios didn’t run javascript but alas cest la vie

Dylan16807
May 12, 2010

eversion posted:

LetsEncrypt has disabled tls-sni challenges due to "strong credibility of a vulnerability report": https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/5a55777ed9a9c1024c00b241

and this is out now: https://community.letsencrypt.org/t/2018-01-09-issue-with-tls-sni-01-and-shared-hosting-infrastructure/49996

on some shared hosts, if you're on the same server as a site you can upload certs that pass the tls-sni challenges for that site

quote:

Over the next 48 hours we will be building a list of vulnerable providers and their associated IP addresses. Our tentative plan, once the list is completed, is to re-enable the TLS-SNI-01 challenge type with vulnerable providers blocked from using it.

cinci zoo sniper
Mar 15, 2013




looks like some estonian medical institution paid its way out of ransomware

Max Facetime
Apr 18, 2009

Shinku ABOOKEN posted:

i wish ios didn’t run javascript but alas cest la vie

it’s too bad JavaScript is so fast and runs so close to the metal that accurate high-precision clocks are unavoidable, we’ll have to slow down everything else to compensate
      - every OS vendor

flakeloaf
Feb 26, 2003

Still better than android clock

cinci zoo sniper posted:

looks like some estonian medical institution paid its way out of ransomware

laughing all the way to the eestibank

what's the rate of reinfection on folks who pay

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
post the actual details of your proposed scheme for preventing javascript from being able to figure out this sort of thing, so everyone else can laugh at how dumb you are

Cybernetic Vermin
Apr 18, 2005

Jabor posted:

post the actual details of your proposed scheme for preventing javascript from being able to figure out this sort of thing, so everyone else can laugh at how dumb you are

for most of its existence (changed in ios 8 iirc) ios did not let apps run javascript with jit, by disallowing embedding scripting engines and only providing interpreted execution in the ui toolkit webview. as the interpreter most likely does every indirect branch from the same code (the code implementing that bytecode) it will not be possible to seed branch prediction. steve saw this coming~

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



4lokos basilisk
Jul 17, 2008


cinci zoo sniper posted:

looks like some estonian medical institution paid its way out of ransomware

hey, can you point to any links? curious to know what fuckup my brave compatriots have managed to do :)

Max Facetime
Apr 18, 2009

Jabor posted:

post the actual details of your proposed scheme for preventing javascript from being able to figure out this sort of thing, so everyone else can laugh at how dumb you are

don’t JIT third-party JavaScript nor run it without throttling

easy peasy cheesy on my peeny

Cybernetic Vermin
Apr 18, 2005

tbqh the coolest thing apple has done since the iphone is that they committed to an actually vetted software ecosystem. not uncontroversial, and without outside pressures would no doubt have been a truly repressive horrorshow, but it is a pretty good point of reference to judge the rest of the jungle by. does not matter too much for spectre, but it is sort of easy to imagine an alternative take where apple would have put themselves in a situation where they could truly rule out the attacks running rather than defend against them

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

Idea: make a "check your computer for meltdown" script that also roots the machine. Put on GitHub. Tell people in the instructions to clone and run as administrator/root. Seed in various Facebooks and other social media channels.

akadajet
Sep 14, 2003

this poo poo again?
https://twitter.com/MacRumors/status/951133444909580288

Schadenboner
Aug 15, 2011

by Shine

mrmcd posted:

Idea: make a "check your computer for meltdown" script that also roots the machine. Put on GitHub. Tell people in the instructions to clone and run as administrator/root. Seed in various Facebooks and other social media channels.

I'll make the wiki!

flakeloaf
Feb 26, 2003

Still better than android clock


mac security: anyone can log into a small, carefully curated number of programs

MiniFoo
Dec 25, 2006

METHAMPHETAMINE


was just about to post this. tried it out and startled the whole office from how loud I snorted with laughter

akadajet
Sep 14, 2003

Yeah, I tried it too. It's exactly as straight forward as putting in any garbage and hitting "unlock".

Trabisnikof
Dec 24, 2005

mrmcd posted:

Idea: make a "check your computer for meltdown" script that also roots the machine. Put on GitHub. Tell people in the instructions to clone and run as administrator/root. Seed in various Facebooks and other social media channels.

just make a medium post about how you did this and infected a million computers in under a day (send me :10bux: to get the number of Google boxes owned) and optionally include a comment about this being a fiction to make you think

Diva Cupcake
Aug 15, 2005

But, I mean, you have to be an admin already and you can only change super important functions like Automatically Check for Updates.

minato
Jun 7, 2004

cutty cain't hang, say 7-up.
Taco Defender
Not a security fuckup, but a literal SecFuck
https://twitter.com/matt_levine/status/951147744772743168

apseudonym
Feb 25, 2011


Lol Apple

Shaggar
Apr 26, 2006

shouldn't the dialog be the same as for any other elevation prompt? Did they write a different one for just the app store?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
https://twitter.com/daviottenheimer/status/949348043744309248

loool

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Excellent job... *squints* France.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lmao

Diva Cupcake
Aug 15, 2005

Diva Cupcake posted:

But, I mean, you have to be an admin already and you can only change super important functions like Automatically Check for Updates.
oh nevermind
https://twitter.com/lintile/status/951192859272761345

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/lintile/status/951199657245446144

Shaggar
Apr 26, 2006

lol

Adbot
ADBOT LOVES YOU

redleader
Aug 18, 2005

Engage according to operational parameters

computers were a mistake

  • Locked thread