Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Bulgogi Hoagie
Jun 1, 2012

We
clown show

https://twitter.com/jedisct1/status/951215576474685440

Adbot
ADBOT LOVES YOU

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
https://twitter.com/mik235/status/951217727422611456

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
hard to miss when the last post talking about it was two whole posts before yours

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
hi. i play derby and i love it a lot

https://twitter.com/KateLibc/status/951211904482951168

this is a problem for me directly :(

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
I'm sure the rest of the payments system is perfectly secure once you get past that pesky lack of TLS.

FlapYoJacks
Feb 12, 2009
edit: never mind

FlapYoJacks fucked around with this message at 07:01 on Jan 11, 2018

vOv
Feb 8, 2014

Lain Iwakura posted:

hi. i play derby and i love it a lot

https://twitter.com/KateLibc/status/951211904482951168

this is a problem for me directly :(

isn't this a pci violation

i mean not that that has any teeth

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

people who are using telegram aren’t using it for group chats, right?

https://twitter.com/tqbf/status/951231270025158657

cinci zoo sniper
Mar 15, 2013




Subjunctive posted:

people who are using telegram aren’t using it for group chats, right?

https://twitter.com/tqbf/status/951231270025158657

much like people using whatsapp or signal if the headlines are to be believed?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I’m pretty sure those encrypt group chats.

Proteus Jones
Feb 28, 2013



cinci zoo sniper posted:

much like people using whatsapp or signal if the headlines are to be believed?

RE: signal, are you talking about the patched bug in the Android version that let someone attach random bits to the end of an encrypted attachment?

https://pwnaccelerator.github.io/2016/signal-part1.html
https://pwnaccelerator.github.io/2016/signal-part2.html

Or the dubious CIA claim?

Subjunctive posted:

I’m pretty sure those encrypt group chats.
Signal does, at least. Don't know about Whats App, never used it.

cinci zoo sniper
Mar 15, 2013




Subjunctive posted:

I’m pretty sure those encrypt group chats.

so was i

Kassad
Nov 12, 2005

It's about time.
This has been making the rounds: WhatsApp Security Flaws Could Allow Snoops to Slide Into Group Chats:

quote:

The German researchers say their WhatsApp attack takes advantage of a simple bug. Only an administrator of a WhatsApp group can invite new members, but WhatsApp doesn't use any authentication mechanism for that invitation that its own servers can't spoof. So the server can simply add a new member to a group with no interaction on the part of the administrator, and the phone of every participant in the group then automatically shares secret keys with that new member, giving him or her full access to any future messages. (Messages sent prior to an illicit invitation, fortunately, still can't be decrypted.)

Shame Boy
Mar 2, 2010

Subjunctive posted:

people who are using telegram aren’t using it for group chats, right?

https://twitter.com/tqbf/status/951231270025158657

everyone i know uses it almost exclusively for group chats lol

Shame Boy
Mar 2, 2010

also that's sorta wrong, it does at least SSL the connection to the server, it's just nothing's encrypted other than that. everyone i know who uses it already knows that so :shrug:

cinci zoo sniper
Mar 15, 2013




Proteus Jones posted:

RE: signal, are you talking about the patched bug in the Android version that let someone attach random bits to the end of an encrypted attachment?

https://pwnaccelerator.github.io/2016/signal-part1.html
https://pwnaccelerator.github.io/2016/signal-part2.html

https://eprint.iacr.org/2017/713.pdf

Proteus Jones
Feb 28, 2013




Thanks, that one flew under my radar due to all the Meltdown and Spectre poo poo last week.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


nowhere in there does it say that the chats aren't encrypted? in fact, it pretty much explicitly says they are

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

vOv posted:

isn't this a pci violation

i mean not that that has any teeth

PCI does have teeth and there's a website where you can report poo poo like that

canis minor
May 4, 2011

This popped up on my radar in regards to discussion - Attack of the Week: Group Messaging in WhatsApp and Signal

vvv Different article in regards to the same subject

canis minor fucked around with this message at 15:33 on Jan 11, 2018

30 TO 50 FERAL HOG
Mar 2, 2005



canis minor posted:

This popped up on my radar in regards to discussion - Attack of the Week: Group Messaging in WhatsApp and Signal

did it pop up on your radar from two posts earlier?



:thunk:

30 TO 50 FERAL HOG fucked around with this message at 15:35 on Jan 11, 2018

Shifty Pony
Dec 28, 2004

Up ta somethin'


crossing from the tech bubble thread

good security idea: deploy something that lets you instantly remotely lock and encrypt any system and train overseas office managers on how to quickly trigger it if a bunch of unauthorized people force their way into the office to gain access to sensitive data.

bad security idea: defining "police with a search warrant" as unauthorized.

quote:

Like managers at Uber’s hundreds of offices abroad, they’d been trained to page a number that alerted specially trained staff at company headquarters in San Francisco. When the call came in, staffers quickly remotely logged off every computer in the Montreal office, making it practically impossible for the authorities to retrieve the company records they’d obtained a warrant to collect. The investigators left without any evidence.

Cybernetic Vermin
Apr 18, 2005

Proteus Jones posted:

RE: signal, are you talking about the patched bug in the Android version that let someone attach random bits to the end of an encrypted attachment?

https://pwnaccelerator.github.io/2016/signal-part1.html
https://pwnaccelerator.github.io/2016/signal-part2.html

Or the dubious CIA claim?

Signal does, at least. Don't know about Whats App, never used it.

whatsapp encrypts end-to-end, in groups as well, yeah. the issue reported is that all clients will trust the whatsapp server when it says "client xyz joined the group chat", so they will add the key, report the join to all users, and the joined clients gets all messages from there on (they get no access to history)

does not seem hugely serious (hard to see how it'd get abused) , but one could indeed require the client(s) which are admins to sign the join for other clients to accept it, where the enforcement is apparently only server-side for that now (likely to enable multiple join scenarios like mailed invites etc.)

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/taviso/status/951526615145566208

Proteus Jones
Feb 28, 2013



LOL. FBI still trying to wage a "woe is me" PR war against encryption.



https://motherboard.vice.com/en_us/article/59wkkk/fbi-hacker-says-apple-are-jerks-and-evil-geniuses-for-encrypting-iphones

quote:

For example, Flatley complained that Apple recently made password guesses slower, changing the hash iterations from 10,000 to 10,000,000.

That means, he explained, that "password attempts speed went from 45 passwords a second to one every 18 seconds," referring to the difficulty of cracking a password using a "brute force" method in which every possible permutation is tried. There are tools that can input thousands of passwords in a very short period of time—if the attempts per minute are limited, it becomes much harder and slower to crack.

Shame Boy
Mar 2, 2010

looking forward to the FBI issuing a formal tantrum about how anyone under investigation should just turn themselves in and immediately confess to anything and everything because otherwise they're a total meanie buttface jerk!!

apseudonym
Feb 25, 2011


First they said we helped pedophiles with encryption and now they just call us jerks

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

jerkophiles

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
going to the Jerk Store today to get my battery swapped

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
This is the same FBI that says they can't find any good Computer Security guys because they all smoke pot.

haveblue
Aug 15, 2005



Toilet Rascal
well, the jerk store called, and your iphone is ready for pickup

LP0 ON FIRE
Jan 25, 2006

beep boop
any updates on twitter storing passwords thing? google search results in a surprising amount of radio silence

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

LP0 ON FIRE posted:

any updates on twitter storing passwords thing? google search results in a surprising amount of radio silence
the what

Arcsech
Aug 5, 2008

Shifty Pony posted:

crossing from the tech bubble thread

good security idea: deploy something that lets you instantly remotely lock and encrypt any system and train overseas office managers on how to quickly trigger it if a bunch of unauthorized people force their way into the office to gain access to sensitive data.

bad security idea: defining "police with a search warrant" as unauthorized.

I mean if your business is literally “operate an obviously illegal unlicensed taxi service” and therefore your threat model explicitly includes law enforcement, this doesn’t seem like that bad a security idea

at least until local law enforcement gets wise and just takes bolt cutters to the ISP lines into your building before raiding you and/or decides to prosecute for obstruction

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Arcsech posted:

I mean if your business is literally “operate an obviously illegal unlicensed taxi service” and therefore your threat model explicitly includes law enforcement, this doesn’t seem like that bad a security idea

at least until local law enforcement gets wise and just takes bolt cutters to the ISP lines into your building before raiding you and/or decides to prosecute for obstruction
imo the simple answer would be to arrest every executive at that site and charge them with willful obstruction, but the rich don't get treated like everyone else

LP0 ON FIRE
Jan 25, 2006

beep boop



https://www.projectveritas.com/2018...ate-dms-to-doj/

Main Paineframe
Oct 27, 2010

LP0 ON FIRE posted:

any updates on twitter storing passwords thing? google search results in a surprising amount of radio silence

you're seeing radio silence because the source isn't exactly known for its reliability

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
what the hell, why are they attacking twitter? their god-emperor LOVES the site.

Trabisnikof
Dec 24, 2005

for the non-Americans, project veritas is well known for making poo poo up

Adbot
ADBOT LOVES YOU

Wiggly Wayne DDS
Sep 11, 2010



and none of that should be surprising given they mean password hash

  • Locked thread