Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Methanar posted:

This would get you burned at the stake in Christianity

Not usually

Adbot
ADBOT LOVES YOU

Agile Vector
May 21, 2007

scrum bored



Potato Salad posted:

Security loving Megathread - Hello, is this a religion thread?

Secularity Fuckup Megathread v6.1.6 - Hello, is this a divinity order?

Zamujasa
Oct 27, 2010



Bread Liar

Agile Vector posted:

Secularity Fuckup Megathread v6.1.6 - Hello, is this a divinity order?

god drat

Truga
May 4, 2014
Lipstick Apathy

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

Unexpected privilege escalation using specially crafted input to check_kosher()

hobbesmaster
Jan 28, 2008

mrmcd posted:

Unexpected privilege escalation using specially crafted input to check_kosher()

CLOSED: Works as intended

Pile Of Garbage
May 28, 2007



oh dear

https://twitter.com/Jayniehaka/status/955727847850524672

ate shit on live tv
Feb 15, 2004

by Azathoth

Ciaphas posted:

that's why judaism rules and christianity drools

And Atheism is better then both.

haveblue
Aug 15, 2005



Toilet Rascal

mrmcd posted:

Unexpected privilege escalation using specially crafted input to check_kosher()

should have used the proper salt

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

haveblue posted:

should have used the proper salt

oy vey

Notorious b.s.d.
Jan 25, 2003

by Reene

Ciaphas posted:

jewish God approves of people rules-lawyering the poo poo out of Him

it's a joke though

nearly all of the "rules" come from rabbinical efforts to take whatever is written in holy texts and go at least two steps further than is necessary. like jewish men wearing a hat over a yarmulke.

so the rules-lawyering is not working around core items in the torah but rather slicing and dicing centuries of rabbinical thought

i imagine it to be a fine sport

post hole digger
Mar 21, 2011

ate poo poo on live tv posted:

And Atheism is better then both.

nah

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

how are people so bad at this in tyool 2018

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


Chris Knight posted:

how are people so bad at this in tyool 2018

they dont pay enough to get people who care

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

haveblue posted:

should have used the proper salt

coffeetable
Feb 5, 2006

TELL ME AGAIN HOW GREAT BRITAIN WOULD BE IF IT WAS RULED BY THE MERCILESS JACKBOOT OF PRINCE CHARLES

YES I DO TALK TO PLANTS ACTUALLY

ate poo poo on live tv posted:

And Atheism is better then both.
fyi, this schtick will get you a lot of eye-rolling for the same reason that anti-trump chat will get you a lot of eye-rolling. you're preaching to the choir. you're saying something that almost everyone itt is already gonna agree with, and you're expecting some kind of applause for it

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

haveblue posted:

should have used the proper salt

excellent

Truga
May 4, 2014
Lipstick Apathy

duz posted:

they dont pay enough to get people who care

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
https://twitter.com/matix_wolf/status/949026227037368321

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

We had a system that would automatically generate new account passwords by grabbing two random words from a dictionary file and slapping some numbers on the end and that worked great until someone got the password infectedtesticles69 or whatever and they replaced the dictionary with a censored one

Pile Of Garbage
May 28, 2007



BangersInMyKnickers posted:

We had a system that would automatically generate new account passwords by grabbing two random words from a dictionary file and slapping some numbers on the end and that worked great until someone got the password infectedtesticles69 or whatever and they replaced the dictionary with a censored one

did it happen because it was offensive or because it created an inadvertent HIPAA violation?

ohgodwhat
Aug 6, 2005

BangersInMyKnickers posted:

We had a system that would automatically generate new account passwords by grabbing two random words from a dictionary file and slapping some numbers on the end and that worked great until someone got the password infectedtesticles69 or whatever and they replaced the dictionary with a censored one

Your new password is: *************

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug
long ago i put a decent amount of effort into reducing the english alphabet into a version that could not encode any common profanity, i think with 0-9 and a subset of A-Z i ended up with 29 characters, to map integer database PKs to short strings and make sure that "gently caress" would not be one of them

oh also doing some redundancy/error correction, like not using B because it oculd be mistaken for a 8, S with 5, etc

e: maybe 29 before error correction, definitely 25 after

fishmech
Jul 16, 2006

by VideoGames
Salad Prong
https://twitter.com/xoreaxeaxeax/status/951052854881636353

https://github.com/xoreaxeaxeax/movfuscator/tree/master/validation/doom

"A branchless DOOM

This directory provides a branchless, mov-only version of the classic DOOM video game.

This is thought to be entirely secure against the Meltdown and Spectre CPU vulnerabilities, which require speculative execution on branch instructions.

The mov-only DOOM renders approximately one frame every 7 hours, so playing this version requires somewhat increased patience."

Pile Of Garbage
May 28, 2007



Lysidas posted:

long ago i put a decent amount of effort into reducing the english alphabet into a version that could not encode any common profanity, i think with 0-9 and a subset of A-Z i ended up with 29 characters, to map integer database PKs to short strings and make sure that "gently caress" would not be one of them

oh also doing some redundancy/error correction, like not using B because it oculd be mistaken for a 8, S with 5, etc

e: maybe 29 before error correction, definitely 25 after

why didnt you just string literal hex or whatever?

Deacon of Delicious
Aug 20, 2007

I bet the twist ending is Dracula's dick-babies

CommieGIR posted:

Linus is still saying Intel is half adding it on microcosm patches and are not taking this seriously

https://linux.slashdot.org/story/18/01/22/0648227/linus-torvalds-calls-intel-patches-complete-and-utter-garbage

i like this autocorrect

ate shit on live tv
Feb 15, 2004

by Azathoth

coffeetable posted:

fyi, this schtick will get you a lot of eye-rolling for the same reason that anti-trump chat will get you a lot of eye-rolling. you're preaching to the choir. you're saying something that almost everyone itt is already gonna agree with, and you're expecting some kind of applause for it

I mean that's true. I probably should have put a :smug: after the statement. I wasn't honestly looking for theological engagement. Because lol at that, but also this is the security thread.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

fishmech posted:

https://twitter.com/xoreaxeaxeax/status/951052854881636353

https://github.com/xoreaxeaxeax/movfuscator/tree/master/validation/doom

"A branchless DOOM

This directory provides a branchless, mov-only version of the classic DOOM video game.

This is thought to be entirely secure against the Meltdown and Spectre CPU vulnerabilities, which require speculative execution on branch instructions.

The mov-only DOOM renders approximately one frame every 7 hours, so playing this version requires somewhat increased patience."
no sweat just press the minus key a bunch

suffix
Jul 27, 2013

Wheeee!

anthonypants posted:

thought all these posts were about blizzard v. tavis

quote:

I plan to look at other games with very high install bases (100M+) in the coming weeks.

godspeed, there must be so much trivial crap there
and that was just protocol level stuff, he didn't even look at any of the hastily written c++ networking code

flakeloaf
Feb 26, 2003

Still better than android clock

You just know pubg or one of its clones is broken as gently caress

Sapozhnik
Jan 2, 2005

Nap Ghost

duz posted:

they dont pay enough to get people who care

this and management screaming WHY THE gently caress IS THIS TAKING YOU SO LONG???? and people just ceasing to give a poo poo after enough iterations of that

e: you might as well ask why food safety and fire safety were poo poo before there were laws on this matter backed by severe and aggressively-enforced penalties imposed by the government

Sapozhnik fucked around with this message at 21:25 on Jan 24, 2018

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

Sapozhnik posted:

e: you might as well ask why food safety and fire safety were poo poo before there were laws on this matter backed by severe and aggressively-enforced penalties imposed by the government

Question time!

Would it be feasible to write laws around having to make programs secure, similar to food/fire safety laws?

The biggest hurdle obviously would be the speed that technology moves vs. the speed of government. But I'd like some discussion on how it could be/could not be done, and what could it look like? Please no "I don't want the government to do that," or "they'd just gently caress it up and make poo poo worse"

cinci zoo sniper
Mar 15, 2013




Avenging_Mikon posted:

Would it be feasible to write laws around having to make programs secure, similar to food/fire safety laws?
no

Truga
May 4, 2014
Lipstick Apathy

Avenging_Mikon posted:

Question time!

Would it be feasible to write laws around having to make programs secure, similar to food/fire safety laws?

you'd need govt sponsored pentesters that continuously hack your poo poo, because that's what they had to do to get food/fire safety laws to work (inspectors showing up at random and closing down your buildings if they don't conform)

PIZZA.BAT
Nov 12, 2016


:cheers:


Avenging_Mikon posted:

Question time!

Would it be feasible to write laws around having to make programs secure, similar to food/fire safety laws?

The biggest hurdle obviously would be the speed that technology moves vs. the speed of government. But I'd like some discussion on how it could be/could not be done, and what could it look like? Please no "I don't want the government to do that," or "they'd just gently caress it up and make poo poo worse"

just like finance, health, and law, make it so that if your company is handling PII the only people allowed to engage it are licensed software engineers.

FAT32 SHAMER
Aug 16, 2012



Any law that they'd come up with would either be overly broad or too specific and would need to be changed eventually

I seem to remember some goofy online payment system mandated by the government in South Korea that only ran on Windows 95 or XP or something else incredibly out of date

also,

Truga posted:

you'd need govt sponsored pentesters that continuously hack your poo poo, because that's what they had to do to get food/fire safety laws to work (inspectors showing up at random and closing down your buildings if they don't conform)

if that were the case it'd mean that the NSA gets all the 0days ever

the privacy aspect that necc0 brings up is a good idea though, i like it a lot

Workaday Wizard
Oct 23, 2009

by Pragmatica

Avenging_Mikon posted:

Question time!

Would it be feasible to write laws around having to make programs secure, similar to food/fire safety laws?

The biggest hurdle obviously would be the speed that technology moves vs. the speed of government. But I'd like some discussion on how it could be/could not be done, and what could it look like? Please no "I don't want the government to do that," or "they'd just gently caress it up and make poo poo worse"

I love regulation but software moves way too fast.

reminder that docker is less than 4 years old.

Arcsech
Aug 5, 2008

Truga posted:

you'd need govt sponsored pentesters that continuously hack your poo poo, because that's what they had to do to get food/fire safety laws to work (inspectors showing up at random and closing down your buildings if they don't conform)

jail time for ceos/executives in cases where data breaches are deemed sufficiently negligent by an appropriate regulatory body could maybe work

except lol that will never ever happen because rich people never face consequences for anything

Truga
May 4, 2014
Lipstick Apathy

FAT32 SHAMER posted:

if that were the case it'd mean that the NSA gets all the 0days ever

yeah, i'm not saying it's a good and i don't think it's even a feasible idea, but i think it'd take no less than that. if it's just penalties after breaches that's too late, and also big corps can just shrug off almost anything

Arcsech posted:

jail time for ceos/executives in cases where data breaches are deemed sufficiently negligent by an appropriate regulatory body could maybe work

except lol that will never ever happen because rich people never face consequences for anything

yeah, exactly

Adbot
ADBOT LOVES YOU

Trabisnikof
Dec 24, 2005

the smart way would be to empower a regulator and fund them so they can update the rules as tech changes, it would most be process regulation anyway


id assume we'd implement some sort of mandatory programmer's liability insurance instead

  • Locked thread