Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
vanity slug
Jul 20, 2010

https://github.com/qbittorrent/qBittorrent

You could just compile it yourself from Github if that tickles your fancy.

e: I thought the main version has been hosted on FossHub for ages? https://www.fosshub.com/qBittorrent.html

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Jeoh posted:

https://github.com/qbittorrent/qBittorrent

You could just compile it yourself from Github if that tickles your fancy.

e: I thought the main version has been hosted on FossHub for ages? https://www.fosshub.com/qBittorrent.html
And didn't FossHub get compromised a few years ago?

Evis
Feb 28, 2007
Flying Spaghetti Monster

anthonypants posted:

And didn't FossHub get compromised a few years ago?

Can’t you say this for basically anything? Just s/FossHub/anything you want/.

vanity slug
Jul 20, 2010

anthonypants posted:

And didn't FossHub get compromised a few years ago?

https://www.theregister.co.uk/2016/08/05/pegglecrew_we_hacked_fosshub_so_ransomware_scum_couldnt_and_also_for_fun/

the internet was a mistake

The Fool
Oct 16, 2003


Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

CLAM DOWN posted:

Whatever you want to think dude, but qBittorrent is objectively the client to use these days.

I only recently switched to qBittorrent (from Transmission) because it supports connecting through a SOCKS proxy. My VPN service offers a SOCKS host on the other end of the tunnel which can be used as an extra security measure -- if the VPN tunnel drops (or you forget to turn it on), your torrents and/or browser can't re-connect "in the clear" from your real location and accidentally give away the game.

Coxswain Balls
Jun 4, 2001

I'm going to have to make a career change soon, so I'm curious about how realistic it would be to get into information security. I definitely have an interest in it, and it appears to be something in demand, just going by all of the screw-ups that are constantly showing up in the news. I deal with it in my current role from a process and training standpoint (making processes and training to prevent breaches from frontline staff, catching it when it does happen, and the steps taken afterwards), but outside of what I pick up through osmosis here and there I don't have much in the way of technical background in the subject outside of the basics. Because of my passion to make sure we don't end up in the news for dumb poo poo that happens due to my department's actions I've been able to carve out a niche for myself, but I know if I want anything outside of here I'm going to need more than a high school education.

The trade school here has a one year Network Security course and a two year Cyber-Defense and Cloud Administration course that might be up my alley, so I'm wondering what kind of value they would be in pursuing this type of career path if I decide to go down this path.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Evis posted:

Can’t you say this for basically anything? Just s/FossHub/anything you want/.
I suppose you could, but you should be prepared to give an example.

Trabisnikof
Dec 24, 2005

Evis posted:

Can’t you say this for basically anything? Just s/FossHub/anything you want/.

lol

quote:

We're told that in late July, the miscreants easily found an internet-facing service that was not password-protected. This contained all the source code and passwords they needed to obtain deeper access to FossHub's production and mirror systems as well as its caching servers via FTP, the crew said. They were able to grab the accounts database of developers who upload files to FossHub; the passwords were not salted, apparently.

Samizdata
May 14, 2007

RFC2324 posted:

I know this was discussed recently, but I don't think any actual answer was come to.

What is the safe(won't infest the poo poo out of your computer on its own) bittorrent client for windows right now?

Tixati looks good and clean. It's what I use.

Internet Explorer
Jun 1, 2005





Good thing this Spectre/Meltdown patching is going so well!

https://twitter.com/avtestorg/status/959015892997861376

Docjowles
Apr 9, 2009

I mean, basically every vendor has recalled and reissued multiple versions of their fixes, right? And even the microcode updates appear to be poo poo? Like we are all Dell and I don’t think I can download a fixed BIOS from them right now. They released 2.7.0 and then revoked it.

It’s no wonder it’s easy to find exploitable hosts.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Docjowles posted:

I mean, basically every vendor has recalled and reissued multiple versions of their fixes, right? And even the microcode updates appear to be poo poo? Like we are all Dell and I don’t think I can download a fixed BIOS from them right now. They released 2.7.0 and then revoked it.

It’s no wonder it’s easy to find exploitable hosts.
Same with HPE, we have some Gen10s that didn't have their BIOS removed until last week.

BlankSystemDaemon
Mar 13, 2009



This time I bring good news. :unsmith:

The Fool
Oct 16, 2003


Where’s Praxis when you need them

Sheep
Jul 24, 2003

Coxswain Balls posted:

I'm going to have to make a career change soon [...]
The trade school here has a one year Network Security course and a two year Cyber-Defense and Cloud Administration course that might be up my alley, so I'm wondering what kind of value they would be in pursuing this type of career path if I decide to go down this path.

I can't speak to infosec so much despite having a two-year degree in it, but I did transition from something entirely different to IT four years ago. Unfortunately all the hiring I've done has also been for technical positions so I'm not really sure how feasible it is to just get an infosec degree and then get a job doing infosec aside from noting that it was more my other qualifications that landed me where I am today. Obviously didn't hurt though.

Worst case you've now got a two year degree and hopefully a decent footing in general IT shenanigans that you can use to get your foot in the door and then transition to infosec down the road.

Sheep fucked around with this message at 04:39 on Feb 2, 2018

Coxswain Balls
Jun 4, 2001

Thanks for the advice. I'm also looking into university for other things and spent this evening with a friend to talk about that. We ran into one of her friends who does infosec for a big company, who was able to give me some decent advice of his own.

Apparently the courses are good for what they are, but could end up being too specialized. While going to university for the other career path, he suggested that the comp-sci courses here for the first two years would give me a good foundation, and if getting a degree ends up not being my jam I could then end up taking one of those college programs and be a lot more well rounded for that line of work.

Furism
Feb 21, 2006

Live long and headbang
Is anybody here starting to implement/deploy TLS 1.3? If so, I'd like to hear about your use cases.

Disclosure: my job consists of selling fuzzing/load testing, and one area is HTTPS/TLS, so this is also in that context (no, I'm not trying to sell to Goons, I'm using goon experience to try to sell to other people).

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

The Fool posted:

Where’s Praxis when you need them

Look at this boot licker over here.

Pile Of Garbage
May 28, 2007



Furism posted:

Is anybody here starting to implement/deploy TLS 1.3? If so, I'd like to hear about your use cases.

Disclosure: my job consists of selling fuzzing/load testing, and one area is HTTPS/TLS, so this is also in that context (no, I'm not trying to sell to Goons, I'm using goon experience to try to sell to other people).

This article discusses a lot of the sticking points regarding TLS 1.3 adoption: https://blog.cloudflare.com/why-tls-1-3-isnt-in-browsers-yet/. The key takeaway IMO is that a large amount of devices that do HTTPS intercept simply crap the bed when they encounter TLS 1.3. It will probably be quite some time before the various vendors start officially supporting it on their products (Or at least release software that doesn't break when it sees TLS 1.3).

vanity slug
Jul 20, 2010

Also everyone using different draft versions doesn't help adoption either.

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

Jeoh posted:

Also everyone using different draft versions doesn't help adoption either.

Reminds me that there was a 56k standard war at one point and that sucked. Not as much as this, mind you, because you didnt have to work with both 56k standards, just once to connect

Furism
Feb 21, 2006

Live long and headbang

Jeoh posted:

Also everyone using different draft versions doesn't help adoption either.

What I'm told is that the differences between draft 19 and 22 (the latest one) are very minor and the versions are virtually backward compatible. But yeah by the time my company started the implementation and the beta release, we went from draft 19 to 21 and now for GA we had to implement 22. No idea what the actual differences are because I'm not on the product development side.

I'm also told american vendors lag behind because NSA hasn't broken/can't break (apparently you can't really brute force them?) the new ciphers. But it's a non-american vendor who told me this so it could just be propaganda. Saying you're NSA-proof sounds like a good selling point.

But I'd like to hear horror (or not stories) of trying to deploy this. Maybe it's too early still.

cheese-cube posted:

This article discusses a lot of the sticking points regarding TLS 1.3 adoption: https://blog.cloudflare.com/why-tls-1-3-isnt-in-browsers-yet/. The key takeaway IMO is that a large amount of devices that do HTTPS intercept simply crap the bed when they encounter TLS 1.3. It will probably be quite some time before the various vendors start officially supporting it on their products (Or at least release software that doesn't break when it sees TLS 1.3).

Looks like a good article, will definitively read it thanks!

The Fool
Oct 16, 2003


Military reaction to strava tracking

orange sky
May 7, 2007

Lol there is no satire anymore

orange sky fucked around with this message at 03:12 on Feb 4, 2018

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

Took me reading the post below the linked one to notice that was duffleblog.

Anti-Bunny
Mar 14, 2007
word

Coxswain Balls posted:

The trade school here has a one year Network Security course and a two year Cyber-Defense and Cloud Administration course that might be up my alley, so I'm wondering what kind of value they would be in pursuing this type of career path if I decide to go down this path.

Find out what kind of talent pipelines are in place for after graduation. Do companies recruit from the class and offer coops/internships during the summer to students? This is important.

Absurd Alhazred
Mar 27, 2010

by Athanatos
https://twitter.com/kelseyhightower/status/961026365146320896

Sheep
Jul 24, 2003
Forked that so hard.

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Sheep posted:

Forked that so hard.

Fork it, ignore the entire premise, deploy lovely code developed by a HS senior in C, ignore exploits, declare more secure thing.

Boris Galerkin
Dec 17, 2011

I don't understand why I can't harass people online. Seriously, somebody please explain why I shouldn't be allowed to stalk others on social media!

Methylethylaldehyde posted:

Fork it, ignore the entire premise, deploy lovely code developed by a HS senior in C, ignore exploits, declare more secure thing.

Fill it up with nonsense too. Licenses that don’t make sense. Header blocks bigger than the code. Require Java to compile a JSON compatible input file (that you preprocess from Markdown) to a whatever code/language Etherum uses.

wargames
Mar 16, 2008

official yospos cat censor

Boris Galerkin posted:

Fill it up with nonsense too. Licenses that don’t make sense. Header blocks bigger than the code. Require Java to compile a JSON compatible input file (that you preprocess from Markdown) to a whatever code/language Etherum uses.

gooncoin i can see it now.

Sefal
Nov 8, 2011
Fun Shoe
I've been using qbittorrent ever since Utorrent went to poo poo.

Darchangel
Feb 12, 2009

Tell him about the blower!


Sefal posted:

I've been using qbittorrent ever since Utorrent went to poo poo.

Same.

BlankSystemDaemon
Mar 13, 2009



:allears:
You can click it

The Fool
Oct 16, 2003


That man has brought so much entertainment since he moved back stateside.

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

The Fool posted:

That man has brought so much entertainment since he moved back stateside.

I forgot just how much a gem John McAfee is, and how much joy he brings to the technology world.

Boris Galerkin
Dec 17, 2011

I don't understand why I can't harass people online. Seriously, somebody please explain why I shouldn't be allowed to stalk others on social media!
Isn’t he like an actual murderer?

Absurd Alhazred
Mar 27, 2010

by Athanatos
I wonder whom he'll kill next.

Adbot
ADBOT LOVES YOU

Proteus Jones
Feb 28, 2013



Absurd Alhazred posted:

I wonder whom he'll kill next.

From the looks of it, anyone who engages in a twitter slap-fight with him.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply