Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Samizdata
May 14, 2007

Knormal posted:

I don't think any operating system has anything to prevent a program written to take screenshots from taking screenshots. If there's a way to capture a screenshot from something passive like a web page then yeah, that's a problem, but if an app wants to be malicious it can just be a keylogger and not bother with screenshots and OCR. Bottom line as always is don't install apps you don't trust.

I think their point was if you use a "Security Sandbox" like the blog posts mentions, then that sandboxed process should be untouchable by anything else in the system. Since you know, that's sort of the point of a sandbox.

Adbot
ADBOT LOVES YOU

goatsestretchgoals
Jun 4, 2011

Knormal posted:

I don't think any operating system has anything to prevent a program written to take screenshots from taking screenshots. If there's a way to capture a screenshot from something passive like a web page then yeah, that's a problem, but if an app wants to be malicious it can just be a keylogger and not bother with screenshots and OCR. Bottom line as always is don't install apps you don't trust.

A given application should not have access to anything outside it's own context. Taking a screenshot of it's own window is OK (subject to some dogmatic nerd poo poo) but being able to capture the entire display is capital F hosed.

To the best of my knowledge, no win32 application has the ability to capture outside of its own window except for whatever the screen snip tool is dot exe.

Windows NT (aka 2000, XP, and on) is actually pretty good at separating user/superuser on the back end.

Microsoft has traditionally failed at preventing people who aren't experienced computer touchers from shooting themselves in the foot.

'I need to install a thing!': The entire screen dims out except for the 'Are you sure about this?' prompt.

'This poo poo app from 1995 needs to write to its own directory but our entire business depends on it.': I could go through UAC every time I run this critical app or I could just turn off UAC.

*continues not backing critical data up to a 2nd source*

*later that day*

'Ugh some Eastern European is asking for half a bitcoin to get my word docs back. Microsoft is bad!!'

E: The true schad is me

Grey Fox
Jan 5, 2004

https://i.imgur.com/yqPGnDQ.gifv sucks that its instinct was to put all of its weight onto a tiny area

Sarcopenia
May 14, 2014

Burt Sexual posted:

Crabs eat sand

This kills the LA Beast.

Applesnots
Oct 22, 2010

MERRY YOBMAS

Solice Kirsk posted:

Nothing gold can stay.

Stay gold Beasty boy, stay gold.

Fuzzy Mammal
Aug 15, 2001

Lipstick Apathy

goatsestretchgoals posted:

A given application should not have access to anything outside it's own context. Taking a screenshot of it's own window is OK (subject to some dogmatic nerd poo poo) but being able to capture the entire display is capital F hosed.

To the best of my knowledge, no win32 application has the ability to capture outside of its own window except for whatever the screen snip tool is dot exe.

Windows NT (aka 2000, XP, and on) is actually pretty good at separating user/superuser on the back end.

Microsoft has traditionally failed at preventing people who aren't experienced computer touchers from shooting themselves in the foot.

'I need to install a thing!': The entire screen dims out except for the 'Are you sure about this?' prompt.

'This poo poo app from 1995 needs to write to its own directory but our entire business depends on it.': I could go through UAC every time I run this critical app or I could just turn off UAC.

*continues not backing critical data up to a 2nd source*

*later that day*

'Ugh some Eastern European is asking for half a bitcoin to get my word docs back. Microsoft is bad!!'

E: The true schad is me

Any browser can do desktop sharing through webrtc. Any application could scrape the whole screen if it wanted.

Knormal
Nov 11, 2001

There are tons of third-party Windows screen capture apps of various levels of trustworthiness, think Snagit or Twitch streamers down to Unregistered HyperCam2. Running an app sandboxed isn't a full virtual machine, it's isolated from other apps but it can still read from basic OS functions. I guess it depends on how robust you expect the sandbox to be, I would assume basic sandbox that comes with MacOS isn't ultra-locked down and makes some concessions for user-friendliness, but admittedly I've never used it. From a quick skim of this that looks to be the case, if I grant an app permission to access my Downloads folder, which I would assume just about everyone lets every app get, then there's nothing stopping it from reading mycreditcards.txt.

While it would be ideal if a sandboxed app could only "see" its own window I'm not sure that's feasible to implement with current graphics implementations, other than running each sandboxed app with its own graphics stack which would get incredibly resource-intensive. But my ultimate point was that this isn't some basic oversight by Apple like the "one character causes the OS to crash thing", considering Windows doesn't offer native sandboxing home users at all this is more like a Meltdown/Specte kind of "oops didn't think of that" oversight than bad coding.

Edit: It looks like sandboxing under Linux does by default does create its own entire separate instance of an X server, so I guess someone had thought of that.

Knormal has a new favorite as of 06:41 on Feb 16, 2018

iospace
Jan 19, 2038


"Walk around me, humans"
https://i.imgur.com/Ojbose1.gifv

Tunicate
May 15, 2012

syscall girl posted:

Microsoft did the same thing with font rendering in the kernel and had similar problems iirc.


You can't install a font on windows 10 without the firewall active.

Knormal
Nov 11, 2001

Tunicate posted:

You can't install a font on windows 10 without the firewall active.
You can't open the Start Menu on Windows 10 without the firewall active. That one blows my mind even more than the font thing.

vektuz
Sep 19, 2005
Endangered Species

Fuzzy Mammal posted:

Any browser can do desktop sharing through webrtc. Any application could scrape the whole screen if it wanted.

Yes. The reason no hacker has posted github code on how to do this on windows is becuase microsoft did like, years ago, there is no challenge
https://msdn.microsoft.com/en-us/library/dd183402(v=vs.85).aspx

Couple that with microsoft pretty much never wanting to deprecate anything and yeah.
https://www.codeproject.com/Articles/5051/Various-methods-for-capturing-the-screen

The fact that ordinary applications like photoshop or Krita or The Gimp can just eyedropper any color pixel from any other app should give a hint that yeah, there's no sandboxing really whatsoever. There's no permissions to ask for, no manifest files to fill in, no sandbox to escape from.

The fact that its happening in a MacOS sandbox is what makes it interesting because there is the presumption of sandboxing. They're actually trying to sandbox apps and protect them from each other, so when someone finds a hole in the sandbox its interesting. On windows there's no such presumption :)

vektuz has a new favorite as of 08:35 on Feb 16, 2018

Away all Goats
Jul 5, 2005

Goose's rebellion

Linked for size

https://gfycat.com/EveryMiserlyHornedtoad

Panfilo
Aug 27, 2011

EXISTENCE IS PAIN😬

Applesnots posted:

Stay gold Beasty boy, stay gold.

*LA Beast holding fathers cremated remains on the edge of a pier* "I won't scatter your ashes to the heartless sea. You're all diamond subscribers to me. Like and Subscribe, dad." *Awkwardly wolfs down ashes* "Urk, it's got a texture to it, like grits. Not too bad when you Siracha up the cremains though."

Poops Mcgoots
Jul 12, 2010


Oh man, I'm garbage at these puzzles.

Aramoro
Jun 1, 2012




Poops Mcgoots posted:

Oh man, I'm garbage at these puzzles.

Start executing people who don't wait for their exit to be clear. Puzzle solved.

SpacePig
Apr 4, 2007

Hold that pose.
I've gotta get something.

Aramoro posted:

Start executing people who don't wait for their exit to be clear. Puzzle solved.

But then you just have a car without a driver stuck in the exit. This is a really poor strategy.

Rick_Hunter
Jan 5, 2004

My guys are still fighting the hard fight!
(weapons, shields and drones are still online!)

SpacePig posted:

But then you just have a car without a driver stuck in the exit. This is a really poor strategy.

Execute the car too. Lay down with humans, wake up stuck in traffic.

Some Pinko Commie
Jun 9, 2009

CNC! Easy as 1️⃣2️⃣3️⃣!

Would've kicked the poo poo out of that cat.

SulfurMonoxideCute
Feb 9, 2008

I was under direct orders not to die
🐵❌💀

I'd give it a friendly pet :3:

Tagra
Apr 7, 2006

If you gaze long into an abyss, the abyss will gaze back into you.


biracial bear for uncut posted:

Would've kicked the poo poo out of that cat.

It would have given you a disdainful look and shuffled 2cm to the left.

Some Pinko Commie
Jun 9, 2009

CNC! Easy as 1️⃣2️⃣3️⃣!
We apparently have very different definitions for "kicked the poo poo out of".

DandyLion
Jun 24, 2010
disrespectul Deciever

biracial bear for uncut posted:

Would've kicked the poo poo out of that cat.

Shame you didn't; We would be featuring you in a video in this thread shortly after methinks...

funmanguy
Apr 20, 2006

What time is it?
I would have tried to put a "Kick Me" sign on the cat, then after that failed I would go to the doctor to clean my wounds.

Ghost Leviathan
Mar 2, 2017

Exploration is ill-advised.
I would have done my usual procedure for a cat being annoying; pick it up and pet it and call it silly names and wave it around randomly until it flees out of sheer embarrassment.

Shnag
Dec 8, 2010

"I'll be whatever I wanna do!"

biracial bear for uncut posted:

We apparently have very different definitions for "kicked the poo poo out of".

Apparently you are a psychopath who lusts to hurt animals who slightly inconvenience you.

Some Pinko Commie
Jun 9, 2009

CNC! Easy as 1️⃣2️⃣3️⃣!

Shnag posted:

Apparently you are a psychopath who lusts to hurt animals who slightly inconvenience you.

LOL if I'm supposed to have any kind/generous feelings towards the animal equivalent of a race of Jeffrey Dahmers.

gschmidl
Sep 3, 2011

watch with knife hands

Definitely a pyschopath.

Furthermore:

quote:

Sony once turned down a chance to buy all of Marvel’s movie rights for only $25 million

enigmahfc
Oct 10, 2003

EFF TEE DUB!!
EFF TEE DUB!!

biracial bear for uncut posted:

LOL if I'm supposed to have any kind/generous feelings towards the animal equivalent of a race of Jeffrey Dahmers.

your an awesome person.

Some Pinko Commie
Jun 9, 2009

CNC! Easy as 1️⃣2️⃣3️⃣!

enigmahfc posted:

your an awesome person.

Yeah, well, we're all in the Schadenfreude thread.

Good job on the bad grammar, by the way.

enigmahfc
Oct 10, 2003

EFF TEE DUB!!
EFF TEE DUB!!

biracial bear for uncut posted:

Yeah, well, I''m a piece of human garbage.

Good job on the bad grammar, by the way.

Thank yuo

Doggles
Apr 22, 2007

https://twitter.com/TIME/status/964529896797204481

Ariong
Jun 25, 2012



biracial bear for uncut posted:

Yeah, well, we're all in the Schadenfreude thread.

Good job on the bad grammar, by the way.

Nonchalant endorsement of animal cruelty is one thing, but pedantry? This is a bridge too far.

Data Graham
Dec 28, 2009

📈📊🍪😋



biracial bear for uncut posted:

Would've kicked the poo poo out of that cat.

ExecuDork
Feb 25, 2007

We might be fucked, sir.
Fallen Rib

Say Nothing posted:

This guy is going to be murdered.

Yes. And he will be murdered in a way that creates a new category of war crime.

Kim Jong Un had his half-brother killed. The hit was carried out with VX. A couple of random young women in Malasia were recruited by N. Korean agents pretending to be running a reality TV prank show: "Smear this goo on the face of that man over there! It will be hilarious!".

VX is a chemical weapon that has been completely banned everywhere. Simple possession of ANY amount is automatically considered an atrocity; actually using it to kill people is grounds for national governments around the world to start making plans to invade your country (obviously most of these discussions amount to nothing, but you do get some infamy).

So I'm gonna say that KJU-impersonator is going to die in a way inspired by a James Bond movie.

Transmogrifier
Dec 10, 2004


Systems at max!

Lipstick Apathy
Anyone know what happened for Lowtax to get banned from Twitter again?

https://twitter.com/steak_umm/status/964521901690359811

Iron Crowned
May 6, 2003

by Hand Knit

Transmogrifier posted:

Anyone know what happened for Lowtax to get banned from Twitter again?

https://twitter.com/steak_umm/status/964521901690359811

I bet it was because he called AR-15s lovely guns yesterday

Aramoro
Jun 1, 2012




Transmogrifier posted:

Anyone know what happened for Lowtax to get banned from Twitter again?

https://twitter.com/steak_umm/status/964521901690359811

Didn't he tell Baked Alaska to drown himself in concrete or similar?

edit: Again? You mean he got back on after Baked Alaska?

Transmogrifier
Dec 10, 2004


Systems at max!

Lipstick Apathy

Aramoro posted:

Didn't he tell Baked Alaska to drown himself in concrete or similar?

edit: Again? You mean he got back on after Baked Alaska?

He did.

ekuNNN
Nov 27, 2004

by Jeffrey of YOSPOS

Adbot
ADBOT LOVES YOU

SpacePig
Apr 4, 2007

Hold that pose.
I've gotta get something.

Aramoro posted:

Didn't he tell Baked Alaska to drown himself in concrete or similar?

edit: Again? You mean he got back on after Baked Alaska?

Yeah, @lowtax was suspended because of the concrete comment. Not sure what happened with this one.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply