Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
The Fool
Oct 16, 2003


Not double posting

https://www.techrepublic.com/article/50-gb-of-data-left-exposed-on-amazon-s3-bucket-by-analytics-firm-birst/

quote:

Configuration data was placed in an unsecured Amazon S3 bucket by the business analytics software firm Birst, according to security researchers at UpGuard. On January 15th, UpGuard detected the unsecured bucket—which contained IP addresses, administrative credentials, passwords, and private keys.

Adbot
ADBOT LOVES YOU

ozymandOS
Jun 9, 2004
What's UpGuard?

Sickening
Jul 16, 2007

Black summer was the best summer.

ozymandOS posted:

What's UpGuard?

http://lmgtfy.com/?q=upguard

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Sickening with the sick anti-joke punchline

Sickening
Jul 16, 2007

Black summer was the best summer.

ChubbyThePhat posted:

Sickening with the sick anti-joke punchline

I couldn't help it, the joke was terrible.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

ozymandOS posted:

What's UpGuard?

Not much, you?

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Sickening posted:

I couldn't help it, the joke was terrible.

It arguably made it more funny.

Absurd Alhazred
Mar 27, 2010

by Athanatos

Stanley Pain posted:

It's only freakin March. :gonk:

Surely you're mistaken. It's still September

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


When September eeeeeends

Furism
Feb 21, 2006

Live long and headbang

Volmarias posted:

Wasn't there some user testing showing that users gave exactly zero fucks about EV and mostly didn't even know that it existed?

And they are correct.

All you have to do is setup a corporation in some state (so you can provide the legal papers), with a synonym name to a (not too) well-known company and register for some TLD nobody will find weird. And there you go, you own a swipe.cx EV cert or whatever.

BlankSystemDaemon
Mar 13, 2009



Do you remember, ∞th night of September?
Not changing the mind of infosecs
While chasing the butts away
Our hearts were crying
In the key that our souls were sighing
As we wasted in the night

Absurd Alhazred
Mar 27, 2010

by Athanatos
https://twitter.com/oculus/status/971556153946669056



Keep your certs up to date, folks!

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

So ridiculous.

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

*snerk*

I really should ask my ex-friend about his oculus.

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.


I'm not very familiar with modern VR stuff, so this is a genuine question: Is there any legitimate reason that a hardware peripheral like a Rift needs to authenticate with a remote server just to function? To get updates, sure, it only makes sense to verify the cert. But to display local content like a game? What on Earth is the sense in that?

Absurd Alhazred
Mar 27, 2010

by Athanatos

Powered Descent posted:

I'm not very familiar with modern VR stuff, so this is a genuine question: Is there any legitimate reason that a hardware peripheral like a Rift needs to authenticate with a remote server just to function? To get updates, sure, it only makes sense to verify the cert. But to display local content like a game? What on Earth is the sense in that?

Because Oculus decided to. The old SDK didn't have this stupid always-online runtime, but they decided to make it required for reasons. :shrug:

I'm glad I wasn't working on the Rift today.

bull3964
Nov 18, 2000

DO YOU HEAR THAT? THAT'S THE SOUND OF ME PATTING MYSELF ON THE BACK.


Powered Descent posted:

I'm not very familiar with modern VR stuff, so this is a genuine question: Is there any legitimate reason that a hardware peripheral like a Rift needs to authenticate with a remote server just to function? To get updates, sure, it only makes sense to verify the cert. But to display local content like a game? What on Earth is the sense in that?

It's not (at least not for this.)

The issue is simply that a code signing cert expired and they didn't timestamp the signature (which would have allowed it to continue to function) so it couldn't load a critical DLL. So, essentially, they hosed up the signing process for a single DLL that caused windows to reject loading a now unsigned DLL which broke the local platform.

Problem now is, it's broken enough that it can't even update itself, so they are going to have to have some sort of offline patching.

bull3964 fucked around with this message at 03:14 on Mar 8, 2018

mewse
May 2, 2006

Powered Descent posted:

I'm not very familiar with modern VR stuff, so this is a genuine question: Is there any legitimate reason that a hardware peripheral like a Rift needs to authenticate with a remote server just to function? To get updates, sure, it only makes sense to verify the cert. But to display local content like a game? What on Earth is the sense in that?

Rift has an app store and they want it to be a device like a cell phone rather than a computer peripheral.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Powered Descent posted:

I'm not very familiar with modern VR stuff, so this is a genuine question: Is there any legitimate reason that a hardware peripheral like a Rift needs to authenticate with a remote server just to function? To get updates, sure, it only makes sense to verify the cert. But to display local content like a game? What on Earth is the sense in that?

They're concerned that someone might download a headset, so having it always online makes it harder for pirates to do that.

bull3964
Nov 18, 2000

DO YOU HEAR THAT? THAT'S THE SOUND OF ME PATTING MYSELF ON THE BACK.


Yeah, like I said though, this doesn't really have anything to do with being online or always connected. They accidentally put a timebomb in a DLL by not timestamping the signature, causing library to spontaneously become unsigned as far as Windows was concerned this afternoon when the cert expired.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

bull3964 posted:

Yeah, like I said though, this doesn't really have anything to do with being online or always connected. They accidentally put a timebomb in a DLL by not timestamping the signature, causing library to spontaneously become unsigned as far as Windows was concerned this afternoon when the cert expired.

But that’s not a funny way to show that you’re smarter and aloof. Please try again.

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

bull3964 posted:

It's not (at least not for this.)

The issue is simply that a code signing cert expired and they didn't timestamp the signature (which would have allowed it to continue to function) so it couldn't load a critical DLL. So, essentially, they hosed up the signing process for a single DLL that caused windows to reject loading a now unsigned DLL which broke the local platform.

Problem now is, it's broken enough that it can't even update itself, so they are going to have to have some sort of offline patching.

Thanks for the explanation. That makes a lot more sense than what I've been seeing in the news articles, which makes it sound like the Rift contains these lines of code: if (IsExpired(OculusWebsite.Certificate)) { BrickDevice(); }

Samizdata
May 14, 2007

Powered Descent posted:

I'm not very familiar with modern VR stuff, so this is a genuine question: Is there any legitimate reason that a hardware peripheral like a Rift needs to authenticate with a remote server just to function? To get updates, sure, it only makes sense to verify the cert. But to display local content like a game? What on Earth is the sense in that?

Because they are owned by Facebook, and FB wants to know EVERYTHING you are using your Rift for. I would hazard to guess so they can add in advertising at some point.

Absurd Alhazred
Mar 27, 2010

by Athanatos

bull3964 posted:

Yeah, like I said though, this doesn't really have anything to do with being online or always connected. They accidentally put a timebomb in a DLL by not timestamping the signature, causing library to spontaneously become unsigned as far as Windows was concerned this afternoon when the cert expired.

Well now I feel stupid! :mad:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Samizdata posted:

Because they are owned by Facebook, and FB wants to know EVERYTHING you are using your Rift for. I would hazard to guess so they can add in advertising at some point.

Just read the thread.

bull3964
Nov 18, 2000

DO YOU HEAR THAT? THAT'S THE SOUND OF ME PATTING MYSELF ON THE BACK.


I just wonder how long that DLL hasn't been countersigned. Did the build process in the most recent release gently caress it up or had it not been countersigned from the beginning?

What Oculus REALLY hosed up is the communication. This is something that can happen to literally any signed application on windows. They should have gotten out in front of this with a very clear statement to spoon-feed the tech blogs, giving the fundamentals of the code signing process. Now everyone is running around saying that this failed due to an SSL cert on some phone home functionality when this was really just a breakdown of process when they signed that library.

The issue isn't even about the cert renewal. It's common for code signing certs to be expired on deployed code, that's why you countersign them. It's sufficient to show that the cert was valid when the code was signed, not at runtime.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Hearing rumours that this happened because they signed releases by hand rather than integrating signing into their CD pipeline and one of their machines didn't get the new signing cert when they renewed it

Rufus Ping fucked around with this message at 05:12 on Mar 8, 2018

RFC2324
Jun 7, 2012

http 418

They should have just made sure everything coming out of their books servers was signed

Absurd Alhazred
Mar 27, 2010

by Athanatos
https://twitter.com/filip_kafka/status/972168475945963523

BlankSystemDaemon
Mar 13, 2009



Hold on to your butts.

The Fool
Oct 16, 2003


Dumpster Fire added to dictionary

Thanks Ants
May 21, 2004

#essereFerrari


Well done everybody

Boris Galerkin
Dec 17, 2011

I don't understand why I can't harass people online. Seriously, somebody please explain why I shouldn't be allowed to stalk others on social media!
https://lists.samba.org/archive/samba-announce/2018/000435.html

quote:

CVE-2018-1057:

On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users.

Thanks Ants
May 21, 2004

#essereFerrari


:toot:

Potato Salad
Oct 23, 2014

nobody cares



Do tell?! vvv ah.

Potato Salad fucked around with this message at 12:39 on Mar 13, 2018

Thanks Ants
May 21, 2004

#essereFerrari


I was :toot:ing that awesome Samba news, not :yotj:

Virigoth
Apr 28, 2009

Corona rules everything around me
C.R.E.A.M. get the virus
In the ICU y'all......



Thanks Ants posted:

I was :toot:ing that awesome Samba news, not :yotj:

You have to be careful with :toot: and :yotj: in these treacherous times.

Absurd Alhazred
Mar 27, 2010

by Athanatos
:confuoot:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
On the subject of dumpster fires...

https://twitter.com/KateLibc/status/973551222023057408

Adbot
ADBOT LOVES YOU

BlankSystemDaemon
Mar 13, 2009



:munch:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply