Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
CLAM DOWN
Feb 13, 2007

nesaM killed Masen

Cup Runneth Over posted:

I trust the report that was linked on the vulnerability that says that the vulnerability has been patched

What about other new vulnerabilities being introduced, which is exactly what happened with the first patch?

Adbot
ADBOT LOVES YOU

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


As another poster said, you could say that about literally any patch. It's a pretty meaningless thing to say and has nothing to do with this vulnerability, which was addressed and fixed before you guys even found out about it. Funny as hell but of little impact.

Potato Salad
Oct 23, 2014

nobody cares


What if KB42069 trades a known exploit for one that nobody's discovered and leveraged yet :ohdear:

CLAM DOWN
Feb 13, 2007

nesaM killed Masen

Cup Runneth Over posted:

As another poster said, you could say that about literally any patch. It's a pretty meaningless thing to say and has nothing to do with this vulnerability, which was addressed and fixed before you guys even found out about it. Funny as hell but of little impact.

Ahh I see, you're not bitter at this industry yet, give it time.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Yeah I'm green as hell

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Potato Salad posted:

What if KB42069 trades a known exploit for one that nobody's discovered and leveraged yet :ohdear:

Wait I thought this was the whole point of patching.

Potato Salad
Oct 23, 2014

nobody cares


ChubbyThePhat posted:

Wait I thought this was the whole point of patching.

that's my point :sun:

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I know, I just wanted to post and couldn't come up with anything better :smith:

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?
:justpost:

Proteus Jones
Feb 28, 2013



Cup Runneth Over posted:

Yeah I'm green as hell

Give it time. You'll soon discover the fundamental axiom of Info Sec:

The most cynical take is the correct one.

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

Cup Runneth Over posted:

I trust the report that was linked on the vulnerability that says that the vulnerability has been patched

We apologise again for the fault in the patch. Those responsible for sacking the people who have just been sacked, have been sacked.

Kassad
Nov 12, 2005

It's about time.

Powered Descent posted:

We apologise again for the fault in the patch. Those responsible for sacking the people who have just been sacked, have been sacked.


The sackings will continue until infosec improves.

Beccara
Feb 3, 2005
New thread title right there

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Kassad posted:

The sackings will continue until infosec improves.

Every time I hear sacking, I'm picturing a full on 3 step run-up punt to the junk. Which to be fair, the programmers who came up with that patch also need.

Beccara
Feb 3, 2005
So this might be old news but Boeing just got WannaCry'ed internally and it may impact production


https://www.seattletimes.com/business/boeing-aerospace/boeing-hit-by-wannacry-virus-fears-it-could-cripple-some-jet-production/

Proteus Jones
Feb 28, 2013



gently caress’s sake.

Docjowles
Apr 9, 2009

Methylethylaldehyde posted:

Every time I hear sacking, I'm picturing a full on 3 step run-up punt to the junk. Which to be fair, the programmers who came up with that patch also need.

For me, it's a football term. And I'm sure most of us have wished this commercial was real life at some point

https://www.youtube.com/watch?v=RzToNo7A-94

orange sky
May 7, 2007

It.. isn't patched?


https://twitter.com/JDCyberSec/status/979417452370112512?s=19

Internet Explorer
Jun 1, 2005





It's gotten to the point where I don't really care about all these security exploit patches. They'll get applied on a regular basis with the rest of the patches, that's about it. I'm not going to do out of band patching maintenance 3x a month.

CLAM DOWN
Feb 13, 2007

nesaM killed Masen

Lol, sorry guy from earlier who said he had faith MS fixed it. Lol. This loving industry.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


I didn't say I had faith. I said that the link which described and explained the vulnerability and how to do it said that it was fixed in the 2018-03 patch.

CLAM DOWN
Feb 13, 2007

nesaM killed Masen
I'm just cynical as poo poo I guess and didn't believe him at all. Especially given the history gong show of bad/pulled/faulty/problematic Meltdown/Spectre fixes this year.

Proteus Jones
Feb 28, 2013



CLAM DOWN posted:

I'm just cynical as poo poo I guess and didn't believe him at all. Especially given the history gong show of bad/pulled/faulty/problematic Meltdown/Spectre fixes this year.

That early patches were straight up swept off the stage by the clowns from the Amateur Nights at the Apollo.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
Microsoft released a patch for it today https://support.microsoft.com/en-us/help/4100480/windows-kernel-update-for-cve-2018-1038 https://www.catalog.update.microsoft.com/Search.aspx?q=4100480

Here's their article about it https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1038

evil_bunnY
Apr 2, 2003

https://twitter.com/theregister/status/979472597157949440?s=21

orange sky
May 7, 2007

Lol meanwhile a shitload of critical infrastructure was wide open

Don't worry about it guys, everything's ok, the world is definitely not gonna be completely hosed when state actors let their pets off the leash

Tapedump
Aug 31, 2007
College Slice
I know we ain't got a DumpsterFire emoticon yet, but surely we've got one for "slumped above keyboard, banging head on desk/keyboard," right?

Frivolous Sam
Apr 15, 2001

The aliens might be coming, THE ALIENS MIGHT BE COMING.
150 million user accounts with email addresses and mostly bcrypt hashed passwords lost by Under Armour's myfitnesspal website:
https://www.theverge.com/2018/3/29/17177848/under-armour-myfitnesspal-data-breach-150-million-accounts-security

Lost back in Feb, they found out on 25 March but didn't announce until yesterday.

Thanks Ants
May 21, 2004

#essereFerrari


Tapedump posted:

I know we ain't got a DumpsterFire emoticon yet, but surely we've got one for "slumped above keyboard, banging head on desk/keyboard," right?

We have :tif:

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Frivolous Sam posted:

mostly bcrypt hashed passwords

Mostly? :pwn:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Cross posting the good answer

Lysidas posted:

yeah thats p reasonable, after you upgrade to bcrypt there isnt much you can do to the old passwords* and you update users passwords to the newer hasher/params after they log in next, if a user hasnt used the service since you updated the password hashing you will probably have the password stored in the old format still

*without doing something super hacky like if all you have in the database is old_sha1_method(password), update everything and store bcrypt(old_sha1_method(password)) under a separate format like https://docs.djangoproject.com/en/2.0/topics/auth/passwords/#password-upgrading-without-requiring-a-login and this can be enough of a pain that "let it work itself out for any active users" is a reasonable choice, not to mention the big cost of hashing everything all at once instead of as each user logs in

Invalidating the old passwords eventually is the way to go but there's no info on when they switched to bcrypt.

Frivolous Sam
Apr 15, 2001

The aliens might be coming, THE ALIENS MIGHT BE COMING.

quote:

The MyFitnessPal account information that was not protected using bcrypt was protected with SHA-1, a 160-bit hashing function.

Volmarias posted:

Invalidating the old passwords eventually is the way to go but there's no info on when they switched to bcrypt.

They're all invalid now.

Frivolous Sam fucked around with this message at 13:40 on Mar 30, 2018

The Fool
Oct 16, 2003


Frivolous Sam posted:

Lost back in Feb, they found out on 25 March but didn't announce until yesterday.

This is probably the quickest turnaround for a data breach I've heard of.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Yeah, it takes that long to get the lawyers to approve the press release.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Why is the de-facto argument of people who don't care about privacy, "I have nothing to hide"? It's the most tiring conversation to have since literally ever.

Thanks Ants
May 21, 2004

#essereFerrari


Especially as it’s not true. Any request for them to let you borrow their unlocked phone would be met with resistance.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Thanks Ants posted:

Especially as it’s not true. Any request for them to let you borrow their unlocked phone would be met with resistance.

Holy gently caress your new AV lmao

Darchangel
Feb 12, 2009

Tell him about the blower!


ChubbyThePhat posted:

Why is the de-facto argument of people who don't care about privacy, "I have nothing to hide"? It's the most tiring conversation to have since literally ever.

Because they are unthinking and/or stupid.
Usually the best answer is to show them something they should have hidden, but that takes effort and is probably illegal in a lot of examples.

Thanks Ants
May 21, 2004

#essereFerrari


ChubbyThePhat posted:

Holy gently caress your new AV lmao

Yeah it’s a spicy one

Adbot
ADBOT LOVES YOU

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010

Thanks Ants posted:

Especially as it’s not true. Any request for them to let you borrow their unlocked phone would be met with resistance.

"Nothing to hide" meets "keep swiping on their pictures"

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply