Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Wiggly Wayne DDS
Sep 11, 2010



i can't recommend an online service as that kind of defeats the purpose of not giving a single service access rights over all of your accounts. at the least with a software or hardware manager you're mitigating the risk to physical access and can contain it if exposure attacks became feasible

Adbot
ADBOT LOVES YOU

Potato Salad
Oct 23, 2014

nobody cares


Ciaphas posted:

thanks, yeah, this affirms what i've learned through googling around for the last hour or so. no specific context in mind, really, i'm just a hopeless neophyte when it comes to security and what I Should Be Doing when the question goes beyond "strong passwords and 2FA are nice"

(specifically I only thought about it again because I was gonna set up a digitalocean droplet for loving around with hosted gitlab, saw the thing about ssh keys, and went "oh yeah")


Since you bring it up, any online service you'd recommend to migrate away from Lastpass to? As I said before I'd use Keepass but between me not being able to carry it on a usb key and only having mobile support through third party ports, it's kind of a non option.

Migrating from LastPass to 1Password is really easy, Google it. Enable MFA. Keep only a physical copy of your access key. Still commit the extremely important/dangerous passwords like your core email and bank only to memory.

Potato Salad fucked around with this message at 23:45 on Apr 6, 2018

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


Potato Salad posted:

Migrating from LastPass to 1Password is really easy, Google it

Is 1Password better regarded than LastPass then?

I completely understand where Wiggly Wayne DDS is coming from, but in this case I'm further to the left on the Convenience<---->Security scale than they are, I think. :v:

Wiggly Wayne DDS
Sep 11, 2010



i can't comment on 1password's new online service, but their old service was good and they've had a good approach to security

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


Alright, I'll do that this weekend then. Thanks for humoring me!

Potato Salad
Oct 23, 2014

nobody cares


Ciaphas posted:

Is 1Password better regarded than LastPass then?

I completely understand where Wiggly Wayne DDS is coming from, but in this case I'm further to the left on the Convenience<---->Security scale than they are, I think. :v:

KeepAss and 1 rear end Word are generally more responsible/proactive than lastpass, yes.

Now, on the token side, I've sat down with sec researchers who defeat physical tokens you can buy on Amazon for a living, so :shrug: you have to thoroughly research any solution.

Wiggly, I'd actually like to hear of your recommendations on tokens

Shaggar
Apr 26, 2006
just use a password protected xlsx on ur one drive.

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

BangersInMyKnickers posted:

I wish dipshits would stop farting over 3DES on TLS1.0. Its the only thing left that XP/IE6 can support and it isn't broken despite qualys making scary red marks next to it. It's stupid that we live in a world were we have to still consider those clients but well Microsoft kinda hosed us all over on that.
enough sites have disabled it that xp/ie8 is now unusable which is an ends-justify-the-means situation for me

keep finding these vulns until use of non-latest browser is made illegal

Wiggly Wayne DDS
Sep 11, 2010



Potato Salad posted:

KeepAss and 1 rear end Word are generally more responsible/proactive than lastpass, yes.

Now, on the token side, I've sat down with sec researchers who defeat physical tokens you can buy on Amazon for a living, so :shrug: you have to thoroughly research any solution.

Wiggly, I'd actually like to hear of your recommendations on tokens
i don't have a lot of experience on physical tokens, could only agree with you on researching them before trying it. i remember langley's research and there seems to be more effort put forward, can't attest to the accuracy of it outside of langley semi-endorsing it

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

Shaggar posted:

yeah its confusing cause you'd think fips mode would be the greatest.

Quoting this cause it's the best

fisting by many
Dec 25, 2009



Main Paineframe posted:

i like how every tweet is signed with the name of the customer service agent who made it so they know exactly who to fire if someone complains, without having to keep track of it themselves

and I'm sure such a brilliant system could never be gamed or subverted


either it's in Javascript, or they're lying. take your pick

if they're using delegated access i'm pretty sure twitter saves the account that made the tweet

but if they're amazingly secure they probably just give every intern the password

computer toucher
Jan 8, 2012

ErIog posted:

This reminds me of how Anaconda Cloud very "helpfully" injects a newline when you copy package install commands from a package page to the clipboard so that it auto-executes when you paste it to a terminal. It's one of the dumbest convenience features I've seen.

it is also trivially easy to hide commands in the middle of lines of text with css fuckery so that what you think you copy isn’t actually what you paste. always copypaste commands to a text editor first.

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

i sit and type out the command by hand usually. dork alert!!

computer toucher
Jan 8, 2012

Ciaphas posted:

gonna be honest i forgot javascript was even a thing for local processing when i asked. i am the worst computertron toucher and should not be trusted :smith:

I absolve you of your sins. go, my son, you may touch a computer again.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

mrmcd posted:

A bit late to this, but the pricier model YubiKey will let you upload (or even generate right on the hardware) a keypair you can use for ssh.

I'm pretty sure it involves touching gpg and some minor client side janitoring, but if your work doesn't prohibited a YubiKey it's a decent option.

yeah it 100% involves gpg, but it’s extremely good

Mr. Nice!
Oct 13, 2005

bone shaking.
soul baking.

BangersInMyKnickers posted:

Every time I've seen it, it has been because there is some business-critical thing that was abandoned by the creators long ago and they don't feel like paying the money to having it re-developed. lovely old code on commodity hardware makes the world go round. I'm not terribly sympathetic to that position but it exists and plenty of places just decided to accept the risk and live with it.

it exists a lot in the military as well. plenty of navy ships were still on xp on almost all of their shipboard workstations in 2013 and there were multiple systems on the ship that ran on standalone NT or 2000 boxes.

Pile Of Garbage
May 28, 2007



isn't the US military payroll system still a monolithic cobol application? and over the years they've made multiple attempts to upgrade it at the cost of hundreds of millions of dollars and every single attempt failed?

edit: just remembered that the US navy used (still uses?) IRC for vessel and fleet communications. not really a secfuck as it's all on internal servers but still funny

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Lutha Mahtin posted:

i sit and type out the command by hand usually. dork alert!!

Same :shobon::hf::shobon:

Mr. Nice!
Oct 13, 2005

bone shaking.
soul baking.

cheese-cube posted:

isn't the US military payroll system still a monolithic cobol application? and over the years they've made multiple attempts to upgrade it at the cost of hundreds of millions of dollars and every single attempt failed?

edit: just remembered that the US navy used (still uses?) IRC for vessel and fleet communications. not really a secfuck as it's all on internal servers but still funny

secret irc is great. everyone thought i was a wizard since i knew how to skin mirc. i was like nah i was just a nerd in the 90s. but, yeah, it's super good for navy comms.

and yeah dfas is still on an ancient cobol mainframe afaik

Mr. Nice! fucked around with this message at 15:53 on Apr 7, 2018

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS
how do you folks keep up with security news?

i follow a few accounts on twitter but i'm not an active user so i don't read them that much.

beyond that it's basically this thread and the occasional article that comes up at work.

Proteus Jones
Feb 28, 2013



Blinkz0rz posted:

how do you folks keep up with security news?

i follow a few accounts on twitter but i'm not an active user so i don't read them that much.

beyond that it's basically this thread and the occasional article that comes up at work.

Basically twitter, this thread, and colleagues and friends in the industry.

Pile Of Garbage
May 28, 2007



Mr. Nice! posted:

secret irc is great. everyone thought i was a wizard since i knew how to skin mirc. i was like nah i was just a nerd in the 90s. but, yeah, it's super good for navy comms.

and yeah dfas is still on an ancient cobol mainframe afaik

i don't post in or really read GiP except for the "Let's Talk About Idiots!" thread where i'm certain i read an amazing story about people loving up on the channels for some fleet during an exercise. also depressing stories about people getting owned simultaneously by dfas and veteran services

edit:

Blinkz0rz posted:

how do you folks keep up with security news?

i follow a few accounts on twitter but i'm not an active user so i don't read them that much.

beyond that it's basically this thread and the occasional article that comes up at work.

what do you do for a job (if you don't mind me asking)? i personally am not in a direct security role however i like to stay abreast of things so i'm doing basically what you're already doing at the moment.

Pile Of Garbage fucked around with this message at 16:42 on Apr 7, 2018

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

Mr. Nice! posted:

and yeah dfas is still on an ancient cobol mainframe afaik

Lol that mainframe and cobol is more modern than the xp/2000 boxes on the ships.

Shaggar
Apr 26, 2006

cheese-cube posted:

isn't the US military payroll system still a monolithic cobol application? and over the years they've made multiple attempts to upgrade it at the cost of hundreds of millions of dollars and every single attempt failed?

edit: just remembered that the US navy used (still uses?) IRC for vessel and fleet communications. not really a secfuck as it's all on internal servers but still funny

every single attempt was successful at spending the money which was the goal

Raere
Dec 13, 2007

Blinkz0rz posted:

how do you folks keep up with security news?

i follow a few accounts on twitter but i'm not an active user so i don't read them that much.

beyond that it's basically this thread and the occasional article that comes up at work.

risky.biz podcast news section. skip the second half

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shaggar posted:

every single attempt was successful at spending the money which was the goal

defense spending in a nutshell

the only penalty for blowing the budget or the schedule is getting more money and time

Pile Of Garbage
May 28, 2007



Shaggar posted:

every single attempt was successful at spending the money which was the goal

yes i am aware of the military industrial complex shaggar

Pile Of Garbage
May 28, 2007



Cocoa Crispies posted:

defense spending in a nutshell

the only penalty for blowing the budget or the schedule is getting more money and time

no you see it's simply "early operation support" / "capability extension" / "extended protocol testing" "integration facilitation" / "phase/block 2"

Heavy_D
Feb 16, 2002

"rararararara" contains the meaning of everything, kept in simple rectangular structures
https://uk.reuters.com/article/uk-u...E96818K20130709

quote:

"At last count, there were 167 "manual workarounds" for the 40-year-old pay system used by DFAS and all the services except the Marines, he said. As a result, staff members often must write down information from one system, carry it to another office and hand it off to other workers who then manually enter it into other systems - a process called "finger-gapping" that Wallace faults as a further source of errors.

420 SWAGLORD
Apr 20, 2014

saban bajramovic
Imho similar measures should be encouraged in industry to encourage fraud and decrease accountability :911:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
when i was in the air force 10+ years ago it was commonly assumed that if you had to go to finance for any reason, they would gently caress up your paycheck somehow

Mr. Nice!
Oct 13, 2005

bone shaking.
soul baking.

cheese-cube posted:

i don't post in or really read GiP except for the "Let's Talk About Idiots!" thread where i'm certain i read an amazing story about people loving up on the channels for some fleet during an exercise. also depressing stories about people getting owned simultaneously by dfas and veteran services

honestly gip is pretty decent all in all. most of the alt-right types bailed 5 years ago or so and it’s been mostly chill. i’ve had to tell more than one vet goon that, but seriously come on down and join the party.

My PIN is 4826
Aug 30, 2003

Raere posted:

risky.biz podcast news section. skip the second half

this is the only podcast i listen to reliably the day it comes out, every week, it's great

i'm going to get hate from this thread now, but security now is also good for getting more technical details if you're prepared to skip a lot and can tolerate listening to stebe gibson

Raere
Dec 13, 2007

My PIN is 4826 posted:

this is the only podcast i listen to reliably the day it comes out, every week, it's great

i'm going to get hate from this thread now, but security now is also good for getting more technical details if you're prepared to skip a lot and can tolerate listening to stebe gibson

I’d like to take a moment and talk to you about SpinRite.

Babies Getting Rabies
Apr 21, 2007

Sugartime Jones

Raere posted:

risky.biz podcast news section. skip the second half

they sometimes do have good feature interviews

spankmeister
Jun 15, 2008






Yeah the feature interviews are p great sometimes. The sponsor interviews you can skip.

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.


unethical penetration testing on public infrastructure results in security hole

ElZilcho
Apr 4, 2007



Hahaha - http://www.abc.net.au/news/2018-04-06/porn-displayed-on-screen-at-yagan-square/9625808

Chalks
Sep 30, 2009


Wow someone really put some time into writing that article

Adbot
ADBOT LOVES YOU

ElZilcho
Apr 4, 2007

Chalks posted:

Wow someone really put some time into writing that article

My bad, I linked the photo caption page.

Proper link - http://www.abc.net.au/news/2018-04-06/porn-site-pornhub-displayed-on-perth-yagan-square-touchscreen/9624428

  • Locked thread