Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp

ate all the Oreos posted:

i've been sketching out designs for simple to build basic little radio systems you could in theory make using cheap parts taken out of other things or bought for a few bucks and use to establish links in phone-jammed environments for this same reason. i'm not actually any good at it though so they probably won't work once i get around to building one ¯\_(ツ)_/¯

after i deal with some IRL stuff over the next couple months, i'm going to be starting an (infrequent) podcast and blog about this very issue and trying to network people up for ideas and stuff. PM me some time.

Adbot
ADBOT LOVES YOU

Salt Fish
Sep 11, 2003

Cybernetic Crumb
I can't share details but I came in direct personal contact with a systems administrator who was responsible for one of the sec fucks in this thread. I did a little consulting as part of the clean up, and while getting a debrief I thought 'man this sounds familiar' and looked up the news article here. It was pretty weird to be honest.

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp

Salt Fish posted:

I can't share details but I came in direct personal contact with a systems administrator who was responsible for one of the sec fucks in this thread. I did a little consulting as part of the clean up, and while getting a debrief I thought 'man this sounds familiar' and looked up the news article here. It was pretty weird to be honest.

i've got about 16 months left on my NDA, gonna be fun up in this poo poo

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).



Company that makes a game I once bought about the existential horror of a ubiquitous surveillance state is now desperately begging me for consent to keep my data so they can spam me about their games.

:ironicat:

Truga
May 4, 2014
Lipstick Apathy
https://twitter.com/hanno/status/999554344386224128

Wiggly Wayne DDS
Sep 11, 2010



Salt Fish posted:

I can't share details but I came in direct personal contact with a systems administrator who was responsible for one of the sec fucks in this thread. I did a little consulting as part of the clean up, and while getting a debrief I thought 'man this sounds familiar' and looked up the news article here. It was pretty weird to be honest.
at least it wasn't one of the older threads?

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

nothing smarter than using a multinational’s infrastructure for your illegal POC

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

is ZeroTier as much of a clusterfuck as it looks like? I just wasted 3 days back and forth troubleshooting some goober's vpn client because that thing was installed and trashing the route configs at the same time. Indiegogo VPN client/server/tunnel device is setting off a bunch of alarms in my head

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

BangersInMyKnickers posted:

is ZeroTier as much of a clusterfuck as it looks like? I just wasted 3 days back and forth troubleshooting some goober's vpn client because that thing was installed and trashing the route configs at the same time. Indiegogo VPN client/server/tunnel device is setting off a bunch of alarms in my head



yeah i think lain had a website about that trash

it's all bad, none of the vendors will ever support the poo poo they ship, and the dunning-krueger crowd will refuse to see any flaw with 'em

Loky11
Dec 12, 2006

Pull on the new flesh like borrowed gloves and burn your fingers once again
I literally just texted their intel lead about this. hopefully it gets fixed but lmao.


Edited with info:

He reported it to Hackerone but since it's not a Sony problem they slow rolled him. Wouldn't give him his t-shirt because of the low severity.
Outsourced external dns.

Loky11 fucked around with this message at 15:19 on May 24, 2018

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

Loky11 posted:

I literally just texted their intel lead about this. hopefully it gets fixed but lmao.


Edited with info:

He reported it to Hackerone but since it's not a Sony problem they slow rolled him. Wouldn't give him his t-shirt because of the low severity.
Outsourced external dns.

they've taken it down

edit: welp

Loky11
Dec 12, 2006

Pull on the new flesh like borrowed gloves and burn your fingers once again

Ur Getting Fatter posted:

they've taken it down

edit: welp



yeah...it's gotten...sony legal's attention.

RIP.

spankmeister
Jun 15, 2008






They should put TLS on it with let's encrypt and see if they can harvest cookies.

Truga
May 4, 2014
Lipstick Apathy
the original poster did put a letsencrypt cert on, the page was https lmao

spankmeister
Jun 15, 2008






Haha awesome.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Truga posted:

the original poster did put a letsencrypt cert on, the page was https lmao
yeah it's still the pink scrolly one for me and the https site is signed by let's encrypt
https://www.myhomemanager.sony.com

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe

mrmcd posted:



Company that makes a game I once bought about the existential horror of a ubiquitous surveillance state is now desperately begging me for consent to keep my data so they can spam me about their games.

:ironicat:

lmao

Wiggly Wayne DDS
Sep 11, 2010



happy gdpr everyone

spankmeister
Jun 15, 2008






Wiggly Wayne DDS posted:

happy gdpr everyone

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Wiggly Wayne DDS posted:

happy gdpr everyone

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

Wiggly Wayne DDS posted:

happy gdpr everyone

OldAlias
Nov 2, 2013

Wiggly Wayne DDS posted:

happy gdpr everyone

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Wiggly Wayne DDS posted:

happy gdpr everyone

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Wiggly Wayne DDS posted:

happy gdpr everyone

susan b buffering
Nov 14, 2016

Wiggly Wayne DDS posted:

happy gdpr everyone

ate shit on live tv
Feb 15, 2004

by Azathoth

Wiggly Wayne DDS posted:

happy gdpr everyone

I did not consent to this communication, and according to the GDPR article 69, section 420 signed by president Bill Clinton, you must delete this message within 24 hours or you will be hearing from my attorney.

ate shit on live tv
Feb 15, 2004

by Azathoth
also lol:

quote:

The typical "calls are recorded for training and security purposes" warnings will no longer be sufficient to gain assumed consent to record calls.

redleader
Aug 18, 2005

Engage according to operational parameters

Wiggly Wayne DDS posted:

happy gdpr everyone

Zamujasa
Oct 27, 2010



Bread Liar

Wiggly Wayne DDS posted:

happy gdpr everyone

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Wiggly Wayne DDS posted:

happy gdpr everyone

Mad Wack
Mar 27, 2008

"The faster you use your cooldowns, the faster you can use them again"

Wiggly Wayne DDS posted:

happy gdpr everyone

Doom Mathematic
Sep 2, 2008
'Twas the night before GDPR and all through the house it was not known how many creatures were stirring because we do not have a legitimate business reason to store that information.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Doom Mathematic posted:

'Twas the night before GDPR and all through the house it was not known how many creatures were stirring because we do not have a legitimate business reason to store that information.

i did not consent to sharing my data with santa

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Doom Mathematic posted:

'Twas the night before GDPR and all through the house it was not known how many creatures were stirring because we do not have a legitimate business reason to store that information.
https://twitter.com/moonpolysoft/status/999798397887381506

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Has anyone cataloged LastPass's fuckups with their browser plugin in a single thing? The CVE sites only have a single DoS issue listed from last year and I know there was at least a half dozen trivial fuckups on their part that allowed disclosure of the decrypted store. We're in the process of implementing an internal credential management platform but it isn't ready yet and we need to steer people towards something else to bridge the gap. If I don't have good ammo against LastPass they're going to go there instead of 1Password. Hell, I'd rather them sync a shared OneDrive with a KeepAss db.

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

i know they've had a few isssues turned up by Project Zero, you could try searching the archives there

Proteus Jones
Feb 28, 2013



Maybe even search the last few iterations of SecFuck threads for the Tavis/LastPass stuff.

Not sure how well the SA search function works, since I mostly lurk and shitpost.

Phone
Jul 30, 2005

親子丼をほしい。

BangersInMyKnickers posted:

Has anyone cataloged LastPass's fuckups with their browser plugin in a single thing? The CVE sites only have a single DoS issue listed from last year and I know there was at least a half dozen trivial fuckups on their part that allowed disclosure of the decrypted store. We're in the process of implementing an internal credential management platform but it isn't ready yet and we need to steer people towards something else to bridge the gap. If I don't have good ammo against LastPass they're going to go there instead of 1Password. Hell, I'd rather them sync a shared OneDrive with a KeepAss db.

type into google "taviso shower"

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Phone posted:

type into google "taviso shower"

I love the security holes he finds but I don't want to see his sorry

Adbot
ADBOT LOVES YOU

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

ate poo poo on live tv posted:

also lol:

quote:

The typical "calls are recorded for training and security purposes" warnings will no longer be sufficient to gain assumed consent to record calls.

Please tell me this is actually true and not a joke

  • Locked thread