Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Khablam
Mar 29, 2012

Poster B (Me) explained the analogy of the street cleaners posited by poster A (Potato Salad) because poster A had clearly given up on the will to live and I genuinely feared you'd be asking about street cleaners ITT forever.
Does that explain it?

Adbot
ADBOT LOVES YOU

Downs Duck
Nov 19, 2005
"It's only after we've lost everything that we're free do to anything"

Khablam posted:

Poster B (Me) explained the analogy of the street cleaners posited by poster A (Potato Salad) because poster A had clearly given up on the will to live and I genuinely feared you'd be asking about street cleaners ITT forever.
Does that explain it?

Take a break, seriously. Then read the posts again. I don't think I am alone in believing you are wrong here.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Genuinely curious if you've ever been diagnosed with, or been accused of suffering from, mania

Downs Duck
Nov 19, 2005
"It's only after we've lost everything that we're free do to anything"

Rufus Ping posted:

Genuinely curious if you've ever been diagnosed with, or been accused of suffering from, mania

Not me, but I'm not sure about Khablam and his "street cleaners"/strawmen obsession.

Anyway, I'm taking a break from this insane derail, hope no one has a heart attack, have a nice day everyone.

Downs Duck fucked around with this message at 17:33 on Aug 23, 2018

DoctorTristan
Mar 11, 2006

I would look up into your lifeless eyes and wave, like this. Can you and your associates arrange that for me, Mr. Morden?
Do you know the difference between a straw man and an analogy?

Wiggly Wayne DDS
Sep 11, 2010



DoctorTristan posted:

Do you know the difference between a straw man and an analogy?
he never mentioned straw men, please keep to the topic

Potato Salad
Oct 23, 2014

nobody cares


Wiggly Wayne DDS posted:

he never mentioned straw men, please keep to the topic

DoctorTristan
Mar 11, 2006

I would look up into your lifeless eyes and wave, like this. Can you and your associates arrange that for me, Mr. Morden?

Wiggly Wayne DDS posted:

he never mentioned straw men, please keep to the topic

I was misdirected by his awesome Infosec practice of writing incomprehensible walls of text.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I’ve twice tried to start writing a patient, compassionate post explaining where Duck went wrong, but I can’t get my head all the way around it. It is a lot to unpack. Wheels within wheels.

apseudonym
Feb 25, 2011

Downs Duck posted:

To make it easy, a mechanic or a nurse wouldn't respond like many (not all) IT-professionals do (various degrees of angry/insults/etc like in this thread), when asked politely about something related to their field of expertise. In my humble, anecdotal experience.
I wouldn't take the vast majority of IT professionals views on how to secure a device (fite me thread), because they're where a lot of the paranoid and non productive security advice comes from.

When I said to switch off custom ROMs its because I do OS security, and you've taken your security from people who do it for a living and put it all on yourself, and you're not a mechanic.

Fundamentally the view that you need to do extra things to make yourself secure is the problem, because you're not an expert and can't be expected to do so correctly, and in your attempts to do something you've made your situation worse.

Corsair Pool Boy
Dec 17, 2004
College Slice
The sarcasm, sass, and confrontational attitudes are in no way unique to IT. They're generally an internet thing, and very much a dead gay comedy forum thing. If you don't know much about cars, go into Automotive Insanity. Describe your understanding of how a car works and what you think specifically can be done to keep it running and see what happens. It will be functionally the same as what you got here: facts and good advice interspersed with people telling you your ideas are dumb or wrong in a spectrum of different ways.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Downs Duck posted:

Take a break, seriously. Then read the posts again. I don't think I am alone in believing you are wrong here.

Holy crap dude, there's no way you're this dense. I can understand "how did this get here I am not good with computer" tier infosec knowledge when you're not in or peripheral to the industry, but this is something else.

Also I use a jailbroken phone because it's the only way to remap the Bixby button. gently caress Samsung.

Khablam
Mar 29, 2012

No, it's not.
There's a couple of apps that achieve it.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


They aren't as good as bxActions.

I am Communist
Apr 19, 2002

I can show you what endless looks like
I can show you a single infinite thing
I can let you taste the sweet and sour of forever
Unending. Eternal. Inevitable
Taste my darkness
Climb into my abyss
Fall into me. Into my eyes
Look at them. Depths unfathomable
Pain immeasurable
A cruel promise fulfilled




https://www.youtube.com/watch?v=N9wsjroVlu8





Just want to say I've gotten a lot from this thread about security and practices. Regardless of the arguments & derails, there is quite a bit of experience here and people are worth listening to.
So for a positive note: I'd like to thank the advice, good and otherwise!
I don't think it's been said enough that for free tips, advice, & experience this thread has helped many for not a lot of thanks. (I'm sure in IT you're all used to it)

Khablam
Mar 29, 2012

Cup Runneth Over posted:

They aren't as good as bxActions.
bxactions doesn't require root, it runs using the accessibility workarounds. You can use ADB to further expand the options but you do not need to root.
If you've somehow got an app that needs it, you've got a fraudulent app.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Khablam posted:

bxactions doesn't require root, it runs using the accessibility workarounds. You can use ADB to further expand the options but you do not need to root.
If you've somehow got an app that needs it, you've got a fraudulent app.

I've got this one: https://play.google.com/store/apps/details?id=com.jamworks.bxactions&hl=en_US

I'm pretty sure that's why I installed root. It's been a while.

Khablam
Mar 29, 2012

Cup Runneth Over posted:

I've got this one: https://play.google.com/store/apps/details?id=com.jamworks.bxactions&hl=en_US

I'm pretty sure that's why I installed root. It's been a while.
Yeah this doesn't require root.
Don't root phones.

Kerning Chameleon
Apr 8, 2015

by Cyrano4747
Google has started selling their Titan security key bundle to the general public for $50. It comes with one NFC-capable USB key and one Bluetooth key with USB dongle. If I'm in the market to buy security keys, is there any reason I wouldn't buy these in favor of a pair of good ol' Yubikey NEOs for $100?

My phone is a NFC-capable Android, so the Bluetooth key is the one that would get shoved into the firesafe as a backup.

Red_Fred
Oct 21, 2010


Fallen Rib
I’m keen to purchase some sort of internal security camera for my apartment. My thoughts were that it doesn’t need to be internet enabled (I would actually prefer it isn’t for security reasons). I was thinking some kind of cheap IP camera and cheap NAS that saves like a week’s footage. Low FPS is fine. Can anyone recommend something?

I’m renting at the moment so it’s really just to keep an eye on unsupervised people in my apartment. I try to be there generally but can’t always.

This may be outside the scope of this thread, please let me know if so.

Rexxed
May 1, 2010

Dis is amazing!
I gotta try dis!

Red_Fred posted:

I’m keen to purchase some sort of internal security camera for my apartment. My thoughts were that it doesn’t need to be internet enabled (I would actually prefer it isn’t for security reasons). I was thinking some kind of cheap IP camera and cheap NAS that saves like a week’s footage. Low FPS is fine. Can anyone recommend something?

I’m renting at the moment so it’s really just to keep an eye on unsupervised people in my apartment. I try to be there generally but can’t always.

This may be outside the scope of this thread, please let me know if so.

You may want to ask in the Home automation and security systems thread. IP cameras are very cheap these days and are usually pretty good. If you want to keep an eye on your place because you think someone may do something, consider that they may do something and then steal your camera and NAS as well when you plan it out. A lot of IP cameras can even just record onto a micro-sd hc card if you don't want to involve saving it to a drive, but this further increases the danger of one device being stolen or broken and leaving you with no footage.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Got infected by some malware recently, probably from a torrent. It went by SoundMixer.exe and the only reason I found out I had it was because it (presumably accidentally) disabled the Command Prompt. Surprisingly easy to clean out; just deleted it from AppData, cleaned out the few registry entries it made, and force-killed the "Sound Mixing Utility" processes it started, and everything was back to normal. Anyway, if cmd.exe suddenly stops working for you, that's probably why.

Carbon dioxide
Oct 9, 2012

Cup Runneth Over posted:

Got infected by some malware recently, probably from a torrent. It went by SoundMixer.exe and the only reason I found out I had it was because it (presumably accidentally) disabled the Command Prompt. Surprisingly easy to clean out; just deleted it from AppData, cleaned out the few registry entries it made, and force-killed the "Sound Mixing Utility" processes it started, and everything was back to normal. Anyway, if cmd.exe suddenly stops working for you, that's probably why.

Malwares can leave secondary payloads. Make sure to do a very thorough scan of your computer for other malware, and keep at it because if there's something else it might stay dormant for a long time until something (like a timer or whatever) triggers it.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Carbon dioxide posted:

Malwares can leave secondary payloads. Make sure to do a very thorough scan of your computer for other malware, and keep at it because if there's something else it might stay dormant for a long time until something (like a timer or whatever) triggers it.
:pt:

crazypenguin
Mar 9, 2005
nothing witty here, move along
I'm probably switching from android to ios. Anyone got a recommendation for Keepass on iOS? My requirements are only: not-stupid, no ads, supports dropbox. MiniKeePass comes up first...

And I guess just for the record, I've found the following to be fine keepass clients for various OSes:

Windows: KeePass 2
MacOS: MacPass (Thank you OP for pointing this one out!)
Linux: KeePassX
Android: KeePassDroid

These all work fine syncing together.

Second question: I want to adopt Yubikeys in the not too distant future. I seem to recall that iOS has problems with NFC. Is that getting resolved at all? Or has it? Basically, any reason I should be wary of going to iOS in this respect?

Finally: Anybody here adopted that Google Account Advanced Protection feature? Any problems? Do the usual iOS integrations still work just fine? (contacts, calendar, mail)

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
For what it is worth, there isn't really a good option for KeePass on iOS but I have been using the shared clipboard option when I am at home--I have no idea about its risk of use here.

This has been a recommendation to me but I have yet to test:
https://www.kyuran.be/software/kypass/

drainpipe
May 17, 2004

AAHHHHHHH!!!!
I use MiniKeePass on iOS and it's been fine for me. You can export your database from your Dropbox app to it and upload key files via iTunes.

Khablam
Mar 29, 2012

+1 to MiniKeePass, but bear in mind the sync is one way and it can be frustrating if you ever need to sign up to anything on your phone.
Yubikey has some support on iOS, but it's walled in as is anything iOS and I don't think minikeepass supports it.

Red_Fred
Oct 21, 2010


Fallen Rib

Lain Iwakura posted:

For what it is worth, there isn't really a good option for KeePass on iOS but I have been using the shared clipboard option when I am at home--I have no idea about its risk of use here.

This has been a recommendation to me but I have yet to test:
https://www.kyuran.be/software/kypass/

I use this and it’s good! Think it’s paid though. Can update you DB using your phone which is pretty handy.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Carbon dioxide posted:

Malwares can leave secondary payloads. Make sure to do a very thorough scan of your computer for other malware, and keep at it because if there's something else it might stay dormant for a long time until something (like a timer or whatever) triggers it.

Good advice. Just found out it disabled Windows Defender via group policy (short registry fix there), so :pt: might be the best option (my only option!). Any advice on whether Fresh Start is better than a full flatten?

Kerning Chameleon
Apr 8, 2015

by Cyrano4747

Cup Runneth Over posted:

Good advice. Just found out it disabled Windows Defender via group policy (short registry fix there), so :pt: might be the best option (my only option!). Any advice on whether Fresh Start is better than a full flatten?

I don't think anyone on these forums is ever going to recommend anything other than the straight nuke reinstall, especially when malware is involved. Quite frankly, one could argue the "soft" reinstall options Windows gives these days are misleading, false reassurance for people who don't make backups, and could theoretically cause bigger diagnostic problems for regular users later on down the road.

Carbon dioxide
Oct 9, 2012

I have no idea what those soft reset options even do.

DoctorTristan
Mar 11, 2006

I would look up into your lifeless eyes and wave, like this. Can you and your associates arrange that for me, Mr. Morden?

Khablam posted:

+1 to MiniKeePass, but bear in mind the sync is one way and it can be frustrating if you ever need to sign up to anything on your phone.
Yubikey has some support on iOS, but it's walled in as is anything iOS and I don't think minikeepass supports it.

You can sync both ways by re-uploading the file to dropbox from MiniKeePass, though the sequence for doing that is weirdly counterintuitive and I have to look it up every single loving time.

hooah
Feb 6, 2006
WTF?
Speaking of KeePass et al., I switched the storage from Google Drive to Dropbox a whole back since in either this thread or one of the Android threads people said it worked better with Keepass2Android, the app I've been using. However, it still doesn't sync from my phone. What other combinations should I try? I just downloaded KeePassDroid, but it can't pull from Dropbox at all.

Potato Salad
Oct 23, 2014

nobody cares


Fresh Start redownloads the OS and performs an in-place, same-version upgrade preserving user files. It's okay, I've used it to eliminate Trojans/adware/bloatware/spyware successfully. It will eliminate most rootkits as the downloaded payload is signed and verified.

It's hard to give an endorsement to a system with terrible QA and non-existent transparency, but researchers have spent and continue to spend significant effort on investigating the integrity of the always-on, P2P Windows Update and Install/Upgrade stacks as a sort of Holy Grail of watering hole attacks. It's good so far, with the only significant, unmitigated issue being that Reset installs a Windows-brand operating system on your machine.

Potato Salad fucked around with this message at 14:49 on Sep 1, 2018

Oysters Autobio
Mar 13, 2017
Dumb question here but for the life of me I have still not been able to figure this out. This is one of those questions where I've let it go on too long before finally admitting I don't get it.

I know password managers with complex passwords are the way to go now. My question is, if I understand how they work, is that essentially you have some sort of password for access to your Password manager, and then the manager autogenerates long and complex passwords for each of your websites or accounts you go to (do they do it automatically like Google's password thing?).

If my understanding of the above is correct, does that mean you pretty much have to only use your computer or device that has this manager on it to login to your accounts? If I have a password manager on my laptop that manages Something Awful, then I go on my phone, how do I login when the manager is on my phone?

Finally, I'm assuming this precludes you really using any of your accounts from a public computer or your friend's, right?

Potato Salad
Oct 23, 2014

nobody cares


It's not all that hard to enter a 15 character password on a friend's computer, reading from your phone

If you're regularly doing lots of work on shared computers, put that in your use case.

Khablam
Mar 29, 2012

If you're in the situation where you might need to do that, leave symbols out of the password and check it - eliminate any ambiguous characters O / 0 and I / l for instance.
Keepass and a few others will use a font to help, but it's still a good idea.

hooah posted:

Speaking of KeePass et al., I switched the storage from Google Drive to Dropbox a whole back since in either this thread or one of the Android threads people said it worked better with Keepass2Android, the app I've been using. However, it still doesn't sync from my phone. What other combinations should I try? I just downloaded KeePassDroid, but it can't pull from Dropbox at all.
Your phone is probably power managing dropbox, let it run as an exception and it should push changes fine.

Pile Of Garbage
May 28, 2007



IMO the most important aspect of using a password manager is that it encourages you to use unique passwords for each service that you interact with. If a service you use is doing something stupid like storing passwords in plain text it won't matter how complex your password is if their DB gets popped. However if your password is unique to that one service then it will prevent whomever from compromising your other accounts.

Realistically having 2FA enabled with an OTP app is more important than making sure your password is complex.

Adbot
ADBOT LOVES YOU

Kerning Chameleon
Apr 8, 2015

by Cyrano4747

cheese-cube posted:

Realistically having 2FA enabled with an OTP app is more important than making sure your password is complex.

This still leaves the user vulnerable to phishing and MITM attacks, however. That's why the glacial adoption rate of FIDO security keys is so frustrating, as they both kill those attacks dead and have the benefit of being easier to use and understand for the average user.

At that point, using both a password manager and security key (with any SMS recovery notably disabled), the last remaining front-end account vulnerabilities would be compromised devices and physical coercion.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply