Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Cocoa Crispies posted:

continuing to pay for apps as they get used is important so that developers can afford to fix problems that show up later instead of just riding off into the sunset with a one-time lump sum

we should just discourage connectivity and networking functions instead

Adbot
ADBOT LOVES YOU

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

I use like a 6 year old version of budgeting software because the devs got it in their heads to go ~~cloud based subscription app~~ for the next version and it more expensive and way worse now and also now demands all your bank account logins when it didn't before.

I will keep using the old version I paid for until I die or the Adobe Air runetime finally stops working on windows.

Shifty Pony
Dec 28, 2004

Up ta somethin'


I have no problem with app subscriptions.


consumable in-app purchases are usually barely disguised gambling and everyone in the industry knows it.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
So, our company is pushing Stealth as a solution for our end point security, but in an environment where we even struggle to patch, how useful would a encrypted tunnel/network segmentation like Stealth be?

That and I'm really skeptical about a software tunnel solution for network segmentation...

EMILY BLUNTS
Jan 1, 2005

Yesterday I Learned how to rekey kwikset smartkey without the original key, or the rekey tool or the locksmith reset tool.
(You just take it all apart then reassemble it with the new key in)

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

CommieGIR posted:

So, our company is pushing Stealth as a solution for our end point security, but in an environment where we even struggle to patch, how useful would a encrypted tunnel/network segmentation like Stealth be?

That and I'm really skeptical about a software tunnel solution for network segmentation...

its a replacement for host-based firewalls for micro segmentation but beyond that ehhhhhhhhhhhhh. Protected enclaves are great and all but you still need to assume something is going to bypass it and get inside those tunnels. You can pretty much do this for free today by utilizing IPsec in Windows for AD enrolled clients and kerberos auth

Crime on a Dime
Nov 28, 2006

EMILY BLUNTS posted:

Yesterday I Learned how to rekey kwikset smartkey without the original key, or the rekey tool or the locksmith reset tool.
(You just take it all apart then reassemble it with the new key in)

explain

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
with physical access you can get root

Shifty Pony
Dec 28, 2004

Up ta somethin'


Ulf posted:

with physical access you can get root

kwikset locks are garbage but yeah this is pretty much the situation.

you can rekey pretty much any lock that you are able to disassemble.

Shame Boy
Mar 2, 2010

one of my coworkers thinks putting credentials in query string parameters is "just as secure" as in POST body or auth headers and refuses to believe otherwise, help im dying

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shifty Pony posted:

kwikset locks are garbage but yeah this is pretty much the situation.

you can rekey pretty much any lock that you are able to disassemble.

yeah, if you're taking the parts that make the lock lock you can change which keys it works with

spankmeister
Jun 15, 2008






My car was broken into and I got a new lock for it which was keyed differently. So I got the wafers from the old busted lock and put them in the new lock. Fiddly job but it worked out ok.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

spankmeister posted:

Fiddly job but it worked out ok.

locks.txt

MrMoo
Sep 14, 2000

ate all the Oreos posted:

one of my coworkers thinks putting credentials in query string parameters is "just as secure" as in POST body or auth headers and refuses to believe otherwise, help im dying

Because the coworker is only thinking about the immediate execution, that would appear logical. It's intermediary HTTP proxies and HTTP servers logging all requests and thus being promoted into being a convenient credential feed for consumption.

Shame Boy
Mar 2, 2010

MrMoo posted:

Because the coworker is only thinking about the immediate execution, that would appear logical. It's intermediary HTTP proxies and HTTP servers logging all requests and thus being promoted into being a convenient credential feed for consumption.

yeah i told him this and his answer was "but we control the server so we can control what it's logging, and besides i'm sure servers log headers too so it's the same"

MrMoo
Sep 14, 2000

The other important area: the credentials will end up in the browser history, not forgetting bookmarks, leading to accidental replay and an easy attack vector. It's also easy for third party JavaScript to pickup window.location and thus the credentials, e.g. advertising.


ate all the Oreos posted:

yeah i told him this and his answer was "but we control the server so we can control what it's logging, and besides i'm sure servers log headers too so it's the same"

"Yes" but without the full URL the logging will be useless, and "no" unless you are only expecting a handful of users, for most setups it simply does not scale.

MrMoo fucked around with this message at 20:25 on Aug 27, 2018

prisoner of waffles
May 8, 2007

Ah! well a-day! what evil looks
Had I from old and young!
Instead of the cross, the fishmech
About my neck was hung.

ate all the Oreos posted:

one of my coworkers thinks putting credentials in query string parameters is "just as secure" as in POST body or auth headers and refuses to believe otherwise, help im dying

this is true*

* for a specific definition of security**
** this definition of security is dumb as heck

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

prisoner of waffles posted:

this is true*

* for a specific definition of security**
** this definition of security is dumb as heck

great stuff here

apseudonym
Feb 25, 2011

ate all the Oreos posted:

yeah i told him this and his answer was "but we control the server so we can control what it's logging, and besides i'm sure servers log headers too so it's the same"

"Mistakes happen and you should develop defensively, being one missed url stripping call away from a password in the logs isn't acceptable"

Truga
May 4, 2014
Lipstick Apathy

ate all the Oreos posted:

yeah i told him this and his answer was "but we control the server so we can control what it's logging, and besides i'm sure servers log headers too so it's the same"

lol which server is this that logs headers

asking for a friend, not to send 5tb of http headers in my request, promise :v:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

many log Referer and UA at least

prisoner of waffles
May 8, 2007

Ah! well a-day! what evil looks
Had I from old and young!
Instead of the cross, the fishmech
About my neck was hung.
i'll be sure to not use referer and user agent to transmit authentication info then, thanks

Truga
May 4, 2014
Lipstick Apathy

Subjunctive posted:

many log Referer and UA at least

hmm you're right. my next worm is going to be just a browser addon that sets UA to 10MB, then watch the world burn

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Truga posted:

hmm you're right. my next worm is going to be just a browser addon that sets UA to 10MB, then watch the world burn

in a couple years i think we'll get there.

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.1

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

prisoner of waffles posted:

i'll be sure to not use referer and user agent to transmit authentication info then, thanks

yeah transmit authentication information in the tls handshake

Shaggar
Apr 26, 2006

ate all the Oreos posted:

yeah i told him this and his answer was "but we control the server so we can control what it's logging, and besides i'm sure servers log headers too so it's the same"

hes right in that if your security worry is server side logging, then headers and post content are just as easy to log as the url, however I don't think any servers do headers or content by default. client side url caching is way more of an issue


Truga posted:

hmm you're right. my next worm is going to be just a browser addon that sets UA to 10MB, then watch the world burn

most servers have a header size limit of a few kb

Salt Fish
Sep 11, 2003

Cybernetic Crumb

Truga posted:

hmm you're right. my next worm is going to be just a browser addon that sets UA to 10MB, then watch the world burn

413 entity too large.

Mr. Nice!
Oct 13, 2005

bone shaking.
soul baking.

Salt Fish posted:

413 entity too large.

that's what your mum said

Last Chance
Dec 31, 2004

Mr. Nice! posted:

that's what your mum said

their mom's a computer?!!?

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Mr. Nice! posted:

that's what your mum said

was she looking in a mirror?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Mr. Nice! posted:

that's what your mum said

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

Mr. Nice! posted:

that's what your mum said

kind of rude of her to turn you down like that, but you really could stand to lose a few pounds

Salt Fish
Sep 11, 2003

Cybernetic Crumb

Mr. Nice! posted:

that's what your mum said

My mom is 451, your mom is 402.

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

Salt Fish posted:

My mom is 451, your mom is 402.

Yo momma is 418 -- short and stout.

Vesi
Jan 12, 2005

pikachu looking at?
to my momma I'll always be 417

Mr. Nice!
Oct 13, 2005

bone shaking.
soul baking.
my mom is 404 :smith:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy
is this the new computer janitor thread?

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
No please don't poo poo it up

evil_bunnY
Apr 2, 2003

speaking of gossi

https://twitter.com/gossithedog/status/1034334475101130753?s=21

Adbot
ADBOT LOVES YOU

BlankSystemDaemon
Mar 13, 2009




You missed the most important part:

someone making a tweet posted:

Here is the alpc bug as 0day: https://github.com/SandboxEscaper/randomrepo/blob/master/PoC-LPE.rar … I don't loving care about life anymore. Neither do I ever again want to submit to MSFT anyway. gently caress all of this poo poo.
Shine on, you crazy diamond.

BlankSystemDaemon fucked around with this message at 22:49 on Aug 28, 2018

  • Locked thread