Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug
then what the gently caress else do people use it for

Adbot
ADBOT LOVES YOU

bob dobbs is dead
Oct 8, 2017

I love peeps
Nap Ghost
arent a ridiculous fraction of "models" on instagram prostitutes

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug

Shaggar posted:

yeah its a sketchy uefi module installed by manufacturers for tracking stolen laptops. its essentially a rootkit and exploits a hijacking of a windows system component (autochk) in order to install itself in the os. It is equally easily hijacked by other, more nefarious malware like the one presented in the article.

If Microsoft were to have signed this and other components in the boot sequence that particular exploit would not be possible.

The separate task of the malware modifying the firmware with its own rootkit requires misconfiguration or exploitation of secure boot. That's on manufacturers and admins to handle properly, but if Microsoft is not checking signatures on the stuff windows is running you may still run into bad ideas like computrace/lojack.

and this was superseded by microsoft allowing a sepcific ACPI key to just execute the contents as a binary blob on windows boot, so a thid party bios would not have to understand ntfs and overwrite a specific core windows component

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Janitor Prime posted:

you know you can’t hire hit men and hookers on FB right?
last i checked you could still buy drugs and guns there

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Janitor Prime posted:

you know you can’t hire hit men and hookers on FB right?

Shows what u know

akadajet
Sep 14, 2003

bob dobbs is dead posted:

arent a ridiculous fraction of "models" on instagram prostitutes

twitch seems to be full of sex workers nowadays

Shaggar
Apr 26, 2006

Lysidas posted:

and this was superseded by microsoft allowing a sepcific ACPI key to just execute the contents as a binary blob on windows boot, so a thid party bios would not have to understand ntfs and overwrite a specific core windows component

that seems like a better idea but its still kind of sketchy for the ultimate goal to be installing software in the os. maybe its something that could be handled out of band instead.

cinci zoo sniper
Mar 15, 2013




akadajet posted:

twitch seems to be full of sex workers nowadays

it’s good advertising for them, much like instagram

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

akadajet posted:

twitch seems to be full of sex workers nowadays

gamers are easy marks, so that makes sense

sadus
Apr 5, 2004

https://twitter.com/congressedits/status/1045422483082551302 :smugdon:

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

anthonypants posted:

you can set windows 10 to make msis do this



where is that setting I am interested

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Farmer Crack-rear end posted:

this sounds familiar. is this the same kind of poo poo lenovo was pulling to push their crapware onto windows installs?

There's an optional partition on UEFI that you can dump software on to and the Windows install routine will fire that off silently. It was made for OEMs and Lenovo abused it immediately

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BangersInMyKnickers posted:

where is that setting I am interested
settings > apps & features, it's the drop-down at the top. the setting that displays that message is "warn me before installing apps outside of the store"

i don't know what specifically triggers it because there's installers that don't set it off, but non-microsoft .msi packages definitely generate that popup

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug

BangersInMyKnickers posted:

There's an optional partition on UEFI that you can dump software on to and the Windows install routine will fire that off silently. It was made for OEMs and Lenovo abused it immediately

is this distinct from the windows platform binary table https://download.microsoft.com/download/8/A/2/8A2FB72D-9B96-4E2D-A559-4A27CF905A80/windows-platform-binary-table.docx ? because its super easy to get around what youre describing by zeroing a disk before a windows install

akadajet
Sep 14, 2003

https://newsroom.fb.com/news/2018/09/security-update/

quote:

On the afternoon of Tuesday, September 25, our engineering team discovered a security issue affecting almost 50 million accounts. We’re taking this incredibly seriously and wanted to let everyone know what’s happened and the immediate action we’ve taken to protect people’s security.

Our investigation is still in its early stages. But it’s clear that attackers exploited a vulnerability in Facebook’s code that impacted “View As”, a feature that lets people see what their own profile looks like to someone else. This allowed them to steal Facebook access tokens which they could then use to take over people’s accounts. Access tokens are the equivalent of digital keys that keep people logged in to Facebook so they don’t need to re-enter their password every time they use the app.

Here is the action we have already taken. First, we’ve fixed the vulnerability and informed law enforcement.

Second, we have reset the access tokens of the almost 50 million accounts we know were affected to protect their security. We’re also taking the precautionary step of resetting access tokens for another 40 million accounts that have been subject to a “View As” look-up in the last year. As a result, around 90 million people will now have to log back in to Facebook, or any of their apps that use Facebook Login. After they have logged back in, people will get a notification at the top of their News Feed explaining what happened.

Third, we’re temporarily turning off the “View As” feature while we conduct a thorough security review.

This attack exploited the complex interaction of multiple issues in our code. It stemmed from a change we made to our video uploading feature in July 2017, which impacted “View As.” The attackers not only needed to find this vulnerability and use it to get an access token, they then had to pivot from that account to others to steal more tokens.

Since we’ve only just started our investigation, we have yet to determine whether these accounts were misused or any information accessed. We also don’t know who’s behind these attacks or where they’re based. We’re working hard to better understand these details — and we will update this post when we have more information, or if the facts change. In addition, if we find more affected accounts, we will immediately reset their access tokens.

People’s privacy and security is incredibly important, and we’re sorry this happened. It’s why we’ve taken immediate action to secure these accounts and let users know what happened. There’s no need for anyone to change their passwords. But people who are having trouble logging back into Facebook — for example because they’ve forgotten their password — should visit our Help Center. And if anyone wants to take the precautionary action of logging out of Facebook, they should visit the “Security and Login” section in settings. It lists the places people are logged into Facebook with a one-click option to log out of them all.

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

https://www.nytimes.com/2018/09/28/technology/facebook-hack-data-breach.html


quote:

SAN FRANCISCO — Facebook on Friday said an attack on its computer network led to the exposure of information from nearly 50 million of its users.

The company discovered the breach earlier this week, finding that attackers had exploited a feature in Facebook’s code that allowed them to take over user accounts. Facebook fixed the vulnerability and notified law enforcement officials.

More than 90 million of Facebook’s users were forced to log out of their accounts Friday morning, a common safety measure for compromised accounts.

Ron Paul its happening dot gif

akadajet
Sep 14, 2003

securing facebook sounds like an impossible nightmare

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

akadajet posted:

securing facebook sounds like an impossible nightmare
protect the graph

Last Chance
Dec 31, 2004

lol that it's the "view as" feature that is probably a rat's nest of poo poo to deal with

also they force logged me out today, does that mean my identtiy is stolen

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

anthonypants posted:

protect the graph

lol

akadajet
Sep 14, 2003

Last Chance posted:

lol that it's the "view as" feature that is probably a rat's nest of poo poo to deal with

also they force logged me out today, does that mean my identtiy is stolen

I didn't get logged out. So I'd assume all your facebook poo poo was stolen, assuming you have facebook poo poo.

akadajet
Sep 14, 2003

anthonypants posted:

protect the graph

protect deez nuts

Evis
Feb 28, 2007
Flying Spaghetti Monster

I wonder how long it’s been broken, and if one person exploited it 90 million times, or if millions of people exploited it a few times. can’t imagine law enforcement would enjoy receiving a csv with 45 million IP addresses to investigate.

Last Chance
Dec 31, 2004

akadajet posted:

I didn't get logged out. So I'd assume all your facebook poo poo was stolen, assuming you have facebook poo poo.

luckily ive never put anything on FB that i dont assume is public anyway. hope they like my pics of fllowers and pups :frogbon:

Wiggly Wayne DDS
Sep 11, 2010



Evis posted:

I wonder how long it’s been broken, and if one person exploited it 90 million times, or if millions of people exploited it a few times. can’t imagine law enforcement would enjoy receiving a csv with 45 million IP addresses to investigate.

akadajet posted:

https://newsroom.fb.com/news/2018/09/security-update/

quote:

This attack exploited the complex interaction of multiple issues in our code. It stemmed from a change we made to our video uploading feature in July 2017, which impacted “View As.” The attackers not only needed to find this vulnerability and use it to get an access token, they then had to pivot from that account to others to steal more tokens.
also not surprised view as was the culprit, that feature always seemed like it created to allow for unintended interactions

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
according to the page they're only admitting to 50m exploits, but they invalidated sessions for 90m people because the other 40m had been "view as"-ed at some point

BlankSystemDaemon
Mar 13, 2009




So at this point it's just safest to assume that no data hasn't been leaked? I'm gonna go ahead and assume that.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Last Chance posted:

also they force logged me out today, does that mean my identtiy is stolen

not necessarily, no. you’ll get a feed notification AIUI

(view as is a disaster)

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

D. Ebdrup posted:

So at this point it's just safest to assume that no data hasn't been leaked? I'm gonna go ahead and assume that.
if you scroll up you'll see that facebook is admitting on their very public blog that data has been leaked. what are you talking about

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

anthonypants posted:

if you scroll up you'll see that facebook is admitting on their very public blog that data has been leaked. what are you talking about

what if the attackers accessed the accounts but kept their eyes closed the whole time

BlankSystemDaemon
Mar 13, 2009




anthonypants posted:

if you scroll up you'll see that facebook is admitting on their very public blog that data has been leaked. what are you talking about
poo poo, I didn't even realize I'd made a double-negative. What I meant was "it's safe to assume that all data has been leaked forever", basically, but that's clearly not what the sentence says. Don't know what the gently caress is up with my brain, I'm not even drunk.

Wiggly Wayne DDS
Sep 11, 2010



Subjunctive posted:

what if the attackers accessed the accounts but kept their eyes closed the whole time
the term is 'bug bounty researchers' op

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

From the ars article:


quote:

"We saw this attack being used at a fairly large scale," Rosen said. "The attackers could get an access token, pivot to other accounts, and look up other users to get further access tokens."

Facebook contacted the FBI and other law enforcement on Wednesday after identifying the nature of the attack. After turning off the "view as" feature and patching the other bugs, Facebook security then deauthorized all access tokens from the 50 million accounts that had been breached. They also deauthorized access tokens for another 40 million that had been accessed with the "view as" feature to ensure no other accounts were compromised

The 50 million is not like "lol oops we leaked your email and phone number" but 50 million accounts got popped and had an illegitimate access token minted. They were popping accounts automated and at scale.

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

Facebook: 90 million people finally logged off.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Have any of these security talks discussed security of elevator emergency phones? I know of at least one major install site where the call phones are just standard (unpublished) phone numbers that pretty much anyone can call. They automatically pick up on the speakerphone in the ceiling and you can just eavesdrop all day long on them.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

mrmcd posted:

From the ars article:


The 50 million is not like "lol oops we leaked your email and phone number" but 50 million accounts got popped and had an illegitimate access token minted. They were popping accounts automated and at scale.

yeah, I really wish I could see that thread

Wiggly Wayne DDS
Sep 11, 2010



mrmcd posted:

From the ars article:


The 50 million is not like "lol oops we leaked your email and phone number" but 50 million accounts got popped and had an illegitimate access token minted. They were popping accounts automated and at scale.
other reports going around that there was a spike in abuse starting 3 days ago which is why they noticed it

not wanting to be the only one running up to journalists and creating pr fires:

https://twitter.com/ashleymadison/status/1045758306525089792

https://twitter.com/ashleymadison/status/1045764170845704200

in similar news: https://twitter.com/josephmenn/status/1045753337675730944

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
if you post an article about the facebook breach on facebook, it will get taken down for being spam https://twitter.com/alanjames/status/1045761238872051718

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

BangersInMyKnickers posted:

Have any of these security talks discussed security of elevator emergency phones? I know of at least one major install site where the call phones are just standard (unpublished) phone numbers that pretty much anyone can call. They automatically pick up on the speakerphone in the ceiling and you can just eavesdrop all day long on them.

I remember this from years ago, don't recall if it was in a talk or article or book or what

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Rufus Ping posted:

I remember this from years ago, don't recall if it was in a talk or article or book or what
there's that elevator talk that everyone loves, it might've been in there

https://www.youtube.com/watch?v=ZUvGfuLlZus&hd=1

  • Locked thread