Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

https://twitter.com/arstechnica/status/1060250790860910593

And I'm sure that Snowden endorsement on their (seized) website was totally legit as well.

Adbot
ADBOT LOVES YOU

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

Midjack posted:

my balls are my passport. verify me.

ah yes the TBAG cipher

Immanentized
Mar 17, 2009

Raere posted:

What's this?

Invitational event to develop their standards and create test questions.

Wiggly Wayne DDS posted:

they have standards?
They're very small

Immanentized fucked around with this message at 12:37 on Nov 8, 2018

Wiggly Wayne DDS
Sep 11, 2010



they have standards?

Stanley Pain
Jun 16, 2001

by Fluffdaddy

Ur Getting Fatter posted:

ah yes the TBAG cipher

:laugh:

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Dumb little security advice thing, but a lot of malware payloads target Mshta.exe because its essentially IE6 with zero javascript restrictions so they can go fuckwild without running afoul of browser restrictions. Remove the execute permissions from it for the users and administrators group, and maybe add in a R+X permissions to an override group that you can control if you're worried about something valid actually using it

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

you should also remove permissions from calc.exe since that seems to be involved in all these exploit write-ups I keep reading

flakeloaf
Feb 26, 2003

Still better than android clock

shoulda been my name

mshta cellophane

cause you can log right in me

root right through me

they'll never know you're there

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Powered Descent posted:

https://twitter.com/arstechnica/status/1060250790860910593

And I'm sure that Snowden endorsement on their (seized) website was totally legit as well.

when will people stop using these stupid applications? they get owned over and over again.

just use gpg.

flakeloaf
Feb 26, 2003

Still better than android clock

Powered Descent posted:

https://twitter.com/arstechnica/status/1060250790860910593

And I'm sure that Snowden endorsement on their (seized) website was totally legit as well.

quote:

Key among them: warning messages that notified users when their contacts’ encryption keys had changed were easy to overlook because they were provided in a font much smaller than the rest of the conversation.

hi where are you crimesing today

conversation ended with mudasir, now detective salman is your internet friend

Proteus Jones
Feb 28, 2013



Ur Getting Fatter posted:

ah yes the TBAG cipher

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

flakeloaf posted:

hi where are you crimesing today

conversation ended with mudasir, now detective salman is your internet friend

hahahaha

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Luv 2 have unproductive conversations with an Online Pharmacy Service™ where I explain to them that using RC4 by default and supporting 1028-bit DHE is a Bad Idea Stop Stop Please Stop It

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

BangersInMyKnickers posted:

Luv 2 have unproductive conversations with an Online Pharmacy Service™ where I explain to them that using RC4 by default and supporting 1028-bit DHE is a Bad Idea Stop Stop Please Stop It

um 10 years ago they said this would take a thousand years to crack, we still have 990 years to replace it

Wiggly Wayne DDS
Sep 11, 2010



tbf 1028 is very forward thinking

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
when you figure out how to do this, let the rest of the class know

Janitor Prime
Jan 22, 2004

PC LOAD LETTER

What da fuck does that mean

Fun Shoe

Bhodi posted:

when you figure out how to do this, let the rest of the class know

What's the challenge, getting your gpg key on the phone? Sharing it with people over the internet?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

flakeloaf posted:

hi where are you crimesing today

conversation ended with mudasir, now detective salman is your internet friend

Beautiful

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Janitor Prime posted:

What's the challenge, getting your gpg key on the phone? Sharing it with people over the internet?
find one other person on earth who uses it, and for extra credit: successfully encrypt and decrypt your emails to them on your phone

Shame Boy
Mar 2, 2010

i got all set up with gpg and a yubikey a few years ago, got mail signing and optional encryption configured, got all excited about it, then quickly found out that literally nobody in the world cares and never used it a single time. i mean i signed some emails by default for a little while but all that did was confuse my mom.

the bridge that lets you use it as an SSH key is useful as hell though and i still use that to this day

Diva Cupcake
Aug 15, 2005

just use microsoft OME or whatever.

i remember being upset in like 2002 after publishing a public key to the MIT key server after having lost the private key and thinking that now all the people who want to send me encrypted email wont ever know which public key to use. literally zero people have ever attempted to send me a pgp encrypted message.

endlessmonotony
Nov 4, 2009

by Fritz the Horse

Midjack posted:

my balls are my passport. verify me.

ERROR: Key too small.

Identity verified.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

hacking IoT garbage through the analog sensor inputs

https://www.youtube.com/watch?v=d2_lFovD4NA

e: skip to 33:30 to jump past the theory stuff to the first computer attacks

BangersInMyKnickers fucked around with this message at 23:10 on Nov 8, 2018

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

endlessmonotony posted:

ERROR: Key too small.

Identity verified.

4chan nazis hate the tbag cipher because it refuses to let them in to their anime drive on dec 1st

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Bhodi posted:

find one other person on earth who uses it, and for extra credit: successfully encrypt and decrypt your emails to them on your phone

if you have real life security concerns that absolutely must be encrypted, you have to deal with maybe not reading your email on your phone.

otherwise lovely software written by idiots, for idiots, will get cracked and then you're worse off than if you just waited to get to a computer to read a loving email.

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Shame Boy posted:

i got all set up with gpg and a yubikey a few years ago, got mail signing and optional encryption configured, got all excited about it, then quickly found out that literally nobody in the world cares and never used it a single time. i mean i signed some emails by default for a little while but all that did was confuse my mom.

the bridge that lets you use it as an SSH key is useful as hell though and i still use that to this day

yeah i use yubikey for both gpg and ssh and I enforce the policy here that nobody has access to their SSH key outside of a yubikey.

the private keys are generated on an airgapped computer, sent to the yubikey, then printed out as a few QR codes and jammed into a safe and a safety deposit box, then the airgapped machine's drive are erased.

but i've also sent a decent amount of files/passwords to third parties via gpg so if you can't find people who will use it to send/receive sensitive information to you probably shouldn't be sending them sensitive information.

pseudorandom name
May 6, 2007

in finest ValuJet style, Comodo is now Sectigo

funeral home DJ
Apr 21, 2003


Pillbug

BangersInMyKnickers posted:

hacking IoT garbage through the analog sensor inputs

https://www.youtube.com/watch?v=d2_lFovD4NA

e: skip to 33:30 to jump past the theory stuff to the first computer attacks

the microphone hack makes me want to go on a ghost tour with those loony people that carry those recorders and make a civil war ghost ask if he can suck someone’s dick

Pile Of Garbage
May 28, 2007



Ulf posted:

please enjoy my sophomore effort, where i've documented tls 1.3 instead of 1.2: https://tls13.ulfheim.net

now nobody can accuse me of holding back TLS 1.3 adoption.

this is very cool ty for sharing

e: also added you on the twitter

Pile Of Garbage fucked around with this message at 11:12 on Nov 9, 2018

Soricidus
Oct 21, 2010
freedom-hating statist shill

CRIP EATIN BREAD posted:

the private keys are generated on an airgapped computer, sent to the yubikey, then printed out as a few QR codes and jammed into a safe and a safety deposit box, then the airgapped machine's drive are erased.

did you remember to epoxy the ports and then bury the yubikey under a birdbath

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



flakeloaf posted:

hi where are you crimesing today

conversation ended with mudasir, now detective salman is your internet friend

rofl

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Soricidus posted:

did you remember to epoxy the ports and then bury the yubikey under a birdbath

yubikey stays on my keychain.

epoxying ports is dumb but at least i know none of the devs here can accidentally upload their SSH keys anywhere, or have it compromised, unless someone steals the physical yubikey and uncaps it.

Shame Boy
Mar 2, 2010

CRIP EATIN BREAD posted:

yubikey stays on my keychain.

epoxying ports is dumb but at least i know none of the devs here can accidentally upload their SSH keys anywhere, or have it compromised, unless someone steals the physical yubikey and uncaps it.

i just have one of those yubikeys that can sit flush inside the USB port and leave it there, since i'm pretty sure nobody who could steal my laptop would even know what the hell it is so that's not really a risk, but poo poo that breaks into my computer digitally would probably immediately go looking for id_rsa etc.

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer


this exposed ethernet is 100% connected to their internal network, isn't it?

Janitor Prime
Jan 22, 2004

PC LOAD LETTER

What da fuck does that mean

Fun Shoe

Shame Boy posted:

i just have one of those yubikeys that can sit flush inside the USB port and leave it there, since i'm pretty sure nobody who could steal my laptop would even know what the hell it is so that's not really a risk, but poo poo that breaks into my computer digitally would probably immediately go looking for id_rsa etc.

I couldn't stand brushing up against it and having it spit all these characters into my text editor

Potato Salad
Oct 23, 2014

nobody cares


Ur Getting Fatter posted:



this exposed ethernet is 100% connected to their internal network, isn't it?

Nah it's totally using 802.1x certs and a well-sanitized network

See, they cut corners on their physical installation only because they wanted to spend more on netsec

Potato Salad fucked around with this message at 18:59 on Nov 9, 2018

Xarn
Jun 26, 2015

Shame Boy posted:

i got all set up with gpg and a yubikey a few years ago, got mail signing and optional encryption configured, got all excited about it, then quickly found out that literally nobody in the world cares and never used it a single time. i mean i signed some emails by default for a little while but all that did was confuse my mom.

the bridge that lets you use it as an SSH key is useful as hell though and i still use that to this day

I spent 4 days getting GPG + Yubikey working from WSL -- it remains yet to be seen if it was worth it.


Janitor Prime posted:

I couldn't stand brushing up against it and having it spit all these characters into my text editor

You can turn that off.

Janitor Prime
Jan 22, 2004

PC LOAD LETTER

What da fuck does that mean

Fun Shoe

Xarn posted:

You can turn that off.

I know but I wanted to use it that way, it was just annoying that it would do it randomly even when I wasn't pushing on it.

Guy Axlerod
Dec 29, 2008
I almost immediately changed the settings on my yubikey to require a 1 second press before typing out random poo poo and can't understand why that isn't the loving default.

Adbot
ADBOT LOVES YOU

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Janitor Prime posted:

I couldn't stand brushing up against it and having it spit all these characters into my text editor

it just likes you

  • Locked thread