Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang




lol

Adbot
ADBOT LOVES YOU

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Cocoa Crispies posted:

bricked my pants

when the 360 Kinect first came out my friend discovered that yelling that would cause the whole system to shut down

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shame Boy posted:

i was looking up a particular SSL cipher suite and stumbled across this site:

https://ciphersuite.info/

anyone know if it's any good? it seems useful, you plug in something and it gives you info on it and also tells you if its "recommended" or not, but I'm not really sure what criteria it's using to decide that...

e:


i guess that's legit enough :shrug:

I gave it a once-over and the only bone I have to pick with it is that it's marking DHE suites as "strong" or whatever. DHE is a minefield at this point and you should probably avoid/disable it. Lots of things that support it enable it with broken/weak 512/768/1024-bit keys and often doesn't give you the option to select stronger groups to fix that, and on the client side they will often blindly accept 768/1024-bit key exchange without complaint and is once again not configurable (512 is at least disabled for most anything now). ECDHE is mostly good all around at the moment since things are moving on to new curves like x25519 and even the older NIST curves are still going to be generally better and more configurable that the dice roll of DHE.

Shame Boy
Mar 2, 2010

BangersInMyKnickers posted:

I gave it a once-over and the only bone I have to pick with it is that it's marking DHE suites as "strong" or whatever. DHE is a minefield at this point and you should probably avoid/disable it. Lots of things that support it enable it with broken/weak 512/768/1024-bit keys and often doesn't give you the option to select stronger groups to fix that, and on the client side they will often blindly accept 768/1024-bit key exchange without complaint and is once again not configurable (512 is at least disabled for most anything now). ECDHE is mostly good all around at the moment since things are moving on to new curves like x25519 and even the older NIST curves are still going to be generally better and more configurable that the dice roll of DHE.

to be clear DHE with your own generated 2048-bit+ dh params still works fine as far as anyone knows though right?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shame Boy posted:

to be clear DHE with your own generated 2048-bit+ dh params still works fine as far as anyone knows though right?

Yeah, but it's sorta in "who cares" territory at this point because either the things that support DH support ECDH or they're RSA-only

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
https://www.zdnet.com/article/popular-dark-web-hosting-provider-got-hacked-6500-sites-down/

Popular Dark Web hosting provider got hacked, 6,500 sites down
Hosting provider is still looking for the hacker's point of entry.

quote:

The hack took place on Thursday, November 15, according to Daniel Winzen, the software developer behind the hosting service.

"As per my analysis it seems someone got access to the database and deleted all accounts," he said in a message posted on the DH portal today.

Winzen said the server's root account was also deleted, and that all 6,500+ Dark Web services hosted on the platform are now gone.

Nomnom Cookie
Aug 30, 2009



lol i tried to post about r**t and /e**/p***** and cloudflare blocked me

WAF 1 my posting 0

Pile Of Garbage
May 28, 2007



Shame Boy posted:

to be clear DHE with your own generated 2048-bit+ dh params still works fine as far as anyone knows though right?

worth noting that you can't change DH parameters on windows last i checked so the only mitigation is to disable DH entirely so it will only negotiate ECDH

Trabisnikof
Dec 24, 2005

Kevin Mitnick P.E. posted:

lol i tried to post about r**t and /e**/p***** and cloudflare blocked me

WAF 1 my posting 0

/𝖊𝖙𝖈/𝖕𝖆𝖘𝖘𝖜𝖔𝖗𝖉

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Trabisnikof posted:

/𝖊𝖙𝖈/𝖕𝖆𝖘𝖘𝖜𝖔𝖗𝖉

shameful

pseudorandom name
May 6, 2007

it also blocks boot.‍ini

Bulgakov
Mar 8, 2009


рукописи не горят

Trabisnikof posted:

/𝖊𝖙𝖈/𝖕𝖆𝖘𝖘𝖜𝖔𝖗𝖉

we got us a hacker

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
oy, a chav nicked me boot.ini

Salt Fish
Sep 11, 2003

Cybernetic Crumb

Trabisnikof posted:

/𝖊𝖙𝖈/𝖕𝖆𝖘𝖘𝖜𝖔𝖗𝖉

Oh my god not my /etc/password file

Shame Boy
Mar 2, 2010

i order all my passwd files hand-made from etc

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Trabisnikof posted:

/𝖊𝖙𝖈/𝖕𝖆𝖘𝖘𝖜𝖔𝖗𝖉

get psyched!

abigserve
Sep 13, 2009

this is a better avatar than what I had before

Shame Boy posted:

i order all my passwd files hand-made from etc

drat

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

Shame Boy posted:

i order all my passwd files hand-made from etc

Same except regretc

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

OH YEAH since we're talking stupid cipher poo poo for some reason older version of windows, when applications use the WinHTTP handler in schannel, will only use tls 1.0 instead of 1.2 being supported (win7,2008r2,2012)

https://support.microsoft.com/en-us/help/3140245/update-to-enable-tls-1-1-and-tls-1-2-as-default-secure-protocols-in-wi

you gotta jump through some stupid hoops to get it to turn on. this affects outlook fyi. gently caress you, michaelsoft

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
um

Bulgakov
Mar 8, 2009


рукописи не горят

close call but dot xlsx remains safe

Truga
May 4, 2014
Lipstick Apathy
tayne.exe

Proteus Jones
Feb 28, 2013




Oh boy

Bulgakov
Mar 8, 2009


рукописи не горят

running as fast as I can to chromeinstaller.exe and etc

Bulgakov
Mar 8, 2009


рукописи не горят

eager to see microsoft appealing the decision, not because its wrong in some fundamental way, but because dot msi isn't on the list

DrPossum
May 15, 2004

i am not a surgeon

:woop:

Media Bloodbath
Mar 1, 2018

PIVOT TO ETERNAL SUFFERING
:hb:

what could go wrong :pseudo:

vanity slug
Jul 20, 2010

can't wait to register hello.jpg

Bulgakov
Mar 8, 2009


рукописи не горят

Jeoh posted:

can't wait to register hello.jpg

oh hell :bahgawd:

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Got a source on that I can spread around?

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
piracy has never been easier, now that you can just go directly to game.of.thrones.s06e01.PROPER.HDTV[XviD]720p.mkv and get your files

Babies Getting Rabies
Apr 21, 2007

Sugartime Jones

this seems like an abbreviated version of a few paragraphs from an icann draft paper from 2008. i don't think that file extension idea ever went anywhere, so i have no idea why it would pop up now

flakeloaf
Feb 26, 2003

Still better than android clock

i want to search for a filename from the address bar, exe is not a tld

stop it

fukcing stop it

Chalks
Sep 30, 2009

letting people search for things in the address bar was a mistake

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
https://twitter.com/LastPassStatus/status/1064904151166083082

https://twitter.com/topherkus/status/1064907380759191553

https://twitter.com/just1ntime32/status/1064914128840454144

going on for about 4 hours now. you literally can't log in unless you had offline mode enabled before the outage lol

cinci zoo sniper
Mar 15, 2013




lmao

Wiggly Wayne DDS
Sep 11, 2010



Babies Getting Rabies posted:

this seems like an abbreviated version of a few paragraphs from an icann draft paper from 2008. i don't think that file extension idea ever went anywhere, so i have no idea why it would pop up now
someone noticed it existed on twitter yesterday and everyone acted like it was new info

so a normal day

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Ive had a pre-order on gap.zip for years. No prizes for guessing whats going on it

Wiggly Wayne DDS
Sep 11, 2010



on a further check the one everyone's throwing around now is from 2016

https://twitter.com/kpyke/status/789156391726387200

it wasn't exactly breaking news then either

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

Chalks posted:

letting people search for things in the address bar was a mistake

correct

a thing should not do two things badly it should do one thing well

  • Locked thread