Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Raere
Dec 13, 2007

Hi, I need y'all software vendors to stop implementing mitigations and being decent about fixing bugs to the point where more and more research is being done on hardware side channel attacks because it's a pain in my rear end

Adbot
ADBOT LOVES YOU

Pile Of Garbage
May 28, 2007



Jabor posted:

Based on the blog post, it's still flipping three bits, but you can identify what bits are flippable without causing any crashes - and then once you know which bits are flippable you can flip exactly the three desired bits pretty reliably.

Presumably if you had a paranoid ecc mode that faulted on 1-bit errors it would shut down this attack vector.

flipmode is the greatest

Phone
Jul 30, 2005

親子丼をほしい。

Pile Of Garbage posted:

flipmode is the greatest

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

NoneMoreNegative posted:

lol I got a slew of these over a couple of days a week or so past, all to different sitename@mypersonaldomain.com addresses I used for exactly this purpose - none of the sites I’d used in years, but also none of the sites had ever (to my knowledge) posted a ‘oops we were hacked’ mea culpa.

same here and to be honest i'm way more embarrassed about someone finding out that i registered an account at tv tropes rather than any porn habits i may have

Midjack
Dec 24, 2007



Pile Of Garbage posted:

flipmode is the greatest

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

Pile Of Garbage posted:

flipmode is the greatest

FlapYoJacks
Feb 12, 2009
https://handshake.org/

Pile Of Garbage
May 28, 2007




quote:

Handshake is a UTXO-based blockchain protocol

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


quote:

Majority ownership of Handshake is granted to Free and Open Source Software contributors via a faucet.

The faucet dispenses coins to freenode users,

a bold strategy, if my recollections of freenode are still accurate

DrPossum
May 15, 2004

i am not a surgeon

CommieGIR posted:

I think I'll stick with KeePass

KeepAss

DrPossum
May 15, 2004

i am not a surgeon

Pile Of Garbage posted:

flipmode is the greatest

Pile Of Garbage
May 28, 2007




https://twitter.com/davidgerard/status/1065677949767229440

hobbesmaster
Jan 28, 2008

Subjunctive posted:

https://arstechnica.com/information-technology/2018/11/potentially-disastrous-rowhammer-bitflips-can-bypass-ecc-protections/

in unrelated news, I’ve asked my team to put together a plan for solving knapsack problems with legal pads and HB pencils

put as many legal pads as you can fit in the knapsack then fill the voids with pencils

problem solved!!!!

crazysim
May 23, 2004
I AM SOOOOO GAY
in which your android anime game's rootkit exploits a 0 day to fight another rootkit

evil_bunnY
Apr 2, 2003

redleader
Aug 18, 2005

Engage according to operational parameters

NoneMoreNegative posted:

lol I got a slew of these over a couple of days a week or so past, all to different sitename@mypersonaldomain.com addresses I used for exactly this purpose - none of the sites I’d used in years, but also none of the sites had ever (to my knowledge) posted a ‘oops we were hacked’ mea culpa.

no need to say they were hacked when they outright sold your data instead

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



redleader posted:

no need to say they were hacked when they outright sold your data instead

yea its this

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

put your bits where my eyes can see

Bulgakov
Mar 8, 2009


рукописи не горят

Kevin Mitnick P.E. posted:

i would worry more about people knowing about the bridled ones

hollow, pence spokesperson


did it all go in instantly or did it take a few hours until the reagan quote could be put on a bad generic press photo shot with caption below?

txhx

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

A good read, thank you

DrPossum
May 15, 2004

i am not a surgeon
https://i.imgur.com/0TnYPVw.mp4

Midjack
Dec 24, 2007




i'm this entire video

redleader
Aug 18, 2005

Engage according to operational parameters

Nomnom Cookie
Aug 30, 2009



Bulgakov posted:

hollow, pence spokesperson


did it all go in instantly or did it take a few hours until the reagan quote could be put on a bad generic press photo shot with caption below?

txhx

what the gently caress?

Potato Salad
Oct 23, 2014

nobody cares



what in the everliving hell is happening im losing my poo poo here

cinci zoo sniper
Mar 15, 2013




Potato Salad posted:

what in the everliving hell is happening im losing my poo poo here

its exit motion sensor mounted on entrance for whatever reason

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

Kevin Mitnick P.E. posted:

what the gently caress?

It's how the whole "Mike Pence wants to get hosed by a horse" thing got started.

https://twitter.com/VP/status/863182608552906755

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

cinci zoo sniper posted:

its exit motion sensor mounted on entrance for whatever reason

looks more like an nfc card reader to me, i've seen loads of basically identical ones. doesn't explain the behaviour though.

Shame Boy
Mar 2, 2010

goddamnedtwisto posted:

looks more like an nfc card reader to me, i've seen loads of basically identical ones. doesn't explain the behaviour though.

yes it's an nfc card reader, there is a motion detector above the door that you can't see which is triggering on the throwing of stuff, and the card reader lights up because it's all hooked into the same system, making it appear that the card reader is "reading" the random objects being thrown at it.

Trabisnikof
Dec 24, 2005

reminded me of this classic https://www.youtube.com/watch?v=SDl4AO4ancI

Midjack
Dec 24, 2007



Shame Boy posted:

yes it's an nfc card reader, there is a motion detector above the door that you can't see which is triggering on the throwing of stuff, and the card reader lights up because it's all hooked into the same system, making it appear that the card reader is "reading" the random objects being thrown at it.

kind of goofy to have the rex activation flash the reader light, though. they had to go out of their way to do that.

amishjosh
Jul 16, 2004
Yeah

Chalks posted:

I get the theory of the scam but i wonder what made them think that prattling on for 15 paragraphs was an effective tactic. I'd have tldr'd that poo poo almost instantly

people that know what they're doing tldr that poo poo, people like my boss call me freaking out because there's been a major security virus problem and i need to come in and fix things because he got one of these.

pseudorandom name
May 6, 2007


is there a reason for whisky specifically other than it was funny?

Midjack
Dec 24, 2007



pseudorandom name posted:

is there a reason for whisky specifically other than it was funny?

mostly to be funny. water has a higher specific heat capacity so it'll make a larger thermal change but takes a little longer to heat up as a result.

Shame Boy
Mar 2, 2010

Midjack posted:

kind of goofy to have the rex activation flash the reader light, though. they had to go out of their way to do that.

does that not normally happen? the ones in my office do that when the (correctly placed) motion sensors activate :shrug:

Midjack
Dec 24, 2007



Shame Boy posted:

does that not normally happen? the ones in my office do that when the (correctly placed) motion sensors activate :shrug:

the reader, rex, and door release are all wired into the controller, so the controller is telling the reader to flash the light on rex activation, though the reader will default to flash on read in most cases. i havent seen a controller default to command the reader on rex activation though you can often set them up however you want.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

pseudorandom name posted:

is there a reason for whisky specifically other than it was funny?

because deviant is an alchie

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
week one of working in it security proper, and I already love the disdain for engineering practices
did I say love, because I meant what the gently caress, we had better engineering in a four person shop making mobile apps

things are going to change around here *cracks knuckles*

(hackbunny was never heard of again)

DrPossum
May 15, 2004

i am not a surgeon
:rip: hackbunny

Adbot
ADBOT LOVES YOU

geonetix
Mar 6, 2011


lmao engineers listening to security people

  • Locked thread