Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Uhhhh

https://www.dansdeals.com/more/dans-commentary/went-tesla-delivery-hell-tesla-giving-control-site-forums-1-5-million-tesla-account-contacts/

Adbot
ADBOT LOVES YOU

astral
Apr 26, 2004

That article originally had a lot of people's names and e-mail addresses in those screenshots before he mspainted those little white boxes on them. :)

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


That's pretty loving funny considering he made a slight at other users' infosec capabilities because they used Gmail

Truga
May 4, 2014
Lipstick Apathy
the problem isn't people using gmail, the problem is admin accounts that aren't connected to a tesla-controlled email.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Daman posted:

bitlocker doesn't even default to hw encryption for any ssds I've seen, including my 850 evo running in transparent mode.

it's going to be more of a problem in the enterprise space with the drives from dell/hp/whatever where they paid the extra $50 for it to ship in OPEL mode

Dans Macabre
Apr 24, 2004


Hey y'all I'm trying to get the CISSP cert. I'm using the Kaplan exam prep site and the questions are all terribly dated (like asking about Back Orifice and talking about XSS as if it's a nascent threat). MY QUESTION is, am I using a terribly outdated exam guide, or is the exam really outdated?

Wiggly Wayne DDS
Sep 11, 2010



its the cert op

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Look out here comes my CISSP lol

Diva Cupcake
Aug 15, 2005

Just use the Official CISSP Practice Tests book. It’s like $20 for 2000 questions in all domains. Track your results. If you’re getting in the 75-80% range over a large enough sample size you’ll be fine.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

NevergirlsOFFICIAL posted:

Hey y'all I'm trying to get the CISSP cert. I'm using the Kaplan exam prep site and the questions are all terribly dated (like asking about Back Orifice and talking about XSS as if it's a nascent threat). MY QUESTION is, am I using a terribly outdated exam guide, or is the exam really outdated?

if they aren't making you memorize every mundane detail about old blockmode ciphers like DES/2DES/3DES and their various modes then you're probably on the new material

xss stuff definitely was in the latest revision

CLAM DOWN
Feb 13, 2007




Ugh, CISSP, ugh. Ugh.

xThrasheRx
Jul 12, 2005

Surrealistic

CLAM DOWN posted:

Ugh, CISSP, ugh. Ugh.


clam down, CLAM DOWN

repiv
Aug 13, 2009

1Password is letting users give away a 1 year subscription for thanksgiving, PM me your email if you want some free 1Password.

Dans Macabre
Apr 24, 2004


Rufus Ping posted:

Look out here comes my CISSP lol

Shut up rufo
Also hi

Wiggly Wayne DDS
Sep 11, 2010



didn't they rename CISSP to be CEH+?

some kinda jackal
Feb 25, 2003

 
 
CISSP was the most worthless cert I ever achieved. That said, it was also the most profitable.

Sickening
Jul 16, 2007

Black summer was the best summer.

Martytoof posted:

CISSP was the most worthless cert I ever achieved. That said, it was also the most profitable.

The entire thing is baffling. The test is fairly easy yet the dumb outside requirements and corporate adoption keeps it a thing.

some kinda jackal
Feb 25, 2003

 
 

Sickening posted:

The entire thing is baffling. The test is fairly easy yet the dumb outside requirements and corporate adoption keeps it a thing.

Yeah I don't understand it either. Work paid for my bootcamp, my exam, and then they paid me more money when I got it. I mean, they could have just saved some time and given me all that money to begin with I guess.

Diva Cupcake
Aug 15, 2005

lol at the CPEs too. I watched 25 sales pitch webinars and listened to 15 hours of Security Weekly on my commute this year. I get to retain my certification.

Proteus Jones
Feb 28, 2013



Martytoof posted:

CISSP was the most worthless cert I ever achieved. That said, it was also the most profitable.

That the entirety of why I keep it up to date.

Submitting CEs are a pain in the rear end, and thank god work pays the dues. But, people are irrationally impressed by it. So It stays. I’ve even let some of my GCIS carts lapse, because while I feel they more accurately reflect a depth of knowledge, no one outside certain circles knows what the gently caress they are (although I usually go “I need more alphabet in my email sig” and take the re-cert challenge a year or so later)

Dans Macabre
Apr 24, 2004


Martytoof posted:

CISSP was the most worthless cert I ever achieved. That said, it was also the most profitable.

so that sounds like it's actually worth a lot?

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

NevergirlsOFFICIAL posted:

so that sounds like it's actually worth a lot?

The fact that if you do audits or have to be aware of audits, yes.

Also it's one of the terms HR people know when they have no idea what a good security people should have. OSCP, OSCE, .... what's that? CEH? Oh I think that's a tough one!!

the ceh used to be good until the government decide to commandeer it and then ask to remove all the stuff that made it good so govt workers could actually pass it.

Wiggly Wayne DDS
Sep 11, 2010



lmao if you actually believe that about ceh

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

Wiggly Wayne DDS posted:

lmao if you actually believe that about ceh

Well thanks for letting me know it was always poo poo then?

EVIL Gibson fucked around with this message at 11:05 on Nov 26, 2018

Wiggly Wayne DDS
Sep 11, 2010



i mean when was this change meant to have occurred? it's been a joke in the industry for over a decade

some kinda jackal
Feb 25, 2003

 
 

NevergirlsOFFICIAL posted:

so that sounds like it's actually worth a lot?

Money? Yes.

Self-improvement? No.

AlternateAccount
Apr 25, 2005
FYGM

repiv posted:

1Password is letting users give away a 1 year subscription for thanksgiving, PM me your email if you want some free 1Password.

Is this still a thing? They didn’t send me anything and I’d love to give one away.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

AlternateAccount posted:

Is this still a thing? They didn’t send me anything and I’d love to give one away.

the option is still showing up for me in the bottom right corner of my.1password.com when I log in

I think you need to be an individual or family subscriber (not 'teams') whose plan expiry date is in 2019 or later

Diva Cupcake
Aug 15, 2005

This is a pretty great Humble Bundle for security books.

https://www.humblebundle.com/books/cybersecurity-packt-books

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

Diva Cupcake posted:

This is a pretty great Humble Bundle for security books.

https://www.humblebundle.com/books/cybersecurity-packt-books

I am not busting on this collection but I feel someone would start rubbing one out when they read the title of this book.





"Finally. Someone....someone gets me. "

Whenever I see a talk that has the word block chain in it, I always feel I have to give it a chance to see if there is any reason for this to exist and it always seems its about a dude that crammed malware into a eth contract or some poo poo.

EVIL Gibson fucked around with this message at 22:54 on Nov 26, 2018

TinTower
Apr 21, 2010

You don't have to 8e a good person to 8e a hero.
https://twitter.com/kennwhite/status/1067133581435305984

this is quite possibly the stupidest node dev thing since "HTTP is secure"

Proteus Jones
Feb 28, 2013



Node.js is poison.

Inept
Jul 8, 2003

Hey now, that rando stranger probably also Paypaled him a few hundred for it.

And charged it back after he was given control.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


TinTower posted:

https://twitter.com/kennwhite/status/1067133581435305984

this is quite possibly the stupidest node dev thing since "HTTP is secure"

Ohhhh man, this is great. Horrible, but great.

bitprophet
Jul 22, 2004
Taco Defender
To be fair, aside from JavaScript's inherent language issues & the problems it gains from popularity & low barriers to entry (hi PHP!) this sort of thing could happen to any other open source project.

Of course, JS also has an extra cultural weakness, in the form of significantly larger attack surface for "lol you depended on poo poo you didn't even know existed": https://twitter.com/greybaker/status/1064861297152585728

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Should be required reading for Node users IMO: https://hackernoon.com/im-harvesting-credit-card-numbers-and-passwords-from-your-site-here-s-how-9a8cb347c5b5

Volguus
Mar 3, 2009
The advantage of PHP in 2005 was that there were no package/library managers for it. So the only thing the kids could/would ruin would be the websites they were building. Nowadays, everything is distributed. Including incompetence.

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Volguus posted:

The advantage of PHP in 2005 was that there were no package/library managers for it. So the only thing the kids could/would ruin would be the websites they were building. Nowadays, everything is distributed. Including incompetence.

The Cloud: Distributed Incompetence running on Other People's Computers

Thanks Ants
May 21, 2004

#essereFerrari


Volguus posted:

Nowadays, everything is distributed. Including incompetence.

:vince:

Adbot
ADBOT LOVES YOU

Nalin
Sep 29, 2007

Hair Elf

bitprophet posted:

To be fair, aside from JavaScript's inherent language issues & the problems it gains from popularity & low barriers to entry (hi PHP!) this sort of thing could happen to any other open source project.

See: uBlock vs uBlock Origin

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply