Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Rufus Ping posted:

whats this about


p sure its just a "hurr spy agency has u" thing

Adbot
ADBOT LOVES YOU

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Father Jack posted:

how subtle are phishing things these days? i wouldn't fall for the most obvious kinds, but i can't claim to be either an expert nor on constant high alert.

no idea tbh. I like to imagine I've never fallen for one but who knows

just sidestep the issue entirely and use a password manager that can tell what site you're currently viewing and doesn't even give you the option of filling your gmail password into gmail-com.fake.biz

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

Father Jack posted:

possible I guess, and i'd rather own up to being suckered than nuke every machine i've ever signed in on.

how subtle are phishing things these days? i wouldn't fall for the most obvious kinds, but i can't claim to be either an expert nor on constant high alert.

all the ones I’ve ever seen are incredibly obvious

which I imagine is deliberate cause they want to target idiots

Pierre Chaton
Sep 1, 2006

Rufus Ping posted:

no idea tbh. I like to imagine I've never fallen for one but who knows

just sidestep the issue entirely and use a password manager that can tell what site you're currently viewing and doesn't even give you the option of filling your gmail password into gmail-com.fake.biz

yeah, i know i should, but :effort: and the last time i tried keepass i found it wonky enough that i was genuinely concerned about locking myself out of things. freaked out enough by this to try again though.

My Linux Rig posted:

all the ones I’ve ever seen are incredibly obvious

which I imagine is deliberate cause they want to target idiots

does that mater when phishing for passwords? 419 scams sure, but passwords?

evil_bunnY
Apr 2, 2003

flakeloaf posted:

in a move literally everyone saw coming (yet continues to cause shock and astonishment), GSK has bought 23andme
hahahahaha

bob dobbs is dead
Oct 8, 2017

I love peeps
Nap Ghost

My Linux Rig posted:

all the ones I’ve ever seen are incredibly obvious

which I imagine is deliberate cause they want to target idiots

spear phish is good as hell but closely targeted towards important peeps

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
https://www.zdnet.com/article/kubernetes-first-major-security-hole-discovered/

update your k8s masters if you havent.

if you are on AWS EKS you are at their mercy until then.

lol.

flakeloaf
Feb 26, 2003

Still better than android clock


60 noscript blocks, a "know your location" dialog box, a popup at lower left to sign up to their newsletter AND an autoplaying video

the internet was a mistake

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

Father Jack posted:

possible I guess, and i'd rather own up to being suckered than nuke every machine i've ever signed in on.

how subtle are phishing things these days? i wouldn't fall for the most obvious kinds, but i can't claim to be either an expert nor on constant high alert.

the good ones are extremely good, but thankfully rare.

Shame Boy
Mar 2, 2010

CRIP EATIN BREAD posted:

https://www.zdnet.com/article/kubernetes-first-major-security-hole-discovered/

update your k8s masters if you havent.

if you are on AWS EKS you are at their mercy until then.

lol.

psh i'm sure nobody has their kubernetes' API available unrestricted to the public internet right?

:smith:

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Shame Boy posted:

psh i'm sure nobody has their kubernetes' API available unrestricted to the public internet right?

:smith:

google compute and AWS both do

pr0digal
Sep 12, 2008

Alan Rickman Overdrive
The National Republican Congressional Committee is saying they got hacked during the 2018 midterms.

https://www.washingtonpost.com/worl...m=.e240149b037f (maybe paywalled)
https://www.politico.com/story/2018/12/04/exclusive-emails-of-top-nrcc-officials-stolen-in-major-2018-hack-1043309

Current reports are saying some sensitive e-mails were stolen.

Shame Boy
Mar 2, 2010

during the glut of black-friday-related sales on newegg i impulse bought a few stupid off-brand "smart" devices to take apart and try to reverse-engineer, including the usual kinda stuff like a smart plug and smart switch, but also a smart "essential oil vapor diffuser" which connects to wifi and lets you control what your house smells like from anywhere in the world!!!

i'll report back if i find anything fun in them, hopefully i can figure out how hackers can turn it into a stink bomb

Potato Salad
Oct 23, 2014

nobody cares


pr0digal posted:

The National Republican Congressional Committee is saying they got hacked during the 2018 midterms.

https://www.washingtonpost.com/worl...m=.e240149b037f (maybe paywalled)
https://www.politico.com/story/2018/12/04/exclusive-emails-of-top-nrcc-officials-stolen-in-major-2018-hack-1043309

Current reports are saying some sensitive e-mails were stolen.

Shame.

Maybe they could stop stonewalling legislation on exactly this matter.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Shame Boy posted:

during the glut of black-friday-related sales on newegg i impulse bought a few stupid off-brand "smart" devices to take apart and try to reverse-engineer, including the usual kinda stuff like a smart plug and smart switch, but also a smart "essential oil vapor diffuser" which connects to wifi and lets you control what your house smells like from anywhere in the world!!!

i'll report back if i find anything fun in them, hopefully i can figure out how hackers can turn it into a stink bomb

:yeshaha: make everything smell like farts

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Krankenstyle posted:

:yeshaha: make everything smell like farts

he doesn't need a device to do that

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
if you are on EKS fyi: https://aws.amazon.com/security/security-bulletins/AWS-2018-020/

bob dobbs is dead
Oct 8, 2017

I love peeps
Nap Ghost

its all of k8sland and all of k8s

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
lomarf

https://twitter.com/rudygiuliani/status/1070118915139923968

Shame Boy
Mar 2, 2010


is he dictating lovely punctuation to whoever writes his tweets :psyduck:

Gobbeldygook
May 13, 2009
Hates Native American people and tries to justify their genocides.

Put this racist on ignore immediately!

Shame Boy posted:

is he dictating lovely punctuation to whoever writes his tweets :psyduck:
no, but voice to text transcription is pretty good these days

Samuel L. ACKSYN
Feb 29, 2008


reminder that giuliani was (or still is) trump's cybersecurity advisor

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



Samuel L. ACKSYN posted:

reminder that giuliani was (or still is) trump's cybersecurity advisor

a noun, a verb, and digital 9/11

checks out

Jewel
May 2, 2009

https://github.com/systemd/systemd/issues/11026

"Unprivileged users with UID > INT_MAX can successfully execute any systemctl command"

:v:

Jewel fucked around with this message at 12:38 on Dec 5, 2018

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
a major security vendor claimed to me that a very popular log format was not parseable

probably the wrong person to ever say that to seeing that i enjoyed at one point parsing unstructured data and making it structured

i e-mailed them back with the regex to parse it into the appropriate fields and they're now all, "oh oh okay yeah that makes sense now"

NoneMoreNegative
Jul 20, 2000
GOTH FASCISTIC
PAIN
MASTER




shit wizard dad

uk parliament published some of the docs seized from Facebook about an hour back, not had chance to browse the info yet but the bbc story says there’s some definite ‘soft’ secfuckery therein :o:

https://www.bbc.co.uk/news/technology-46456695

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
"we never sold people's data - we gave it away for free, but only to developers that spent a sufficient amount of money on our ads platform. totally different."

Schadenboner
Aug 15, 2011

by Shine

Lain Iwakura posted:

a major security vendor claimed to me that a very popular log format was not parseable

probably the wrong person to ever say that to seeing that i enjoyed at one point parsing unstructured data and making it structured

i e-mailed them back with the regex to parse it into the appropriate fields and they're now all, "oh oh okay yeah that makes sense now"

I wish I knew how to do this sort of thing. It sounds neat.

Proteus Jones
Feb 28, 2013



Schadenboner posted:

I wish I knew how to do this sort of thing. It sounds neat.

Get the O'Reilly Regex book

Cybernetic Vermin
Apr 18, 2005

friedl specifically, there are other worse ones

graph
Nov 22, 2006

aaag peanuts

Shame Boy posted:

also a smart "essential oil vapor diffuser"

fyi if you have pets this can make them very sick

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

Father Jack posted:

does that mater when phishing for passwords? 419 scams sure, but passwords?

it's probably easier to capture login credentials from less savvy users but I was thinking more of 419 scams

bob dobbs is dead posted:

spear phish is good as hell but closely targeted towards important peeps

ah so that's why I get all the generic ones

FCKGW
May 21, 2006

NoneMoreNegative posted:

uk parliament published some of the docs seized from Facebook about an hour back, not had chance to browse the info yet but the bbc story says there’s some definite ‘soft’ secfuckery therein :o:

https://www.bbc.co.uk/news/technology-46456695

https://twitter.com/ashk4n/status/1070349123516170240?s=21

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



graph posted:

fyi if you have pets this can make them very sick

pets like cat-sized mammals or like birds?

bicycle
Oct 23, 2013

this is a good thread, thank you

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

androids app model is such trash. ive always wondered what they thought would happen when they decided to allow apps to access poo poo like the call history

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug

My Linux Rig posted:

androids app model is such trash. ive always wondered what they thought would happen when they decided to allow apps to access poo poo like the call history

yeah that information seems like stuff google would want to keep to itself instead of giving access to its advertising/panopticon compeittors

Guy Axlerod
Dec 29, 2008
Ha, maybe spoofed number robocalls are just a way to poison the data for anyone fetching call logs.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Besesoth posted:

A German group set up a website for the project they were working on: using facial recognition software to ID people at neo-Nazi rallies, so they could then send that information on to the people's bosses etc.. This was, of course, leaked to neo-Nazi groups, who began going to the site to see if they or their friends had been IDed yet.

Except it was a honeypot. There was no facial recognition going on; what the site was really doing was gathering names, operating on the principle of "let people doxx themselves". They started with 1500 known neo-Nazis in their database, and anytime someone searched for someone who wasn't in their database, that name got added and assigned a likelihood score based on how many other known neo-Nazis the searcher had already searched for. They've apparently now got thousands of people, each with at least one connection to known neo-Nazis, and the owners of the site (the Center for Political Beauty) are now offering their database to law enforcement and employers.

Adbot
ADBOT LOVES YOU

bicycle
Oct 23, 2013

yesssssss

  • Locked thread