Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
"what do you do to relax" is definitely a more loaded question than most

i didn't even mention the person who wrote "furiously masturbate" in the top corner

edit: a respectable snipe

Adbot
ADBOT LOVES YOU

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

CRIP EATIN BREAD posted:

unfettered write access to a publicly available display seems like a infosec fuckup imho

Loky11
Dec 12, 2006

Pull on the new flesh like borrowed gloves and burn your fingers once again

rjmccall posted:

"what do you do to relax" is definitely a more loaded question than most

i didn't even mention the person who wrote "furiously masturbate" in the top corner

edit: a respectable snipe

did someone actually write that?

:psyduck:

Wiggly Wayne DDS
Sep 11, 2010



i gather you have no experience dealing with people in security outside of professional environments?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Loky11 posted:

being told "you don't get LGBT issues" while being LGBT myself and growing up not ever talking about it with people outside my close friends is frustrating. Maybe it's a generational thing. Good luck bringing up things on social media. It's just not my style and try maybe, to at least give people the benefit of the doubt. I will too.

just as a reminder, i am in the LGBTQ+ community myself and i will not ever speak on behalf of those who are not me. heck i will not even talk on behalf of all lesbians or transgender women because that is not what i am here for (i describe myself as "queer woman" and typically refrain from talking about my being trans because it's irrelevant to who i am daily).

it's usually poor form to speak on behalf of the whole community when these matters affect a small subset. we're talking about the treatment of non-men at conferences and not specifically anything else here. i have a problem with infosec because i work in it and have to deal with all sorts of nonsense with it being transphobic, sexist, or just outright ignorance

you may get the issues that you face as part of the LGBTQ+ community but your views do not necessitate everyone as a whole. i am not asexual so i never talk on behalf of those who are aces nor am i bisexual so i cannot comment on their challenges either. this is something that should always remain in mind for anyone under our colourful umbrella as it helps not step on toes

Lain Iwakura fucked around with this message at 21:13 on Jan 16, 2019

Main Paineframe
Oct 27, 2010

Shame Boy posted:

maybe we should have a queer questions thread explicitly for exploring this poo poo? idk i get why people should put in a little effort to figure stuff out on their own and not expect others to have to explain it to them and all, but sometimes you do genuinely wanna ask / talk it through with others. it's just the security thread isn't the best place, and the yosqueer thread isn't the best place since it's meant to be safe / relaxing... i know a bunch of people were wandering into the yosqueer thread a while ago asking earnestly how they should go about doing [x] better and we kinda shuffled them out since it's not really the place for it, so maybe there should be a place explicitly for it?

(i realize this isn't really a queer issue specifically, more of a feminist issue, but i think it still applies :shrug:)

there's the Great Race Space subforum under D&D that's kind of a dedicated space for these sorts of discussions, a lot of knowledgeable people hang out there, and there's a couple threads set aside for asking questions and stuff. it's pretty slow, though

---

also, personal secfuck news: i got an email containing one of my passwords and a blackmail note saying that they hacked my webcam and my facebook, and that if I don't send them eight hundred bucks in bitcoin they'll send nudes of me to all my contacts

except I don't have a webcam and my facebook uses a different password. the password they had was an old one that I never use on anything remotely important. so they probably got their hands on passwords from some crappy old forum or something, then decided trying to scam password-reusers with fake blackmail threats was more time-efficient than trying to break into people's accounts directly

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
in sec news on my end, i am finally starting my years long security orchestration project

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Lain Iwakura posted:

in sec news on my end, i am finally starting my years long security orchestration project

global rm -rf / job on puppet

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

BangersInMyKnickers posted:

global rm -rf / job on puppet

you have no idea how tempting that is

Shame Boy
Mar 2, 2010

Main Paineframe posted:

also, personal secfuck news: i got an email containing one of my passwords and a blackmail note saying that they hacked my webcam and my facebook, and that if I don't send them eight hundred bucks in bitcoin they'll send nudes of me to all my contacts

except I don't have a webcam and my facebook uses a different password. the password they had was an old one that I never use on anything remotely important. so they probably got their hands on passwords from some crappy old forum or something, then decided trying to scam password-reusers with fake blackmail threats was more time-efficient than trying to break into people's accounts directly

yeah those have been going around, i posted a few in the last thread. did it say you have ~UNBRIDLED FANTASY~ 'cuz that's my favorite one :allears:

spankmeister
Jun 15, 2008






Main Paineframe posted:

also, personal secfuck news: i got an email containing one of my passwords and a blackmail note saying that they hacked my webcam and my facebook, and that if I don't send them eight hundred bucks in bitcoin they'll send nudes of me to all my contacts

except I don't have a webcam and my facebook uses a different password. the password they had was an old one that I never use on anything remotely important. so they probably got their hands on passwords from some crappy old forum or something, then decided trying to scam password-reusers with fake blackmail threats was more time-efficient than trying to break into people's accounts directly

Recently this has been a common tactic. They use passwords from leaked dumps that are available all over the internet to make the threat look credibile. It's also a very clever threat because it works on people's shame and most aren't savvy enough to figure how the scam works.

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

Loky11 posted:

did someone actually write that?

:psyduck:

i misremembered, it was "rageing masturbation"

https://twitter.com/deborahlindseyl/status/1048401891913334785/

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
yeah. i got one of those e-mails and it had my password from the lastfm breach. it shook me to my bones :laugh:

Shame Boy
Mar 2, 2010

spankmeister posted:

Recently this has been a common tactic. They use passwords from leaked dumps that are available all over the internet to make the threat look credibile. It's also a very clever threat because it works on people's shame and most aren't savvy enough to figure how the scam works.

on top of that all the ones i've gotten set the From header (or similar) to make it look like it was sent from your own account, which they point out multiple times in the text, because obviously you can only do that if you've hacked the account for real!!!

Shame Boy
Mar 2, 2010

Lain Iwakura posted:

yeah. i got one of those e-mails and it had my password from the lastfm breach. it shook me to my bones :laugh:

oh poo poo that's where they got mine from i bet too, thinking about it that was the last time i used that password...

Shame Boy
Mar 2, 2010


did someone write NEDM? is this from loving 2005?

EMILY BLUNTS
Jan 1, 2005

if someone wants to send out nude videos of me I’m the one that should be getting paid

Main Paineframe
Oct 27, 2010

Shame Boy posted:

yeah those have been going around, i posted a few in the last thread. did it say you have ~UNBRIDLED FANTASY~ 'cuz that's my favorite one :allears:

unfortunately not

the only part that's amusing is the one where it goes out of its way to assure me that absolutely no one is paying them to do it

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

Shame Boy posted:

maybe we should have a queer questions thread explicitly for exploring this poo poo? idk i get why people should put in a little effort to figure stuff out on their own and not expect others to have to explain it to them and all, but sometimes you do genuinely wanna ask / talk it through with others. it's just the security thread isn't the best place, and the yosqueer thread isn't the best place since it's meant to be safe / relaxing... i know a bunch of people were wandering into the yosqueer thread a while ago asking earnestly how they should go about doing [x] better and we kinda shuffled them out since it's not really the place for it, so maybe there should be a place explicitly for it?

(i realize this isn't really a queer issue specifically, more of a feminist issue, but i think it still applies :shrug:)

i mean, I'm down with having a specific queer-square alliance thread or whatever where people can come ask questions (because yes the yeerk pool is meant to be for queer folk to talk amongst themselves), but I feel like at that point we'd need an IK just for the queer threads because graph only has so many hours in the day to probe disingenuous morons and I don't want to kill him!

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

spankmeister posted:

Recently this has been a common tactic. They use passwords from leaked dumps that are available all over the internet to make the threat look credibile. It's also a very clever threat because it works on people's shame and most aren't savvy enough to figure how the scam works.

yeah i think it's pretty genius because not everyone is knowledgeable of the fact that password dumps get leaked onto things like pastebin. i know a lot of people who would fall for that kind of thing.

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

CRIP EATIN BREAD posted:

yeah i think it's pretty genius because not everyone is knowledgeable of the fact that password dumps get leaked onto things like pastebin. i know a lot of people who would fall for that kind of thing.

There's a big wave of these apparently because a bunch of people were talking about receiving them in the break room today.
one guy was like "there's hundreds of pictures of me in nothing but a harness at Folsom, wtf kind of lame threat is this "

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

rjmccall posted:

alright, straight white dude here to explain everything and render judgement, be warned

in one corner of this con they apparently put up an unmonitored whiteboard for people to write down things that help them cope with stress. this is the sort of thing that seems like a really good idea, because it's fun and it makes people feel engaged and maybe starts conversations around it, but actually it's maybe not a great idea because especially for this topic because it might go places you don't really want it to go, like happened here, and you look like an idiot

so a couple different people write down "weed", which is presumably an honest answer, but which also makes people laugh and want to put up their own funny answers. now somebody else puts up "boobies", which in their mind is funny and in keeping, but actually is unprofessional and rude but because it's sexualizing in a way that's predictably and understandably going to make some women really uncomfortable. and then another person puts down "boobies", and to put their own own twist on it they (or maybe a third person?) add "#metoo"

okay so the best possible spin on this is that they're not trying to make a statement, just trying to say "same" in a funny way by making a reference to something they vaguely remember hearing about. now even that is messed up; anyone who paid enough attention to the reporting around "#metoo" to remember it really should've realized that it is not a super funny topic that they should be making random "wacky" references to on a whiteboard about ways to relieve stress. even if this is somehow an honest mistake, it's also a revealing mistake. and that's the best spin; it's not at all crazy to think this is some intentional misogynist troll, because that happens, it is a real thing

so someone points it out to the con staff, and they don't seem like they're doing anything about it, and so that person escalates, and the staff eventually write huffy posts on social media about the terrible attendee who yelled at them for hours. because apparently they knew the guy who wrote "#metoo" and he's a big deal in their little world and they didn't want to piss him off by asking him to make amends or even explain himself. and having to listen to this wholly justified criticism of their actions is such a headache that they're literally going to shut down their con rather than deal with it anymore. which is both lovely and hilariously weak

im glad you wrote this because everything between the initial tweet and the announcement they're going to not have a con anymore was a mess of barely readable tweet arguments that made it really hard to follow what happened when with who tbh

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

RE Symantec IPS vulnerability: I don't think its been properly fixed in the IPS module. I'm seeing evidence in the logs of clients getting popped all over the place (not servers) and the ones that don't throw SEHOP errors have their SONAR module uploading copies of their ccSvcHst process to Symantec for analysis

Raere
Dec 13, 2007

Sometimes I'm glad the networks I manage aren't connected to the internet

Doom Mathematic
Sep 2, 2008

CRIP EATIN BREAD posted:

unfettered write access to a publicly available display seems like a infosec fuckup imho

Well put.

Stanley Pain
Jun 16, 2001

by Fluffdaddy

Raere posted:

Sometimes I'm glad the networks I manage aren't connected to the internet

that you know of. :tinfoil:

graph
Nov 22, 2006

aaag peanuts

jit bull transpile posted:

graph only has so many hours in the day to probe disingenuous morons

i check the report queue often, just mash that button

sadus
Apr 5, 2004


I found the problem

Midjack
Dec 24, 2007



Shame Boy posted:

yeah those have been going around, i posted a few in the last thread. did it say you have ~UNBRIDLED FANTASY~ 'cuz that's my favorite one :allears:

when i read about this scam i'm always reminded of the story about when the cia tried to blackmail sukarno with a fake sex film and he thought it was awesome and asked them for copies to send to his friends.

Hexyflexy
Sep 2, 2011

asymptotically approaching one

Wiggly Wayne DDS posted:

i gather you have no experience dealing with people in security outside of professional environments?

I wasn't going to write anything, but as it's all here so why not. I spent a lot of my early life doing reverse engineering stuff, specifically x86 binary reverse engineering, started with games cracking same as everyone else - I'm not infosec, too old, we didn't really care about networks. Back in the day I was involved with lots of groups on the net doing it, but maybe 10 years ago I backed off because it was so toxic, specifically seeing my transgender friends getting attacked (and it was always them). It's definitely a thing.

Still do the odd RE contract to keep my maths in it and I enjoy it, but there is no way I'd be involved with the community again or ever go to a conference.

akadajet
Sep 14, 2003

sadus posted:

the java autoupdater now shows this handy dialog - why yes, don't mind if I do



does it also uninstall the ask toolbar it originally shipped with?

cinci zoo sniper
Mar 15, 2013




Shame Boy posted:

oh poo poo that's where they got mine from i bet too, thinking about it that was the last time i used that password...

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

e whoops

Lutha Mahtin fucked around with this message at 05:52 on Jan 17, 2019

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

e whoops

evil_bunnY
Apr 2, 2003


BangersInMyKnickers posted:

Symantec says its something in the wild hitting against the IPS engine but it should be resolved with the latest def set. They're not really sure who's doing it or what the payload is, so I suspect its a bandaid fix
how’s the payload delivered?

evil_bunnY fucked around with this message at 08:01 on Jan 17, 2019

Wiggly Wayne DDS
Sep 11, 2010



Hexyflexy posted:

I wasn't going to write anything, but as it's all here so why not.
unfortunately too many people go into the same cycle due to the toxicity, and it's hard for a pushback against toxic culture to happen without majority opinion or you'll be seen as causing drama yourself

the post wasn't directed at you, more at any lack of awareness at how a loud portion of the industry acts

Feisty-Cadaver
Jun 1, 2000
The worms crawl in,
The worms crawl out.

CRIP EATIN BREAD posted:

unfettered write access to a publicly available display seems like a infosec fuckup imho

who was it that goatse’d the RSA conference tweet wall again?

LordSaturn
Aug 12, 2007

sadly unfunny

just wanted to thank everyone for talking about what happened to Derbycon. my boss shared around the big tearful goodbye notice and I could clearly see the fingerprint of "our mods hosed up, and we would rather implode than admit it" but I could only remember the fuckup at lambdacon, not this whiteboard thing

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Shame Boy posted:

lmao i think this is the first time i've seen a company admit you're better off without their product

got to get that "java is installed on 9 trillion device, even your car!" count up somehow and making people remove it and add it again would do it

Adbot
ADBOT LOVES YOU

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Main Paineframe posted:

except I don't have a webcam and my facebook uses a different password. the password they had was an old one that I never use on anything remotely important. so they probably got their hands on passwords from some crappy old forum or something, then decided trying to scam password-reusers with fake blackmail threats was more time-efficient than trying to break into people's accounts directly

remember kids, use a password manager and different randomly generated password for every service you use.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply