Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
EMILY BLUNTS
Jan 1, 2005

also more PW’s came out
https://twitter.com/campuscodi/status/1086061689190170624?s=20

Adbot
ADBOT LOVES YOU

Schadenboner
Aug 15, 2011

by Shine

EMILY BLUNTS posted:

YOSPOS › Security Fuckup Megathread - v18.0 - the thread title says “security fuckups” not “insecurity fuckups”

Mods, plz do the needful &c. &c.

invlwhen
Jul 28, 2012

please do your best

EMILY BLUNTS posted:

the thread title says “security fuckups” not “insecurity fuckups”

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
it won't fit and it would be v17.1, not v18.0 thanks

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
anyone going to shmoocon in d/c this weekend? I think I can get a ticket, and if not, I’ll be around for hallwaycon lol

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

EMILY BLUNTS posted:

the thread title says “security fuckups” not “insecurity fuckups”

holy poo poo lmao

fisting by many
Dec 25, 2009



sadus posted:

Not a sec-gently caress but on topic as of late, this person SLEEPYCATT had another Minecraft music festival with donations going to the Trevor Project, kind of neat https://minecraft.xxx/. Second festival of theirs I've heard of but there might have been more. Luckily no second life style goons have infiltrated their events yet as far as I know with flying dicks and the like.

Unrelated but apparently custom Minecraft servers made tons of money at least as of a couple years ago, from donations and people paying to buy extra items and such. A lot of DDOS attacks at a previous hosting company I worked for were aimed at Minecraft servers, apparently hired by other server operators trying to knock their competition offline. Krebs has been reporting on an increasing number of "booter" providers getting arrested lately, Mirai copycats and the like, darn.

yeah apparently the mirai guy got rich operating a booter/extortion racket solely for minecraft servers (krebs did a huge exposé on it)

that's crazy

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Lain Iwakura posted:

it won't fit and it would be v17.1, not v18.0 thanks

perhaps
code:
YOSPOS › Security Fuckup Megathread - v17.1 - "security fuckups" not "insecurity fuckups"

spankmeister
Jun 15, 2008






fisting by many posted:

yeah apparently the mirai guy got rich operating a booter/extortion racket solely for minecraft servers (krebs did a huge exposé on it)

that's crazy

Yep. The biggest DDoS in history was done by Minecraft kids.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



turns out the internet is a piece of poo poo

redleader
Aug 18, 2005

Engage according to operational parameters

jesus loving christ

Wiggly Wayne DDS
Sep 11, 2010



meh, its being blown out of proportion

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

evil_bunnY posted:

do you have some kind of exec logging? some parts of our org are still on Symantec, I’ll ask if they’ve seen crashes.

Not at the moment, still waiting on approval for a sysmon rollout. Not sure if it would have given us anything if the heap is being modified in-memory. Hopefully is just some manner of memory leak that’s being inadvertently triggered and overwriting nonsense to the heap but I don’t have confirmation yet.

Stanley Pain
Jun 16, 2001

by Fluffdaddy

EMILY BLUNTS posted:

the thread title says “security fuckups” not “insecurity fuckups”

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


https://twitter.com/RGB_Lights/status/1086328344327507968

im sure it can be trusted

spankmeister
Jun 15, 2008






Unironically tho, it's gonna be fine.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/magen_wu/status/1086394054265458689

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
hey. if you're gonna go murdering people...

https://www.runnersworld.com/news/a25924256/mark-fellows-runner-hitman-murder/

quote:

A British runner, cyclist, and mob hitman has been convicted for the murders of two rival gangsters, in part, because of his GPS watch. Mark “Iceman” Fellows, 39, was found guilty by a jury at Liverpool Crown Court of killing organized crime leader Paul “Mr. Big” Massey and his associate John Kinsella, 55 and 53 at the time of their deaths. Massey and Kinsella were also career criminals, part of a gang scene near Manchester, England, with a reputation known across Europe, according to the Manchester Evening News.

Though police already suspected Fellows in Kinsella’s death, it was his Garmin Forerunner that linked him to Massey’s unsolved 2015 murder. While detectives were investigating Fellows, they came across a photo of the suspect wearing his Garmin Forerunner during 2015’s Great Manchester 10K (he ran 47:17, pictured above) two months before the murder of Massey that July. Detectives then located the device at Fellows’s home and checked its GPS data for files that could link him to Massey.

They found that the runner plotted these murders with the attention and precision of any serious athlete, and accordingly, he recorded his recon missions. (Runner’s World has not been able to link Fellows to a public Strava or Garmin account.)

spankmeister
Jun 15, 2008







Nuh uh! Sometimes I use Bing!

EMILY BLUNTS
Jan 1, 2005

thats one way to set a personal best

Stanley Pain
Jun 16, 2001

by Fluffdaddy

spankmeister posted:

Nuh uh! Sometimes I use Bing!

only when I forget to change the default search option in vivaldi browser.

Raere
Dec 13, 2007

osint is being intellegent about operating systems

Agile Vector
May 21, 2007

scrum bored




not turning off, or only turning off location features intermittently, is a great way to reveal illicit behavior and it never stops being amusing how people trap themselves by their own devices

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Raere posted:

osint is being intellegent about operating systems

Your Operating System Is Not Trash

LIVE AMMO COSPLAY
Feb 3, 2006

https://kotaku.com/atlas-player-gets-into-admins-account-summons-swarm-of-1831870230

“To be clear this was not caused by a hack, third party program, or exploit. We have taken the appropriate steps to ensure this does not happen again.” aka some admin for a video game reuses his passwords.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.



good to see the speed running community are still setting new times in Hitman

Agile Vector
May 21, 2007

scrum bored



Powerful Two-Hander posted:

good to see the speed running community are still setting new times in Hitman

Midjack
Dec 24, 2007



Powerful Two-Hander posted:

good to see the speed running community are still setting new times in Hitman

awful chavs done quick

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Powerful Two-Hander posted:

good to see the speed running community are still setting new times in Hitman

abigserve
Sep 13, 2009

this is a better avatar than what I had before

Powerful Two-Hander posted:

good to see the speed running community are still setting new times in Hitman

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

Powerful Two-Hander posted:

good to see the speed running community are still setting new times in Hitman

Carbon dioxide
Oct 9, 2012

https://twitter.com/11rcombs/status/1086531879178829824

They verify against a PGP key that they download over HTTP.

Edit: It gets better, apparently they roll their own PGP implementation too. And they don't think they're doing anything wrong.

Carbon dioxide fucked around with this message at 09:02 on Jan 19, 2019

Celexi
Nov 25, 2006

Slava Ukraini!

Carbon dioxide posted:

https://twitter.com/11rcombs/status/1086531879178829824

They verify against a PGP key that they download over HTTP.

Edit: It gets better, apparently they roll their own PGP implementation too. And they don't think they're doing anything wrong.

No threat model, no security bug. This is your last warning.

Carbon dioxide
Oct 9, 2012

Celexi posted:

No threat model, no security bug. This is your last warning.

New thread title?

Anyway, the hardcoded key is 1024-bit DSA.

Nude
Nov 16, 2014

I have no idea what I'm doing.

Carbon dioxide posted:

https://twitter.com/11rcombs/status/1086531879178829824

They verify against a PGP key that they download over HTTP.

Edit: It gets better, apparently they roll their own PGP implementation too. And they don't think they're doing anything wrong.

admittedly this went over my head but I find a lot of open source software is rather lax about security. Like brew (the goto osx shell package manager) up until 2017?2016? had you use admin access for installing packages.

Truga
May 4, 2014
Lipstick Apathy
how are you going to install system packages when you're not an admin though?

a problem would be those packages not being signed, not the requiring admin access bit.

crazysim
May 23, 2004
I AM SOOOOO GAY

quote:

No threat model, no security bug. This is your last warning.

those VLC guys sure are friendly.

Carbon dioxide
Oct 9, 2012

https://twitter.com/11rcombs/status/1086559891542687744

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
security fuckup thread 17.1 - YDGKJFTQDFGQWYFTDUKYWQG loving HELL

Adbot
ADBOT LOVES YOU

Soricidus
Oct 21, 2010
freedom-hating statist shill

Celexi posted:

No threat model, no security bug. This is your last warning.

:nsavince:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply