Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


florida lan posted:

security fuckup thread 17.1 - YDGKJFTQDFGQWYFTDUKYWQG loving HELL

-----BEGIN PGP PUBLIC KEY BLOCK-----
loving HELL
-----END PGP PUBLIC KEY BLOCK-----

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




just in time for eu vlc bug bounty huh

Wiggly Wayne DDS
Sep 11, 2010



didn't know pagancow had twitter

Schadenboner
Aug 15, 2011

by Shine

Carbon dioxide posted:

Anyway, the hardcoded key is 1024-bit DSA.

So the police are in on it too, then?

:crossarms:

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Powerful Two-Hander posted:

-----BEGIN PGP PUBLIC KEY BLOCK-----
loving HELL
-----END PGP PUBLIC KEY BLOCK-----

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

florida lan posted:

security fuckup thread 17.1 - The attack you suggest, if it is possible, is not trivial to describe judging by the size of the description.

akadajet
Sep 14, 2003

no threat model
no threat model
you're the threat model

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
stop decrypting yourself

Trabisnikof
Dec 24, 2005

lol they're sticking with it

https://twitter.com/videolan/status/1086662728763260930

Shaggar
Apr 26, 2006
they're correct though. (altho idk if id use gpg)

Wiggly Wayne DDS
Sep 11, 2010



yeah this isn't the first time http then verify was used, and it causes an argument every time

the general use case is to allow transparent caching for large volumes of data though, not a lovely media player

Trabisnikof
Dec 24, 2005

gently caress the thread is amazing

https://twitter.com/videolan/status/1086665545896861701

https://twitter.com/videolan/status/1086667525998424066

https://twitter.com/videolan/status/1086670052106162177

https://twitter.com/videolan/status/1086674134829092866

https://twitter.com/videolan/status/1086680831165415424

https://twitter.com/videolan/status/1086685066384818178

Shaggar
Apr 26, 2006
oh it sounds like they maybe aren't using a good key and/or aren't using it properly which is a problem.

Shaggar
Apr 26, 2006
just use Authenticode you idiots.

Celexi
Nov 25, 2006

Slava Ukraini!




lmao they are mad

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

Shaggar posted:

oh it sounds like they maybe aren't using a good key and/or aren't using it properly which is a problem.

aiui the problem is if the key doesn't match it tries to check the vlc website for a new key, and then download it (over http of course)

ozymandOS
Jun 9, 2004
it seems that if the upgrade can't be verified with the built-in key, vlc downloads a new key from their server




over http

lol

Shaggar
Apr 26, 2006

goddamnedtwisto posted:

aiui the problem is if the key doesn't match it tries to check the vlc website for a new key, and then download it (over http of course)

sub par open sores tools lead to sub par open sores solutions.

Celexi
Nov 25, 2006

Slava Ukraini!
lol they deleted the ticket in the tracker

akadajet
Sep 14, 2003

Celexi posted:

lol they deleted the ticket in the tracker

yea they're real mad

and french

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/shivasinghal00/status/1086665612326105089

simmer down everyone, okay?

Lightbulb Out
Apr 28, 2006

slack jawed yokel
not a bug

uhhh okay its a bug but we're working on it

but its not a big deal im not mad im actually laughing

Xarn
Jun 26, 2015
I, for one, am thankful to the VLC devs for their exemplary handling of this bug report, and will definitely contact them with other issues.



:suicide:

Last Chance
Dec 31, 2004

why is https so hard for them

Wiggly Wayne DDS
Sep 11, 2010



ozymandOS posted:

it seems that if the upgrade can't be verified with the built-in key, vlc downloads a new key from their server




over http

lol
i'd say i'm surprised but its vlc, the surprising part is they aren't touting it as a feature and having everyone complain that other media players don't use their foolproof strategy

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

ozymandOS posted:

it seems that if the upgrade can't be verified with the built-in key, vlc downloads a new key from their server




over http

lol

i think it then checks this key is signed by a hardcoded one. this makes sense (ish) because it allows the signing key to be rotated without locking old exe's out of the auto update mechanism

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
i.e. he signs vlc.exe with whatever the current key is whenever he builds it
and signs new keys with all the old keys, so old versions of vlc can update to the new key safely if they don't have it

arguably a safer scheme than relying on tens of millions of users having a correct clock / sensible root ca store / some other way to bootstrap trust in the tls cert (dane lol)

although he should probably just try https first and fall back to this if necessary

Rufus Ping fucked around with this message at 00:54 on Jan 20, 2019

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

i don't know much about cert stuff but it does seem weird to me that they don't even try to do it in a more secure way first

ozymandOS
Jun 9, 2004

Rufus Ping posted:

i think it then checks this key is signed by a hardcoded one. this makes sense (ish) because it allows the signing key to be rotated without locking old exe's out of the auto update mechanism

yeah it's very possible i don't have the whole story, i am repeating what i heard

cinci zoo sniper
Mar 15, 2013




https://twitter.com/gwillem/status/1086275952915533828?s=21

jre
Sep 2, 2011

To the cloud ?




:psyduck: what the gently caress

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Same bug as the scp one from last week. Guess it made someone go looking

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

https://github.com/mysql/mysql-server/commit/98ed3d8bc8ad724686d26c7bf98dced3bd1777be

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Rufus Ping posted:

Same bug as the scp one from last week. Guess it made someone go looking

people stress out so much about intelligence agencies having secret encryption backdoors and stuff like that, but uh i don't know if they will ever need anything that fancy

cinci zoo sniper
Mar 15, 2013




Lutha Mahtin posted:

people stress out so much about intelligence agencies having secret encryption backdoors and stuff like that, but uh i don't know if they will ever need anything that fancy

like that encryption xkcd

crazysim
May 23, 2004
I AM SOOOOO GAY

cinci zoo sniper posted:

like that encryption xkcd

the last panel wasn't a goatse nor was the punchline "why didn't you just ask nicely?"

Raere
Dec 13, 2007

in soviet russia file uploads to you

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Soviet query language

4lokos basilisk
Jul 17, 2008


Volmarias posted:

Soviet query language

needs more swears

Adbot
ADBOT LOVES YOU

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

have an excellent thread: https://twitter.com/hacks4pancakes/status/1086000837615382529

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply