Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
LordSaturn
Aug 12, 2007

sadly unfunny

burn them all, OP

Adbot
ADBOT LOVES YOU

Partycat
Oct 25, 2004

I will let someone with more InfoSec clout tell you to stop putting Apple on blast for operating in China following Chinese regulation and law I guess.

none of this information explains anything that is actually occurring or what the circumstances actually are

salted hash browns
Mar 26, 2007
ykrop

Partycat posted:

I will let someone with more InfoSec clout tell you to stop putting Apple on blast for operating in China following Chinese regulation and law I guess.

none of this information explains anything that is actually occurring or what the circumstances actually are

i am putting apple on blast for following Chinese regulation and law because it will result in human harm.

many other companies (incl. Fb/goog) have done the right thing and chose not to operate in China.

but you have such a boner for Apple you don’t care

salted hash browns
Mar 26, 2007
ykrop

LordSaturn posted:

burn them all, OP

this

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

it takes a special kind of sociopathy to facilitate literal genocides and pogroms and land on a gotta-take-the-good-with-the-bad shrug

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

salted hash browns posted:

i am putting apple on blast for following Chinese regulation and law because it will result in human harm.

many other companies (incl. Fb/goog) have done the right thing and chose not to operate in China.

but you have such a boner for Apple you don’t care

I'm the potential harm to Chinese being equated to actually-happened genocide

Last Chance
Dec 31, 2004

salted hash browns posted:

i get that everyone in this thread has an angry FB boner because they feel personally slighted by zucc, but Apple has put far more individuals at risk in China — and they did so fully knowing those consequences!

if you're not disgusted by facebook's repeatedly awful fuckups and clear contempt for protecting its users and their information ever since zuckerberg called his users dumb fucks for trusting them, i really don't know or want to know your malfunction

salted hash browns
Mar 26, 2007
ykrop

Last Chance posted:

if you're not disgusted by facebook's repeatedly awful fuckups and clear contempt for protecting its users and their information ever since zuckerberg called his users dumb fucks for trusting them, i really don't know or want to know your malfunction

I am.

my issue is with Apple taking a wholier-than-thou approach while selling out the largest country in the world

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

sure they’ve put a million people in camps and are building a terrifying ai panopticon but giving access to opt-in backups is the tipping point

Last Chance
Dec 31, 2004

salted hash browns posted:

I am.

my issue is with Apple taking a wholier-than-thou approach while selling out the largest country in the world

imho apple has a right to be aggravated by fb doing shady poo poo because oftentimes, and most recently, they're doing it on apple hardware. wpuld it be better if they were just like "yeah, nah, just stop installing spyware on teenagers' phones and we're cool bro"?

salted hash browns
Mar 26, 2007
ykrop

Last Chance posted:

imho apple has a right to be aggravated by fb doing shady poo poo because oftentimes, and most recently, they're doing it on apple hardware. wpuld it be better if they were just like "yeah, nah, just stop installing spyware on teenagers' phones and we're cool bro"?

no one is trying to justify FB doing dumb poo poo

salted hash browns
Mar 26, 2007
ykrop
I recognize this has now veered from nation-state security talk to a pissing match and I’ll stop

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

salted hash browns posted:

many other companies (incl. Fb/goog) have done the right thing and chose not to operate in China.

Lol, just lol if you think it's because "it's the right thing"

sadus
Apr 5, 2004

This thread could use a reeducation camp or two
RIP Uyghurs, Tibet, and Emagic GmbH

apseudonym
Feb 25, 2011

Partycat posted:

I will let someone with more InfoSec clout tell you to stop putting Apple on blast for operating in China following Chinese regulation and law I guess.

The "well its the local law" as argument for justifying actively supporting repressive regimes is disgusting, please don't make it.

sadus posted:

This thread could use a reeducation camp or two
RIP Uyghurs, Tibet, and Emagic GmbH
RIP

Doom Mathematic
Sep 2, 2008
Please, please! All these corporations are terrible.

Truga
May 4, 2014
Lipstick Apathy

Doom Mathematic posted:

Please, please! All these corporations are terrible.

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Doom Mathematic posted:

Please, please! All corporations are terrible.

Achmed Jones
Oct 16, 2004



Doom Mathematic posted:

Please, please! All these corporations are terrible.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong
apple sucks lol

cinci zoo sniper
Mar 15, 2013




salted hash browns posted:

no one is trying to justify FB doing dumb poo poo

have you seen your posts? also i love how all facebook actions, including facilitating a genocide, can be swept under the rug as “dumb poo poo” if it fits your white knighting narrative

cinci zoo sniper fucked around with this message at 06:02 on Feb 6, 2019

cinci zoo sniper
Mar 15, 2013




Volmarias posted:

Lol, just lol if you think it's because "it's the right thing"

also google hasn’t even bothered to not to try

Feisty-Cadaver
Jun 1, 2000
The worms crawl in,
The worms crawl out.

salted hash browns posted:

i get that everyone in this thread has an angry FB boner because they feel personally slighted by zucc, but Apple has put far more individuals at risk in China — and they did so fully knowing those consequences!

spoiler alert: everyone uses wechat so it doesn't fuckiiiiiiiiin matter

CCP already knows everything about everybody and actively censors poo poo they dont like, like pooh bear

(unless you have a non-mainland sim then they dont care as much)

Feisty-Cadaver fucked around with this message at 06:17 on Feb 6, 2019

cinci zoo sniper
Mar 15, 2013




also apple admits and announces their privacy fuckups, including cheese data migration, publicly. facebook is just sorry it got caught

LIVE AMMO COSPLAY
Feb 3, 2006

Maybe make fun of Apple fuckups when they happen rather than defensively bringing them up when somebody else gets caught loving up.

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
kinda convenient that apple catches someone else loving up shortly after they've had a major fuckup of their own and would want people to stop talking about it

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Jabor posted:

kinda convenient that apple catches someone else loving up shortly after they've had a major fuckup of their own and would want people to stop talking about it

not like you need to wait long for fb to gently caress up

cinci zoo sniper
Mar 15, 2013




Jabor posted:

kinda convenient that apple catches someone else loving up shortly after they've had a major fuckup of their own and would want people to stop talking about it

both facebook and subsequently google enterprise certificate misuse was caught by security researchers and taken to media?

simble
May 11, 2004

cinci zoo sniper posted:

both facebook and subsequently google enterprise certificate misuse was caught by security researchers and taken to media?

how loving convenient

cinci zoo sniper
Mar 15, 2013




simble posted:

how loving convenient

PCjr sidecar posted:

not like you need to wait long for fb to gently caress up

apseudonym
Feb 25, 2011

simble posted:

how loving convenient

There's always bugs going on. The FaceTime thing was never going to be more a flash in the pan in the media anyways.

Cybernetic Vermin
Apr 18, 2005

Jabor posted:

kinda convenient that apple catches someone else loving up shortly after they've had a major fuckup of their own and would want people to stop talking about it

we didn't really know what rules apple had in place for facebooks use of the certificates, i'd presume someone whistleblew on google when the publicity revealed that such use wasn't ok

also apple is plenty terrible and the real mindbender is the attempt to defend facebook

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
the FaceTime bug was also a massive nothingburger that was way overhyped by the media

haveblue
Aug 15, 2005



Toilet Rascal

Cybernetic Vermin posted:

we didn't really know what rules apple had in place for facebooks use of the certificates

the terms of the generic enterprise cert program agreement are public and were cited as the reason for the revocation, I don't think they had a special private contract since apple removed ios's built-in facebook integration

Cybernetic Vermin
Apr 18, 2005

haveblue posted:

the terms of the generic enterprise cert program agreement are public and were cited as the reason for the revocation, I don't think they had a special private contract since apple removed ios's built-in facebook integration

yeah, this turns out to have been the right take all along, but i at least suspect that people who had seen wonky google apps on their enterprise cert up to that point had gone "huh" and assumed that they had some deal cut with apple (and thus didn't bother to report it to the right people at apple)

at least i find that to be more likely than there being anything particularly conspiratorial about google getting called out the day after facebook

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

Jabor posted:

kinda convenient that apple catches someone else loving up shortly after they've had a major fuckup of their own and would want people to stop talking about it

are you comparing a software bug (an unavoidable thing that happens all the time to all software) to deliberate espionage and exploitation of minors?

gently caress are Facebook tankies a thing and have they invaded this thread?

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

VikingofRock posted:

This is a cool article about different ways to fool answer validation in automated CS assignment grading: Smart like a fox: How clever students trick dumb automated programming assignment assessment systems.

There are a lot of fun techniques in there, but my favorite is that this code will result in a perfect grade on every assignment for the software tested:

Java code:
System.out.println("Grade :=>> 100");
System.exit(0);

funny story about my cs classes: i used to have a professor who insisted that students print out their code and turn it in instead of using the school's tool for digitally turning in stuff. my final project ended up being 20+ pages printed back and front

rumor was that he had stock in hp and all the school printers got their supplies from them

my thinking is he was looking for students doing this poo poo and was just good at working out execution paths in his head

Cybernetic Vermin
Apr 18, 2005

My Linux Rig posted:

funny story about my cs classes: i used to have a professor who insisted that students print out their code and turn it in instead of using the school's tool for digitally turning in stuff. my final project ended up being 20+ pages printed back and front

rumor was that he had stock in hp and all the school printers got their supplies from them

my thinking is he was looking for students doing this poo poo and was just good at working out execution paths in his head

yeah, i still require printouts for the usual small scale assignments (where it'll be a few pages with suitable a2ps settings), not for projects where it gets lengthy though

it is just easy both to annotate a bit on, and with rather little practice you get good at visually spotting both bugs and e.g. plagiarism in that form

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

My Linux Rig posted:

funny story about my cs classes: i used to have a professor who insisted that students print out their code and turn it in instead of using the school's tool for digitally turning in stuff. my final project ended up being 20+ pages printed back and front

my first programming-related class in community college I had a professor that requested code be printed out and handed in. it was java, and he didn't want comments in the code, emphasized that the code be "self-documenting". people would turn stuff in and he could look at it and immediately say "this doesn't compile".

it was weird but he was a really good professor. probably better than the ones I had when I transferred to a university.

Adbot
ADBOT LOVES YOU

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
This is definitely some kind of gently caress up


https://www.secjuice.com/security-researcher-assaulted-ice-atrient/ posted:

Following a serious vulnerability disclosure affecting casinos globally, an executive of casino technology vendor Atrient has assaulted the security researcher who disclosed the vulnerability at the ICE conference in London. This is the story of a vulnerability disclosure gone bad, one involving the FBI, a vendor with a global customer base of casinos and a severe security vulnerability which has gone unresolved for four months without being properly addressed.

...

These kiosks and the back end server communicate the personal details of their users and send data like drivers license scans (used for enrollment), user home addresses and contact details, as well as details about user activity, unencrypted over publicly accessible internet. When the researcher discovered that the unauthenticated reward server was directly connected to the kiosks on the casino floor they realized that the API the kiosks used was wide open and extremely vulnerable to criminal abuse.

The researchers told me that every single kiosk was calling home to the server in plain text and all data sent from the kiosks to the server clearly visible on the network. Because there is no SSL protection and because the API is wide open and vulnerable to abuse, it is possible to identify kiosks by their MAC address and use the unsecured API to change details, track users and add credit to user accounts and even spin up a kiosk on a virtual machine in order to have your own personal kiosk at home.

Atrient were not segregating these kiosks into vlans, their FTP access was wide open and unencrypted, and all of this was discovered using the Shodan search engine, all of it was publicly visible to anyone on the internet who knew where to look.

Atrient is a market leader in selling these loyalty kiosks to casinos and because these kiosks have been sold to casinos all over Las Vegas, the United States and (via their partnership with Konami) to casinos all over the world. Considering that Atrient COO Jessie Gill said in the media recently that they "don’t have a different version for different operators; we integrate all functions in a single product", there is a very high likelihood that this vulnerability affects all of their customers, including their white label partners Konami who rebranded Atrient's tech for sale to their own customers.



  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply