Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
ewiley
Jul 9, 2003

More trash for the trash fire

Volmarias posted:

This is definitely some kind of gently caress up

That is a fuckup on an impressive number of levels, but pretty par for the course. Casino threat models are like 99% physical.

Adbot
ADBOT LOVES YOU

haveblue
Aug 15, 2005



Toilet Rascal
looks like they think "physical threat model" is the guy manning their booth at the convention

ewiley
Jul 9, 2003

More trash for the trash fire
Also, lol

quote:

They even found Atrient's third party contractors (based in India) posting Atrient's source code on Github and asking stack overflow questions about it, an indicator which made it obvious to the researchers that security was not being taken seriously.

cinci zoo sniper
Mar 15, 2013




https://www.bleepingcomputer.com/news/security/researcher-declines-to-share-zero-day-macos-keychain-exploit-with-apple/

not disclosing due to lack of bug bounties, ostensibly

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
that rules, i'd hold out, too.

yoloer420
May 19, 2006

Volmarias posted:

This is definitely some kind of gently caress up

I wonder if the "researcher's" mother is still in jail.

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
"He was also charged with possession of child pornography, an offensive weapon and drugs. He remains overseas."

so uh. yeah.

GWBBQ
Jan 2, 2005


i was shodan surfing and came across someone with an unsecured NAS that has enormous amounts of personal information on it. i kind of feel like i should contact them and let them know, but i also don't want to creep them out by being some random guy contacting them about computer security. thoughts?

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
wipe it

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

yoloer420 posted:

I wonder if the "researcher's" mother is still in jail.

Oh, it's that dude.

How the gently caress did he manage to attend a security conference in the UK without being insta-extradited to Australia the moment he touched British soil?

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
ugh i seriously don’t get our resistance to run a bounty program across the product line

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

rjmccall posted:

ugh i seriously don’t get our resistance to run a bounty program across the product line

probably because things are not uniformly open-source across the company and different orgs have different legal folks with different positions on this stuff.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

CRIP EATIN BREAD posted:

"He was also charged with possession of child pornography, an offensive weapon and drugs. He remains overseas."

so uh. yeah.

:eyepoop:

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

GWBBQ posted:

i was shodan surfing and came across someone with an unsecured NAS that has enormous amounts of personal information on it. i kind of feel like i should contact them and let them know, but i also don't want to creep them out by being some random guy contacting them about computer security. thoughts?

the official position of this thread is "do not touch the poop"

James Baud
May 24, 2015

by LITERALLY AN ADMIN
Apparently the February Android update includes a fix for a code execution via PNG vulnerability.

Since, you know, surely all Android devices have received their regular monthly security updates by now. (Hey, mine has!)

https://threatpost.com/google-patches-critical-png-image-bug/141524/

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

yoloer420 posted:

I wonder if the "researcher's" mother is still in jail.

CRIP EATIN BREAD posted:

"He was also charged with possession of child pornography, an offensive weapon and drugs. He remains overseas."

so uh. yeah.

the most offensive part of that article is referencing Czechoslovakia. what year is it Australia??

spankmeister
Jun 15, 2008






rjmccall posted:

ugh i seriously don’t get our resistance to run a bounty program across the product line

It takes a LOT of effort to run a good bounty program, and running a lovely one is a lot worse than not running one at all.

I'm sure that's not the reason though :v:

cinci zoo sniper
Mar 15, 2013




yoloer420 posted:

I wonder if the "researcher's" mother is still in jail.

at least her baby boy is safe in czechoslovakia

Phone
Jul 30, 2005

親子丼をほしい。
he’s on twitter goin “don’t try to paint me as a bad guy” with the replies being “don’t let them drag you we all make mistakes!”

https://twitter.com/xormalware/status/1093269096970534914?s=21

Phone fucked around with this message at 10:53 on Feb 7, 2019

Potato Salad
Oct 23, 2014

nobody cares


salted hash browns posted:

Like people at Apple had to look at each other and say "Yes we will hand over iCloud encryption keys to a PRC owned organization" for this to happen.

At least Facebook and Google said "no thank you" to operating in PRC over the exact same concern Apple seems to not give a poo poo about.

Friend, Facebook marketing reps have been literally holding seminars on using data exfiltration loopholes as added value of their ad products. They can burn in hell and are at least as bad.

Potato Salad
Oct 23, 2014

nobody cares


GWBBQ posted:

i was shodan surfing and came across someone with an unsecured NAS that has enormous amounts of personal information on it. i kind of feel like i should contact them and let them know, but i also don't want to creep them out by being some random guy contacting them about computer security. thoughts?

You have no surefire safe way to report this to the owner.

Two months weeks days from now, there will be more discovered script-kiddie-level exploits against it anyways.

GWBBQ
Jan 2, 2005


Captain Foo posted:

the official position of this thread is "do not touch the poop"

Potato Salad posted:

You have no surefire safe way to report this to the owner.
you're right. I just feel bad that an identity thief's dream for a whole family is out there and they don't know.

ate shit on live tv
Feb 15, 2004

by Azathoth

CRIP EATIN BREAD posted:

my first programming-related class in community college I had a professor that requested code be printed out and handed in. it was java, and he didn't want comments in the code, emphasized that the code be "self-documenting". people would turn stuff in and he could look at it and immediately say "this doesn't compile".

it was weird but he was a really good professor. probably better than the ones I had when I transferred to a university.

"Self-documenting" code for a homework assignment is basically just encouraging good variable names and structure, but that is the only place it should exist.

post hole digger
Mar 21, 2011

Phone posted:

he’s on twitter goin “don’t try to paint me as a bad guy” with the replies being “don’t let them drag you we all make mistakes!”

https://twitter.com/xormalware/status/1093269096970534914?s=21

lol ah yes, whomst among us hasnt copped a child pornography charge

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

ate poo poo on live tv posted:

"Self-documenting" code for a homework assignment is basically just encouraging good variable names and structure, but that is the only place it should exist.

well yeah. he was trying to get people to absorb the fact that you should name stuff in a sane way. it was obviously education focused.

he also used to tell a story when he was working for some big company where they undertook a huge project. he was the project lead, and they sat in a meeting room and drew up design documents. they had little cards with operations on them all over the wall. they were given something like 6 months to do it.

the management kept asking "how much is written" and he kept replying with "nothing yet, still designing". weeks passed. management asked again, "how much is written?", "nothing yet, still design stage".

kept going, using humans as virtual actors in the system. management started panicking because nobody was writing code. they used 4 months to do the design phase. development began, and they knocked it out the implementation in a month because all the operations/classes were defined before any code was written. they had a whole month of testing to work with at that point.

that story always stuck with me. it's too bad you rarely see that.

chemosh6969
Jul 3, 2004

code:
cat /dev/null > /etc/professionalism

I am in fact a massive asswagon.
Do not let me touch computer.
Not China or Facebook news

https://techcrunch.com/2019/02/06/iphone-session-replay-screenshots/

quote:

“This lets Air Canada employees — and anyone else capable of accessing the screenshot database — see unencrypted credit card and password information,” he told TechCrunch.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

"Every tap, button push and keyboard entry is recorded — effectively screenshotted — and sent back to the app developers."

so we're just using screenshot to mean every form of recording now???

Stanley Pain
Jun 16, 2001

by Fluffdaddy
what is logging, alex.

haveblue
Aug 15, 2005



Toilet Rascal
glassbox's selling point is that they take the recorded taps and keystrokes and combine them with a mockup of your app/site to reconstitute what the screen looked like during the session. whether this counts as "screen recording" is a semantic argument so expect it to go on for another five pages

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

haveblue posted:

glassbox's selling point is that they take the recorded taps and keystrokes and combine them with a mockup of your app/site to reconstitute what the screen looked like during the session. whether this counts as "screen recording" is a semantic argument so expect it to go on for another five pages

did you know, log4j can turn your pii into a bomb???

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

fishmech posted:

"Every tap, button push and keyboard entry is recorded — effectively screenshotted — and sent back to the app developers."

so we're just using screenshot to mean every form of recording now???

yeah it’s like “bricked” meaning any inconvenience

Vapor Moon
Feb 24, 2010

Neato!
The Human Font

Annnnd banned https://techcrunch.com/2019/02/07/apple-glassbox-apps/

Last Chance
Dec 31, 2004

Glassbox's response is layered with salt that apple may have just killed their product on ios lol

quote:


TechCrunch's piece raised valid concerns. Yet we believe it is partial and doesn't adequately convey the many benefits for our customers and their users; or reflect the security and privacy capabilities inherent in Glassbox.

Glassbox and its customers are not interested in "spying" on consumers. Our goals are to improve online customer experiences and to protect consumers from a compliance perspective. Since its inception, Glassbox has helped organizations improve millions of customer experiences by providing tools that record and analyze user activity on web sites and apps. This information helps companies better understand how consumers are using their services, and where and why they are struggling.

We are strong supporters of user privacy and security. Glassbox provides its customers with the tools to mask every element of personal data. We firmly believe that our customers should have clear policies in place so that consumers are aware that their data is being recorded -- just as contact centers inform users that their calls are being recorded.

Furthermore: No data collected by Glassbox customers is shared with third parties, nor enriched through other external sources.
Glassbox meets the highest security and data privacy standards and regulations (e.g. SOC2, GDPR), and all data captured via our solution is highly secured and encrypted.

We provide our customers with the ability to mask every piece of data entered by a consumer, restrict access to authorized users, and maintain a full audit log of every user accessing the system.

We don't simply record data and provide customers with session replay. Brands come to us because Glassbox means source-proof, tamper-proof, encrypted records of digital activity. These characteristics make Glassbox invaluable, not to 'spy' on customers, but to (a) aid in creating the best and easiest digital journey, and (b) protect both brands and customers with evidential truth that allows for safe and compliant digital experiences.

sadus
Apr 5, 2004

Compliant except for that minor "user concent" bit

Shaggar
Apr 26, 2006

apple wants them to use official apple analytics so nobody else can get that sweet, sweet data

fisting by many
Dec 25, 2009



we believe everyone using our spyware should inform users they are being spied on, but uh, that's up to them

:fuckoff:

fisting by many
Dec 25, 2009



i wonder if in the future, if app stores crack down enough on privacy-invading apps, companies will migrate off apps back to webpages/pwa. especially as mobile apis become more supported in mainstream browsers.

ok apple says you're not allowed to record peoples' screens anymore, but you can embed this javascript that will do the same thing and nobody will stop you (provided you're outside the EU)

apseudonym
Feb 25, 2011

Analytics are a loving privacy dumpster fire

Shame Boy
Mar 2, 2010

man i love it when marketing at a completely transparently evil company has to try to make themselves sound not-awful :allears: it always feels so uncomfortable, like they don't even believe it themselves

sadus posted:

Compliant except for that minor "user concent" bit

hey now they clearly say they give their customers the option to mask that information so clearly it's on them :colbert:

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

also i'm the word """"enriched"""" in the 4th paragraph

e: and the sentiment of "we don't just spy on you, we spy on you to make lawsuits against you easier!" in the last paragraph that i didn't pick up on until reading it again

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply