Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Wiggly Wayne DDS posted:

good luck trying to get someone to argue with you over implicit vs explicit protections

so you admit your post was invalid, great

Adbot
ADBOT LOVES YOU

power botton
Nov 2, 2011

Is it insane to think that the NSA has started VPN companies to log all traffic or just have more sample data to work on deanonymizing/breaking encyption

Wiggly Wayne DDS
Sep 11, 2010



no more than any other intel agency, really it'd be cheaper than tapping points and filtering traffic down to interesting targets if they'll pay you to do it themselves

Wiggly Wayne DDS
Sep 11, 2010



although if you want to get in-depth on that question there's operational costs where your passive monitoring will cover those targets anyway and you won't gain more data by popping up random vpns vs just inspecting existing ones. then there's the underlying tech shared across projects and balancing putting those on external entities and connecting to them which puts additional risk on other projects that share resources

so for a large intel agency you'd hit diminishing returns, but it'd be cost-effective on small-mid especially if you're targeting them on forums with discounts and the like

Soricidus
Oct 21, 2010
freedom-hating statist shill

Wiggly Wayne DDS posted:

no more than any other intel agency, really it'd be cheaper than tapping points and filtering traffic down to interesting targets if they'll pay you to do it themselves

the difficulty there is persuading the interesting targets to use the vpn you own. I doubt the nsa actually has much interest in people who just want to block ads or bypass geographic blocks or w/e, and the russian government and isis probably run their own vpns

people in like iran or china wanting to use a vpn to bypass govt censorship may be at risk from this kind of attack tho

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Lain Iwakura posted:

we've got a genius in the sec help thread


:allears:

I recommend this VPN service that cannot be assed to update your ipv6 routes despite that protocol being enabled by default since Vista

Wild EEPROM
Jul 29, 2011


oh, my, god. Becky, look at her bitrate.

Soricidus posted:

the difficulty there is persuading the interesting targets to use the vpn you own. I doubt the nsa actually has much interest in people who just want to block ads or bypass geographic blocks or w/e, and the russian government and isis probably run their own vpns

people in like iran or china wanting to use a vpn to bypass govt censorship may be at risk from this kind of attack tho

what if they offered you 10% off if you use the coupon code from your favorite podcaster

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

fishmech posted:

printers are portals between the computer realm and the flesh realm, of course the diagrams for how they work are horrific sigils and they constantly break

printers are just disobedient little robots

Wasabi the J
Jan 23, 2008

MOM WAS RIGHT

Farmer Crack-rear end posted:

What is a printer?
A disobedient pile of robots!
But enough Appletalk!
Have at UDP!

pseudorandom name
May 6, 2007

now post the stellaris mod

Salt Fish
Sep 11, 2003

Cybernetic Crumb
My friends want me to play apex with them which requires an EA account. An EA account password cannot be longer than 16 characters. I found this thread:


https://answers.ea.com/t5/EA-General-Questions/Why-limit-max-password-to-16/m-p/5803599

Barry, an EA community manager, helpfully explains internet security basics:

quote:

At a minimum, there are 26+10 possible characters per position, of which there can be 16. My napkin math shows

36^16=7,958,661,109,946,400,884,391,936 possible passwords. Nearly eight septillion possible passwords should be enough, especially if you use https://www.random.org/passwords/ to generate strong passwords.

Shame Boy
Mar 2, 2010

Salt Fish posted:

My friends want me to play apex with them which requires an EA account. An EA account password cannot be longer than 16 characters. I found this thread:


https://answers.ea.com/t5/EA-General-Questions/Why-limit-max-password-to-16/m-p/5803599

Barry, an EA community manager, helpfully explains internet security basics:

thanks for making sure there's "enough" passwords for everyone barry

LIVE AMMO COSPLAY
Feb 3, 2006

Salt Fish posted:

My friends want me to play apex with them which requires an EA account. An EA account password cannot be longer than 16 characters. I found this thread:


https://answers.ea.com/t5/EA-General-Questions/Why-limit-max-password-to-16/m-p/5803599

Barry, an EA community manager, helpfully explains internet security basics:

When the Xbox 360 was a thing you could have a microsoft account password that was too long for the console to use, so you would have to shorten it to play your games.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



i think there is a world market for maybe five passwords

mystes
May 31, 2006

Krankenstyle posted:

i think there is a world market for maybe five passwords
Just have everyone in the world have the same password, but make sure to change it every thirty days and include punctuation so it's secure.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


mystes posted:

Just have everyone in the world have the same password, but make sure to change it every thirty days and include punctuation so it's secure.

look at this idiot



everyone knows you put a number on the end and increment by 1 each time

Feisty-Cadaver
Jun 1, 2000
The worms crawl in,
The worms crawl out.

Powerful Two-Hander posted:


everyone knows you put a number on the end and increment by 1 each time

I worked with a guy a long time ago who, when he had to change his password, immediately changed it 7 times in a row or w/e so he could bypass AD’s “you can’t use the last 7 passwords” rule and keep the same password.

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

Feisty-Cadaver posted:

I worked with a guy a long time ago who, when he had to change his password, immediately changed it 7 times in a row or w/e so he could bypass AD’s “you can’t use the last 7 passwords” rule and keep the same password.

you can set that up to 99 last passwords if you particularly hate your users or at least guarantee they get all the way up to hunter100

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD
I think the "can only change pw once every 24 hours" is common if not default on modern AD

it's very annoying that windows doesn't have the correct error message for that one...

Feisty-Cadaver
Jun 1, 2000
The worms crawl in,
The worms crawl out.

~Coxy posted:

I think the "can only change pw once every 24 hours" is common if not default on modern AD

it's very annoying that windows doesn't have the correct error message for that one...

o k yeah if we wanna be super pedantic it was technically whatever Novell Netware used for LDAP 15 years ago not AD.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

Doom Mathematic posted:

Is it NPR where they say "Sorry, due to EU privacy laws you can't view our regular site" and then... offer you a link to the same article on their text-only site instead, which loads instantaneously and has no content on it other than the text of the article and is a hundred times better than any other current news site?

Goddamn europe does get everything better than america.

Also how do you access this stateside. Do i need a vpn

geonetix
Mar 6, 2011


https://text.npr.org

Bulgakov
Mar 8, 2009


рукописи не горят

power botton posted:

Is it insane to think that the NSA has started VPN companies to log all traffic or just have more sample data to work on deanonymizing/breaking encyption

Wiggly Wayne DDS posted:

no more than any other intel agency, really it'd be cheaper than tapping points and filtering traffic down to interesting targets if they'll pay you to do it themselves

Wiggly Wayne DDS posted:

although if you want to get in-depth on that question there's operational costs where your passive monitoring will cover those targets anyway and you won't gain more data by popping up random vpns vs just inspecting existing ones. then there's the underlying tech shared across projects and balancing putting those on external entities and connecting to them which puts additional risk on other projects that share resources

so for a large intel agency you'd hit diminishing returns, but it'd be cost-effective on small-mid especially if you're targeting them on forums with discounts and the like

:angel: yesssssss

for any vpn host which keeps podcasts alive, now that the mattress glut is slowing, I assume all the agencies have the common keys needed to intercept it all

(they don’t care about telling Netflix or Hulu or amazon that you’re naughty)

FlapYoJacks
Feb 12, 2009

Salt Fish posted:

My friends want me to play apex with them which requires an EA account. An EA account password cannot be longer than 16 characters. I found this thread:


https://answers.ea.com/t5/EA-General-Questions/Why-limit-max-password-to-16/m-p/5803599

Barry, an EA community manager, helpfully explains internet security basics:

But but but, if they are hashing and salting their passwords, then they should all be the same length in the database????

Crime on a Dime
Nov 28, 2006
just log off

fivehead
Jul 11, 2017

Americans Need Cash Now
late to the UPS chat (is high availability fixing a security fuckup?) - what are the good brands to use for yosposting? what brand has not sabotaged it’s own products with cheap components and lovely controllers

DrPossum
May 15, 2004

i am not a surgeon

Salt Fish posted:

My friends want me to play apex with them which requires an EA account. An EA account password cannot be longer than 16 characters. I found this thread:


https://answers.ea.com/t5/EA-General-Questions/Why-limit-max-password-to-16/m-p/5803599

Barry, an EA community manager, helpfully explains internet security basics:

But how many passwords are enough, Barry? I'll use maybe 1000 in my lifetime? If we have 20 trillion available passwords (enough for everyone without repetition!) we're good with 9 characters. Your overlords will be displeased with your wastefulness.

Carbon dioxide
Oct 9, 2012

https://img-9gag-fun.9cache.com/photo/aOY2OE2_460svvp9.webm

mystes
May 31, 2006

This is amazing.

apseudonym
Feb 25, 2011


I'm dying

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'


ayyyyyy

One-Man-Bucket
Jan 6, 2004
The banjo is the superior instrument
in other news; Sweden is still poo poo at this computer thing

there's this service here in sweden where you call to ask about your embarrassing medical conditions and a nurse will tell you it's ok and to stop worrying (or tell you to go to a hospital you idiot!)

turns out that some contractor subsidiary has dumped all phone calls since 2013 as audio recordings on a public web server exposed to the internet with no authentication. i like how they exposed it on port 443 but serve cleartext http. best quote is from the CEO of the main contractor "It is not so easy today that you only have one server with everything on it is a single jox (swedish for mumbo-jumbo) with a lot of parts involved", drat right everything is poo poo nowadays


google translated article:

quote:

Computer Sweden can today reveal one of the biggest accidents ever when it comes to Swedish patient safety and personal privacy. On an open web server, completely without password protection or other security, we have found 2.7 million recorded calls to the advisory number 1177. The conversations extend back to 2013 and it is about 170,000 hours of sensitive calls that anyone has been able to download or listen to.

Computer Sweden has listened to some of the conversations to form an idea of ​​the extent of the leak and the damage to the public. The conversation contains sensitive information about diseases and other ailments that the needy need to be advised on. Those who call, of course, tell about their symptoms, about the medications they are taking or about previous treatments. In many cases, they call in their personal numbers.


It is also very common for those seeking help to call about their children or other relatives. In the same way, they state the children's symptoms and state the children's social security number and ask how they should proceed with any care.

Some of the audio files have also been marked with the caller's telephone number in the file name. 57 000 Swedish telephone numbers appear in the database.

The fact that the calls are recorded is in itself permitted, it may be necessary for the patient's safety, or to be able to prove abuse, but the saved audio files should be treated with confidentiality according to the patient data law. It is also clearly the question of information that is considered as sensitive personal data according to GDPR.

When a person wants to get counseling via the 1177 Healthcare Guide by telephone, the calls are linked to either the nursing region's own employees, which takes place in most care regions, or is linked to the companies that are entrepreneurs for the healthcare regions that allow contractors to take care of the advice.

The conversation that has been open on the internet has been called to the company Medicall, which is based in Hua Hin, Thailand. Medicall is a subcontractor to the healthcare representative Medhelp who receives patient calls via the 1177 Care Guide. Medhelp, in turn, has an agreement with County Council and municipal owned Inera, which is the principal of the 1177 Care Guide. Medhelp receives all calls to 1177 from the care regions in Stockholm, Södermanland and Värmland.

It is mainly during uncomfortable times that the calls are forwarded to the subcontractor Medicall in Thailand, where Swedish healthcare personnel are working on receiving the calls. The company is registered as MediCall (Sweden) Co. Ltd. in Thailand but has Swedish owners.

- We have checked this out with our IT, and what you say is completely impossible, says Davide Nyblom CEO at Medicall.

But I have the files in front of me now?

- I've checked with our IT and it can't happen.

Do you want me to play a file?

Here Davide Nyblom hangs up the phone.

Medicall uses Biz 2.0, a cloud-based call center system that is delivered by the Swedish company Voice Integrate Nordic AB. The conversation has been saved on the Voice Integrate Nordic's storage server at the IP address http://188.92.248.19:443/medicall/. Tcp port 443 indicates that the connection is over https, but the session is not encrypted.

The storage unit is a nas on the url: nas.applion.se (Applion AB is a sister company to Voice Integrate Nordic).

No password was needed to access Medicall's directory or audio files; they have been completely open. All that is needed is a browser and knowledge of the IP address.

- This is catastrophic, it's sensitive data. We had no idea that it was like this. We will, of course, review our systems and check out what may have happened, says Tommy Ekström, CEO of Voice Integrate Nordic.

- It is not so easy today that you only have one server with everything on it is a single jox with a lot of involved, lots of different parts outside our own company. We use Applion because they have such good certificate management. But of course we have to look over all the parts and see what has happened.

- Do you mean that there is no user name and password on the server?

No, it's wide open. All that is needed is the IP address and a web browser.

- It is sad, so this should not be, says Tommy Ekström.

As a result of our review, access to the storage device is now closed, but Computer Sweden has during the review been able to access all calls, in the form of mp3 or wav files, right back to 2013, and in principle in real time for the latest calls. Once a call has been completed, the corresponding file has been found to play directly in a web browser or, if desired, for download.

Computer Sweden is looking for Inera and Medhelp for a comment.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

One-Man-Bucket posted:


google translated article:

quote:

- We have checked this out with our IT, and what you say is completely impossible, says Davide Nyblom CEO at Medicall. 

But I have the files in front of me now? 

- I've checked with our IT and it can't happen. 

Do you want me to play a file? 

Here Davide Nyblom hangs up the phone. 

That's the good stuff right there.

flakeloaf
Feb 26, 2003

Still better than android clock

that can't have happened

and if it did happen it wasn't our fault

YOU ARE HERE

and if it was our fault i didn't know

Wiggly Wayne DDS
Sep 11, 2010



oh i just checked my spam and turns out i did receive an email 21/1

quote:

SUBJECT: EMAIL_ADDR : CLAIMED_PASS

I know CLAIMED_PASS is one of your passphrases. Lets get straight to point. No-one has compensated me to check about you. You don't know me and you are most likely thinking why you're getting this mail?
yqfdyn EMAIL_ADDR CLAIMED_PASS miuecxue EMAIL_ADDR CLAIMED_PASS ytadebnm EMAIL_ADDR CLAIMED_PASS jygusegu EMAIL_ADDR CLAIMED_PASS xnnqaqyoo EMAIL_ADDR CLAIMED_PASS geyiwlra EMAIL_ADDR CLAIMED_PASS qblqvenk EMAIL_ADDR CLAIMED_PASS noloqhupo EMAIL_ADDR CLAIMED_PASS akymyxooa EMAIL_ADDR CLAIMED_PASS sedeewap EMAIL_ADDR CLAIMED_PASS
in fact, i placed a software on the 18+ video clips (pornography) web site and you know what, you visited this website to experience fun (you know what i mean). When you were viewing video clips, your browser started out functioning as a RDP having a key logger which provided me accessibility to your screen and web cam. Just after that, my software program obtained every one of your contacts from your Messenger, Facebook, as well as e-mail . after that i created a double-screen video. 1st part displays the video you were watching (you have a fine taste ; )), and second part shows the recording of your webcam, and its u.
xuaoutjh EMAIL_ADDR CLAIMED_PASS zjiyd EMAIL_ADDR CLAIMED_PASS veoehori EMAIL_ADDR CLAIMED_PASS e EMAIL_ADDR CLAIMED_PASS lbeiyaci EMAIL_ADDR CLAIMED_PASS ieblev EMAIL_ADDR CLAIMED_PASS reipqouhi EMAIL_ADDR CLAIMED_PASS munavevum EMAIL_ADDR CLAIMED_PASS jpu EMAIL_ADDR CLAIMED_PASS byotdyuju EMAIL_ADDR CLAIMED_PASS
You have got two options. Shall we take a look at the options in particulars:
eemzags EMAIL_ADDR CLAIMED_PASS o EMAIL_ADDR CLAIMED_PASS aslmkx EMAIL_ADDR CLAIMED_PASS xhuqahjuv EMAIL_ADDR CLAIMED_PASS mruc EMAIL_ADDR CLAIMED_PASS puuemcyby EMAIL_ADDR CLAIMED_PASS rprvtu EMAIL_ADDR CLAIMED_PASS ziykioil EMAIL_ADDR CLAIMED_PASS k EMAIL_ADDR CLAIMED_PASS piaijqd EMAIL_ADDR CLAIMED_PASS
First option is to neglect this email message. Then, i am going to send out your video to almost all of your personal contacts and just imagine about the awkwardness that you receive. and consequently in case you are in an intimate relationship, exactly how it is going to affect?
gaemie EMAIL_ADDR CLAIMED_PASS ybjov EMAIL_ADDR CLAIMED_PASS puqikx EMAIL_ADDR CLAIMED_PASS r EMAIL_ADDR CLAIMED_PASS neudoeui EMAIL_ADDR CLAIMED_PASS yhuktxjum EMAIL_ADDR CLAIMED_PASS oibieivsn EMAIL_ADDR CLAIMED_PASS py EMAIL_ADDR CLAIMED_PASS buotiyfux EMAIL_ADDR CLAIMED_PASS rukxoqyco EMAIL_ADDR CLAIMED_PASS
in the second place option should be to give me USD 969. We will think of it as a donation. in this scenario, i will asap discard your video. You could continue on with daily life like this never occurred and you will never hear back again from me.
me EMAIL_ADDR CLAIMED_PASS vbibeyka EMAIL_ADDR CLAIMED_PASS nyvehseme EMAIL_ADDR CLAIMED_PASS cegpzuv EMAIL_ADDR CLAIMED_PASS yofemipe EMAIL_ADDR CLAIMED_PASS zgeoikhai EMAIL_ADDR CLAIMED_PASS ub EMAIL_ADDR CLAIMED_PASS cejnikpc EMAIL_ADDR CLAIMED_PASS yinegoon EMAIL_ADDR CLAIMED_PASS uqyief EMAIL_ADDR CLAIMED_PASS
You'll make the payment by Bi?tco?in (if you do not know this, search 'how to buy b?itcoi?n' in Google search engine).
ip EMAIL_ADDR CLAIMED_PASS qoaf EMAIL_ADDR CLAIMED_PASS izyekewka EMAIL_ADDR CLAIMED_PASS aavudi EMAIL_ADDR CLAIMED_PASS kez EMAIL_ADDR CLAIMED_PASS paxhyu EMAIL_ADDR CLAIMED_PASS k EMAIL_ADDR CLAIMED_PASS mfose EMAIL_ADDR CLAIMED_PASS dh EMAIL_ADDR CLAIMED_PASS pbhoemueo EMAIL_ADDR CLAIMED_PASS
B?T?C? ad?dre?ss to send to: 18z5c6TjLUosqPTEnm6q7Q2EVNgbCy16Td
jeca EMAIL_ADDR CLAIMED_PASS uiryxei EMAIL_ADDR CLAIMED_PASS jqtycl EMAIL_ADDR CLAIMED_PASS qryraa EMAIL_ADDR CLAIMED_PASS axyirebus EMAIL_ADDR CLAIMED_PASS quwjeu EMAIL_ADDR CLAIMED_PASS bjepu EMAIL_ADDR CLAIMED_PASS d EMAIL_ADDR CLAIMED_PASS vusa EMAIL_ADDR CLAIMED_PASS uu EMAIL_ADDR CLAIMED_PASS
[case-SeNSiTiVe so copy & paste it]
zemuga EMAIL_ADDR CLAIMED_PASS chi EMAIL_ADDR CLAIMED_PASS qgysukym EMAIL_ADDR CLAIMED_PASS xumat EMAIL_ADDR CLAIMED_PASS uiuzeydor EMAIL_ADDR CLAIMED_PASS wafyjsa EMAIL_ADDR CLAIMED_PASS xe EMAIL_ADDR CLAIMED_PASS cyhmezyew EMAIL_ADDR CLAIMED_PASS c EMAIL_ADDR CLAIMED_PASS hewhopi EMAIL_ADDR CLAIMED_PASS
in case you are making plans for going to the authorities, anyway, this email can not be traced back to me. I have covered my actions. i am not attempting to demand a huge amount, i just want to be paid. pay%}. {%ROT :i have %}VNgbCy16Td if i do not get the ?bi?tco?in?, i will definately send out your video to all of your contacts including close relatives, colleagues, and many others. Nonetheless, if i do get paid, i will destroy the video right away. If you need evidence, reply Yes and i will send your video recording to your 10 friends. This is a non:negotiable offer and thus don't waste my time and yours by responding to this message.
i've subbed the first part of my email for EMAIL_ADDR, but the CLAIMED_PASS isn't anything i've ever used, ever. so uh, have fun with that dump it may have some issues

also good luck getting me to pay %}. {%ROT :i have %}VNgbCy16Td

Last Chance
Dec 31, 2004

okay

Carbon dioxide
Oct 9, 2012

They just said on the radio that the EU passed a law that says that third party companies are allowed to ask a bank account holder for permission to get access to their bank data, and in that case the bank must provide this data.

This includes all money transfers and card payment information (date, time, amount, company you paid to).

It is supposed to help out startups that offer online personal finance management apps. And they supposedly have all kinds of checks in place where companies using the bank data get regularly audited and stuff.

I can't see any way this could possibly go wrong...

geonetix
Mar 6, 2011


imagine all those bank accounts with personal details of people (recipients/senders) who did not agree to access

cinci zoo sniper
Mar 15, 2013




i have professional experience with that kind of information in eu, and the real extent of information banks provide, even comparing different banks within a single member state, differs from each other and also from what it says in the post, very often.

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




a lot of bigger banks, that have some clout, basically are like “yeah, cool, but you see, this central bank ordnance 69-420 based on the degree of Minister Foo Bar from 2017-15-16 stipulates is that the data requests are subject to the national law on third party permittance upon monetary whereabouts of permanent residents...” and so on and so on with pages of legal drivel, and most fintechs just throw their hands up and mark “bank xyz of republic baz is a gaggle of assholes” in their docs, as none of them have enough time, money, and lunacy to get into a legal fight with a foreign bank on a foreign soil

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply