Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
cinci zoo sniper
Mar 15, 2013




other cool strat, especially favoured by multinational banks, is “yeah we’ll pass this to our integration team for API access, but meanwhile we can offer you this data via our secure ftp server” rigmarole that pits you against a gigantic pile of autogenerated RTFs or some other ancient garbage format that has you abandon the affair out of sheer cost/benefit analysis

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




and internally it will be like a circus of teams in 5-6 countries doing various parts of it in no particular hurry, with all the implications about the number of final versions and such

Shaggar
Apr 26, 2006

cinci zoo sniper posted:

other cool strat, especially favoured by multinational banks, is “yeah we’ll pass this to our integration team for API access, but meanwhile we can offer you this data via our secure ftp server” rigmarole that pits you against a gigantic pile of autogenerated RTFs or some other ancient garbage format that has you abandon the affair out of sheer cost/benefit analysis

man I wish we could get quality data like that from the healthcare providers we deal with

geonetix
Mar 6, 2011


you can it's probably on an insecure samba share exposed to the internet. just portscan them

Cybernetic Vermin
Apr 18, 2005

having been on the side providing such ftps at big banks you should probably appreciate that the stuff on the ftp is actually the easiest to access form of that data that exists, to the point where half the internal systems just pull from that same server ;p

Shaggar
Apr 26, 2006

geonetix posted:

you can it's probably on an insecure samba share exposed to the internet. just portscan them

its easy to get, but its in random formats cause they manually add it to excel every week.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Carbon dioxide posted:

They just said on the radio that the EU passed a law that says that third party companies are allowed to ask a bank account holder for permission to get access to their bank data, and in that case the bank must provide this data.

This includes all money transfers and card payment information (date, time, amount, company you paid to).

It is supposed to help out startups that offer online personal finance management apps. And they supposedly have all kinds of checks in place where companies using the bank data get regularly audited and stuff.

I can't see any way this could possibly go wrong...

if they're referring to PSD2 / Open Banking it's actually a good thing, certainly much better than the old system where you have to give your accounting software your various online banking logins and security answers and they give them to some shady screen scraping company who totally aren't selling your data on the side and in doing so you waive any right to recourse if they get pwned and you lose your life savings

cinci zoo sniper
Mar 15, 2013




Shaggar posted:

man I wish we could get quality data like that from the healthcare providers we deal with

:catstare:

Cybernetic Vermin posted:

having been on the side providing such ftps at big banks you should probably appreciate that the stuff on the ftp is actually the easiest to access form of that data that exists, to the point where half the internal systems just pull from that same server ;p

:stonklol:

vanity slug
Jul 20, 2010

cant wait for the banks to offer their poo poo through an api rather than loving e-mail or sftp

Notorious b.s.d.
Jan 25, 2003

by Reene

Jeoh posted:

cant wait for the banks to offer their poo poo through an api rather than loving e-mail or sftp

don't hold your breath

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS
man bouncy castle's documentation ranges from garbage to non-existent. great way to handle the crypto library :rolleyes:

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Blinkz0rz posted:

man bouncy castle's documentation ranges from garbage to non-existent. great way to handle the crypto library :rolleyes:

java libraries don’t need documentation, that’s what method signatures are for

:w00t:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
https://twitter.com/thomasareed/status/1097152433724289024

Discuss.

Salt Fish
Sep 11, 2003

Cybernetic Crumb

Why would they want to buy Coffee Hitlers.

Agile Vector
May 21, 2007

scrum bored



Salt Fish posted:

Why would they want to buy Coffee Hitlers.

how else are you going to brew a stronger cup?

Phone
Jul 30, 2005

親子丼をほしい。

Jeoh posted:

cant wait for the banks to offer their poo poo through an api rather than loving e-mail or sftp

i look forward to working on this 15 years from now

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Agile Vector posted:

how else are you going to brew a stronger cup?

I like my coffee strong and black, not dying a coward's death in a bunker

evil_bunnY
Apr 2, 2003


That's the good stuff right there.
[/quote]
These guys are going to catch a GDPR sized brick right in the loving face and I am loving here for it.

actionjackson
Jan 12, 2003

hey is this video accurate because I can't understand all this techno-moon language

https://www.youtube.com/watch?v=O13G5A5w5P0

Wiggly Wayne DDS
Sep 11, 2010



going 1s into the video and the description that's clickbait

so enjoy them monetising that and if what they say is true they're extremely talented at finding CP so they should show themselves to the local police force

e: yeah that's an incel for starters, let's not delve further into that guy's past...

Wiggly Wayne DDS fucked around with this message at 22:37 on Feb 18, 2019

Wiggly Wayne DDS
Sep 11, 2010



now let's get away from the crazy person and not ask where they found that video

https://twitter.com/matthew_d_green/status/1097605046198517766

Wiggly Wayne DDS
Sep 11, 2010



Blinkz0rz posted:

man bouncy castle's documentation ranges from garbage to non-existent. great way to handle the crypto library :rolleyes:
okay own up were you involved

https://twitter.com/SarahJamieLewis/status/1097584389750284289

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

i know better than to roll my own c'mon

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER


actionjackson posted:

hey is this video accurate because I can't understand all this techno-moon language

https://www.youtube.com/watch?v=O13G5A5w5P0

I don’t want to test if this is accurate or not

seems plausible tho, since the YouTube algo is designed to keep you on the site and nothing keeps pedos on a site like little girls

:chloe: x 1000

actionjackson
Jan 12, 2003

Wiggly Wayne DDS posted:

now let's get away from the crazy person and not ask where they found that video

https://twitter.com/matthew_d_green/status/1097605046198517766

which video? I already knew there was all sorts of creepy "children's" videos on youtube.

Wiggly Wayne DDS
Sep 11, 2010



actionjackson posted:

which video? I already knew there was all sorts of creepy "children's" videos on youtube.
you're not making a good case for yourself here

Partycat
Oct 25, 2004

Cybernetic Vermin posted:

having been on the side providing such ftps at big banks you should probably appreciate that the stuff on the ftp is actually the easiest to access form of that data that exists, to the point where half the internal systems just pull from that same server ;p

knowing people who work on IT at banks , when having a conversation in 2016 it took me a long time to realize FTP was literally “File Transfer Protocol” and not “Financial Transaction Processing”

actionjackson
Jan 12, 2003

Wiggly Wayne DDS posted:

you're not making a good case for yourself here

I'm Chris Hansen

why don't you have a seat Wiggly Wayne (if that is your real name)

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
please enjoy this security fuckup

https://i.imgur.com/j9TbCF7.mp4

fisting by many
Dec 25, 2009



bug: authentication bypass

notes: couldn't reproduce, possibly only works if user is already trusted

akadajet
Sep 14, 2003

actionjackson posted:

hey is this video accurate because I can't understand all this techno-moon language


Man, Pete Townshend is seriously online these days.

Edit: yeah, that's terrible. don't watch it

akadajet fucked around with this message at 01:17 on Feb 19, 2019

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

fisting by many posted:

bug: authentication bypass

notes: couldn't reproduce, possibly only works if daemon is hungry

actionjackson
Jan 12, 2003

akadajet posted:

Man, Pete Townshend is seriously online these days.

Edit: yeah, that's terrible. don't watch it

I mean it's true youtube in Nov. 2017 said they would disable comments on videos that their algorithm determined were sexually exploitive towards children

and yet here they are

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
nobody should be on youtube.

spankmeister
Jun 15, 2008






Ulf posted:

please enjoy this security fuckup

https://i.imgur.com/j9TbCF7.mp4

Clever girl

Wiggly Wayne DDS
Sep 11, 2010



what a strange collection of domains to whitelist flash on edge by default

https://bugs.chromium.org/p/project-zero/issues/detail?id=1722

Shame Boy
Mar 2, 2010

Wiggly Wayne DDS posted:

what a strange collection of domains to whitelist flash on edge by default

https://bugs.chromium.org/p/project-zero/issues/detail?id=1722

im dilidili dot wang

Midjack
Dec 24, 2007



from the corporate america thread:

Ashcans posted:

Also this morning, I come to you with a tale of IT security. We use a secure file service, where people can upload documents to you and you get an email notification, log in and access them, I assume this is a pretty typical tool. When we started using this, you could allocate permissions so that someone else in the system could look at your received files. Which is ideal for when you have some old senior staff who are not prepared to handle document security, they just forward the notification to their staff and someone can log in and access the documents.

Well, a little while ago the secure file service stripped out this feature because, I dunno, I guess maybe sharing access was not considered best practice? Or more accurately, they made it so that in order to access anyone else's files, you have to be an administrator. So we were faced with two options; give all these staff admin privileges, or force senior staff to learn to use the service and spend time accessing/sharing documents. Yea, no. So the office settles on a third option; put our senior staff login information and passwords in a word file on the server, so when they forward something you can login as them and get what you need. But that's clearly not great either, so.... they password-lock the word file. But now how do people get the password for the word file with the passwords they need to get the files?

It is written on a notepad, which is kept under someone's file tray on their desk.

This is definitely a better system.

The Fool
Oct 16, 2003


quote:

- The whitelist was trimmed down to just 2 entries:

5e50a8b6afbcc3d33e38f30ba7a29542261e1191631481adbb7ef36bc63dc768:1:https://www.facebook.com
f363c150f2c13e39b50ff011438b4ba54ce67a433dd0f2cce9caa33dd3e3e0e4:1:https://apps.facebook.com

Adbot
ADBOT LOVES YOU

the yeti
Mar 29, 2008

memento disco



privacy.com seems like a secfuck waiting to happen no matter how much I like the idea of insulating my actual credit/debit channels from random lovely vendors.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply