Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
The Fool
Oct 16, 2003


can't be worse than paypal

Adbot
ADBOT LOVES YOU

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

fivehead posted:

late to the UPS chat (is high availability fixing a security fuckup?) - what are the good brands to use for yosposting? what brand has not sabotaged it’s own products with cheap components and lovely controllers

I got a refurb APC thinger to run my router and water heater damper/ignition and it seems very knees-suiting

Carbon dioxide
Oct 9, 2012

Several password managers leave traces of their master password or individually accessed passwords in the Windows 10 memory, sometimes even after they've been locked. Someone with access to the computer could potentially extract those passwords from memory.

https://www.securityevaluators.com/casestudies/password-manager-hacking/



Dashlane and Keepass seem to be doing relatively well on this test.

Note: this is a rather esoteric way of attack and is not at all a reason to not use password managers. If someone installs a keylogger to your computer they can get access whether you have a password manager or not.

Carbon dioxide fucked around with this message at 23:39 on Feb 19, 2019

mystes
May 31, 2006

Carbon dioxide posted:

Several password managers leave traces of their master password or individually accessed passwords in the Windows 10 memory, sometimes even after they've been locked. Someone with access to the computer could potentially extract those passwords from memory.

https://www.securityevaluators.com/casestudies/password-manager-hacking/



Dashlane and Keepass seem to be doing relatively well on this test.

Note: this is a rather esoteric way of attack and is not at all a reason to not use password managers. If someone installs a keylogger to your computer they can get access whether you have a password manager or not.
Basically the only situation where it would matter would be having a laptop stolen while it's suspended.

Raere
Dec 13, 2007



Ok cool an extra 8 bits

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

mystes posted:

Basically the only situation where it would matter would be having a laptop stolen while it's suspended.

how would it being suspended (s3) help?

(cf. hibernation (s4) which would dump ram to disk)

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Carbon dioxide posted:

Several password managers leave traces of their master password or individually accessed passwords in the Windows 10 memory, sometimes even after they've been locked. Someone with access to the computer could potentially extract those passwords from memory.

https://www.securityevaluators.com/casestudies/password-manager-hacking/



Dashlane and Keepass seem to be doing relatively well on this test.

Note: this is a rather esoteric way of attack and is not at all a reason to not use password managers. If someone installs a keylogger to your computer they can get access whether you have a password manager or not.

physical access trumps everything

Schadenboner
Aug 15, 2011

by Shine
:laffo: if you let your laptop "sleep" or "hibernate". Pull the battery, hold down the power button to discharge the capacitors, turn 360 degrees and walk the gently caress away.

Not for any security reason, mind you. Just because: gently caress you laptops! If "on" and "off" is good enough for every other computer you don't get special power states just because you're skinny.

The Fool
Oct 16, 2003


Schadenboner posted:

turn 360 degrees and walk the gently caress away.

apseudonym
Feb 25, 2011

Carbon dioxide posted:

Several password managers leave traces of their master password or individually accessed passwords in the Windows 10 memory, sometimes even after they've been locked. Someone with access to the computer could potentially extract those passwords from memory.

https://www.securityevaluators.com/casestudies/password-manager-hacking/



Dashlane and Keepass seem to be doing relatively well on this test.

Note: this is a rather esoteric way of attack and is not at all a reason to not use password managers. If someone installs a keylogger to your computer they can get access whether you have a password manager or not.

Pearl clutching over things being in ram is dumb and misguided.

Schadenboner
Aug 15, 2011

by Shine

:laffo: if you're not just constantly moonwalking everywhere. Like, how can you expect people to take you seriously if you can't even manage that?

mystes
May 31, 2006

Rufus Ping posted:

how would it being suspended (s3) help?

(cf. hibernation (s4) which would dump ram to disk)
There is really no consistency in the terminology for the names of the acpi states, and in general "suspending" doesn't refer specifically to s3. I think the ACPI spec actually refers to both S3 and S4 as "sleep" states but it is also very common to refer to s3 as "suspend to ram" and s4 as "suspend to disk".

Also, on many laptops when you tell windows to sleep it is configured to use hybrid sleep which also writes the memory to disk in case the battery dies, but even assuming that isn't the case and assuming the computer locked itself before it went into S3 there are still lots of ways to get the memory out of the computer when you wake it up: dumping the memory through a thunderbolt device, cold boot attacks, etc.

This obviously assumes that whoever steals your laptop is specifically targeting your information, but if they aren't they aren't going to bother trying to extract your key from the hard drive if the laptop is put into S4 either.

mystes fucked around with this message at 02:33 on Feb 20, 2019

Shaggar
Apr 26, 2006

Carbon dioxide posted:

Several password managers leave traces of their master password or individually accessed passwords in the Windows 10 memory, sometimes even after they've been locked. Someone with access to the computer could potentially extract those passwords from memory.

https://www.securityevaluators.com/casestudies/password-manager-hacking/



Dashlane and Keepass seem to be doing relatively well on this test.

Note: this is a rather esoteric way of attack and is not at all a reason to not use password managers. If someone installs a keylogger to your computer they can get access whether you have a password manager or not.

now lets see excel

cinci zoo sniper
Mar 15, 2013




Shaggar posted:

now lets see excel

speaking or, i recently had the realisation that im most likely one of the two people in office who don’t use an excel spreadsheet to track all their passwords for various poo poo

spankmeister
Jun 15, 2008






apseudonym posted:

Pearl clutching over things being in ram is dumb and misguided.

Yeah this is one of those "you can get code exec if you have code exec" things.

I mean, it's bad that some of them leave plaintext in memory after the database is locked but really now.

Just install a keylogger.

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

cinci zoo sniper posted:

speaking or, i recently had the realisation that im most likely one of the two people in office who don’t use an excel spreadsheet to track all their passwords for various poo poo

do you need us to teach you excel

spankmeister
Jun 15, 2008






I use keep rear end op

cinci zoo sniper
Mar 15, 2013




Sniep posted:

do you need us to teach you excel

no, im not a savage and thus

spankmeister posted:

I use keep rear end op

,for work

DrPossum
May 15, 2004

i am not a surgeon
keep asses represent

NoneMoreNegative
Jul 20, 2000
GOTH FASCISTIC
PAIN
MASTER




shit wizard dad

DrPossum posted:

keep asses represent

they toss it and leave it
and I pull up quick to retrieve it

Pile Of Garbage
May 28, 2007



i'm the one dingus still using password safe how does it rate?

cinci zoo sniper
Mar 15, 2013




Pile Of Garbage posted:

i'm the one dingus still using password safe how does it rate?

nice post/username combo

cinci zoo sniper
Mar 15, 2013




no idea about password safe, just to be clear

flakeloaf
Feb 26, 2003

Still better than android clock

if you want to take an apple's password from scratch ram, you must first create the universal system-level process

Vanadium
Jan 8, 2005

I feel conflicted about using 1password because the linux app is a browser extension. I don't really know anything about the browser extension security model but it doesn't make me extremely confident that cloud2butt isn't going to run off with all my passwords at some point. Am I being stupid here?

Andohz
Aug 15, 2004

World's Strongest Smelly Hobo

One-Man-Bucket posted:

in other news; Sweden is still poo poo at this computer thing

there's this service here in sweden where you call to ask about your embarrassing medical conditions and a nurse will tell you it's ok and to stop worrying (or tell you to go to a hospital you idiot!)

turns out that some contractor subsidiary has dumped all phone calls since 2013 as audio recordings on a public web server exposed to the internet with no authentication. i like how they exposed it on port 443 but serve cleartext http. best quote is from the CEO of the main contractor "It is not so easy today that you only have one server with everything on it is a single jox (swedish for mumbo-jumbo) with a lot of parts involved", drat right everything is poo poo nowadays


google translated article:

The CEO and others keep answering questions from the press for some reason, even though it's obvious they don't know what they're talking about : https://medium.com/@rikardhjort/2-7...7j4K9fo4l4JulhI

CEO of Company posted:

A regular person can’t do it, but those who are knowledgeable about these things could perform some sort of special command move [sic] and sneak in through the back.

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
love to perform a special command move and shoryuken my way into a complete stranger's medical records

Achmed Jones
Oct 16, 2004



“ceo” posted:

special command move

mods, please

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
*opens browser, types an address*

:cool: I'm in.

haveblue
Aug 15, 2005



Toilet Rascal

Meat Beat Agent posted:

love to perform a special command move and shoryuken my way into a complete stranger's medical records

are you the hacker in my mandated online security training who tries to hack our network by powering up to super saiyijin and throwing fireballs at the server

bob dobbs is dead
Oct 8, 2017

I love peeps
Nap Ghost
On that subject, the cto is talking up putting all the passwords in a big google spreadsheet cuz google is better at security than all the password manager guys

(They probably are but lol at the spreadsheet)

What do, security thread

Shame Boy
Mar 2, 2010

bob dobbs is dead posted:

On that subject, the cto is talking up putting all the passwords in a big google spreadsheet cuz google is better at security than all the password manager guys

(They probably are but lol at the spreadsheet)

What do, security thread

maybe say that keeping the passwords with a company whose business is specifically indexing, repackaging and selling data about its users isn't a great idea?

Shame Boy
Mar 2, 2010

or ask why chrome has a password manager built in if google expects you to use spreadsheets for this?

Shame Boy
Mar 2, 2010

or register your complaint on the blockchain and start looking for a new job?

fisting by many
Dec 25, 2009



bob dobbs is dead posted:

On that subject, the cto is talking up putting all the passwords in a big google spreadsheet cuz google is better at security than all the password manager guys

(They probably are but lol at the spreadsheet)

What do, security thread

actually show him a password manager

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

fisting by many posted:

actually show him a password manager

"This is going to be too complicated for me us"

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/KateLibc/status/1098258502714183680

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Raere posted:



Ok cool an extra 8 bits

I mean, they could be doing it with some goofy asymm ecc cipher but I doubt it

Shame Boy
Mar 2, 2010

is it normal for CTO's to be morons, because ours thinks SHA-256 is the "most secure encryption" and we should use it to hash passwords because "it's what bitcoin uses"

i mean at least he actually listened to me when i told him very nicely what an idiot he was and now we use bcrypt if we have to handle passwords at all

Adbot
ADBOT LOVES YOU

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

apseudonym posted:

Pearl clutching over things being in ram is dumb and misguided.

ram is writing to disk during standby on most systems now but any password manager worth a poo poo should be locking on S3/S4 and purging key material from memory

BangersInMyKnickers fucked around with this message at 17:56 on Feb 20, 2019

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply