Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Proteus Jones
Feb 28, 2013



fishmech posted:

what the gently caress are you smoking to not understand what i said? why do you keep talking about entirely unrelated things?



Jesus gently caress, take your slap-fight to DMs. You're going to get yet another thread shut down.

Adbot
ADBOT LOVES YOU

Wiggly Wayne DDS
Sep 11, 2010



Proteus Jones posted:

Jesus gently caress, take your slap-fight to DMs. You're going to get yet another thread shut down.
or they argue endlessly here and everyone else makes their escape to a different thread

Luigi Thirty
Apr 30, 2006

Emergency confection port.

cum fishmeche non argue

Fuzzy Mammal
Aug 15, 2001

Lipstick Apathy

Wiggly Wayne DDS posted:

or they argue endlessly here and everyone else makes their escape to a different thread

well now that you posted....

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
https://twitter.com/j_opdenakker/status/1099779107829829632

DrPossum
May 15, 2004

i am not a surgeon

fishmech posted:

what the gently caress are you smoking to not understand what i said? why do you keep talking about entirely unrelated things?

Yeah! Get back to spelling discussion in the secfuck thread!

Shame Boy
Mar 2, 2010


i highly recommend everyone go to their website https://centerzero.org/ and watch the video, it's great :allears:

Shame Boy
Mar 2, 2010




Shame Boy
Mar 2, 2010

pretty much their selling point is "instead of a master password, you select a sequence of pictures, and pictures are unhackable!" :downs:

graph
Nov 22, 2006

aaag peanuts

Shame Boy posted:

blargh agrhg blarghl

same

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

so who wrote this crap? their website is all sorts of vague. i am not even sure where to start with an llc search since every state handles it--assuming they even exist

the fact that they are centerzero.org and not .com or whatever is even more weird

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Notorious b.s.d. posted:

perfectly clear, with highly regular spelling, over 99% of which is still valid today

are you illiterate?
https://twitter.com/bethwalkr/status/1099117191922962434

you're just wrong

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

drop this conversation; it's not even security-related jfc

Fuzzy Mammal
Aug 15, 2001

Lipstick Apathy
so usenix dumped a whole whack of videos on their youtube from the latest conference. anyone go or have any recs for good ones to watch?

Wiggly Wayne DDS
Sep 11, 2010



no

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

lol one of our CMS boxes was publishing its private key openly on some no-auth uri and it looks like this was somehow intentional thanks Oracle

fisting by many
Dec 25, 2009




i'm tOAD

abigserve
Sep 13, 2009

this is a better avatar than what I had before

Shame Boy posted:

pretty much their selling point is "instead of a master password, you select a sequence of pictures, and pictures are unhackable!" :downs:

The good thing about it being pictures is you don't have to hash the passwords because they aren't passwords they are pictures ya bozo

for your cyberhealth

redleader
Aug 18, 2005

Engage according to operational parameters
just serve up 128 choices between two images and have someone remember which ones they picked. ez

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

how do you make an uppercase dog?

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

BangersInMyKnickers posted:

how do you make an uppercase dog?

Achmed Jones
Oct 16, 2004



BangersInMyKnickers posted:

how do you make an uppercase dog?

it’s a wolf op

DrPossum
May 15, 2004

i am not a surgeon

BangersInMyKnickers posted:

how do you make an uppercase dog?

what's uppercase dog?

Proteus Jones
Feb 28, 2013



DrPossum posted:

what's uppercase dog?

Not much. What's uppercase with you?

Shame Boy
Mar 2, 2010

i was just showing the site to my wife cuz she loves laughing at this dumb poo poo too and we checked the terms and conditions to find some gems:

first sentence, on its own line

quote:

Center Zero is not responsible for any misuse or neglect by the user

:thunk:

you're expressly forbidden from translating the app into another language, and we reserve all our "database rights"

quote:

You’re not allowed to copy, or modify the app, any part of the app, or our trademarks in any way. You’re not allowed to attempt to extract the source code of the app, and you also shouldn’t try to translate the app into other languages, or make derivative versions. The app itself, and all the trade marks, copyright, database rights and other intellectual property rights related to it, still belong to Center Zero.


did we say guaranteed in that video? we meant not guaranteed at all:

quote:

With respect to Center Zero’s responsibility for your use of the app, when you’re using the app, it’s important to bear in mind that although we endeavor to ensure that it is updated and correct at all times, Center Zero accepts no liability for any loss, direct or indirect, you experience as a result of relying wholly on this functionality of the app.

i also noticed if you look closely at the images in the demo screenshot you can see an ad for 1Password and some other password manager i can't quite make out, a screenshot of the homepage of imgur as of a few weeks ago, and pictures of what appear to be the vending machine in their office:

Phone
Jul 30, 2005

親子丼をほしい。
someone likes EF civics

mike12345
Jul 14, 2008

"Whether the Earth was created in 7 days, or 7 actual eras, I'm not sure we'll ever be able to answer that. It's one of the great mysteries."





https://twitter.com/Anotherfilmnerd/status/1100258243736203265

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
one thousand two hundred and thirty four people is a pretty nice total for a movie monster

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


everyone knows the best monsters are where the threat is implied rather than explicit which is why mine is the best with 0000 kills

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

Jabor posted:

one thousand two hundred and thirty four people is a pretty nice total for a movie monster

great now i have to change the code on my luggage

fritz
Jul 26, 2003

BangersInMyKnickers posted:

how do you make an uppercase dog?

an uppercase dog is when they stand on their hind legs to see what's on top of the table (and steal same)

CmdrRiker
Apr 8, 2016

You dismally untalented little creep!

What the gently caress happened itt? I laughed, I loved, and I learned.

Wiggly Wayne DDS
Sep 11, 2010



Fuzzy Mammal posted:

so usenix dumped a whole whack of videos on their youtube from the latest conference. anyone go or have any recs for good ones to watch?
okay this upcoming talk will be good
https://twitter.com/ic0nz1/status/1100413895141773312
https://github.com/RUB-NDS/TLS-Padding-Oracles

quote:

TLS Padding Oracles
The TLS protocol provides encryption, data integrity, and authentication on the modern Internet. Despite the protocol’s importance, currently-deployed TLS versions use obsolete cryptographic algorithms which have been broken using various attacks. One prominent class of such attacks is CBC padding oracle attacks. These attacks allow an adversary to decrypt TLS traffic by observing different server behaviors which depend on the validity of CBC padding.

We evaluated the Alexa Top Million Websites for CBC padding oracle vulnerabilities in TLS implementations and revealed vulnerabilities in 1.83% of them, detecting nearly 100 different vulnerabilities. These padding oracles stem from subtle differences in server behavior, such as responding with different TLS alerts, or with different TCP header flags. We suspect the subtlety of different server responses is the reason these padding oracles were not detected previously.

Full Technical Paper
Robert Merget, Juraj Somorovsky, Nimrod Aviram, Craig Young, Janis Fliegenschmidt, Jörg Schwenk, Yuval Shavitt: Scalable Scanning and Automatic Classification of TLS Padding Oracle Vulnerabilities. USENIX Security 2019

The full paper will be presented at USENIX Security in August 2019.

FlapYoJacks
Feb 12, 2009
UGGGGGHHHHH Amazon and it’s third party security auditing service.

Them: “This device must have full disk encryption.”

Us: “It’s in a locked box, no root user, a signed bootloader, custom SELinux contexts, and a TPM for update keys, we don’t have the man power to ssh into every device and unlock the disk in the event of a power outage.”

Them: “No, this won’t pass without full disk encryption.”

Us: “What if we auto-unlock the device on boot up?”

Them: “That will work.”

Thanks checkbox checking guy for the security theater!

Last Chance
Dec 31, 2004

ratbert90 posted:

UGGGGGHHHHH Amazon and it’s third party security auditing service.

Them: “This device must have full disk encryption.”

Us: “It’s in a locked box, no root user, a signed bootloader, custom SELinux contexts, and a TPM for update keys, we don’t have the man power to ssh into every device and unlock the disk in the event of a power outage.”

Them: “No, this won’t pass without full disk encryption.”

Us: “What if we auto-unlock the device on boot up?”

Them: “That will work.”

Thanks checkbox checking guy for the security theater!

good for them. disk encryption is important whether you think it is or not

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
yeah disk encryption helps you in the case that someone smuggles a drive out or you don't properly destroy a disk when you toss it.

there's zero reason to not use it.

ozymandOS
Jun 9, 2004
otoh, if the box can unlock its own encryption on boot, so can an attacker

GWBBQ
Jan 2, 2005


lol

The Fool
Oct 16, 2003


ozymandOS posted:

otoh, if the box can unlock its own encryption on boot, so can an attacker

there are plenty of scenarios where the drive could be exposed but not the rest of the computer

the improper disposal example above doesn't even require a malicious actor

Adbot
ADBOT LOVES YOU

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

ozymandOS posted:

otoh, if the box can unlock its own encryption on boot, so can an attacker

that's what tpm is for, surely?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply