Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Sickening posted:

I don’t see the benefit to be this emotionally invested.

Facebook intentionally works to be part of people’s emotional landscape, so it’s not uncommon whether it’s valuable or not.

Adbot
ADBOT LOVES YOU

apseudonym
Feb 25, 2011

Subjunctive posted:

I think Facebook has enough documented bullshit by this point to be condemned pretty soundly on several fronts. (Boris seems to not want to raise any of those, though, which is an odd strategy.) I wanted (want) to know if clipboard upload has changed to be one of those cases, and I know apseudonym can cut through folklore to evidence (if I’m interpreting his post correctly in the first place), that’s all. I still periodically have chastising conversations with FB C-suite and VPs about their bullshit. I know they are hosed up. I just want to know if they hosed this specific thing up, because I have a direct historical relationship to it.
I don't know if FB uploads the URLs without interaction, I was being somewhat hyperbolic trying to emphasize that clipboard listeners make clipboard based password managers insane.

CLAM DOWN
Feb 13, 2007




If you want to talk infosec or make any remote claim that you work in this field, loving post proof/evidence for your wild rear end claims or shut the gently caress up. This field doesn't operate on your hyperbolic assumptions and biases.

apseudonym
Feb 25, 2011

CLAM DOWN posted:

If you want to talk infosec or make any remote claim that you work in this field, loving post proof/evidence for your wild rear end claims or shut the gently caress up. This field doesn't operate on your hyperbolic assumptions and biases.
:jerkbag:

It's 'cool' if you really want to defend implementations that send your password to any application on the device that wants to listen for it, but you continue to miss the point.

CLAM DOWN
Feb 13, 2007




apseudonym posted:

:jerkbag:

It's 'cool' if you really want to defend implementations that send your password to any application on the device that wants to listen for it, but you continue to miss the point.

Can you show me where I stated a stance on either side of this topic? "Present evidence for your claims" isn't defending anything wtf

apseudonym
Feb 25, 2011

CLAM DOWN posted:

Can you show me where I stated a stance on either side of this topic? "Present evidence for your claims" isn't defending anything wtf

You seemed to take a pretty hostile stance to my rant that using the clipboard for a password manager is straight up insane, which I assumed was a defense of that implementation -- because I've had this argument elsewhere recently

If it was a hostile stance at my poo poo posting then :shrug: let's move along to the next thing.

Wiggly Wayne DDS
Sep 11, 2010



ya all of your recent posts are getting overly defensive at clipboards and the autofill api

not as defensive as boris though

apseudonym
Feb 25, 2011

Wiggly Wayne DDS posted:

ya all of your recent posts are getting overly defensive at clipboards and the autofill api

not as defensive as boris though

It makes me angry that a password manager would do that not gonna lie.

CLAM DOWN
Feb 13, 2007




apseudonym posted:

You seemed to take a pretty hostile stance to my rant that using the clipboard for a password manager is straight up insane, which I assumed was a defense of that implementation -- because I've had this argument elsewhere recently

If it was a hostile stance at my poo poo posting then :shrug: let's move along to the next thing.

I'm not defending poo poo. I'm hostile to your worthless shitposting, correct.

apseudonym
Feb 25, 2011

CLAM DOWN posted:

I'm not defending poo poo. I'm hostile to your worthless shitposting, correct.

Then in non rant form:

There is no valid reason, except :effort:, to use the clipboard for a password manager on Android, there are multiple alternative approaches that span all versions, and to do so is reckless way to handle user passwords.


Happy?

CLAM DOWN
Feb 13, 2007




apseudonym posted:

Then in non rant form:

There is no valid reason, except :effort:, to use the clipboard for a password manager on Android, there are multiple alternative approaches that span all versions, and to do so is reckless way to handle user passwords.


Happy?

And that's exactly why I mentioned that autofill that they introduced I think in Oreo addresses the clipboard weakness? And I think iOS has an autofill thing too? What even is your point?

apseudonym
Feb 25, 2011

CLAM DOWN posted:

And that's exactly why I mentioned that autofill that they introduced I think in Oreo addresses the clipboard weakness? And I think iOS has an autofill thing too? What even is your point?

The point is "there is no reason to use the clipboard for this on any version of Android".

Autofill in O is the right way to do this, but the standard response to sending people there is "but that's not on enough devices yet", which is a fair point for an app developer to make. Even with that though on older devices they should be using things like a custom ime or accessibility services (you see good password managers implementing these or similar), not the clipboard

On O+ Autofill is great (and someday I'll effort post in yospos how it works) and is designed with properly handling passwords inside the Android security model in mind, so yes that's the thing they should obviously use if they can. I was specifically ranting about clipboard being dumb even if you didn't have that.

apseudonym fucked around with this message at 18:33 on Feb 23, 2019

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

CLAM DOWN posted:

This field doesn't operate on your hyperbolic assumptions and biases.

Lmao that's crazy of course it does.

apseudonym
Feb 25, 2011

Blinkz0rz posted:

Lmao that's crazy of course it does.

Given how much I rant about how lovely the security industry is for the straight up off the mark crazy (e.g. the current poorly written freakout about analytics going around) it's a fair enough call-out.

evil_bunnY
Apr 2, 2003

Subjunctive posted:

I’m asking because a) I know it wasn’t transmitted when that was first added, and b) because I want to yell at people there if it is now. (Similarly with Chrome, whose parent also had a network-interposing research app using enterprise certificates app until FB got in trouble. I have better people to yell at for FB though.)
Did you yell at your FB peeps about the vpn app?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

evil_bunnY posted:

Did you yell at your FB peeps about the vpn app?

I yelled about Onavo when I was there and killed a crazy plan to bundle it with the main app on Android, and several times since I’ve left. Most people I know there think that team are dangerous and not very bright (their HTTP proxy engine — the whole point of the thing really — was historically very fragile and repeatedly kept us from rolling out networking improvements in the apps). And yet they keep getting to do stuff. :thunk:

E: FWIW the internal threads about the cert being revoked were 95% “well we loving deserve it” and 4% “but google has one too!”, I’m told.

Subjunctive fucked around with this message at 19:43 on Feb 23, 2019

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

apseudonym posted:

I don't know if FB uploads the URLs without interaction, I was being somewhat hyperbolic trying to emphasize that clipboard listeners make clipboard based password managers insane.

You gotta tell me when to not take you literally, friend. Maybe we can agree on an emoji signal.

I’m gonna try to get a friend to take over the source watch I had on clipboard calls anyway, though. :tinfoil:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

CLAM DOWN posted:

If you want to talk infosec or make any remote claim that you work in this field, loving post proof/evidence for your wild rear end claims or shut the gently caress up. This field doesn't operate on your hyperbolic assumptions and biases.

What does proof of working in the field entail?

(Historically some pieces of the field actually have bent to my biases, probably mostly to our mutual detriment. I wouldn’t be surprised if the same were true of apseudonym, minus the detriment.)

apseudonym
Feb 25, 2011

Subjunctive posted:

You gotta tell me when to not take you literally, friend. Maybe we can agree on an emoji signal.

I’m gonna try to get a friend to take over the source watch I had on clipboard calls anyway, though. :tinfoil:

Sorry about that, off my shitposting game, how about :v:?

Subjunctive posted:

What does proof of working in the field entail?

(Historically some pieces of the field actually have bent to my biases, probably mostly to our mutual detriment. I wouldn’t be surprised if the same were true of apseudonym, minus the detriment.)

:shrug:, TLS usage is way up, insecure TLS usage is way way down, work stress levels more or less unchanged.


As for the VPN thing, the pure research version is a lot less interesting to me than what it used to be which IMO didn't make it clear to users they were being spied on. I at least now have good ammunition against the endless claim that VPNs are the solution.

apseudonym fucked around with this message at 19:59 on Feb 23, 2019

CLAM DOWN
Feb 13, 2007




Blinkz0rz posted:

Lmao that's crazy of course it does.

You're right, I should have used the word "shouldn't".

evil_bunnY
Apr 2, 2003

Subjunctive posted:

killed a crazy plan to bundle it with the main app on Android
jesus loving christ

AlternateAccount
Apr 25, 2005
FYGM
OK, so if you had to speculate, what does the following represent?

code:
05wqxDzZzGzKnqHm03uUxVSa+NuUHSFWzBxl9TftEiq239mFSsRO5wumvSQBSbtUZTTMukWUiaMdCIatnL6bOuHW71pQAmOuO/a
En9WijrzP1Em4y7mgnrTJiP7mZXipiLsdKxZtlNnXd6v2M2DLiqxlKheaA0UOhPIhDaqpufELmhd6asAIhGSANC5ukxSE2cyQND
ftV/TIuPTBZ6FFCIGMZrQFSa2tmN2hGFioFVLb+MFl0UAmcIxnxunXSTXWXH6UAsDp3AxFGbdHQGtPwzVKlsLniG/XA+msbXp+O
ZVK4fouD1WatLcBfo+iHLqjvaPazpUMe5UFW1RcGYxooE5Dq1lpJGfOxYoAA+RDJktW9aTIQXiCrv34onqSt/DmkWRfwbF6guoF
9ijYrJQCNP9IwydUeZdJFAUuGr6Zu9zx5HCabuZyNsr8Tq7oWSOvmCZcFxupFLf5pYvLrPuman1w==

lament.cfg
Dec 28, 2006

we have such posts
to show you




Bitcoin wallet

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

AlternateAccount posted:

OK, so if you had to speculate, what does the following represent?

code:
05wqxDzZzGzKnqHm03uUxVSa+NuUHSFWzBxl9TftEiq239mFSsRO5wumvSQBSbtUZTTMukWUiaMdCIatnL6bOuHW71pQAmOuO/a
En9WijrzP1Em4y7mgnrTJiP7mZXipiLsdKxZtlNnXd6v2M2DLiqxlKheaA0UOhPIhDaqpufELmhd6asAIhGSANC5ukxSE2cyQND
ftV/TIuPTBZ6FFCIGMZrQFSa2tmN2hGFioFVLb+MFl0UAmcIxnxunXSTXWXH6UAsDp3AxFGbdHQGtPwzVKlsLniG/XA+msbXp+O
ZVK4fouD1WatLcBfo+iHLqjvaPazpUMe5UFW1RcGYxooE5Dq1lpJGfOxYoAA+RDJktW9aTIQXiCrv34onqSt/DmkWRfwbF6guoF
9ijYrJQCNP9IwydUeZdJFAUuGr6Zu9zx5HCabuZyNsr8Tq7oWSOvmCZcFxupFLf5pYvLrPuman1w==

How'd you get my wifi password?

CLAM DOWN
Feb 13, 2007




AlternateAccount posted:

OK, so if you had to speculate, what does the following represent?

code:
05wqxDzZzGzKnqHm03uUxVSa+NuUHSFWzBxl9TftEiq239mFSsRO5wumvSQBSbtUZTTMukWUiaMdCIatnL6bOuHW71pQAmOuO/a
En9WijrzP1Em4y7mgnrTJiP7mZXipiLsdKxZtlNnXd6v2M2DLiqxlKheaA0UOhPIhDaqpufELmhd6asAIhGSANC5ukxSE2cyQND
ftV/TIuPTBZ6FFCIGMZrQFSa2tmN2hGFioFVLb+MFl0UAmcIxnxunXSTXWXH6UAsDp3AxFGbdHQGtPwzVKlsLniG/XA+msbXp+O
ZVK4fouD1WatLcBfo+iHLqjvaPazpUMe5UFW1RcGYxooE5Dq1lpJGfOxYoAA+RDJktW9aTIQXiCrv34onqSt/DmkWRfwbF6guoF
9ijYrJQCNP9IwydUeZdJFAUuGr6Zu9zx5HCabuZyNsr8Tq7oWSOvmCZcFxupFLf5pYvLrPuman1w==

That's my SA password?!

vanity slug
Jul 20, 2010

AlternateAccount posted:

OK, so if you had to speculate, what does the following represent?

code:
05wqxDzZzGzKnqHm03uUxVSa+NuUHSFWzBxl9TftEiq239mFSsRO5wumvSQBSbtUZTTMukWUiaMdCIatnL6bOuHW71pQAmOuO/a
En9WijrzP1Em4y7mgnrTJiP7mZXipiLsdKxZtlNnXd6v2M2DLiqxlKheaA0UOhPIhDaqpufELmhd6asAIhGSANC5ukxSE2cyQND
ftV/TIuPTBZ6FFCIGMZrQFSa2tmN2hGFioFVLb+MFl0UAmcIxnxunXSTXWXH6UAsDp3AxFGbdHQGtPwzVKlsLniG/XA+msbXp+O
ZVK4fouD1WatLcBfo+iHLqjvaPazpUMe5UFW1RcGYxooE5Dq1lpJGfOxYoAA+RDJktW9aTIQXiCrv34onqSt/DmkWRfwbF6guoF
9ijYrJQCNP9IwydUeZdJFAUuGr6Zu9zx5HCabuZyNsr8Tq7oWSOvmCZcFxupFLf5pYvLrPuman1w==

Don't doxx me

(base64 encoded string?)

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

AlternateAccount posted:

OK, so if you had to speculate, what does the following represent?

code:
05wqxDzZzGzKnqHm03uUxVSa+NuUHSFWzBxl9TftEiq239mFSsRO5wumvSQBSbtUZTTMukWUiaMdCIatnL6bOuHW71pQAmOuO/a
En9WijrzP1Em4y7mgnrTJiP7mZXipiLsdKxZtlNnXd6v2M2DLiqxlKheaA0UOhPIhDaqpufELmhd6asAIhGSANC5ukxSE2cyQND
ftV/TIuPTBZ6FFCIGMZrQFSa2tmN2hGFioFVLb+MFl0UAmcIxnxunXSTXWXH6UAsDp3AxFGbdHQGtPwzVKlsLniG/XA+msbXp+O
ZVK4fouD1WatLcBfo+iHLqjvaPazpUMe5UFW1RcGYxooE5Dq1lpJGfOxYoAA+RDJktW9aTIQXiCrv34onqSt/DmkWRfwbF6guoF
9ijYrJQCNP9IwydUeZdJFAUuGr6Zu9zx5HCabuZyNsr8Tq7oWSOvmCZcFxupFLf5pYvLrPuman1w==

A miserable pile of secrets

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


It's a public key block, right?

Jedi425
Dec 6, 2002

THOU ART THEE ART THOU STICK YOUR HAND IN THE TV DO IT DO IT DO IT

Jeoh posted:

Don't doxx me

(base64 encoded string?)

Looks to me like an SSL cert encoded into base64 for a Cisco ASA.

I wish to God I didn't know that.

AlternateAccount
Apr 25, 2005
FYGM
Thanks for the guessing, I really don't know what it is, I hadn't gotten any further than some kind of base64 string that didn't decode into anything readable. It uhhh... turned up in an AD attribute, so I was trying to figure out wtf it was.

Jedi425 posted:

Looks to me like an SSL cert encoded into base64 for a Cisco ASA.

I wish to God I didn't know that.

How do you know it's specifically a Cisco ASA thing?

taqueso
Mar 8, 2004


:911:
:wookie: :thermidor: :wookie:
:dehumanize:

:pirate::hf::tinfoil:

It's the continue code for the last level of Battle Toads NES.



e: does the trailing == mean anything? I feel like I've seen it before but that's probably my pattern matching in overdrive.

Jedi425
Dec 6, 2002

THOU ART THEE ART THOU STICK YOUR HAND IN THE TV DO IT DO IT DO IT

AlternateAccount posted:

Thanks for the guessing, I really don't know what it is, I hadn't gotten any further than some kind of base64 string that didn't decode into anything readable. It uhhh... turned up in an AD attribute, so I was trying to figure out wtf it was.


How do you know it's specifically a Cisco ASA thing?

I don't, but every time in my life I have seen one of those it's been for setting up a trustpoint on an ASA. As far as I know, the ASA is the only device that requires you to install certs via the CLI in base64 format. (I think ASDM can do regular people certificates but gently caress the ASDM.) I hate them.

Docjowles
Apr 9, 2009

base64 strings are padded to a certain length with trailing equals signs if necessary. It's just part of the format.

AlternateAccount
Apr 25, 2005
FYGM

Jedi425 posted:

I don't, but every time in my life I have seen one of those it's been for setting up a trustpoint on an ASA. As far as I know, the ASA is the only device that requires you to install certs via the CLI in base64 format. (I think ASDM can do regular people certificates but gently caress the ASDM.) I hate them.

Yeah but you wouldn't... stick it an AD attribute for that....

Jedi425
Dec 6, 2002

THOU ART THEE ART THOU STICK YOUR HAND IN THE TV DO IT DO IT DO IT

AlternateAccount posted:

Yeah but you wouldn't... stick it an AD attribute for that....

What's the attribute called? (When I guessed, I didn't know you'd found it in AD. :v: )

The Fool
Oct 16, 2003


Jedi425 posted:

What's the attribute called? (When I guessed, I didn't know you'd found it in AD. :v: )

Additionally, is it on a computer or a user?

The Electronaut
May 10, 2009

Jedi425 posted:

What's the attribute called? (When I guessed, I didn't know you'd found it in AD. :v: )

I hope it's userCertificate.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
So in an effort to get back into doing fun coding things again, I'm going to probably demonstrate how I worked with breach data via Twitch streams. Still trying to come up with an angle I like but I feel like it's time to let people know that I am a terrible software developer and have bad ideas on how I approached the entire mess.

I'm not going to release the Canario source code but I'll probably rewrite it for funsies and dump that on Github as I go along.

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

Cup Runneth Over posted:

It's a public key block, right?

Public key blocks usually start with "MI".

This is a unknown encrypted/compressed block that has been encoded to base64. Utils I'm using is not seeing this as any normal compression so going with encrypted now since the de-base64 output entropy is very high.

Adbot
ADBOT LOVES YOU

Proteus Jones
Feb 28, 2013



Lain Iwakura posted:

So in an effort to get back into doing fun coding things again, I'm going to probably demonstrate how I worked with breach data via Twitch streams. Still trying to come up with an angle I like but I feel like it's time to let people know that I am a terrible software developer and have bad ideas on how I approached the entire mess.

I'm not going to release the Canario source code but I'll probably rewrite it for funsies and dump that on Github as I go along.

I doubt you're worse than me. My whole approach:

hack at the keyboard until it works
does it work every time (trap exceptions)
repeat last step until it runs all the way
am I getting results that look like they might be correct
Done.

Solicit input from team members? NO BECAUSE I SAID IT WAS DONE

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply