Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
cinci zoo sniper
Mar 15, 2013




Lutha Mahtin posted:

you can make strong passwords that are easy to remember tho

or you can just memorise one-two competently strong passwords, that sounds like something an average adult can handle

Adbot
ADBOT LOVES YOU

univbee
Jun 3, 2004




I heard back from one of the 1password team members, the tl;dr is that 1password by design stores an encrypted offline cache and as such can't be tied to a 2FA system as such (passwords need to be recoverable in cases of limited connectivity). it's not a feature they've outright written off, but it's not in their current active plans either

pseudorandom name
May 6, 2007

https://twitter.com/zer0pwn/status/1102048690414501889
https://twitter.com/zer0pwn/status/1102053664120848385
https://twitter.com/zer0pwn/status/1102699816226742274

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

:rip:

CmdrRiker
Apr 8, 2016

You dismally untalented little creep!

Wow, that was a few days ago. I hope they addressed it by now.

https://twitter.com/RespawnJobs/status/1096090384239714305

lol

CmdrRiker fucked around with this message at 20:29 on Mar 5, 2019

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

CmdrRiker posted:

Wow, that was a few days ago. I hope they addressed it by now.

https://twitter.com/RespawnJobs/status/1096090384239714305

lol

guess the new hire just learned a few valuable security lessons rofl

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

My Linux Rig posted:

guess the new hire just learned a few valuable security lessons rofl

whoomfp

Shame Boy
Mar 2, 2010

is it just me or are these "i've got your old password via hacking and definitely not just using a big list" emails getting less and less understandable

quote:

Hi!

As you may have noticed, I sent you an email from your account.
This means that I have full access to your account: At the time of hacking your account had this password: [snip]

You can say: this is my, but old password!
Or: I can change my password at any time!

Of course! You will be right,
but the fact is that when you change the password, my malicious code every time saved a new one!

I've been watching you for a few months now.
But the fact is that you were infected with malware through an adult site that you visited.

If you are not familiar with this, I will explain.
Trojan Virus gives me full access and control over a computer or other device.
This means that I can see everything on your screen, turn on the camera and microphone, but you do not know about it.

I also have access to all your contacts and all your correspondence from e-mail and messangers.

Why your antivirus did not detect my malware?
Answer: My malware uses the driver, I update its signatures every 4 hours so that your antivirus is silent.

I made a video showing how you satisfy yourself in the left half of the screen, and in the right half you see the video that you watched.
With one click of the mouse, I can send this video to all your emails and contacts on social networks. I can also post access to all your e-mail correspondence and messengers that you use.

If you want to prevent this, transfer the amount of $716 to my bitcoin address (if you do not know how to do this, write to Google: "Buy Bitcoin").

My bitcoin address (BTC Wallet) is: 1B3Lx1t4CQSt3ck85bqzGHC9TeEQGANhUR

After receiving the payment, I will delete the video and you will never hear me again.
I give you 48 hours to pay.
I have a notice reading this letter, and the timer will work when you see this letter.

Filing a complaint somewhere does not make sense because this email cannot be tracked like my bitcoin address.
I do not make any mistakes.

If I find that you have shared this message with someone else, the video will be immediately distributed.
Bye!

tbh changing the signatures every 4 hours sounds like a great way to get past antiviruses

also if you look up that address some people actually seem to have paid in the last few hours :v:

https://www.blockchain.com/btc/address/1B3Lx1t4CQSt3ck85bqzGHC9TeEQGANhUR

haveblue
Aug 15, 2005



Toilet Rascal

Shame Boy posted:

is it just me or are these "i've got your old password via hacking and definitely not just using a big list" emails getting less and less understandable

I forced a neural net to read 1,000 threatening emails, and

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

haveblue posted:

I forced a neural net to read 1,000 threatening emails, and

occasionally their bots misfire and you can see that the mails are basically built up like <greeting><first sentence><second sentence> etc, and presumably they come up with a couple of dozen alternatives for each which is why sometimes it jumps from relatively lucid to gibberish.

gmail's spam filters, at least, are supposedly trained to look for "natural language" patterns and presumably this is meant to be a way past it - however not one of these mails has ever made its way past the spam filter on my personal gmail (i get 10 or 12 a day mostly about accounts i'd long forgotten i ever had) so :shrug:

Wiggly Wayne DDS
Sep 11, 2010



ya i posted a broken one i got a month or so ago

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

if I was running a scam with cyber coins I’d use some seed money that way, yeah

Guy Axlerod
Dec 29, 2008
I got one of them, and it didn't even include an old password.

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
at this point about 90% of those emails that i've gotten have included a password that i don't seem to have ever actually used anywhere

Hexyflexy
Sep 2, 2011

asymptotically approaching one
Ghidra is out the NSA's open source reverse engineering framework. Not had a chance to really play with the thing yet. It's unsurprisingly Java.

e: This is awesome, live and quite fast decompilation.

Hexyflexy fucked around with this message at 01:27 on Mar 6, 2019

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

do you nerds actually read the stuff in your spam folder?

related to that, i dunno if this is true but i feel like i just don't get a lot of spam email anymore. my serious business personal account has like 11 in it that haven't been auto-deleted yet, and half of them rn are from local oil change places that i actually did give my email to

e: what the hell is "sleigh"? the ghidra thing says it is a million+ lines of "java and sleigh code"

Lutha Mahtin fucked around with this message at 01:34 on Mar 6, 2019

Hexyflexy
Sep 2, 2011

asymptotically approaching one

Lutha Mahtin posted:

e: what the hell is "sleigh"? the ghidra thing says it is a million+ lines of "java and sleigh code"

The source isn't out yet, I'm going to guess custom scripting language.

Partycat
Oct 25, 2004

Lutha Mahtin posted:

do you nerds actually read the stuff in your spam folder?

yes because it comes into my inbox now as the work spam filter blows

- tiny umbrella
- floating moon lamp
- walking 3D T. rex puzzle
- ear cleaning endoscope

and I got one that says “My kid love trains now” which was the scariest of all

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Hexyflexy posted:

The source isn't out yet, I'm going to guess custom scripting language.

i hope it's just java but to instantiate, instead of "new" you use "wheeeeee"

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

Lutha Mahtin posted:

do you nerds actually read the stuff in your spam folder?

related to that, i dunno if this is true but i feel like i just don't get a lot of spam email anymore. my serious business personal account has like 11 in it that haven't been auto-deleted yet, and half of them rn are from local oil change places that i actually did give my email to

e: what the hell is "sleigh"? the ghidra thing says it is a million+ lines of "java and sleigh code"

idk sometimes I read it cause I’m curious what spam looks like now

i contributed to the Democrats in the last election so now its chock full of scary trump news

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

aside from the oil change promotions my spam folder was pretty much all shady dating site stuff with lots of emojis in the subject line

El Mero Mero
Oct 13, 2001

I'm pretty impressed by spam filters nowadays. I've got a gmail address that's a simplified dictionary word and I pretty much just get legitimately missent emails and almost no spam.

pseudorandom name
May 6, 2007

of the 23 messages in my spam folder, one is a legitimate but unwanted junk mail from WB Games, one is a legitimate notification mail for some rear end in a top hat abusing another forum, two are NETLX credential phishes, one is a United States Posta credential phish, two are Chinese-language dick pill advertisements and the rest are scams (mostly 419, one in German, one in French)

I can't remember the last time an actual spam message landed in my inbox

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD

Meat Beat Agent posted:

at this point about 90% of those emails that i've gotten have included a password that i don't seem to have ever actually used anywhere

I'm also getting a bunch to email addresses that don't exist so therefore can't have been harvested from pw dumps.

sadus
Apr 5, 2004

I mostly just get random full disclosure mailing list emails flagged as spam for no apparent reason
Being subscribed to a bunch of old mailing lists is like my Crudbump NSA butte-defense-shield

astr0man
Feb 21, 2007

hollyeo deuroga

Lutha Mahtin posted:

e: what the hell is "sleigh"? the ghidra thing says it is a million+ lines of "java and sleigh code"

it's basically just xml used to describe a cpu architecture. so if you wanted to add support for a new processor, you use sleigh. just look for all the .sla files in the Ghidra/Processors folder

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

astr0man posted:

it's basically just xml used to describe a cpu architecture. so if you wanted to add support for a new processor, you use sleigh. just look for all the .sla files in the Ghidra/Processors folder

can you provide any URL for this thing because i am apparently a complete moron who fails at web searching

astr0man
Feb 21, 2007

hollyeo deuroga

Lutha Mahtin posted:

can you provide any URL for this thing because i am apparently a complete moron who fails at web searching

their open source repo isn't out yet, so no, but if you download ghidra you can see the sla files for all the currently supported processors. it's been like 7 or 8 years since i last used ghidra, but iirc basically sleigh describes a cpu arch so that instructions from any arbitrary arch can be properly translated into pcode, which is the intermediate format that the ghidra decompiler uses. it looks like they haven't posted any sleigh or pcode related documentation yet though.

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

mfw when our customer indicates that they need intermediate proxies to log full request bodies because "it's necessary for debugging purposes" and they swear that having a regex filter on the contents will avoid any possible issues.

bonus points because said customer is a loving (major) bank

spankmeister
Jun 15, 2008






Important news: Ghidra has undo.

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

Partycat posted:

and I got one that says “My kid love trains now” which was the scariest of all

that's what vaccination gets you

Cybernetic Vermin
Apr 18, 2005

spankmeister posted:

Important news: Ghidra has undo.

that's so 1993

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

spankmeister posted:

Important news: Ghidra has undo.

but does it have reverse?

redleader
Aug 18, 2005

Engage according to operational parameters
better run this application developed by a famously tricky and knowledgeable adversary as soon as it's released!

redleader
Aug 18, 2005

Engage according to operational parameters
like, i know it will be harmless and do exactly what it says on the tin. but still, lol

Wiggly Wayne DDS
Sep 11, 2010



there's a new zachatronics out??

evil_bunnY
Apr 2, 2003

spankmeister posted:

Important news: Ghidra has undo.

https://twitter.com/hackerfantastic/status/1103087869063704576

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


goddamnedtwisto posted:

that's what vaccination gets you

:trumppop:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Wiggly Wayne DDS posted:

there's a new zachatronics out??

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

Cocoa Crispies posted:

if I was running a scam with cyber coins I’d use some seed money that way, yeah

i've checked the bitcoin addresses of all the different ones of these i've gotten and this is the first one that actually had any money in it, and judging by how weird the transfer is structured it was probably transferred from one of those online wallet services and not an individual wallet, which seems like a weird extra step that's gonna cost you a bunch in fees if you're just seeding the pot

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply