Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



fisting by many posted:

about 18 months ago they were basically giving that to anyone who had an app, i'm sure cambridge analytica isn't the only company that's done close to mirror facebook's database

facebook says an ongoing investigation has so far found no indication that anyones ever had unlimited graph api access, probably

Adbot
ADBOT LOVES YOU

unknown
Nov 16, 2002
Ain't got no stinking title yet!


Lol

https://twitter.com/iblueconnection/status/1107702203349979136

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

My buddy says that doesnt work on our ruby stuff cause our version is too old

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Volmarias posted:

The 5x only just stopped getting security updates at the end of 2018, after launching in 2015. It's not iPhone levels of support but it's the best you'll get for Android, for now.

i mean, all 5 people left with a nexus 5x that hasn't selfdestructed via heat yet

Carbon dioxide
Oct 9, 2012

This just popped up from 'Kee', the Keepass plugin for Firefox:

https://forum.kee.pm/t/kee-vault-and-kee-version-3-0/2025

ErIog
Jul 11, 2001

:nsacloud:

Carbon dioxide posted:

This just popped up from 'Kee', the Keepass plugin for Firefox:

https://forum.kee.pm/t/kee-vault-and-kee-version-3-0/2025

Why would you use a Keepass plugin for a browser? If you're going to do that you may as well just use 1Password.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Grace Baiting posted:

facebook says an ongoing investigation has so far found no indication that anyones ever had unlimited graph api access, probably

https://twitter.com/zackwhittaker/status/1108818391324872704

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS
request logging is a hell of a drug

Shame Boy
Mar 2, 2010

Cybernetic Vermin posted:

they are so loving expensive mostly. nokia has a good combo in being pretty cheap, getting updates, and mostly not being terrible

my wife also got a pixel 3 and she managed to get it on sale for $600 though that is still p expensive imo

Shame Boy
Mar 2, 2010

ErIog posted:

Why would you use a Keepass plugin for a browser? If you're going to do that you may as well just use 1Password.

because it lets me right click and automatically fill out the password fields without having to copy/paste everything :shrug:

afaik it's actually implemented reasonably well on the keepass side, like you have to confirm the browser before it'll allow requests for passwords and it does it with a public/private key thingy I think. idk about the browser plugins themselves I'm sure they're probably awful

e: wait the thing linked is actually some kind of browser-based UI? yeah ok that's kinda dumb

flakeloaf
Feb 26, 2003

Still better than android clock

it would be cheaper to buy two sgs10+s with cash and flush one down the toilet than it would be to "upgrade" my cell plan to buy one :bravo:

cheaper still to just plug the sgs6 i have now into the wall more often

evil_bunnY
Apr 2, 2003

Cybernetic Vermin posted:

super-weird at first since they should be running a clean google image outside of the driver layer, but it seens most likely it is a qualcomm driver doing the call "home" https://raw.githubusercontent.com/b...rationTask.java
sure sounds like a great driver feature we should see more of.

neutral milf hotel
Oct 9, 2001

by Fluffdaddy
please rename thread to

Linux on phones? it's worse than you thought... (page 1 of 500000)

pseudorandom
Jun 16, 2010



Yam Slacker

Shame Boy posted:

because it lets me right click and automatically fill out the password fields without having to copy/paste everything :shrug:

Do you not use CTRL+ALT+A to just auto-type your passwords?


neutral milf hotel posted:

please rename thread to

Linux on phones? it's worse than you thought... (page 1 of 500000)

I'm actually kind of considering getting the Librem 5 if initial reviews look promising. :q:

Shame Boy
Mar 2, 2010

pseudorandom posted:

Do you not use CTRL+ALT+A to just auto-type your passwords?

you still have to search for and pick the thing first right? this matches based on the URL and picks the right one for you :shrug:

also i thought auto-type was Bad and you Shouldn't Use It because things were finding ways to hijack it, but maybe i'm thinking of something else

e: yeah I think I was thinking of the auto-fill browser mode where it doesn't wait for you to like, tell it to enter the password, it just goes ahead and does it whenever it feels like it, which is a hilariously bad idea

The Fool
Oct 16, 2003


Shame Boy posted:

you still have to search for and pick the thing first right? this matches based on the URL and picks the right one for you :shrug:

also i thought auto-type was Bad and you Shouldn't Use It because things were finding ways to hijack it, but maybe i'm thinking of something else

e: yeah I think I was thinking of the auto-fill browser mode where it doesn't wait for you to like, tell it to enter the password, it just goes ahead and does it whenever it feels like it, which is a hilariously bad idea

Autotype exists because the clipboard and browser plugins are not secure.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

neutral milf hotel posted:

please rename thread to

Linux on phones? it's worse than you thought... (page 1 of 500000)

eh there's already an android thread

pseudorandom
Jun 16, 2010



Yam Slacker

Shame Boy posted:

you still have to search for and pick the thing first right? this matches based on the URL and picks the right one for you :shrug:

also i thought auto-type was Bad and you Shouldn't Use It because things were finding ways to hijack it, but maybe i'm thinking of something else

e: yeah I think I was thinking of the auto-fill browser mode where it doesn't wait for you to like, tell it to enter the password, it just goes ahead and does it whenever it feels like it, which is a hilariously bad idea

The native application's auto-type works by reading the title of the application, eg "Security Fuckup Megathread - The Something Awful Forums - Mozilla Firefox". So yes, someone could spoof a page title, but you still have to fall for the trick.

This works great most of the time and requires no manual searching for the entry. The only time I need to manually search are for the terrible websites that omit any identifiers from their login page, <title>Log In</title>, so there's no context about what website is active in the browser title.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

pseudorandom posted:

The native application's auto-type works by reading the title of the application, eg "Security Fuckup Megathread - The Something Awful Forums - Mozilla Firefox"

Jesus christ lol just use 1password

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Absolute clown tier password management

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Volmarias posted:

The 5x only just stopped getting security updates at the end of 2018, after launching in 2015. It's not iPhone levels of support but it's the best you'll get for Android, for now.

yeah and until my 5x died (lol thanks LG) i was still getting updates faster than my co-workers with brand new Samsungs

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Lutha Mahtin posted:

the current iteration of Android One (it's one of those names Google has used for multiple unrelated projects over the years) is supposedly some kind of actual contract that the device manufacturer has to sign in order to use the branding. it hasn't been around very long though so i am interested to see if any manufacturers try and weasel out of it

i've got a nokia 7.1 so i may get to find this out first hand!

burning swine
May 26, 2004



The Fool posted:

Autotype exists because the clipboard and browser plugins are not secure.

Just started a new job and went to set up my retirement plan today, and hit this:



Name and shame:
Transamerica

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

pseudorandom posted:

The native application's auto-type works by reading the title of the application, eg "Security Fuckup Megathread - The Something Awful Forums - Mozilla Firefox". So yes, someone could spoof a page title, but you still have to fall for the trick.

This works great most of the time and requires no manual searching for the entry. The only time I need to manually search are for the terrible websites that omit any identifiers from their login page, <title>Log In</title>, so there's no context about what website is active in the browser title.

If only there was some other way to identify what the site is, something that could be used in a uniform way, for whatever location you've gone to. Sadly, the web doesn't have such a resource.

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

COACHS SPORT BAR posted:

Just started a new job and went to set up my retirement plan today, and hit this:



Name and shame:
Transamerica

the icing on the poo poo cake is that they do this by blocking the ctrl+v keyboard shortcut. going to the menu item edit > paste still works.

pseudorandom
Jun 16, 2010



Yam Slacker

Kuvo posted:

the icing on the poo poo cake is that they do this by blocking the ctrl+v keyboard shortcut. going to the menu item edit > paste still works.

For sites that do this dumb stuff, I've ended up just opening the dev console and removing event bindings for the input element.

Hed
Mar 31, 2004

Fun Shoe

CommieGIR posted:

So my company is implementing Stealth to microsegment parts of our DC and network, and I've talked about this previously, but my big concern is lack of info on known weaknesses to Stealth and I'm kinda pissed we are not just doing proper segmenting via VLANs and 802.1x certs.

Anybody know some pertinent questions I should ask as a Red Team guy? My big one up front is "What are you doing to stop pivoting at entry points into the microsegments" and "What happens if someone compromises a common point of interest and MITMs the segment?"

I wanted to respond to this because I had not heard of Stealth but god drat after poking around on their web site I can't understand what this software suite purports to do other than the word salad slick sheets they have. You're right to be skeptical and ask the questions you have. My big thing would be how they protect the integrity of the controller and in relation to your MITM question how do they ensure communications integrity at all layers. Doing some dot1x as you point out would be a good start, but also as a common refrain what are you trying to protect against?

abigserve
Sep 13, 2009

this is a better avatar than what I had before
micro segmentation in the network is an incredibly dumb idea at best and actively detrimental to security at worst. I can make an effort post if required on this.

the only things in that space that looks like it could work atm is something like Consul which is, effectively, a bunch of ssl tunnels between your application components secured by client certs (as I understand it).

is anyone else here getting hammered by "data sovereignty" at work lately? Literally every meeting about a new architecture or application is stalled with 20 minutes of "where is the data located. why does it have to be located there. can we not have the data there???"

for some stuff it makes sense definitely but it's literally anything, we had a meeting about loving github get held up like that. I've tried requesting the paperwork on where, when, and why it's important but I never hear anything back besides very vague theoretical situations that border on conspiracy theories and in some cases literal xenophobia.

Violently Car
Dec 2, 2007

You are now entering completely darkness

Kuvo posted:

the icing on the poo poo cake is that they do this by blocking the ctrl+v keyboard shortcut. going to the menu item edit > paste still works.

lol how about shift+insert

burning swine
May 26, 2004



Violently Car posted:

lol how about shift+insert

I just used don't gently caress with paste

Varkk
Apr 17, 2004

Kuvo posted:

the icing on the poo poo cake is that they do this by blocking the ctrl+v keyboard shortcut. going to the menu item edit > paste still works.

There is a scary number of users who don’t know about keyboard shortcuts. They usually only know right click > paste. ctrl+v is done black magic hacker poo poo to them. Of course they won’t use a password manager anyway. They just have all of their passwords muffins12 or similar.

exmachina
Mar 12, 2006

Look Closer
So apparently the Nokia thing was a small batch of phones "meant for another market" were released into the global stream. So Nokia just told us (as if we need confirmation) that they modify their products to facilitate the surveillance of citizens by that countries government.

In completely unrelated news, the server the info was sent to was a Chinese ISP

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

abigserve posted:

is anyone else here getting hammered by "data sovereignty" at work lately? Literally every meeting about a new architecture or application is stalled with 20 minutes of "where is the data located. why does it have to be located there. can we not have the data there???"

for some stuff it makes sense definitely but it's literally anything, we had a meeting about loving github get held up like that. I've tried requesting the paperwork on where, when, and why it's important but I never hear anything back besides very vague theoretical situations that border on conspiracy theories and in some cases literal xenophobia.

I’ve been to a poo poo ton of meetings covering this but all because of gdpr which is very specific when it comes to the how and the why

cinci zoo sniper
Mar 15, 2013




Boiled Water posted:

I’ve been to a poo poo ton of meetings covering this but all because of gdpr which is very specific when it comes to the how and the why

same here but we also operate in a range of countries where governments have extra restrictions on top of that (also data governance shite is literally part of job responsibilites)

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

exmachina posted:

So apparently the Nokia thing was a small batch of phones "meant for another market" were released into the global stream. So Nokia just told us (as if we need confirmation) that they modify their products to facilitate the surveillance of citizens by that countries government.

In completely unrelated news, the server the info was sent to was a Chinese ISP

This isn't new for the China market. Remember when the flag of Taiwan made iPhones reboot?

abigserve posted:

I can make an effort post ... on this.

:justpost:

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



:posthaste: yes please

hobbesmaster
Jan 28, 2008

abigserve posted:

micro segmentation in the network is an incredibly dumb idea at best and actively detrimental to security at worst. I can make an effort post if required on this.

the only things in that space that looks like it could work atm is something like Consul which is, effectively, a bunch of ssl tunnels between your application components secured by client certs (as I understand it).

is anyone else here getting hammered by "data sovereignty" at work lately? Literally every meeting about a new architecture or application is stalled with 20 minutes of "where is the data located. why does it have to be located there. can we not have the data there???"

for some stuff it makes sense definitely but it's literally anything, we had a meeting about loving github get held up like that. I've tried requesting the paperwork on where, when, and why it's important but I never hear anything back besides very vague theoretical situations that border on conspiracy theories and in some cases literal xenophobia.

don't US/EU/China all have very different implications for your application and data retention?

jammyozzy
Dec 7, 2006

Is that a challenge?
Mercifully it wasn't my job to know or care, but I understood from smarter/more important people at a previous gig that ITAR means it sometimes matters very much where your data is stored.

power botton
Nov 2, 2011

I've only really encountered that with certain swiss/european banks who don't want any data leaving the borders. Nothing like providing support for your software when the guys won't send logs or share their screen.

Its fun when you're dealing with multiple teams and the NY guys will give you keyboard and mouse control to do poo poo logged in as domain admin, and the Swiss data governance guys try to describe what button they're looking at right now.

Adbot
ADBOT LOVES YOU

univbee
Jun 3, 2004




jammyozzy posted:

Mercifully it wasn't my job to know or care, but I understood from smarter/more important people at a previous gig that ITAR means it sometimes matters very much where your data is stored.

when i computer touched 10 years ago in canada, some business clients’ data were required to never get stored in the us since that would make them vulnerable to the use of the patriot act to look at their data, precluding many cloud solutions of the time.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply