Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
salted hash browns
Mar 26, 2007
ykrop
YOSPOS › Security Fuckup Megathread - v17.1a - motherfuckers act like they forgot about jre

Adbot
ADBOT LOVES YOU

burning swine
May 26, 2004



Office depot got nailed for tricking customers into buying magic antivirus software to the tune of $35 million

quote:

From at least 2009 to November 2016, Office Depot, Inc. [...] made misrepresentations to consumers regarding the security of their computers. Support.com provided the Office Depot Companies with the “PC Health Check Program,” a software program designed as a sales tool to convince consumers to purchase diagnostic and repair services. Defendants advertised the PC Health Check Program to consumers as a free service that purportedly diagnosed consumers’ computers for security problems and performance issues, including scanning the computer for viruses.

In numerous instances throughout this time period, Defendants used the PC Health Check Program to report to Office Depot Companies customers that the scan had found or identified “Malware Symptoms” when it had not done so. Additionally, in numerous instances, the PC Health Check Program falsely reported to consumers that the program had found “infections” on the consumer’s computer.

Contrary to these representations, the PC Health Check Program did not and, by design, could not “find” or “identify” anything to return these results.

lol

exhibit A:


https://www.ftc.gov/enforcement/cases-proceedings/172-3023/office-depot-inc

Chalks
Sep 30, 2009

COACHS SPORT BAR posted:

Office depot got nailed for tricking customers into buying magic antivirus software to the tune of $35 million


lol

exhibit A:


https://www.ftc.gov/enforcement/cases-proceedings/172-3023/office-depot-inc

Malware detected, for example, the application showing you this message.

They're not technically wrong I guess

ewiley
Jul 9, 2003

More trash for the trash fire

quote:

ID: CVE-2019-9977
Title: Tesla Unspecified Arbitrary Code Execution Vulnerability
Vendor: Tesla
Description: Tesla Model 3 is exposed to an unspecified arbitrary code-execution vulnerability. Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected device. The renderer process in the entertainment system on Tesla Model 3 vehicles mishandles JIT compilation, which allows attackers to trigger firmware code execution, and display a crafted message to vehicle occupants.
CVSS v2 Base Score: 5.4 (AV:N/AC:M/Au:N/C:P/I:P/A:N)

What's old is new again

abigserve
Sep 13, 2009

this is a better avatar than what I had before

ErIog posted:

Thirding this. All configuration is a transition from some state to another state, and the concept of idempotence with regard to configuration just seems like either pretending the starting state doesn't exist or implicitly assuming a known clean starting state. I like Ansible for configuration automation, but the idempotent paradigm is stupid and I don't use it. I thought I was stupid or that I must have been using Ansible wrong. I may still be stupid, but it seems pretty clear to me after a few years of using it that Ansible itself misunderstands the nature of their own project.

it seems to me that a key part of Ansible is to discourage people writing their own code, evidenced by the plugin system that actually works perfectly well but is completely 100% undocumented.

I used ansible for a bit over two years and I went back to shell/python scripts because it's just easier by every possible metric. The real massive win for me was, during that time, becoming comfortable with CD and various tooling to accomplish that.

ErIog
Jul 11, 2001

:nsacloud:

abigserve posted:

it seems to me that a key part of Ansible is to discourage people writing their own code, evidenced by the plugin system that actually works perfectly well but is completely 100% undocumented.

I used ansible for a bit over two years and I went back to shell/python scripts because it's just easier by every possible metric. The real massive win for me was, during that time, becoming comfortable with CD and various tooling to accomplish that.

I think that is a key part of Ansible, and I think that's probably actually good considering how many people would absolutely gently caress up implementing the basic features of many of the most-used modules if they had to write their own shell/Python scripts.

abigserve
Sep 13, 2009

this is a better avatar than what I had before
you aren't wrong but the issue I found was that you still run into the same logic issues you would coding it but ansible doesn't give you many ways to resolve them without it becoming unreadable

people are cooling off on ansible in a big way as well, everyone I know that was all over it 1-2 years ago have ditched it or are actively looking for alternatives

Methanar
Sep 26, 2013

by the sex ghost
I wrote our last (present but rapidly going away) deployment system with ansible and I absolutely hate it.

I'm probably an idiot for generating ansible manifests with an ERB template, but the Ansible part still sucks.

Now I'm being extremely 2019 and just doing everything in Kubernetes

The Fool
Oct 16, 2003


This is a gold mine:
https://np.reddit.com/r/sysadmin/comments/b6hhrn/software_vendor_vpns_dont_work_and_public_facing/

quote:

nmap caliach.com

Starting Nmap 7.40 ( https://nmap.org ) at 2019-03-28 16:00 EDT
Nmap scan report for caliach.com (119.9.76.6)
Host is up (0.27s latency).
Not shown: 990 filtered ports

PORT STATE SERVICE
21/tcp open ftp
80/tcp open http
135/tcp open msrpc
139/tcp open netbios-ssn
445/tcp open microsoft-ds
990/tcp open ftps
3389/tcp open ms-wbt-server
49154/tcp open unknown
49155/tcp open unknown
49156/tcp open unknown

http://www.caliach.com/caliach/support/knowledge/sql/0015.html

quote:

The server MUST allow us to enter with Remote Desktop AS THE
ADMINISTRATOR to set it up and thereafter for troubleshooting. Your IT
company may tell you we only need to be a user as part of the administrator
group? Please see bit above where it tells you that you will be charged when
your IT company wastes our time....
 You must not use a VPN. Easier said than done we admit as nearly all
computer geeks will wax lyrical on the benefits of using a VPN for “security”?
The problem is, using a VPN with RDP (Remote Desktop( which is what we
have to do – simply does not work! Therefore, if you have a VPN setup, then
you have two choices:-

abigserve
Sep 13, 2009

this is a better avatar than what I had before
fuckin lmao

clowns: "hi, we're about to install some ERP software on your network. we need a windows server with outbound filesharing, rdp, and SQL ports."
IT people: "Uh what? no? That's hideously insecure and a terrible idea"
clowns: "goddamn time wasting IT staff!! Why is it the same story with every single customer!!! Nothing but time wasters!!!"

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
You missed the best part


quote:

If you are unsure if your Server or Firewall have these capabilities, please check with
your IT company, preferably without asking, or listening to, their opinions on why we
need it, what we need it for or what we REALLY need instead, as we really don’t
want to invoice you for wasting our time?
Our experience with Cloud Servers is that they do comply with our requirements by
default.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

no token ring

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

That's some of the worst poo poo and worst attitude ever

Pile Of Garbage
May 28, 2007



Chris Knight posted:

no token ring

it's right there on the left (c/o Soricidus)

Carbon dioxide
Oct 9, 2012


This entire website reads like a Trump campaign speech.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Captain Foo posted:

That's some of the worst poo poo and worst attitude ever

I like the inappropriate question marks, reads like annoying interrogative tone you know???

Chalks
Sep 30, 2009

Krankenstyle posted:

I like the inappropriate question marks, reads like annoying interrogative tone you know???

it just makes it sound like they're really confused

we don't want to invoice you for wasting our time? i thought we did!

abigserve
Sep 13, 2009

this is a better avatar than what I had before
secure network, no inbound RDP.

Oh these IT timewasters got this all screwed up

Secure network? No, inbound RDP!

Pile Of Garbage
May 28, 2007



:lol:

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


abigserve posted:


Secure network? No, inbound RDP!

DrPossum
May 15, 2004

i am not a surgeon
secfuck thread on fire lately

Soricidus
Oct 21, 2010
freedom-hating statist shill
offer them inbound x11 instead

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

offer them some sort of contrived web app but fail to add certificates

simble
May 11, 2004

abigserve posted:

Secure network? No, inbound RDP!

Shame Boy
Mar 2, 2010

i've now started getting those "oo look i have your old password therefore i hacked you!!" spam emails except to accounts where they don't even have my old password. it just assures me that they definitely do, pinky swear

it's been fun to watch this kind of spam slowly transform over time into the most :effort: version possible i guess

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

abigserve posted:

Secure network? No, inbound RDP!

univbee
Jun 3, 2004




abigserve posted:

Secure network? No, inbound RDP!

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
You'll get a VDI and you'll like it.

ewiley
Jul 9, 2003

More trash for the trash fire

abigserve posted:

Secure network? No, inbound RDP!

I'm the Password (not important) from the openssl create script

univbee
Jun 3, 2004




it's nightmares about having to work with these sorts of vendors that make me glad i got the gently caress out of IT

Pile Of Garbage
May 28, 2007



CommieGIR posted:

You'll get a VDI and you'll like it.

lol that reminds me of the last gig I was at. the customer decided to outsource a bunch of BPO stuff to Accenture (massive bastards btw, look em up re Philippines) in order to automate and streamline processes. Accenture decided to implement this with Automation Anywhere, a software package that just records and plays-back mouse+keyboard inputs, but enterprisey (why spend time and money understanding APIs and building scripted orchestration poo poo for whatever product your dealing with when you can just simulate the user interaction).

despite the automation poo poo Accenture were putting in they were still employing a team of poor Filipinos working remotely to operate Automation Anywhere for some reason, probably mad profit min-maxing or some poo poo. anyway to use the AA software front-end it has to run as administrator in the context of the user executing it. at first they wanted to just put it on the Citrix environment to which we said "lol gently caress know"

after weeks of back and forth with us saying "this poo poo is hosed, get it outta here" and the customer saying "yeah but we need it kay" we ended up designing and deploying an entire VDI solution solely for the Accenture drones to run AA from remotely.

basically gently caress BPOs

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



i havent gotten any "we have your password" emails :(

i did get kicked off a linux iso tracker because they apparently found my password in a leak, they said to join their irc to reactivate my account so i just deleted the bookmark :hehe:

theres a bunch of "trumpmedicare" ones in my spam folder for some reason

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Pile Of Garbage posted:

lol that reminds me of the last gig I was at. the customer decided to outsource a bunch of BPO stuff to Accenture (massive bastards btw, look em up re Philippines) in order to automate and streamline processes. Accenture decided to implement this with Automation Anywhere, a software package that just records and plays-back mouse+keyboard inputs, but enterprisey (why spend time and money understanding APIs and building scripted orchestration poo poo for whatever product your dealing with when you can just simulate the user interaction).

despite the automation poo poo Accenture were putting in they were still employing a team of poor Filipinos working remotely to operate Automation Anywhere for some reason, probably mad profit min-maxing or some poo poo. anyway to use the AA software front-end it has to run as administrator in the context of the user executing it. at first they wanted to just put it on the Citrix environment to which we said "lol gently caress know"

after weeks of back and forth with us saying "this poo poo is hosed, get it outta here" and the customer saying "yeah but we need it kay" we ended up designing and deploying an entire VDI solution solely for the Accenture drones to run AA from remotely.

basically gently caress BPOs

i am having multiple running battles with this kind of poo poo because even ignoring security stuff because its 100% internal, if the thing is simple enough that you can run some "record mouse clicks" poo poo on it then it can be replaced/deleted entirely because it's probably a worthless process.

like I've seen 45 page documents illustrating "process automation" that amounts to "screen scrape some data to csv and email it to someone that is gonna delete it because the content is garbage"

Pile Of Garbage
May 28, 2007



Accenture has +469k employees, they've min-maxed the fuckin numbers on the automation game and know exactly how much they need to do and how to make a profit. poo poo is hosed...

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Pile Of Garbage posted:

it's right there on the left (c/o Soricidus)
lol missed that :tipshat:


abigserve posted:

Secure network? No, inbound RDP!

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
> why spend time and money understanding APIs and building scripted orchestration poo poo for whatever product your dealing with when you can just simulate the user interaction

lol at the idea of anything that accenture is being called into automate has documented apis intended for public use. this is ENTERPRISE; nothing is designed well

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


they're consultants, there's no long term money in fixing a problem, only in managing it year after year after year

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
consider me "surprised"

https://twitter.com/stephengillett/status/1111741162535026688

to be fair, no car manufacturer offers FDE in the storage on their car to the best of their knowledge. every time i rent a car i always try and reset the settings to factory because i don't want my phone to inadvertently pair to it again or have my call logs still on there. that said, i can let it slide on having dash cam footage unencrypted for insurance reasons

that said, how the heck do you perform a factory reset when the car is dead? like if the batteries are fried we're not going to be going into the control panel and resetting everything to defaults because you're unlikely to get access to it. furthermore no user knows how to power on the computer post-wreckage usually and they're not going to know where to smash the NAND chips anyway

ate shit on live tv
Feb 15, 2004

by Azathoth
Why have persistent storage on a car at all? If the car loses power, wipe everything.

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

ate poo poo on live tv posted:

Why have persistent storage on a car at all? If the car loses power, wipe everything.

i think that it gets a bit harder these days to do that although i don't disagree. however because of the dash cam footage i personally would advocate against that and instead just make it so the data for the rest of the car is encrypted and unlocked via your car key or whatever tesla uses

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply