Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Progressive JPEG posted:

is Bitwarden (password manager) good?

I just started using it, and it seems OK. you have to buy a premium account ($10/yr) to do TOTP, and due to apple policies they can’t tell you that anywhere in the app.

eventually I’ll probably self-host just to try it

Adbot
ADBOT LOVES YOU

Progressive JPEG
Feb 19, 2003

Subjunctive posted:

I just started using it, and it seems OK. you have to buy a premium account ($10/yr) to do TOTP, and due to apple policies they can’t tell you that anywhere in the app.

eventually I’ll probably self-host just to try it

from digging around the dashboard as a free user it looks like the 2FA situation is:
- totp for logging into bitwarden itself: free
- u2f or duo-prompt for logging into bitwarden itself: premium
- totp codes against logins stored in bitwarden: premium

ive been storing totp codes in my current 1password account and it feels gross so I was planning on moving those to a separate dedicated totp app anyway. but at the same time I don’t mind giving bitwarden 10/yr either

I might self host on my rasppi cluster someday but it’d probably be a pain to get it working on arm. the self host docs specifically list x64 in the requirements

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Progressive JPEG posted:

I might self host on my rasppi cluster someday but it’d probably be a pain to get it working on arm. the self host docs specifically list x64 in the requirements

yeah, I don’t think mssql comes built for arm, does it? there are other implementations of the protocol, like bitwarden_rs, but I don’t know much about them.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
So, we had some training money to spend, so I got to go take the CEH class prior to Hacker Halted in Atlanta, and the company that runs EC Council sells a little portable "Pen Testing Tool"

What is it you ask?

Well, they sell it for $700. Its a $35 Raspberry Pi 3+ with a 7 Inch LCD touchscreen. Its about $100 worth of parts you can get off Amazon. Nice.

geonetix
Mar 6, 2011


for as much as I’ve read about it the ec council seems the biggest ripoff for everything they do

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

geonetix posted:

for as much as I’ve read about it the ec council seems the biggest ripoff for everything they do

Cram a bunch of open source pen-testing tools into a budget SBC computer: Profit!

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

CommieGIR posted:

So, we had some training money to spend, so I got to go take the CEH class prior to Hacker Halted in Atlanta, and the company that runs EC Council sells a little portable "Pen Testing Tool"

What is it you ask?

Well, they sell it for $700. Its a $35 Raspberry Pi 3+ with a 7 Inch LCD touchscreen. Its about $100 worth of parts you can get off Amazon. Nice.

taking as much money as possible from people spending money on ethical hacking certifications is the most ethical action

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
https://twitter.com/cybergibbons/status/1182989623133396992?s=21

it’s gonna be eero

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Ur Getting Fatter posted:

it’s gonna be all of them

The Fool
Oct 16, 2003


as someone that has google Wifi in their house, I am waiting with baited breath

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD

what's the bet that the sidechannel wireless link between WAPs is unencrypted

geonetix
Mar 6, 2011


I think he posted later it’s cloud related

Media Bloodbath
Mar 1, 2018

PIVOT TO ETERNAL SUFFERING
:hb:

Soricidus
Oct 21, 2010
freedom-hating statist shill

:nsavince:

Bulgakov
Mar 8, 2009


рукописи не горят

that sounds extra powerfully lazy

what system(s) don’t have even the most basic of secure sync mechanism between authorized stations?

Workaday Wizard
Oct 23, 2009

by Pragmatica
but you see user journey first experience frictionless onboarding therefore...

BlankSystemDaemon
Mar 13, 2009




Bulgakov posted:

that sounds extra powerfully lazy

what system(s) don’t have even the most basic of secure sync mechanism between authorized stations?
Well, the BitLocker encryption in Windows, when communicating with an installed TPM for key material, does so in plaintext.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
amateur hour, not including “attacker has the device open and a logic analyzer hooked up to the motherboard” in the threat model

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
i heard that an attacker that knows your disk encryption password can unlock it, sounds like a big security flaw if so

BlankSystemDaemon
Mar 13, 2009




Cocoa Crispies posted:

amateur hour, not including “attacker has the device open and a logic analyzer hooked up to the motherboard” in the threat model
It's trivial to communicate with a TPM over the LPC bus connected to the PCH without doing it in plaintext, so it's absolutely a secfuck that they don't.

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD

Bulgakov posted:

that sounds extra powerfully lazy

what system(s) don’t have even the most basic of secure sync mechanism between authorized stations?

if I had to guess it's to make buying additional extended stations seamless

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

all the best parts about Facebook vagueposting, but with public comments!
:allears:

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Can't wait to find out whose AP system it is...

crazysim
May 23, 2004
I AM SOOOOO GAY
https://twitter.com/cybergibbons/status/1183367739060166657

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Niiiiice.

toiletbrush
May 17, 2010
why the gently caress would you ask this over twitter rather than just contacting them directly?

like secfucks should be exposed and all but some of these Twitter threads read like teacher's pet running excitedly to teacher to tell on the naughty kid

Doom Mathematic
Sep 2, 2008

toiletbrush posted:

why the gently caress would you ask this over twitter rather than just contacting them directly?

like secfucks should be exposed and all but some of these Twitter threads read like teacher's pet running excitedly to teacher to tell on the naughty kid

I assume because there's no way to contact them directly or because they've ignored prior attempts at direct contact, is the usual story here.

Happy Thread
Jul 10, 2005

by Fluffdaddy
Plaster Town Cop
calling them forward is the best way to shame them, which is the whole point

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER


not very subtle

i love it

haveblue
Aug 15, 2005



Toilet Rascal
yeah if there’s no listed security contact and he can’t get an answer through private channels, try a public one

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
https://twitter.com/cybergibbons/status/1183335014538170368?s=21


https://twitter.com/cybergibbons/status/1183430737359523840?s=21

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
yeah ya boi travis did that for cloudflare 'cause their security contact didn't get back in 30 minutes on a saturday night

Workaday Wizard
Oct 23, 2009

by Pragmatica
if i learned anything from muddy waters it would be to short the stocks then release the vuln report to the public :homebrew:

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shinku ABOOKEN posted:

if i learned anything from muddy waters it would be to short the stocks then release the vuln report to the public :homebrew:

didn't that internet nazi say he was going to do that?

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
poo poo, gotta narrow it down probably, weev i think?

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Yes that was the idea with TRO LLC, but it's not clear whether they actually did anything

Computer Serf
May 14, 2005
Buglord
whos gonna be debugging that secfuck with the hookers

Garrand
Dec 28, 2012

Rhino, you did this to me!

Computer Serf posted:

whos gonna be debugging that secfuck with the hookers

The doctor

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

Shinku ABOOKEN posted:

if i learned anything from muddy waters it would be to short the stocks then release the vuln report to the public :homebrew:

my takeaway was more that, while my eyes do keep me in trouble, it's still true that i can't never be satisfied, and anyway you can't spend what you ain't got

Adbot
ADBOT LOVES YOU

evil_bunnY
Apr 2, 2003

toiletbrush posted:

why the gently caress would you ask this over twitter rather than just contacting them directly?

like secfucks should be exposed and all but some of these Twitter threads read like teacher's pet running excitedly to teacher to tell on the naughty kid
gibbons has been trying to get in touch for days

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply