Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD
Even if there's edge cases, the worst case is presumably that you get tested and it's negative, which hopefully is better than the alternative of spreading.

Adbot
ADBOT LOVES YOU

dougdrums
Feb 25, 2005
CLIENT REQUESTED ELECTRONIC FUNDING RECEIPT (FUNDS NOW)
I was wondering what prevented someone from getting a burner and wandering around downtown then reporting positive.

Well the only two apps I could find are for RI and the dakotas, the RI one straight up doesn't work for me (as in, it thinks I'm offline for some reason and refuses to work), and the dakotas one requires a health authority to enable the reporting button. I'm thinking that there's a chance you could still send the request some other way though, and it wouldn't be checked against whether you're allowed.

Both apps still require location permissions, so the bluetooth data is just additional info to confirm proximity. Doesn't solve the 'passing in a car' problem though. Either way, getting tested from that sort of false positive doesn't seem harmful. Seems better to use the app data to narrow down the scope of who needs tested rather than shotgunning them out.

~Coxy posted:

Even if there's edge cases, the worst case is presumably that you get tested and it's negative, which hopefully is better than the alternative of spreading.
Yeah, still seems useful for conserving tests.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
there are lots of regional apps that don’t use the google/apple api and instead do actual location tracking on their own which gets sent to the cloud and nsa

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

I’m not too concerned about podunkville’s app siphoning location data to the NSA when the dozen ad networks in candy crush collect location data and tower data aggregators are available to any LEO or bail bondsman?

https://thehill.com/homenews/senate/503760-irs-used-cell-phone-data-to-try-to-track-potential-suspects-report?amp

I expect the governor’s cousin’s app shop leaking unanonymized travel history through unsecured S3 buckets is an inevitability, though.

Jenny Agutter
Mar 18, 2009

what the gently caress is the point of the authenticator app??

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I’d hope high scrutiny of any case that invokes the recovery phone, but hope is not a strategy really.

Shame Boy
Mar 2, 2010

Jenny Agutter posted:

what the gently caress is the point of the authenticator app??


i think when you implement this kinda thing you either need to accept that because you're going to have a lot of people who lose their phone you have to have a system set up where you can properly verify their identity via a good customer support team, or you have to just give up and make it trivially easy to defeat the whole thing. being ubisoft it's unsurprising they chose the cheaper easier option

BlankSystemDaemon
Mar 13, 2009




yeah, i yelled at ubisoft support on twitter about it (to no surprise, they apparently don't care to do something about it when you're just a nobody like me), but they could at least give the option of giving people recover keys if people think they're smart enough to handle it?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

D. Ebdrup posted:

yeah, i yelled at ubisoft support on twitter about it (to no surprise, they apparently don't care to do something about it when you're just a nobody like me), but they could at least give the option of giving people recover keys if people think they're smart enough to handle it?

Think of the dumbest person you know who plays video games, then imagine someone even dumber. That's who they have to design for.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Volmarias posted:

Think of the dumbest person you know who plays video games, then imagine someone even dumber.

my monitor is already off

Raere
Dec 13, 2007

you see, Availability is one third of the CIA triad, so when you compromise security to prioritize availability to users, you are actually doing the right thing

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Shame Boy posted:

i think when you implement this kinda thing you either need to accept that because you're going to have a lot of people who lose their phone you have to have a system set up where you can properly verify their identity via a good customer support team, or you have to just give up and make it trivially easy to defeat the whole thing. being ubisoft it's unsurprising they chose the cheaper easier option

doesnt google do the exact same thing with their stuff?

Applebees
Jul 23, 2013

yospos

spankmeister posted:

radio waves can do weird things.

yeah like give you COVID

Soricidus
Oct 21, 2010
freedom-hating statist shill

Shame Boy posted:

i think when you implement this kinda thing you either need to accept that because you're going to have a lot of people who lose their phone you have to have a system set up where you can properly verify their identity via a good customer support team, or you have to just give up and make it trivially easy to defeat the whole thing. being ubisoft it's unsurprising they chose the cheaper easier option

ok sure but you just know the phone number they provided is gonna be the phone they lost

Vomik
Jul 29, 2003

This post is dedicated to the brave Mujahideen fighters of Afghanistan
a Ubisoft account is the kind of thing you could leave out on the curb and only the trash collectors would take it

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Lain Iwakura posted:

Oh. It's just another "crazy, lying bitch". He's innocent, everybody.

In any event, I don't want to contribute to him abusing women or his children further. Y'all know where I post (Twitter) but if there is a Discord ever for YOSPOS specifically I'll join it.

Wiggly Wayne DDS
Sep 11, 2010



we've had the irc running forever but if anyone cares to have a dedicated discord yell about it

even if it's just to keep in touch for a migration or whatever

Shame Boy
Mar 2, 2010

Wiggly Wayne DDS posted:

we've had the irc running forever but if anyone cares to have a dedicated discord yell about it

even if it's just to keep in touch for a migration or whatever


https://forums.somethingawful.com/showthread.php?threadid=3919429

someone beat you to it

Wiggly Wayne DDS
Sep 11, 2010



oh i wasn't offering to do it just putting it forward

ty for the link

Shame Boy
Mar 2, 2010

echi woke up and made some mods so the discord is getting a bit more bearable fyi

there's even a secfuck channel now

Agile Vector
May 21, 2007

scrum bored



Shame Boy posted:

echi woke up and made some mods so the discord is getting a bit more bearable fyi

there's even a secfuck channel now

they should call it the side channel

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Agile Vector posted:

they should call it the side channel

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Agile Vector posted:

they should call it the side channel

:perfect:

BlankSystemDaemon
Mar 13, 2009




Shame Boy posted:

echi woke up and made some mods so the discord is getting a bit more bearable fyi

there's even a secfuck channel now
there's something quite zen about the dissonance of a secfuck channel on discord given the opsec issue that discord has

Soricidus
Oct 21, 2010
freedom-hating statist shill
dogfooding the secfucks

jre
Sep 2, 2011

To the cloud ?



Agile Vector posted:

they should call it the side channel

evil_bunnY
Apr 2, 2003


https://discord.gg/7sm9xN

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
this somehow seems appropriate for this thread

Truga
May 4, 2014
Lipstick Apathy
narrator: the phones themselves are tracking apps, no installation needed

Pile Of Garbage
May 28, 2007



Agile Vector posted:

they should call it the side channel

Brute Squad
Dec 20, 2006

Laughter is the sun that drives winter from the human race

I remember seeing a secfuck presentation video here on industrial systems that was basically a guy scanning for unsecured networks and seeing what kind of scada systems popped out. Some of the memorable ones included a refinery in canada and a foundry in france. But I'm not finding the video anymore. Anyone else remember this video?

Midjack
Dec 24, 2007



Brute Squad posted:

I remember seeing a secfuck presentation video here on industrial systems that was basically a guy scanning for unsecured networks and seeing what kind of scada systems popped out. Some of the memorable ones included a refinery in canada and a foundry in france. But I'm not finding the video anymore. Anyone else remember this video?

there was a vnc roulette thing that got one of the earlier secfuck threads closed.

ewiley
Jul 9, 2003

More trash for the trash fire
Serious and sadly relevant secfuck
https://techcrunch.com/2020/06/25/aspire-app-dr-phil/

quote:


Aspire News, which claims over 300,000 downloads, is disguised to look
like an innocuous news reading app that domestic violence victims can use
to alert friends and family to abuse or danger. When a victim taps the top
bar of the app three times, the app can alert trusted contacts with a
prewritten message, a prerecorded voice note and the victim’s precise
location by text message to indicate that they need help or are in danger.

But a security lapse meant that those uploaded voice recordings were left
exposed on an unprotected cloud server for anyone to access.

...

The cloud server contained over 4,000 recordings, dating back to September 2017. The recordings varied in length and nature, but some contained personally identifiable information, such as their name, address and phone number — information that could be relayed to the emergency services.

At least one recording we listened to explicitly stated the name of the victim’s abuser.


:stonk:

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Midjack posted:

there was a vnc roulette thing that got one of the earlier secfuck threads closed.

that had a twitter and everything, didn't it?

it was hilarious and also a terrible idea.

Wiggly Wayne DDS
Sep 11, 2010



there's still posts in the older threads covering some of the vnc roulettes that popped up

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


ugh

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang




ugh

at least maybe an abusers name got leaked i guess.

CmdrRiker
Apr 8, 2016

You dismally untalented little creep!

https://developer.apple.com/videos/play/wwdc2020/10047

App control for DOH. That's neat.

Zlodo
Nov 25, 2006

D. Ebdrup posted:

yeah, i yelled at ubisoft support on twitter about it (to no surprise, they apparently don't care to do something about it when you're just a nobody like me), but they could at least give the option of giving people recover keys if people think they're smart enough to handle it?

that's what they used to do, they only added the phone number stuff relatively recently

Adbot
ADBOT LOVES YOU

fins
May 31, 2011

Floss Finder

Brute Squad posted:

I remember seeing a secfuck presentation video here on industrial systems that was basically a guy scanning for unsecured networks and seeing what kind of scada systems popped out. Some of the memorable ones included a refinery in canada and a foundry in france. But I'm not finding the video anymore. Anyone else remember this video?

wayback machine didn't save much from vncroulette, but here's some choice ones from a similar site from the era, compliments archive.org







bonus link from when vncroulette got hacked

https://web.archive.org/web/20160401213748/http://vncroulette.com/

e: one of the above seems like it's still up. whilst i'll ping the poop, I aint touching it.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply