Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Floodkiller
May 31, 2011

boop the snoot posted:

What’s the point of encrypting passwords if they can be stolen anyway

I thought encryption was literally invented to prevent that type of thing

Encryption just slows down how long it takes to get the actual password (by decrypting it), it's never foolproof. It is basically there to buy time for everyone to reset passwords so that the data is outdated by the time it is decrypted.

Adbot
ADBOT LOVES YOU

RFC2324
Jun 7, 2012

http 418

boop the snoot posted:

This is going to be a rabbit hole conversation because now my question is why even require passwords in 2021 if they’re not encrypted?

How do these companies even get off the ground?

Because alot of developers are idiots who feel the need to reinvent the wheel, badly, every time they do a thing, and encryption is actually pretty hard to do right.

And as to how... Did anyone stop to check? Twitch has an appealing product, and security was never advertised as part of it

E: do you think they encrypt your password recovery questions? The answer is no

hobbesmaster
Jan 28, 2008

RFC2324 posted:

Good chance they didn't encrypt if the paswords were stolen,

Don't assume any given site actually has good security, or even minimal security.

Its amazon, I'm sure they mean hashed passwords.

API keys for OBS/whatever though...

shame on an IGA
Apr 8, 2005

the russian space program has just been hurled into a cone of silence

https://arstechnica.com/science/2021/10/russia-tells-its-space-reporters-to-stop-reporting-on-the-space-program/

Hekk
Oct 12, 2012

'smeper fi

boop the snoot posted:

This is going to be a rabbit hole conversation because now my question is why even require passwords in 2021 if they’re not encrypted?

How do these companies even get off the ground?

Because passwords work fine until someone steals all of them and the monetary impact to a business from a data breach is less severe than the expense of protecting themselves against it.

Edit- also am pretty sure every CS student at any school is taught to hash and salt passwords. So hopefully it’s not as simple as using a hash table to decrypt everything.

Hekk fucked around with this message at 17:11 on Oct 6, 2021

Defenestrategy
Oct 24, 2010

Floodkiller posted:

Encryption just slows down how long it takes to get the actual password (by decrypting it), it's never foolproof. It is basically there to buy time for everyone to reset passwords so that the data is outdated by the time it is decrypted.

To clarify, if you force your users to use caps, specials, and numbers, AND your users don't tend to reuse passwords AND your users aren't using pre-cracked passwords [password123,admin,etc,etc] AND you are using a "secure" encryption algorithm AND salting your hash it can take an extremely long time to crack a password.

Without shortcuts even if your password is somewhere in RockYou.txt it can take a really really long time to crack.


If you're a big time streamer though, lol get wrekt because you're the first one anyones gonna try to crack.

Defenestrategy fucked around with this message at 17:22 on Oct 6, 2021

Arven
Sep 23, 2007
This is just pure speculation based off of personal professional observation, but the push for full stack devs everywhere and the phasing out of network and server specialists means that most of the stuff being developed in TYOL2021 is even more held together with paper clips and rubber bands than the years proceeding it. Just like everything on this planet, everything gets made shittier every year in the pursuit of making it cheaper with fewer employees.

hobbesmaster
Jan 28, 2008

Defenestrategy posted:

To clarify, if you force your users to use caps, specials, and numbers, AND your users don't tend to reuse passwords AND your users aren't using pre-cracked passwords [password123,admin,etc,etc] AND you are using a "secure" encryption algorithm AND salting your hash it can take an extremely long time to crack a password.

Without shortcuts even if your password is somewhere in RockYou.txt it can take a really really long time to crack.


If you're a big time streamer though, lol get wrekt because you're the first one anyones gonna try to crack.

This depends heavily though. If they used bcrypt properly this could take centuries. If they used md5 they've all already been decrypted.

Proud Christian Mom
Dec 20, 2006
READING COMPREHENSION IS HARD
working in IT i cannot tell you just how prevalent re-inventing the wheel is in relation to all things security

ASAPI
Apr 20, 2007
I invented the line.

boop the snoot posted:

This is going to be a rabbit hole conversation because now my question is why even require passwords in 2021 if they’re not encrypted?

How do these companies even get off the ground?

There is a case to be made that passwords, in the way they are now, need to go.

Also, does twitch do 2FA? If more people used things like that we would have way better security.

Queue the security expert telling me I am wrong and freaking me out with horror stories in 3....2....1...

RFC2324
Jun 7, 2012

http 418

Proud Christian Mom posted:

working in IT i cannot tell you just how prevalent re-inventing the wheel is in relation to all things security

Its the first thing every cs grad tries after graduation, as far as I can tell.

And then they implement it in the random start up they got hired at because they were cheap, the startup strikes it big, and you have bubblegum for security on a major site that everyone uses.

Never trust a company that has never been hacked. Either they are lying, or the holes in their security are still unknowns

Defenestrategy
Oct 24, 2010

ASAPI posted:

There is a case to be made that passwords, in the way they are now, need to go.

Also, does twitch do 2FA? If more people used things like that we would have way better security.

Queue the security expert telling me I am wrong and freaking me out with horror stories in 3....2....1...

No, 2FA is good, so long as it isn't SMS based.

Raerlynn
Oct 28, 2007

Sorry I'm late, I'm afraid I got lost on the path of life.

Arven posted:

This is just pure speculation based off of personal professional observation, but the push for full stack devs everywhere and the phasing out of network and server specialists means that most of the stuff being developed in TYOL2021 is even more held together with paper clips and rubber bands than the years proceeding it. Just like everything on this planet, everything gets made shittier every year in the pursuit of making it cheaper with fewer employees.

Ehhhhh... You've drawn the correct conclusion from the wrong premise.

Full stack developers are more popular because IT as a whole is moving towards hyper converged services for everything. For example a decade ago you would buy a SAN array for big storage, maintain a cluster of servers on prem, and pay employees to manage it all. Nowadays you can simply host in the cloud, and some platforms are all in one packages that you simply have off site support for.

Most of the stuff you see getting owned nowadays isn't some strange new never before seen attack vector - it's one or more attackers using either a vulnerability that the company wasn't patching to close, or someone with privileged rights was compromised (phishing, reused passwords, etc).

Since there's no real consequences beyond loss of public trust (and if you're big enough like Twitch is, you basically don't have to give a gently caress at all), it's not going to get any better until something puts the fear of God in companies.

Soylent Pudding
Jun 22, 2007

We've got people!


Defenestrategy posted:

To clarify, if you force your users to use caps, specials, and numbers, AND your users don't tend to reuse passwords AND your users aren't using pre-cracked passwords [password123,admin,etc,etc] AND you are using a "secure" encryption algorithm AND salting your hash it can take an extremely long time to crack a password.

Without shortcuts even if your password is somewhere in RockYou.txt it can take a really really long time to crack.


If you're a big time streamer though, lol get wrekt because you're the first one anyones gonna try to crack.

Also just fyi but the must use upper and lower case, numbers, and special characters is depreciated guidance. It turns out the psychology of human memory being what it is most people comply in easily predictable ways and it ends up juts aggravating people while at best not actually adding security.

A Bad Poster
Sep 25, 2006
Seriously, shut the fuck up.

:dukedog:
Not a fan of Twitch asking me to download yet another 2FA app if I want that on my account.

Proud Christian Mom
Dec 20, 2006
READING COMPREHENSION IS HARD

Raerlynn posted:

Since there's no real consequences beyond loss of public trust (and if you're big enough like Twitch is, you basically don't have to give a gently caress at all), it's not going to get any better until something puts the fear of God in companies.

its going to take insurance companies saying 'nope' to cyberinsurance claims since everyone is just punting on security and letting them eat the ransomware cost

hobbesmaster
Jan 28, 2008

A Bad Poster posted:

Not a fan of Twitch asking me to download yet another 2FA app if I want that on my account.

It supports either SMS or google autheticator/whatever other app you want.
https://help.twitch.tv/s/article/two-factor-authentication?language=en_US

RFC2324
Jun 7, 2012

http 418

Soylent Pudding posted:

Also just fyi but the must use upper and lower case, numbers, and special characters is depreciated guidance. It turns out the psychology of human memory being what it is most people comply in easily predictable ways and it ends up juts aggravating people while at best not actually adding security.

Passphrases are the way to go, since adding punctuation and spaces helps technical cracking aspect while still remaining usable.

The downside is some devices don't handle spaces in passwords, which sucks.

brains
May 12, 2004

ASAPI posted:

There is a case to be made that passwords, in the way they are now, need to go.

Also, does twitch do 2FA? If more people used things like that we would have way better security.

Queue the security expert telling me I am wrong and freaking me out with horror stories in 3....2....1...

twitch does have 2FA but i just checked and there is an option on the 2FA prompt to bypass the auth and get an SMS code, so rip.

facialimpediment
Feb 11, 2005

as the world turns
:siren: ATTENTION :siren:

If you work/worked in the public service sector and you still have student loans, look into this:

https://www.cnbc.com/2021/10/06/dept-of-ed-announces-public-service-loan-forgiveness-program-changes.html

https://studentaid.gov/announcements-events/pslf-limited-waiver

Bottom line: the Public Service Loan Forgiveness program has always been a pile of bullshit. It required you to make 10 years of very specific payments against very specific student loans to get your loans forgiven. Nobody ever made those kinds of payments (either splitting the payments into 20 years, or income-graduated). Apparently, they no longer give a gently caress and any payment at all counts.

So if you're a career fed, or served a lot in the military, look into this poo poo.

quote:

Qualifying for PSLF

To qualify for PSLF, you must be employed by a U.S. federal, state, local, or tribal government or not-for-profit organization (federal service includes U.S. military service);

work full-time for that agency or organization;

have Direct Loans (or consolidate other federal student loans into a Direct Loan);

repay your loans under an income-driven repayment plan*; and

make 120 qualifying payments.

*This provision will be waived through October 31, 2022 as part of the limited PSLF waiver.

So by my reading, I need to get my loving money and some of y'all also likely need to.

Raerlynn
Oct 28, 2007

Sorry I'm late, I'm afraid I got lost on the path of life.

Proud Christian Mom posted:

its going to take insurance companies saying 'nope' to cyberinsurance claims since everyone is just punting on security and letting them eat the ransomware cost

Even that's probably not enough - it probably becomes a calculated expense. It's really going to take getting poo poo on legally from such a height that you'd think it was God himself dropping that deuce to change that.

To put it in perspective - the Equifax breach was literally a case of being behind like 6 months on OS updates.

McNally
Sep 13, 2007

Ask me about Proposition 305


Do you like muskets?
Oh look, more reasons not to use AT&T

https://www.reuters.com/investigates/special-report/usa-oneamerica-att/

quote:

A Reuters review of court records shows the role AT&T played in creating and funding OAN, a network that continues to spread conspiracy theories about the 2020 election and the COVID-19 pandemic.

OAN founder and chief executive Robert Herring Sr has testified that the inspiration to launch OAN in 2013 came from AT&T executives.

“They told us they wanted a conservative network,” Herring said during a 2019 deposition seen by Reuters. “They only had one, which was Fox News, and they had seven others on the other [leftwing] side. When they said that, I jumped to it and built one.”

Since then, AT&T has been a crucial source of funds flowing into OAN, providing tens of millions of dollars in revenue, court records show. Ninety percent of OAN’s revenue came from a contract with AT&T-owned television platforms, including satellite broadcaster DirecTV, according to 2020 sworn testimony by an OAN accountant.

Marshal Prolapse
Jun 23, 2012

by Jeffrey of YOSPOS
https://twitter.com/bradheath/status/1445720929775067138?s=10

So basically AT&T created OANN. I wonder if they will still be funding it in the near future?

Efb

Mr. Nice!
Oct 13, 2005

bone shaking.
soul baking.
Friend of mine just said she saw news of a school shooting in Texas.

Also an oil tank in Texas City is busted and is spilling hundreds of thousands of gallons of crude onto the ground.

boop the snoot
Jun 3, 2016

Mr. Nice! posted:

Friend of mine just said she saw news of a school shooting in Texas.

Also an oil tank in Texas City is busted and is spilling hundreds of thousands of gallons of crude onto the ground.

So Wednesday.

ASAPI
Apr 20, 2007
I invented the line.

Mr. Nice! posted:

Friend of mine just said she saw news of a school shooting in Texas.

Also an oil tank in Texas City is busted and is spilling hundreds of thousands of gallons of crude onto the ground.

Apparently the school shooting started as a "normal" fight:

https://www.nbcdfw.com/news/local/lockdown-issued-at-timberview-high-in-arlington-possible-shots-fired/2759727/

RE: AT&T, They are my only option for internet in my neighborhood, so have to stick with them...

A Bad Poster
Sep 25, 2006
Seriously, shut the fuck up.

:dukedog:

ASAPI posted:


RE: AT&T, They are my only option for internet in my neighborhood, so have to stick with them...

Nice to see them going from one monopoly to another.

RFC2324
Jun 7, 2012

http 418

Raerlynn posted:

Even that's probably not enough - it probably becomes a calculated expense. It's really going to take getting poo poo on legally from such a height that you'd think it was God himself dropping that deuce to change that.

To put it in perspective - the Equifax breach was literally a case of being behind like 6 months on OS updates.

My company just onboarded a major telecom client, and when we saw how old the internet facing application we are managing for them was everyone collectively poo poo a brick and started screaming at sales for doing it

ElMaligno
Dec 31, 2004

Be Gay!
Do Crime!

Only sprint and AT&T will let me use my phone number from Puerto Rico, its one of the few things i have left from the island and i dont want to drop it
:negative:

That Works
Jul 22, 2006

Every revolution evaporates and leaves behind only the slime of a new bureaucracy


lmao

https://twitter.com/bradheath/status/1445730199635701760?s=20

CRUSTY MINGE
Mar 30, 2011

Peggy Hill
Foot Connoisseur
Isn't OAN being sued by Dominion?

I'd like to see Dominion go after ATT when they're done with OAN.

That Works
Jul 22, 2006

Every revolution evaporates and leaves behind only the slime of a new bureaucracy


https://twitter.com/nytimes/status/1444029375272325124

LtCol J. Krusinski
May 7, 2013

by Fluffdaddy

loving :lol:

hobbesmaster
Jan 28, 2008


I’m not sure what a more effective statement would look like.

boop the snoot
Jun 3, 2016
What is that woman staring at?

facialimpediment
Feb 11, 2005

as the world turns
1) Accept deal, give $ value equivalent to Trump Tax Cuts

https://twitter.com/LauraLitvan/status/1445814152598102019

2) In BBB Reconciliation package, set Debt Ceiling at eleventy trillion

facialimpediment fucked around with this message at 19:18 on Oct 6, 2021

As Nero Danced
Sep 3, 2009

Alright, let's do this

When I heard about this I thought it was a joke. Holy poo poo he pulled it off!

ElMaligno
Dec 31, 2004

Be Gay!
Do Crime!

boop the snoot posted:

What is that woman staring at?

Art

Duzzy Funlop
Jan 13, 2010

Hi there, would you like to try some spicy products?

boop the snoot posted:

What is that woman staring at?

"Take the money and run" - Nothing on canvas, 2021

Adbot
ADBOT LOVES YOU

TheWeedNumber
Apr 20, 2020

by sebmojo

Duzzy Funlop posted:

"Take the money and run" - Nothing on canvas, 2021

Everyone's been Reenlisted - No DD-214, 2021

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply