Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
evil_bunnY
Apr 2, 2003

4lokos basilisk posted:

i thought you guys were not supposed to use your work machines!
I’d go hungry before I work for the church lmao

Adbot
ADBOT LOVES YOU

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

dpkg chopra posted:

three factor authentication doesn’t work if all factors are the same

heh

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

These loss images are just getting more and more abstract.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
more like windows goodbye (security)

tl;dr: windows hello security devices are, in general, insecure in a bunch of ways that allow either bypassing them or generating valid tokens without the actual biometric factor. none of it is completely trivial, and you still have to have access to the device, but lol nonetheless.

haveblue
Aug 15, 2005



Toilet Rascal
windows hello.jpg

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

haveblue posted:

windows hello.jpg

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

haveblue posted:

windows hello.jpg

Crazy Achmed
Mar 13, 2001

you might say there's a wide open back door into your system

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Hackers can turn your computer into a bum

:yosbutt:

Midjack
Dec 24, 2007



haveblue posted:

windows hello.jpg

Shame Boy
Mar 2, 2010

haveblue posted:

windows hello.jpg

my brain already adds the .jpg every time i see "windows hello" which makes me giggle

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD
Windows Hello For Buttocks

sb hermit
Dec 13, 2016





haveblue posted:

windows hello.jpg

Potato Salad
Oct 23, 2014

nobody cares


infernal machines posted:

more like windows goodbye (security)

tl;dr: windows hello security devices are, in general, insecure in a bunch of ways that allow either bypassing them or generating valid tokens without the actual biometric factor. none of it is completely trivial, and you still have to have access to the device, but lol nonetheless.

between this and drive manufacturers constantly being found faithlessly implementing hardware level encryption, I don't know if you can trust hardware-anything for security critical applications

is a yubikey still safe or did they gently caress a duck too

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


haveblue posted:

windows hello.jpg

oh my god what's that man doing to his Asus?

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


attn:satan, you've hosed up your certs

Armitag3
Mar 15, 2020

Forget it Jake, it's cybertown.


Powerful Two-Hander posted:

attn:satan, you've hosed up your certs



peeved they aren’t using port 666

Carbon dioxide
Oct 9, 2012

Crazy Achmed posted:

you might say there's a wide open back door into your system

I thought modern CPU architectures use rings to prevent these kinds of issues?

sb hermit
Dec 13, 2016





Potato Salad posted:

between this and drive manufacturers constantly being found faithlessly implementing hardware level encryption, I don't know if you can trust hardware-anything for security critical applications

is a yubikey still safe or did they gently caress a duck too

to their credit, yubikeys just do one thing and they do it well

Shame Boy
Mar 2, 2010

sb hermit posted:

to their credit, yubikeys just do one thing and they do it well

they do a bunch of things and they already had one vulnerability that led to them shipping me an entirely new one after sending them a picture of my vulnerable one's serial number

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Carbon dioxide posted:

I thought modern CPU architectures use rings to prevent these kinds of issues?

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Powerful Two-Hander posted:

oh my god what's that man doing to his Asus?

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Carbon dioxide posted:

I thought modern CPU architectures use rings to prevent these kinds of issues?

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
seems like a gaping security flaw

mystes
May 31, 2006

sb hermit posted:

to their credit, yubikeys just do one thing and they do it well
The fido2 only ones do one thing. The other models are way more complicated

Last Chance
Dec 31, 2004

Powerful Two-Hander posted:

oh my god what's that man doing to his Asus?

post hole digger
Mar 21, 2011

Powerful Two-Hander posted:

oh my god what's that man doing to his Asus?

shackleford
Sep 4, 2006

Potato Salad posted:

between this and drive manufacturers constantly being found faithlessly implementing hardware level encryption, I don't know if you can trust hardware-anything for security critical applications

is a yubikey still safe or did they gently caress a duck too

not yubico but someone hosed up and put bluetooth in a security key design and had feitian manufacture it

https://security.googleblog.com/2019/05/titan-keys-update.html

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

quote:

An attacker in close physical proximity at that moment in time can potentially connect their own device to your affected security key before your own device connects. In this set of circumstances, the attacker could sign into your account using their own device if the attacker somehow already obtained your username and password and could time these events exactly.

I think my threat model is OK with me taking on that risk

Potato Salad
Oct 23, 2014

nobody cares


Powerful Two-Hander posted:

oh my god what's that man doing to his Asus?

MiniFoo
Dec 25, 2006

METHAMPHETAMINE

Powerful Two-Hander posted:

oh my god what's that man doing to his Asus?

cock solid, part/clutching

SlowBloke
Aug 14, 2017

Potato Salad posted:

is a yubikey still safe or did they gently caress a duck too

NXP just notified the world that they got hacked and the attacker kept accessing data, searching for chip schematics and microcode for several years.

https://arstechnica.com/security/2023/11/hackers-spent-2-years-looting-secrets-of-chipmaker-nxp-before-being-detected/

Several FIDO2 key makers, yubico included, uses NXP chips.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Subjunctive posted:

I think my threat model is OK with me taking on that risk

are you now or have you ever been ross ulbricht?

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

SlowBloke posted:

NXP just notified the world that they got hacked and the attacker kept accessing data, searching for chip schematics and microcode for several years.

https://arstechnica.com/security/2023/11/hackers-spent-2-years-looting-secrets-of-chipmaker-nxp-before-being-detected/

Several FIDO2 key makers, yubico included, uses NXP chips.

extremely lol

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


infernal machines posted:

are you now or have you ever been ross ulbricht?

god that poo poo was funny

Antigravitas
Dec 8, 2019

Die Rettung fuer die Landwirte:
https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/

quote:

Delete the file owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php. Additionally, we disabled the phpinfo function
in our docker-containers.

Classic.

Trabisnikof
Dec 24, 2005

own cloud indeed

git apologist
Jun 4, 2003

lmao @ getphpinfo, that is something most people sorted in like 2004. great job everyone

mystes
May 31, 2006

I thought owncloud had been migrating away from php

Adbot
ADBOT LOVES YOU

Last Chance
Dec 31, 2004


Lol.. does this mean that the unit tests are just like sitting in the instance ready to be accessed from the web?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply