Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Fuzzy Mammal
Aug 15, 2001

Lipstick Apathy

Powaqoatse posted:

yea the latter i guess

e: well 15k is outside my lol budget

just sign up to be an uber driver lol

Adbot
ADBOT LOVES YOU

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Fuzzy Mammal posted:

just sign up to be an uber driver lol

maybe i should sign you up

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Powaqoatse posted:

yea the latter i guess

e: well 15k is outside my lol budget

pretty sure you're not eligible to apply since you're not 'murican

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Munkeymon posted:

pretty sure you're not eligible to apply since you're not 'murican

yeah probably not

can you do a foia request against the nsa/cia as a non-citizen lol

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



hobbesmaster posted:

it's both

yes those are at odds with each other

they wouldn't be if weak kneed defeatocrats hadn't allowed the export of dangerous weapons like cryptography :beck:

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Powaqoatse posted:

yeah probably not

can you do a foia request against the nsa/cia as a non-citizen lol

Actually, there was a bit on On the Media a couple of weeks ago saying that a large chunk of FOIA requests are from foreigners and that they are allowed. Can't speak for what you might get from the NSA/CIA though...

WrenP-Complete
Jul 27, 2012

Yeah, usually your job pays for your security clearance. Not usually a job applicant expense.

A Man With A Plan
Mar 29, 2010
Fallen Rib

Powaqoatse posted:

yeah probably not

can you do a foia request against the nsa/cia as a non-citizen lol

I mean you can

They'll laugh and say not a fuckin chance tho

E: current drug policy for all TS clearance, afaik, is not within a year of applying. Past use is generally fine if you weren't like, a dope fiend or dealing

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

funny Star Wars parody posted:

I just heard the FBI is considering loosening their drug policy because they can't find any tech people who don't smoke weed

in a year from now canada will have the best cyber intelligence in the world

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

WrenP-Complete posted:

Yeah, usually your job pays for your security clearance. Not usually a job applicant expense.
that's why they love it when your clearance is still active

PIZZA.BAT
Nov 12, 2016


:cheers:


Powaqoatse posted:

yea the latter i guess

e: well 15k is outside my lol budget

also security clearances aren't something you can just 'get'

there has to be an immediate and specific need in the federal gov't for you to get the clearance. usually a specific project that needs to be staffed.

lord of the files
Sep 4, 2012

Speaking of.

https://www.privateinternetaccess.com/blog/2017/04/nato-warns-ipv6-security-concerns-network-intrusion-detection-systems-may-miss/

NATO tried IPv6, and it broke everything.

The world is not ready.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



i know itd just be fun to have a piece of paper on official intelligence letterhead saying "yea this kid is a goddamned commie and probably smoked weeed"

Asshole Masonanie
Oct 27, 2009

by vyelkin

Shaggar posted:

that doesn't make any sense. the NSAs job is to improve the safety and security of the united states

i guess this would be the first time anyone ever did work outside their job description

spankmeister
Jun 15, 2008






https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk/


quote:

Most of the exploits that were disclosed fall into vulnerabilities that are already patched in our supported products. Below is a list of exploits that are confirmed as already addressed by an update. We encourage customers to ensure their computers are up-to-date.

Code NameSolution“EternalBlue”Addressed by MS17-010“EmeraldThread”Addressed by MS10-061“EternalChampion”Addressed by CVE-2017-0146 & CVE-2017-0147“ErraticGopher”Addressed prior to the release of Windows Vista“EsikmoRoll”Addressed by MS14-068“EternalRomance”Addressed by MS17-010“EducatedScholar”Addressed by MS09-050“EternalSynergy”Addressed by MS17-010“EclipsedWing”Addressed by MS08-067

 

Of the three remaining exploits, “EnglishmanDentist”, “EsteemAudit”, and “ExplodingCan”, none reproduces on supported platforms, which means that customers running Windows 7 and more recent versions of Windows or Exchange 2010 and newer versions of Exchange are not at risk. 


Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



quote:

EnglishmanDentist

mods, pls!

vOv
Feb 8, 2014

it's interesting that all of the names start with E

cinci zoo sniper
Mar 15, 2013




vOv posted:

it's interesting that all of the names start with E

Edward Snowden

makes u think

Diva Cupcake
Aug 15, 2005


so shadowbrokers waited until the last of the lot were patched on Tuesday. responsible disclosure imo.

spankmeister
Jun 15, 2008






Diva Cupcake posted:

so shadowbrokers waited until the last of the lot were patched on Tuesday. responsible disclosure imo.

Yes they waited until the vulns had zero value to them.

Wiggly Wayne DDS
Sep 11, 2010



so given ms17-010 affected windows 10 and was patched march 14 should we read into the cancellation of february's update? the fix for this smb 0day was put to the side despite it being public then, so what happened

right now the spokesperson isn't being forthcoming at all, and no one is credited for ms17-010

spankmeister
Jun 15, 2008






Wiggly Wayne DDS posted:

so given ms17-010 affected windows 10 and was patched march 14 should we read into the cancellation of february's update? the fix for this smb 0day was put to the side despite it being public then, so what happened

right now the spokesperson isn't being forthcoming at all, and no one is credited for ms17-010

wasn't the february update the first one in the new style? i got the distinct impression that MS itself had to get used to their own new process

WrenP-Complete
Jul 27, 2012

spankmeister posted:

wasn't the february update the first one in the new style? i got the distinct impression that MS itself had to get used to their own new process

this is one of the most profound things i have ever read on yospos

Shaggar
Apr 26, 2006

spankmeister posted:

EnglishmanDentist

ah so these were non-existent exploits to begin with

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



spankmeister posted:

Yes they waited until the vulns had zero value to them.

same thing though

the real issue is nsa or whoever not giving pointers to ms &c that there were exploits in the wild for more than a year?

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

Powaqoatse posted:

same thing though

the real issue is nsa or whoever not giving pointers to ms &c that there were exploits in the wild for more than a year?

why the gently caress would they?

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



their tools were blown so why not be a comrade to your own country eh

A Man With A Plan
Mar 29, 2010
Fallen Rib
Well the thing is the nsa is never going to claim ownership of any of this. So even if they did notify microsoft, you can bet part of the terms would be to not reveal they had any part in it.

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

Also, the exploits were still useful to them anyway.

Just cause someone has your kit doesn't mean you burn your tools.

Like, they could still use them despite knowing someone has access to them. Ethically questionable. But this is the NSA we're talking about so......

Podima
Nov 4, 2009

by Fluffdaddy

Shaggar posted:

ah so these were non-existent exploits to begin with

heh

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Rex-Goliath posted:

also security clearances aren't something you can just 'get'

there has to be an immediate and specific need in the federal gov't for you to get the clearance. usually a specific project that needs to be staffed.

and then you have to have a bunch of infrastructure to "hold" the clearance, etc., it's a huge expensive pain in the rear end

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

anthonypants posted:

judging by how long some of them held on to sha-1 issuance, i think you'll be waiting a while. if any did, it would increase the level of complexity by offering more choices, and historically people don't do too well with more choices. plus if anyone got an ecdsa cert because they read it was higher security, and then put it on like their storefront domain they would get very unhappy with the ca when customers complain about being unable to shop

it's a private link between our app and our server appliance! I want ecdsa because I want certificate based authentication of clients and ecdsa is what the iphone's built-in crypto token supports. but it seems there's several CAs that will issue them!

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
http://www.cbc.ca/news/canada/montreal/hp-tech-company-data-breach-scam-1.4067975

quote:

When Montrealer Hamid Shirdastian alerted tech company HP Inc. to a possible scam earlier this month, the company admitted to him it had been hacked, he told CBC and then asked him for $100 to try to fix the problem.

You keep being you, HP

FCKGW
May 21, 2006


lol gg guys

also it sounds like they lost product registration info. never register your product with any company of you can help it

Dodoman
Feb 26, 2009



A moment of laxity
A lifetime of regret
Lipstick Apathy
Notepad++ 7.3.3 bug-fixs & enhancements:

1. Fix CIA Hacking Notepad++ issue (https://wikileaks.org/ciav7p1/cms/page_26968090.html)
2. Fix mouse wheel to task list scroll crash bug.
3. Fix flickering issue while switching back after modifying or deleting a document from outside.
4. Support Motorola S-Record, Intel and Tektronix extended hex file formats.
5. Improve multi-line tab: maintaining the selected tab position.
6. Fix add char into word char list bug.
7. Add Shift+Enter in Find dialog for searching in the opposite direction.
8. Fix a regression that delimiter settings is not retained correctely.
9. Add clear command button in shortcut mapper.
10. Enhancement: file extension supported in Load/Save Session dialog if a session file extension is set.

spankmeister
Jun 15, 2008






Nice way to make yourself not look like an idiot because you had a bog-standard DLL hijacking vulnerability.

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

Optimus_Rhyme posted:

Also, the exploits were still useful to them anyway.

Just cause someone has your kit doesn't mean you burn your tools.

Like, they could still use them despite knowing someone has access to them. Ethically questionable. But this is the NSA we're talking about so......

if you were feeling particularly :tinfoil: you could say they released these themselves to muddy the waters if they get caught out in the future, i mean even though they've all been patched now these vulns are still going to be usable over a distressing amount of the internet for years to come

(i don't believe that of course but it's always fun to think that way)

Pile Of Garbage
May 28, 2007



i do all my hacking from the most weird domains, ones that would be extremely awkward for a prosecutor to read out

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

cheese-cube posted:

i do all my hacking from the most weird domains, ones that would be extremely awkward for a prosecutor to read out

they'll never find me because I come from IIIlllIIlIliiilillIlllIlll.com

Adbot
ADBOT LOVES YOU

Pile Of Garbage
May 28, 2007



brb registering

  • Locked thread