Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Midjack
Dec 24, 2007



Cocoa Crispies posted:

why is this in this thread

security-> cliff stoll -> tech is bad -> is any tech unalloyed good? -> twitter thread of dubious opinions

how we got here, anyway.

Adbot
ADBOT LOVES YOU

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Cocoa Crispies posted:

why is this in this thread

redleader
Aug 18, 2005

Engage according to operational parameters

Cocoa Crispies posted:

why is this in this thread

gotta post somewhere

Celexi
Nov 25, 2006

Slava Ukraini!
I think we need a new thread.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Celexi posted:

I think we need a new thread.

that was an oops not a panic

Storysmith
Dec 31, 2006

youre right, let’s get back on topic with something nice and uncontroversial like linux’s random number generation semantics and entropy: https://research.nccgroup.com/2019/12/19/on-linuxs-random-number-generation/

Feisty-Cadaver
Jun 1, 2000
The worms crawl in,
The worms crawl out.

Soricidus posted:

anal uterus

please do not buzz market my grindcore band thx

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Storysmith posted:

youre right, let’s get back on topic with something nice and uncontroversial like linux’s random number generation semantics and entropy: https://research.nccgroup.com/2019/12/19/on-linuxs-random-number-generation/

linus'd again

flakeloaf
Feb 26, 2003

Still better than android clock

Cocoa Crispies posted:

why is this in this thread

iostream of consciousness

motoh
Oct 16, 2012

The clack of a light autocannon going off is just how you know everything's alright.
https://twitter.com/byourseff/status/1209562375478743040

infosec has kayfabe?

Midjack
Dec 24, 2007




table drop off the top rope

Potato Salad
Oct 23, 2014

nobody cares


murray xyzmas


waoh what the ff :dogout:

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

https://twitter.com/todayininfosec/status/1209958197034913797

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
put Kevin back

The Sponge
Sep 15, 2006
Grimey Drawer

:iceburn:

Partycat
Oct 25, 2004

just set a back door with this door stop

Schadenboner
Aug 15, 2011

by Shine
Mitnick seems like one of the most “high on his own supply” (as the kids say these days) guys ever, tbh?

:shrug:

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
he's cool because all his work was just social engineering

Media Bloodbath
Mar 1, 2018

PIVOT TO ETERNAL SUFFERING
:hb:
I too am surprised that a con man would make any over the top claims.

Shame Boy
Mar 2, 2010

i got a security camera for my wife for christmas since she asked for it cuz we can't see who's at the door easily. i explicitly got an IP camera that can just work with a NAS and doesn't need cloud bullshit because yeah no.

i wasn't expecting much from the firmware but boy is this thing fun. first of all, in order to view the video at all if the firmware is earlier than a certain date, you need to install a chrome app that opens in a completely separate window and demands a ton of permissions. however once the firmware is updated to the latest version, the chrome app stops working entirely (and hasn't been updated since 2017 so it will never work again) so installing it was pointless. they did in fact make the web ui capable of showing the video so you don't need the stupid app, so that's some kind of improvement i guess

anyway i go to make an account and it does that loving thing where it prevents you from pasting in a password, both in the user creation area and in the normal login screen and everywhere else a password is used. great, thanks.

it's also an entirely javascript ui that's poorly written to boot so you can't just hit enter on any forms (even the login form), you have to click the button. that one's not a security issue i just loving hate developers that do that.

it supports HTTPS... sort of. you can hit a button to "generate a certificate request", and then download it, and instead of a cert request you just get the public key (??). there's absolutely no way to actually get a CSR out of this thing as far as I can tell. fine, whatever. i generate a certificate externally and upload the public/private pair, and that works fine (after throwing an error saying it failed, of course). except, there's absolutely no way to turn off normal HTTP access, or any of the other insecure protocols it supports, or make it redirect to HTTPS or anything, you just have to remember to always go to https, great. at least it supports EC. it's also by default trying to forward all its sensitive, juicy unencrypted ports via upnp because of course it is

anyway time to set up the external storage. it supports two modes for this, "FTP" and "NAS". i assumed "NAS" would be like, a samba share or something, but no it's some weird Synology-specific thing, so that's out. so the only option for file storage is plain old unencrypted FTP. great :toot:

i mean i know it's consumer-grade garbage and 99% of people are just going to buy the cloud service anyway but maaan

e: also it only supports ipv4 or ipv6, not both, i have no idea why or how they even did that

Shame Boy fucked around with this message at 16:36 on Dec 26, 2019

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
if it's anything like the other generic ip cams i've seen it almost certainly doesn't do any kind of firmware validation, so you could probably grab an update file, dump it with binwalker, hack out everything but rtsp or whatever and flash it to the device if you wanted to

they're usually just an embedded linux kernel, a minimal shell, and some poorly configured services hung together with some jank-rear end scripts

infernal machines fucked around with this message at 16:54 on Dec 26, 2019

mystes
May 31, 2006

Just make sure to roll your own image classifier to detect "suspicious*" people.

*: Please consult your lawyer before attempting to define this word.

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

mystes posted:

Just make sure to roll your own image classifier to detect "suspicious*" people.

*: Please consult your lawyer before attempting to define this word.

one of my earliest gigs was working on consumer in-vehicle navigation systems and we were introducing the ability to avoid "bad neighborhoods" when routing and a bunch of cities complained to us so we halted the feature.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
let me guess, the complaints came from the wealthy people suddenly having through traffic routed through their sleepy quiet neighbourhoods?

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
no it was cities with high crime rates complaining that were going to make people avoid their cities.

Midjack
Dec 24, 2007



CRIP EATIN BREAD posted:

no it was cities with high crime rates complaining that were going to make people avoid their cities.

lmao

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
i can understand people being offended by that but also i can understand maybe lowering the risk of a carjacking of a customer by taking a less-than-optimal route.

navigation algorithms get extremely complex because just using a cost function of "number of seconds to traverse" isn't always the best. this was before every cellphone in the world had nav software, but the consumer market was getting extremely crowded, so every little feature you could add to the router was something you could slap on the box.

klafbang
Nov 18, 2009
Clapping Larry
Didn't Google just recently add a "please don't rape me" function to Maps for pedestrians?

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
possibly. the company i worked for backed down just because they didn't expect the cities to get upset over it. there wasn't any possible backlash we could face, just didn't want to be jerks.

google doesn't seem to care, though.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
tbh, a group of programmers deciding what neighbourhoods/cities to further disadvantage by algorithmic fiat generally isn't a great look

klafbang
Nov 18, 2009
Clapping Larry
It seems it was mostly rumors based on deactivated functionality in some Android firmware. I can see why the feature is controversial, but I have also myself wanted such a feature when walking in unfamiliar areas.

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

infernal machines posted:

tbh, a group of programmers deciding what neighbourhoods/cities to further disadvantage by algorithmic fiat generally isn't a great look

we just pulled stats of carjackings in areas and used that. all the locations that we would have avoided didn't have anywhere to stop, anyways, it was generally just locations with huge stretches of abandoned buildings etc.

most of the stuff we did was based on customer feedback.


once we got into the trucking nav business, guess what our #1 request was?

have the voice that gave you directions be a little naked lady on the screen.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

klafbang posted:

Didn't Google just recently add a "please don't rape me" function to Maps for pedestrians?

automatic incognito mode when it thinks google management is nearby?

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Cocoa Crispies posted:

automatic incognito mode when it thinks google management is nearby?

:five:

Progressive JPEG
Feb 19, 2003

Cocoa Crispies posted:

automatic incognito mode when it thinks google management is nearby?

google what?

mystes
May 31, 2006

klafbang posted:

It seems it was mostly rumors based on deactivated functionality in some Android firmware. I can see why the feature is controversial, but I have also myself wanted such a feature when walking in unfamiliar areas.
If it's literally just how well lit the streets are this could honestly be useful just in terms of not getting run over when the sidewalk crosses driveways, though.

Vomik
Jul 29, 2003

This post is dedicated to the brave Mujahideen fighters of Afghanistan

CRIP EATIN BREAD posted:

one of my earliest gigs was working on consumer in-vehicle navigation systems and we were introducing the ability to avoid "bad neighborhoods" when routing and a bunch of cities complained to us so we halted the feature.

yikes. racism the gps is a powerful feature. too powerful

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

My tomtom loved taking me through the worst parts of DC to save 3 minutes of travel time over 495. Thanks tom tom. thomtom.

Trabisnikof
Dec 24, 2005

CRIP EATIN BREAD posted:

we just pulled stats of carjackings in areas and used that. all the locations that we would have avoided didn't have anywhere to stop, anyways, it was generally just locations with huge stretches of abandoned buildings etc.

most of the stuff we did was based on customer feedback.


once we got into the trucking nav business, guess what our #1 request was?

have the voice that gave you directions be a little naked lady on the screen.

weird how no one has done this with traffic accidents instead, to take a safer route. since a car accident is far more likely than a hijacking.

Adbot
ADBOT LOVES YOU

dreamin of semen
Feb 22, 2013

MULTIPLICATION

Vomik posted:

yikes. racism the gps is a powerful feature. too powerful

global phrenology system

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply