Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe
Ground floor has anime and Sulk. We are off to a great start, people.

Adbot
ADBOT LOVES YOU

Ireland Sucks
May 16, 2004

Subjunctive posted:

can we continue the discussion about why security people tend towards being dicks?

Because they tend to look like

Sharktopus
Aug 9, 2006

"security people" and the "security mindset" both reward pedantry

Sharktopus
Aug 9, 2006

Ireland Sucks posted:

Because they tend to look like



not sure why people are hating on this guy...

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Sharktopus posted:

"security people" and the "security mindset" both reward pedantry

if we've learned anything it's that software absolutely needs to be pedantic to not get exploited

Sharktopus
Aug 9, 2006

Captain Foo posted:

if we've learned anything it's that software absolutely needs to be pedantic to take longer to get exploited

ftfy

carry on then
Jul 10, 2010

by VideoGames

(and can't post for 10 years!)

Sharktopus posted:

"security people" and the "security mindset" both reward pederasty

minivanmegafun
Jul 27, 2004

hey guys, I just want to announce that I am lurking the security thread as usual

I can answer questions about running a CA i guess. the secret is a lot of auditing and record keeping.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

minivanmegafun posted:

hey guys, I just want to announce that I am lurking the security thread as usual

I can answer questions about running a CA i guess. the secret is a lot of auditing and record keeping.

I would like to know more

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

yeah, I think it's probably related to the gotcha/adversarial nature of a lot of the work. now-wife noticed when I stopped doing security stuff full-time, back when dinosaurs and fwtk roamed the earth, because I was nicer to be around. I stopped basically because the security space (mostly firewalls at the time; IDS was the motion detector in the server room) was toxic enough that I was grumpy all day. I can't help but think that we'd be in a better state security-wise if it was more pleasant to interact with the average security professional.

pr0zac is p chill, though, which is true of the FB team as a whole AFAICT.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

minivanmegafun posted:

I can answer questions about running a CA i guess. the secret is a lot of auditing and record keeping.

what do you think of the let's encrypt stuff?

Sharktopus
Aug 9, 2006

an adversarial process is necessary for security in any sense. diversification being the only free lunch running this process in more than one brain is typically beneficial. add egos, lack of tact, and lack of argumentative charity and you get a pretty good idea why security people are the way they are

minivanmegafun
Jul 27, 2004

Captain Foo posted:

I would like to know more
ok

Subjunctive posted:

what do you think of the let's encrypt stuff?

i think it's pretty cool, though automated certificate approval has its own possible headaches. consideration has to be taken as to how to validate that a given domain name belongs to a certain party before signing a CSR, though it's not like the way most CAs handle it ("Here, take this random string and put it in caprovider.txt in your webroot and we'll fetch it over HTTP in the clear!) is a whole lot better.

there's a possible conflict of interest between web browser distributors being closely linked to a CA, but it's not like that situation doesn't already exist.

if this has legs, it could possibly allow let's encrypt to say "lol f u" to webtrust's regulations, which may or may not be a good thing. I imagine most extant CAs will stay in business as EV certs ("green bars") can't be subjected to automated approval; some human has to actually review business records and validate contact information to make sure you are who you say you are. I guess Let's Encrypt could generate revenue from that aspect if they wanted to.

the SSL CA stuff is a rather small part of our business so we don't really see it as a threat to our revenue as far as i am aware.

though, to be entirely honest, i'm not sure dumbing down the certificate process is A Good Thing. I haven't read deeply into ACME yet, but really for an end-user server operator the entire process of getting a key generated, a cert signed, and installed really isn't all that complex.

vOv
Feb 8, 2014

what kinda security do you have the actual signing material under

minivanmegafun
Jul 27, 2004

vOv posted:

what kinda security do you have the actual signing material under

stored on a hardware HSM, behind a locked door that needs two keycards to open that are held by a very small subset of people, system has no outside access other than an API that signs certs.

e: and "outside" in this context is "outside of the CA's network, where the application that process CSR requests from the UI application that end users use is", not the outside world

minivanmegafun fucked around with this message at 04:56 on Nov 29, 2014

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



is it like those bank boxes so the cards have to be slid through simultaneously? thatd be cool

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.

vOv
Feb 8, 2014


lmao

quote:

The film was tentatively titled Cyber


also i'm trying to figure out how they go from 3.5 minutes for an 8-character password to 15 hours for 8 characters + 1 uppercase

vOv fucked around with this message at 05:49 on Nov 29, 2014

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
cyber in theaters this cyber monday

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



please dont cyber in public

Sassafras
Dec 24, 2004

by Athanatos
.

Sassafras fucked around with this message at 21:37 on Nov 29, 2014

vOv
Feb 8, 2014

Sassafras posted:

26^8 vs 52^8, the latter is 256 times the former, and so is 15 hrs vs 3.5 mins

ah they're including any number of uppercase characters

spankmeister
Jun 15, 2008






Peanut and the Gang posted:

+---------------------------------------------------+
| An impromptu security story: Defeating the hackers. |
+---------------------------------------------------+

Oh no! The hackers are here!




They're stealing our lunch money!


         Gimme ur lunch money, punk!
                        \



     Noo! Noooooo!
          ]



 Ha ha ha! I'm downloading your lunch money as we speak!
                       \



          Somebody, please save us!! Somebody help!
                                       \



Don't worry guys! Linux is here to save the day!


I know how to use iptables to defeat the hackers!
      \




# sudo iptables --policy INPUT DROP



  Now they can't attack us!
        \



                    eff you, hackers!
                           \



Good job linux! you saved the day!



                              Thank you LInux. Thank you computer.
                                     \

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Remember that zpanel guy
http://forums.somethingawful.com/showthread.php?threadid=3289126&pagenumber=91&perpage=40#post438278615

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Lol

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Peanut and the Gang posted:

Good job linux! you saved the day!



                              Thank you LInux. Thank you computer.
                                     \


Lol

Elysiume
Aug 13, 2009

Alone, she fights.
in 17 years I change my password to P@ssword2

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

lol gold

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe

Super Dangar Ronpa

theadder
Dec 30, 2011


syscall girl posted:

it was just a google search that highlighted routers that had default passwords

remember when we used to have whole threads for publicly accessible webcams :allears:

sounds about par for the course op

CISADMIN PRIVILEGE
Aug 15, 2004

optimized multichannel
campaigns to drive
demand and increase
brand engagement
across web, mobile,
and social touchpoints,
bitch!
:yaycloud::smithcloud:
i think security people are dicks because they're generally either payed to be ignored or to fix things when something goes really wrong.

fwiw osi been dip is a nice guy irl.

spankmeister
Jun 15, 2008






i know a lot of nice security people but also a lot of really annoying spergy assholes

Tayter Swift
Nov 18, 2002

Pillbug
compare and contrast: brian krebs vs the folks who comment on his blog

spankmeister
Jun 15, 2008






hackernews posters

Acer Pilot
Feb 17, 2007
put the 'the' in therapist

:dukedog:


i hope this is logging passwords

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.

Acer Pilot posted:

i hope this is logging passwords
it's not an app, that's the actual image they distributed

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
if the password is actually P@ssword1 it should take a few seconds honestly

Luigi Thirty
Apr 30, 2006

Emergency confection port.

someone call the gangster computer god

Gooble Gobble
May 2, 2011

One of us
https://www.youtube.com/watch?v=jZ1ZDlLImF8

Adbot
ADBOT LOVES YOU

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

i guess a gunfight on a crowded street is more exciting than cops arresting a guy who starts shouting about gold fringes on flags while getting tazed.

  • Locked thread