Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Last Chance
Dec 31, 2004

sarehu posted:

It's so easy to gently caress up a copy/pasted password so making you type it makes a lot of sense.

You're a dipshit

Adbot
ADBOT LOVES YOU

Last Chance
Dec 31, 2004


Yeah, has to be a troll.

Last Chance
Dec 31, 2004

Salt Fish posted:

I don't get this. Calculating the md5 of something isn't a security flaw, they're supposed to be easy to calculate. Yeah, md5 sucks but....

And at any rate I'm not sure this works because I'm getting 52bfcc1edf4620ceff2c74bb59fc04ea as the md5 for the file, while it calculates f5ca4f935d44685c431a86f788c0eaca.

Someone correct me if I'm wrong 'cause I don't know much, but it's broken because it's now trivial to make an identical hash/fingerprint aka a collision, defeating the whole purpose of calculating it in the first place.

If you can't guarantee the hash is unique, then there's no point. There was already an incident where a committed file with an identical hash to another file broke Webkit's SVN repo because SVN relied on the fact that the hash was supposed to be unique. So unless you're just using the hash to.. show a cool number/letter combo after a file's name? It can't be safely relied upon.

And that file does calculate to f5ca... I checked using hacker tool onlinemd5.com

Last Chance fucked around with this message at 22:01 on Mar 16, 2017

Last Chance
Dec 31, 2004

apropos man posted:

Main positive from this set up is not relying on a third party to handle my db.

Except for the Android app that hasn't been updated in almost two years?

Last Chance
Dec 31, 2004


uh oh

Last Chance
Dec 31, 2004

SeismicTriangle posted:

anyone here come from military background? im currently about to enlist for this. People are saying it will be pretty easy to transition to a civilian career afterwards, just wondering if thats true from your perspectives and anything else you'd like to share. I dont really know anything about infosec/networks atm and school is only 6mo long so i have my doubts about those claims

am i goina be the bad guy

I don't know much about nothin' here, but wtf is this when I visit that URL:

Last Chance
Dec 31, 2004

Evis posted:

Make sure you're using good passwords. I think the default settings don't encrypt metadata. Also: there are crack utilities out there. (I haven't used it, just spent a few seconds on google.

But doesn't that article actually imply that 7zip's using decent encryption?

quote:

At least from version 3.x, 7-Zip has been using a strong AES algorithm, which doesn't allow any attacks more effective than the brute force. Besides, the key derivation function is very similar to RAR one, and uses more than 130000 SHA-256 transformations and brute force rate on modern CPU is very low, only several hundreds of passwords per second. This carries inference that 7-Zip password encryption is one of the strongest between popular encryption systems in the context of brute force rate.

quote:

Please bear in mind you have quite no chance to crack unknown password (longer than 6-7 symbols) if you have no additional info about it.

Last Chance
Dec 31, 2004

Double Punctuation posted:

The Eternal September continues.


:vince:

How is a keychain vuln part of "Eternal September"?

Last Chance
Dec 31, 2004

poisonpill posted:

*beats you with a wrench until you pass out, in turn relaxing your vitals*

maybe pair it with something that ensures your paying attention

*gets roofied

Last Chance
Dec 31, 2004

The Fool posted:

Bad default settings and bad ui design is a different discussion.

*LOUD BUZZER SOUND*

Last Chance
Dec 31, 2004

Proteus Jones posted:

The nice thing is the Apple Keychain syncs across your devices. But it's limited to apps that actually the Keychain, so mostly just Safari.

Starting with iOS 11 you can use the Keychain password manager with most native apps' password fields, not just Safari :thumbsup:

Last Chance
Dec 31, 2004

iCloud Keychain is by FAR the best pass manager if you're deep into the Apple ecosystem.

Last Chance
Dec 31, 2004

Horse Clocks posted:

Back on the subject of password storage and KeePass, how do iOS users sync their kdbx file with their devices? (And which app do you use?)

All my passwords are currently stored using ‘pass’ and a smart card. Which is great for accessing poo poo anywhere linuxy; export GPG agent as the ssh agent, plug in smart card, gently caress around with pcsc and ccid then presto! Passwords.

But outside the Linux world I have no idea how this would work, and just flat out doesn’t on iOS.

I use resilio sync elsewhere as ‘Dropbox’ but the apps I tried don’t seem to use it as a file-like storage, opting to import the kdbx file into the apps own storage space.

I use iCloud Drive

Last Chance
Dec 31, 2004

that sounds dumb to me

Last Chance
Dec 31, 2004

yeah, it'll be a cold day in hell before I send my DNA to a company just for it to be stolen because they left MySQL open to the world, and they use it to breed an army of strong, huge-dicked criminals to commit crimes that they eventually pin on me due to forensic DNA analysis.

Last Chance
Dec 31, 2004

I think most mail apps allow you to have more than one account set up..

Last Chance
Dec 31, 2004

Can you use Thunderbird with Exchange

Last Chance
Dec 31, 2004

Docjowles posted:

I suddenly realize that next year there are going to be people old enough to vote join the army buy smokes and porno mags who weren't alive for 9/11, and that makes me feel profoundly ancient :corsair:

buy "smokes" and "porno mags"? what are those

Last Chance
Dec 31, 2004

Schadenboner posted:

You could have just said you were on Facebook?

:shrug:

???

Last Chance
Dec 31, 2004

stevewm posted:

Finally! I just received word the cogs of government IT have turned and surprisingly the option they picked was to unblock Youtube.

You just became the hero of that office

Last Chance
Dec 31, 2004

as long as your 100% sure all browser extensions you have enabled havent been compromised either

Last Chance
Dec 31, 2004

can we also stop using the term "bug" for a glitch? i don't like bugs

Last Chance
Dec 31, 2004

Schadenboner posted:

Probably not for very long, though?

Depends on how much water or urine they have access to

Last Chance
Dec 31, 2004

Fame Douglas posted:

That's what happens when the NSA doesn't allow you to fix it for a while.

Pfft, next you're going to say that BitLocker is only for Windows Pro users and not home users because the Gov't wants to make it more marginally more expensive/difficult to encrypt files.

Last Chance
Dec 31, 2004

The Iron Rose posted:

I occasionally have salespeople reaching out to bribe me in exchange for listening to their pitch but I've yet to figure out the verbiage to request, say, an Uber eats contribution.


Just love the total lack of ethics rules in software procurement (not really)

tell them it's your scheduled lunch time

Last Chance
Dec 31, 2004

admiraldennis posted:

Yeah, I might do something like this. Though instead of running a bunch of http servers - I'd really just like Chrome itself to be aware of my "default DNS suffix" preference and do the redirecting on its own. Come on, where's the dumb plugin for this?

I may be way out of my depth here, but wouldn't a browser plugin that's designed to be able to forward local traffic to a TLD be a security risk of sorts if used in the wrong hands?

Last Chance
Dec 31, 2004

Dear god lmao

Last Chance
Dec 31, 2004

We are going through that right now at my job :( so many wasted dollars

Last Chance
Dec 31, 2004

CLAM DOWN posted:

you should not trust technology companies to have your privacy, security, or best interest at heart unless it makes them buckets of money.

Isn't this the angle Apple's going for? aka make more money by selling privacy/security and providing an alternative to companies selling and scraping data from consumers' mobile devices.

i appreciate them trying but there is a part of me that's like.. why don't they make the whole phone out of lockdown mode..

Last Chance
Dec 31, 2004

Subjunctive posted:

I’m surprised that there isn’t some standard protocol for talking to a password manager in a separate process such that the browser or other app can request a credential and the manager can pop a confirmation dialog or just rate limit and yell. Similar to what iOS and I presume Android have, I guess.

I wouldn’t want to be in charge of getting it standardized and adopted, though. Not it.

Safari sort of does this on ios. you can choose to fill passwords from another secure storage besides iCloud Keychain, e.g. you can fill in a password from chrome’s password store while using safari

Adbot
ADBOT LOVES YOU

Last Chance
Dec 31, 2004

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply