Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
i'm confused. securid works with your pin(something you know) and your token code(something you have, changes every 60 seconds), and the two of those must be correct when you're challenged. so your passphrase is PASSWORD123456 or PASSWORD456789 or whatever. are you asking about using the code _only_? don't do that.

edit: apparently you're not but i'm still confused by the question

Adbot
ADBOT LOVES YOU

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
i keep forgetting that client exists actually, which is why i was confused, we just pin + fob code directly. same thing ultimately since the server needs access to the token seeds anyway to confirm it was valid, still 2fa

quote:

The fault is that the password you're now authenticating with is just eight numeric characters that changes every X seconds.

you can manage that - trying to log in twice with the same code, or using the incorrect code twice in a row, locks me out of vpn and site logins until an admin resets my account

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

EVIR Gibson posted:

Where/how/why is doing the calculation to take "123456" to "01923227". Where in relation to the application requiring the authentication. How is it converting a the FOB token to 01923227.

his application isn't involved in this part of the chain, it's all rsa securid and their client software. i'd suggest reading their docs if you're curious about the how and why of it

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
you clearly know what shodan is, so why not just use it?

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
i encrypt my end, and you encrypt your end, back and forth forever

))<>((

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

oaok posted:

What are some things that I should study to start learning sec related things? Also resources that would help a beginner/novice looking to get into the field of infosec. Books? Courses? Videos? I'm very interested in netsec and infosec but I don't know where to begin. I was looking at maybe bash/shell, different file encryption, scripts and things like that, but I feel I need some fundamental training on the whole lot of information for these subjects.

here's a bigass wiki full of all kinds of web security stuff: https://www.owasp.org/

here's a really good place to start: https://www.owasp.org/index.php/OWASP_Top_Ten_Project

once you've got your head around how all of that works you'll be ahead of everybody who doesn't give a poo poo about security, and should have a better idea of what you actually want to do(dev, ops, qa, infrastructure, whatever)

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

oaok posted:

Thanks man

np, just don't stress it too much if things look overwhelming - like others said, it's a huge field. if you're finding yourself not understanding XSS exploits because you don't understand how something like text encoding works, that's ok, just keep googling the bits that don't make sense until it starts to come together

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Subjunctive posted:

How do I get in on the coat tails thing? Sounds p sweet.

hold a non-insane opinion

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Paul MaudDib posted:

99.9%+ of known threats, 95%+ of unknown threats

lol

why don't they just catch the other 5% of unknown threats, can't be that hard

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
based on a random sampling of my open tabs, 25% of internet traffic goes to something awful dot com. guess that radium guy knew a thing or two about servers after all

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Paul MaudDib posted:

You're an idiot

You're an idiot

i was laughing at your naivete earlier but you really shouldn't be throwing around insults when you're running around believing things like "95% of the time, it works every time"

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Paul MaudDib posted:

Why? It's just YOSPOS having some drunken weekend anal leakage. You've got OSI Bean Dip, the Internet Antivirus Expert who once interned at Symantec or something, who just keeps asking someone to explain antivirus to him and who thinks the NSA is going after grandma's cat pictures (the explanation he gave in the thread he linked for why antivirus sucked, after I got past all the "under construction" paragraphs), and a bunch of white noise posters.

It would almost be funny if they weren't giving such bad advice. Sure, anyone who posts in this forum can probably avoid clicking any obvious malware links or opening a suspicious attachment. But that's not good advice for a business or for your aunt who loves those FWD: FWD: FWD: emails.


So angry. One of these idiots actually started stalking my posts to yell at me in other forums. Saturday night on Something Awful Dot Com, y'all :lol:

your ability to understand basic english is as good as your understanding of security

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
we live in a world where "sleep(30)" is enough to bypass a lot of av's attempts at sandboxing, yet that kid who had malwarebytes on a usb stick at school still thinks heuristics is a magic spell

paul misspelled reference, your name is a boring word, please stop

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Daman posted:

yeah the point I've heard is "users will disable AV just to run it" but that's less the case if they remember uncle jimmy saying that's how they get you.

uncle jimmy should just tell people to install their software updates

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Swagger Dagger posted:

I'm graduating from college in the fall with a BS in Computer Science, any tips on getting a job in the infosec industry? I'd rather be on the blue team/admin side of things but I'm kinda worried that I'll be job hunting and end up in something akin to a basic tech support job, and I've spent way too much time and money in college to really be able to afford that.

I'll have an S+ and probably a CCNA by then, if those will help. I know those are very basic, entry-level certs but it's what I can afford on my budget and I had to start somewhere.

don't pay for your own certs, that's what employers are for.

i don't know poo poo about entering the job market on your side of the world so i can only really give the incredibly generic "attend meetups around your areas of interest and get talking to people because a) connections are great b) you can find out what the hell they want from new hires" here, sorry. also i wouldn't assume your degree is going to count for anything. good luck with the job hunt

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Daman posted:

At a chosen point of attacker effort, defense against them does not work. the point of a dumb user running an AV solution is to raise that level past "standard irc botnet." poo poo like this is detected just fine all the time.

has there been any malware for sale in the last decade or so that only drops one payload? i have no idea why "well, that probably got them all. it definitely got one" would inspire confidence

also "don't open random attachments from yourbank@jkhagkjakjga.ru" would get you past that level

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
if we must go with analogies, you're advocating safe sex by removing the condom and trusting the rhythm method

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

DeaconBlues posted:

I don't believe that everyone in this thread pays for all of their media, even the most security conscious. ;-)

i do.

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Haquer posted:

You're everyone?
Like a collective conscience or what

more of a gestalt entity, that pays for poo poo

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Subjunctive posted:

So keep it in one file. MIT doesn't preclude that.

Then delete that file.

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Rufus Ping posted:

i mean seriously, if there are people out there who don't trust proper password managers but do trust some pile of poo poo w3schools-quality javascript bookmarklet written by local helpdesk janitor Tod McRetard, then your response shouldn't be to indulge their stupidity

brutal, but fair

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
just think of all the users with a linux server as their desktop who were saved from malware thanks to mcafee, though

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
personally i'm shocked that spies have been spying on people

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Cup Runneth Over posted:

"First, though, a few general points: one, there's very little here that should shock you. The CIA is a spying organization, after all, and, yes, it spies on people."

yes, that's exactly the line i was posting about, good job

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Cup Runneth Over posted:

source your quotes

you already did that for me, thanks

Martytoof posted:

Mild annoyance at the fact that the serial numbers disclosed in the leak are to software I already own. No taxpayer-funder IDA Pro key for me, I guess.

i haven't actually checked but i saw somebody on twitter saying that the windows keys were pirated anyway, lol if true

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
i think you're exaggera
https://twitter.com/taviso/status/843965519371812864
ting a bit

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
attribution is hard

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

22 Eargesplitten posted:

I'm assuming it's a matter of the government having millions of times the resources and expertise of a normal person, but I know basically nothing about infosec.

mickens' "mossad vs not mossad" threat model comes to mind: https://www.usenix.org/system/files/1401_08-12_mickens.pdf

if a nation state really, really, really wants you, good luck. use signal, use tor, use salt circles, use prayer. in the actual case you're talking about though, it's extremely unlikely anybody in sigint would give the remotest of shits who that person is so they're going to be fine as long as it's dipshit investigators sending bad legal threats to twitter instead of a serious unmasking attempt

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

22 Eargesplitten posted:

That first paragraph is the weirdest Lorem Ipsum I've ever read.

Despite his seeming need to make a joke every sentence (Is he a goon?), I get what he's saying. It's a good point, there are some things that just aren't worth bothering about since there's nothing you can do about them. Protect yourself from the more likely threats. That's why I use Bittorrent Sync to sync up my Keepass across my devices, if someone is listening closely enough to know what that is at that exact moment I should stop pissing off the NSA.

Someone's going to tell me why that's a bad method, aren't they?

i had a bit of an internal scream when i saw bittorrent, but tbh i know gently caress all about the protocol these days and from ten seconds on google "bittorent sync" is some kind of private tracker thing where everything in the swarm is under your control? i genuinely have no idea how good or bad that is but there's probably somebody here who does

Adbot
ADBOT LOVES YOU

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!
it's really not, the bespoke bullshit software they paid hundreds of thousands of dollars for that only works on xp is going to be a bigger factor always

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply