Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
andrew smash
Jun 26, 2006

smooth soul

Loving Africa Chaps posted:


As a doctor i'd be super interested in seeing that though. Hospital IT is insanely bad. At my hospital no one can connect to the staff wifi so all the consultants connect their laptops to the open guest wifi to send emails about patients to one another.

Seconded, also I would like to know if I have ever worked for this place.

Adbot
ADBOT LOVES YOU

andrew smash
Jun 26, 2006

smooth soul
What's an ideal approach to security for a home machine mostly used to play video games and browse the forums? I'm curious and would like to make sure I'm not doing anything stupid. At baseline, I keep windows updated, keep UAC on, don't open email attachments, etc.

andrew smash
Jun 26, 2006

smooth soul
Thanks. I gave up pirating poo poo many years and several machines ago.

andrew smash
Jun 26, 2006

smooth soul
So I stumbled into a pretty glaring security flaw in a medical licensing board's Web portal by doing nothing more nefarious than trying to reset my password. Any idea how I should go about reporting this?

andrew smash
Jun 26, 2006

smooth soul
Yes

andrew smash
Jun 26, 2006

smooth soul
State

andrew smash
Jun 26, 2006

smooth soul

Sharktopus posted:

:rip:

be careful dude, the track record on responsible disclosure to the us govt isnt great

I know, here's hoping I don't end up in jail

andrew smash
Jun 26, 2006

smooth soul

is there a larger story to this or is it just an illustrative example of general stupidity?

andrew smash
Jun 26, 2006

smooth soul

Yes, I see

andrew smash
Jun 26, 2006

smooth soul

flosofl posted:

I pitched Network Security and Audit, and made it pretty far up the chain until a VP sent me an email that said:

Go for communication resources protection office and then you can be creepo

andrew smash
Jun 26, 2006

smooth soul

Space Gopher posted:

No, they're completely different.

LastPass is a conventional password manager which lets you define passwords and encrypts them behind a master key. It's had some serious problems in its implementation, but there's nothing special about its theory of operation.

LessPass is basically hash(domain + username + masterPassword). People come up with this idea every once in a while because it "solves" a lot of known problems with traditional password managers, and they're not experienced or careful enough to see the new, bigger problems it introduces.

The weird glyphs are a mnemonic device to validate your password. LessPass doesn't ever give you a "your password was wrong" prompt - a different master password is just a different input to the hash function and gives you a different output. So, they give you a different hash function with a limited output set and map it to some icons, and you remember that your password confirmation is "blue building orange heart black car" or whatever. If you don't see those icons then you know your password is wrong.

Of course, that's an information leak. Especially when you provide confirmation for each character as it's entered, which makes it trivial to break by hand. But what else would you expect from a password manager which doesn't ever let you change your password?

How does the by-hand attack work when the glyphs update for every entered character? I'm not questioning that it works I would just like to understand it as a means of further insight into the problem.

andrew smash
Jun 26, 2006

smooth soul
Oh, I see. It depends on having the full glyph sequence from watching someone input a password. For some reason I was thinking it was more complicated than that and looked right past the obvious answer.

andrew smash
Jun 26, 2006

smooth soul
I wonder if it's a hipaa violation if I'm required to unlock a device with patient info on it by border patrol

andrew smash
Jun 26, 2006

smooth soul
Yeah I was thinking a cheap chromebook with work stuff only accessible through vpn with no stored credentials would not be a bad idea in that instance.

andrew smash
Jun 26, 2006

smooth soul
It's not like I have anything to hide, I just don't think Joe Blow cbp agent needs to know I diagnosed private citizen Brick Hardstack with dick and ball cancer last month, for example. This is all hypothetical as I don't travel with work computers anyway but it's interesting to think about.

andrew smash
Jun 26, 2006

smooth soul
Link to story about the podcast hack?

andrew smash
Jun 26, 2006

smooth soul

seems to be this?
https://twitter.com/taviso/status/861747942314487809

andrew smash
Jun 26, 2006

smooth soul
This is the first time i have ever heard of jake paul but what i could stand to watch of that video reinforces my deeply held prejudice that people with two first names should just be shoveled quietly into a ditch and forgotten

andrew smash
Jun 26, 2006

smooth soul
Yeah but the series as a whole is not nearly as good as the first novel was

andrew smash
Jun 26, 2006

smooth soul

Tamba posted:

Move to a country that doesn't use a single number as both the username and password to people's whole financial life.

*unchangeable username and password no less

andrew smash
Jun 26, 2006

smooth soul
Do you have to file a freeze with all 3 big agencies? There's a post on r/personalfinance about this breach that said you can file with only 1 and they'll push it to the others.

andrew smash
Jun 26, 2006

smooth soul
I have a consumer level question and I wasn't sure where to turn. I have gotten a bunch of emails from amazon with a "reset your password" token that I haven't prompted. I figured it was a phishing attempt but the messages were signed appropriately, so I called customer service and they confirmed the messages were generated by someone or some bot trying the recover password function. My account has a strong password separate from my Gmail account pass, both amazon and Gmail are protected by 2fa (phone token app) and there are no access attempts logged in my Gmail account other than me. Amazon says I'm secure and don't need to do anything but I'm mildly uneasy about somebody even having my login without a pass or access to 2fa token. Should I change the login name or not bother?

andrew smash
Jun 26, 2006

smooth soul
Doubtful, but possible. Thanks

andrew smash
Jun 26, 2006

smooth soul

Proteus Jones posted:

HAHAHAHAHAHAHAHA



I just got a no-warning forced update on windows 10 that gave me a "these updates are to protect you in an online world!" message on restart, i assume it's related to this debacle

andrew smash
Jun 26, 2006

smooth soul

Martytoof posted:

Didn't realize the faceid camera had 100x zoom

andrew smash
Jun 26, 2006

smooth soul
That strava heat map is insane. I played with it last night and it’s stupid easy to find sensitive locations pretty much anywhere you want to look around.

andrew smash
Jun 26, 2006

smooth soul
Is there a way to force a sync in keepass between iOS/desktop using Dropbox? I added a pass on mobile and one at home before they synced, and ended up with multiple key files, one tagged “Andrew Smash’s conflicted copy”. I’m going to manually reconcile the differences and purge the extra file but it’s kind of annoying to have to deal with and I’d like to avoid it in the future if possible.

andrew smash
Jun 26, 2006

smooth soul
Ban computers imo we’ll all be better off

andrew smash
Jun 26, 2006

smooth soul
I keep urls stored in the url field in the relevant keepass database entry and tell keepass to “open in browser”. Am I owning myself?

andrew smash
Jun 26, 2006

smooth soul
you guys see this? Tavis O tweeted about it a bit ago

https://twitter.com/digicert/status/968925980533207040

Adbot
ADBOT LOVES YOU

andrew smash
Jun 26, 2006

smooth soul
Wasn’t there something about al-qaeda or some other group communicating using comments on google drive files going undetected for years?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply