Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

spankmeister posted:

i put forth a proposal for a new gang tag for the thread:



radical

Adbot
ADBOT LOVES YOU

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
1th floor

JawnV6
Jul 4, 2004

So hot ...

spankmeister posted:

i put forth a proposal for a new gang tag for the thread:


i always get confused when im expecting 38400 and see 0x9600 because 9600 is a valid one too but but but

Segmentation Fault
Jun 7, 2012
BAUD DUDES reminds me of this t-shirt my dad had that had this comic book superhero-stylized CAPTAIN CODEC on the front and on the back was another picture of him and the LAN/WAN twins, does anyone know what the gently caress I'm talking about

ChickenOfTomorrow
Nov 11, 2012

god damn it, you've got to be kind

hi

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Parallel Paraplegic posted:

wait what, it would just flag every 100th failed login?
yes

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Subjunctive posted:

Oki Semiconductor! I had an OkiSemi mouse pad with one of the other characters, NetChampion or something.

oh man this press release is so first-bubble adorable http://www.prnewswire.com/news-releases/integrated-web-pr-and-advertising-strategy-pays-off-for-oki-semiconductor-76200872.html

Subjunctive fucked around with this message at 20:23 on Apr 8, 2016

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
still can't believe caro is alive

Segmentation Fault
Jun 7, 2012

Subjunctive posted:

Oki Semiconductor! I had an OkiSemi mouse pad with one of the other characters, NetChampion or something.

I looked it up (apparently I didn't try "captain codec" in quotes before) and got Oki Semiconductor, which I definitely remember. It also reminded me of NetWarrior, which I think was kind of a palette swap of Captain CODEC. Unfortunately I can't for the life of me find any pictures of the shirt or the superheroes or anything apart from a couple of press releases and people mentioning the campaign in passing.

Dad also had an MSN beta test shirt with an anvil falling onto a bug

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Segmentation Fault posted:

Dad also had an MSN beta test shirt with an anvil falling onto a bug

haha, I saw a guy wearing this one like a decade ago

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Chris Knight posted:

Whack for my Larry-o
There's a keystore in the JAR-o

FAT32 SHAMER
Aug 16, 2012



first floor :getin:

ate shit on live tv
Feb 15, 2004

by Azathoth

anthonypants posted:

here is a security fuckup for the new thread:

at my last job, they used solarwinds and most of the stuff piped logs to some server that it monitored. their "ids" solution was a script that checked logs for false ssh entries, and on the 100th hit, it would send a ticket to the noc. the noc was responsible for pulling that ip address, going back into solarwinds to make sure that they were really an active threat, and not some guy who only made two or three invalid attempts in the past hour, and then fed that ip address into another script that null routed that ip to some of the routers. this script was very old and did not affect the routers for the somewhat newer pci/compliance environment.

oh, and solarwinds was helpful in pulling the ptr for ip addresses that had one, and if you had a domain name that didn't have an a record, it couldn't get added to the null route table

Boy it sure is a good thing this hacker registered his source IP in our domain before he started brute forcing SSH logins. :wtc:

Shame Boy
Mar 2, 2010

Powercrazy posted:

Boy it sure is a good thing this hacker registered his source IP in our domain before he started brute forcing SSH logins. :wtc:

just make an IDENT call to their IP to find out if they're legit, they have to tell you. it's like if you ask someone if they're a cop 3 times in a row.

JumpinJackFlash
Nov 15, 2001

Segmentation Fault posted:

Dad also had an MSN beta test shirt with an anvil falling onto a bug

I have that shirt!

30 TO 50 FERAL HOG
Mar 2, 2005



I'm very disappointed. i saw the last thread had closed and assumed something amazing had happened

Segmentation Fault
Jun 7, 2012

BiohazrD posted:

I'm very disappointed. i saw the last thread and closed and assumed something amazing had happened

We went a year without pooptouching! :toot:

apseudonym
Feb 25, 2011

Segmentation Fault posted:

We went a year without pooptouching! :toot:

Something we should all be proud of.

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug
cool imessage vuln found by a friend of mine
https://www.bishopfox.com/blog/2016/04/if-you-cant-break-crypto-break-the-client-recovery-of-plaintext-imessage-data/

quote:

Messages (iMessage) for OS X from Apple implements its user interface via an embedded version of WebKit. Additionally, Messages on OS X will render any URI as a clickable HTML <a href=”URI”> link. An attacker can create a simple JavaScript URI (e.g.,java script:) that when clicked, allows the attacker’s code to gain initial execution (cross-site scripting) in the context of the application DOM.

particularly like this part:

quote:

One of the most notable differences between an embedded version of WebKit and a web browser like Chrome or Safari is that WebKit does not implement any same-origin policy (SOP) because it is a desktop application

pr0zac fucked around with this message at 21:37 on Apr 8, 2016

DrPossum
May 15, 2004

i am not a surgeon
effort lurk posting but thanks for reiterating using a password manager. I neglected that forever and finally transitioned over

that said I'm still using the same two dictionary words for everything, but i feel safer

Shaggar
Apr 26, 2006
nice

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
Speaking of PCI compliance, how's the retail industry handling it these days? I still see tons of places that have new readers, but the EMV slot is taped over?

Sharktopus
Aug 9, 2006

DrPossum posted:

effort lurk posting but thanks for reiterating using a password manager. I neglected that forever and finally transitioned over

that said I'm still using the same two dictionary words for everything, but i feel safer

When I switched over I just did a few phases of transition:

run your password manager and capture all the existing passwords for a few weeks
change weak passwords as you log in to services for a few weeks
check the uncommonly used poo poo that still has a weak pass and bite the bullet and spend an hour or two changing all of them

helps keep it from being a 8 hour password changing marathon

some clients also supposedly can just log in for you and change the passwords so that might be worth trying?

Sharktopus
Aug 9, 2006

Jimmy Carter posted:

Speaking of PCI compliance, how's the retail industry handling it these days? I still see tons of places that have new readers, but the EMV slot is taped over?

same as always, with copious Business Processes and "oh gently caress the audit is next month lets hide all the poopy"

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
assuming state actors aren't after my bitcoins is truecrypt still a decent choice for full disk encryption?

JawnV6
Jul 4, 2004

So hot ...

Sharktopus posted:

next month
heh

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

Ur Getting Fatter posted:

assuming state actors aren't after my bitcoins is truecrypt still a decent choice for full disk encryption?

what os are you running that doesn't have built in full disk encryption already?

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Ur Getting Fatter posted:

assuming state actors aren't after my bitcoins is truecrypt still a decent choice for full disk encryption?

no, because it doesn't work with modern hard drive formats and oses

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe
lets see how quickly we can get this one shut down

a friend of mine works for a major uk government agency. she's just found out that she can log into one of their internal systems - one that holds salary and all sorts of other hr information - by just using the username as a password, and of course the username is just the localpart of their email address (normally firstname.lastname). she found this out because she realised she'd been using her old password to login after changing it, so decided to try the first one she was ever given, which was her username. it worked, and of course everyone on the system was assigned their first password that way.

i have literally no idea how you gently caress things up that badly - not in a normal "i can't believe how dumb this is" but literally i don't know how, let alone why, you'd set up an authentication system that way. the best bit is it enforces a strict 60-day change policy including not allowing old passwords to be reused (which possibly suggests how the bug came in)

so she did the right thing and reported it to her management and the it department. they told her they would look into it but not to worry, nobody could make changes because all changes had to be approved by a line manager. who would have to log in to the system to approve them.

Sharktopus
Aug 9, 2006

brutal :/

this isn't helping my anti-bureaucracy bias btw

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

Sharktopus posted:

brutal :/

this isn't helping my anti-bureaucracy bias btw

tbh a big part of why government it (in the uk at least) is so hosed up is that sort of bias. it goes like this:

"hey this system hasn't been updated in 10 years, can we have budget to fix it?"

"SEE TYPICAL PUBLIC SECTOR INEFFICIENCY! THE PRIVATE SECTOR IS FAR MORE EFFICIENT!"

*pays 200 million quid to logica/serco/cmg/lockheed/bae for poorly-specced and over-promising new system

*new system fails miserably, everyone goes back to old system

"hey this system hasn't been updated in 15 years"

etc

Sharktopus
Aug 9, 2006

ummmmm sure why not

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

goddamnedtwisto posted:

tbh a big part of why government it (in the uk at least) is so hosed up is that sort of bias. it goes like this:

"hey this system hasn't been updated in 10 years, can we have budget to fix it?"

"SEE TYPICAL PUBLIC SECTOR INEFFICIENCY! THE PRIVATE SECTOR IS FAR MORE EFFICIENT!"

*pays 200 million quid to logica/serco/cmg/lockheed/bae for poorly-specced and over-promising new system

*new system fails miserably, everyone goes back to old system

"hey this system hasn't been updated in 15 years"

etc
lowest bidder contract enforcement sure helps a ton

Shaggar
Apr 26, 2006
its not even lowest bidder, its that government contracts are about who you know and your ability to navigate the process.

Sharktopus
Aug 9, 2006

whats unique to govt about that?

vOv
Feb 8, 2014

i'm convinced that humans are just extremely bad at large systems with more than a couple hundred people whether it's governmental or corporate

hobbesmaster
Jan 28, 2008

Shaggar posted:

its not even lowest bidder, its that government contracts are about who you know and your ability to navigate the process.

it is the lowest qualified bidder

it just turns out only one bidder is qualified

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

pr0zac posted:

what os are you running that doesn't have built in full disk encryption already?

win 10 home :/ was hoping to not have to shell out for the pro upgrade but if people say it's the only good choice then I guess it's fine.

Sharktopus
Aug 9, 2006

vOv posted:

i'm convinced that humans are just extremely bad at large systems with more than a couple hundred people whether it's governmental or corporate

have you read systemantics yet?



Ur Getting Fatter posted:

win 10 home :/ was hoping to not have to shell out for the pro upgrade but if people say it's the only good choice then I guess it's fine.

10 home doesnt even support native fde???? lmfaoooooo

Adbot
ADBOT LOVES YOU

Kazinsal
Dec 13, 2011


the home edition strips out all the poo poo you really don't want to have to explain to the average user when they find some way to gently caress it up horribly, like fde and remote desktop server

  • Locked thread