Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Sharktopus
Aug 9, 2006

high quality op, op

Adbot
ADBOT LOVES YOU

Sharktopus
Aug 9, 2006

DrPossum posted:

effort lurk posting but thanks for reiterating using a password manager. I neglected that forever and finally transitioned over

that said I'm still using the same two dictionary words for everything, but i feel safer

When I switched over I just did a few phases of transition:

run your password manager and capture all the existing passwords for a few weeks
change weak passwords as you log in to services for a few weeks
check the uncommonly used poo poo that still has a weak pass and bite the bullet and spend an hour or two changing all of them

helps keep it from being a 8 hour password changing marathon

some clients also supposedly can just log in for you and change the passwords so that might be worth trying?

Sharktopus
Aug 9, 2006

Jimmy Carter posted:

Speaking of PCI compliance, how's the retail industry handling it these days? I still see tons of places that have new readers, but the EMV slot is taped over?

same as always, with copious Business Processes and "oh gently caress the audit is next month lets hide all the poopy"

Sharktopus
Aug 9, 2006

brutal :/

this isn't helping my anti-bureaucracy bias btw

Sharktopus
Aug 9, 2006

ummmmm sure why not

Sharktopus
Aug 9, 2006

whats unique to govt about that?

Sharktopus
Aug 9, 2006

vOv posted:

i'm convinced that humans are just extremely bad at large systems with more than a couple hundred people whether it's governmental or corporate

have you read systemantics yet?



Ur Getting Fatter posted:

win 10 home :/ was hoping to not have to shell out for the pro upgrade but if people say it's the only good choice then I guess it's fine.

10 home doesnt even support native fde???? lmfaoooooo

Sharktopus
Aug 9, 2006

I think at this point we know enough generic systems first principles to know what kind of things tend towards robustness on average and what kind of things tend towards instability

people just generally want to ignore all that literature as soon as they have some problem thats "too important" like healthcare or social safety

Sharktopus
Aug 9, 2006

you sound confused friend

Sharktopus
Aug 9, 2006

watching the eurozone deal with real american style heterogeneity problems is gonna be great

Sharktopus
Aug 9, 2006

https://max00355.github.io/technopy/deploying-production-flask-applications-with-uwsgi-and-nginx.html

quote:

In this post I will be discussing the how we can deploy a production web application with uWSGI and Nginx.

quote:

screen uwsgi --socket 127.0.0.1:7070 --processes 5 --module app --callable app

quote:

production web application

quote:

uWSGI is written in C and is built for performance. Gunicorn is written in Python thus is slower. I have used both of these technologies in my jobs and I have found that every time uWSGI out performs Gunicorn, and even NodeJS at times.

Sharktopus
Aug 9, 2006

http://www.securityforrealpeople.com/2016/04/arris-motorola-surfboard-modem.html

huehuehuehuehuehuehuehuehueuh

Sharktopus
Aug 9, 2006

old as dirt but still startkeylogger level funny

Sharktopus
Aug 9, 2006

I like baud bitches thats my fuckin problem

Sharktopus
Aug 9, 2006

pr0zac posted:

oh hey someone else actually got the same tag as me

im no longer alone :unsmith:

we're both alone together

Sharktopus
Aug 9, 2006

atomicthumbs posted:

i hope those farmers sue maxmind into the loving ground

same but you and choking

Sharktopus
Aug 9, 2006

little of column A, little of column B

Sharktopus
Aug 9, 2006

why burn good exploits when known old ones will suffice???

seems smart to me but maybe I misunderstood

Sharktopus
Aug 9, 2006

anyone know of any good opsec education resources? classes, texts, stories, anything that's accurate and educational really

Sharktopus
Aug 9, 2006

Rooney McNibnug posted:

The gray forums, bicth





thanks?

this is about what I figured though, someone needs to research and produce a functional/practical opsec class imo

Sharktopus
Aug 9, 2006

surely, somewhere, some military force has produced a not totally awful basic opsec principles book

Sharktopus
Aug 9, 2006

spankmeister posted:

pretty sure there are CIA manuals for that kind of thing

yeah I've found some stuff around this, was more just wondering if other people had resources they'd recommend. It seems like most people just kind of do the same thing:

throw their hands up in the air and remove well resourced persistent attackers from the threat model

Sharktopus
Aug 9, 2006

Storysmith posted:

@thegrugq wasn't a jokepost though

his medium posts are probably the best published postmortems of opsec failures and successes around which is a sad reflection on the state of opsec education

yeah I keep up with grugq already :)

Sharktopus
Aug 9, 2006

surebet posted:

looking for talk recommendations, i listen to a lot of stuff at work and i blew through the usual defcon/shmoocon/black hat stuff in the last couple years

what should i work on next? looking for anything sec related, but feel free to go out of scope too

I watch a lot of these

what kind of stuff are you looking for?

Sharktopus
Aug 9, 2006

wish I could find whatever the gently caress you're talking about

Sharktopus
Aug 9, 2006

https://mackeeper.com/blog/post/217-breaking-massive-data-breach-of-mexican-voter-data

wide open mongodb instance on a public aws IP apparently had every mexican votor's info in it

Sharktopus
Aug 9, 2006

how did i misspell voter yowza

Sharktopus
Aug 9, 2006

quote:

The goal of the new campaign is to disrupt the ability of the Islamic State to spread its message, attract new adherents, circulate orders from commanders and carry out day-to-day functions, like paying its fighters. A benefit of the administration's exceedingly rare public discussion of the campaign, officials said, is to rattle the Islamic State's commanders, who have begun to realize that sophisticated hacking efforts are manipulating their data. Potential recruits may also be deterred if they come to worry about the security of their communications with the militant group. "We are dropping cyberbombs," Robert O. Work, deputy secretary of defense said. "We have never done that before."

Sharktopus
Aug 9, 2006

not necessarily a sec fuckup but it makes me giggle:

https://code.google.com/p/android/i...%BC%A9%EF%BC%A4

Sharktopus
Aug 9, 2006

ahahahahhaha thats a real manual

Sharktopus
Aug 9, 2006

https://info.publicintelligence.net/MTTP-TacticalChat.pdf

Sharktopus
Aug 9, 2006

im just gonna start quoting parts of this at people in irc

quote:

(3) Users must realize that based on communications priorities and the tactical
situation, their post may not be the highest priority at the time for the intended
recipient. Patience is required in these situations

Sharktopus
Aug 9, 2006

:eyepop:

Sharktopus
Aug 9, 2006

lots of hand waving and wishful thinking

dont get your hopes up thinking you can ever document requirements accurately

Sharktopus
Aug 9, 2006

im the trusted network

Sharktopus
Aug 9, 2006

Dex posted:

*shoves grey into cryptolocker*

lol

Sharktopus
Aug 9, 2006

i tried with united's new lovely multiple choice security question system but all i got back was 500s

Sharktopus
Aug 9, 2006

:phone: You will need to answer the security questions to your best choice. We conducted a great deal of research into the security issues our customers face and found that the majority of issues can be traced to computer viruses that record typing. We purposely chose to use predefined answers to protect against this keystroke logging. Let us know if you have any trouble processing the request.

:phoneb: Ah, I'm glad you guys did such a great amount of research on this and are trying to protect me. I just realized that I also use keystrokes to enter a password to log in, I didn't realize just how unsafe this was! When do you plan on making multiple choice passwords available? I really don't feel secure now typing in a password.

my attempts to talk with united always end in them telling me to call in so they can tell me to gently caress off via phone instead of via twitter

Sharktopus
Aug 9, 2006

flakeloaf posted:

we live on a planet where it's harder to break into a warcraft account than a bank account

it's very clear exactly why this is imo

Adbot
ADBOT LOVES YOU

Sharktopus
Aug 9, 2006

http://www.dailydot.com/politics/encryption-crypto-wars-police-indiana-charles-cohen-interview/

there are too many gems in this article to individually quote

but rest assured its not a zero-sum article

  • Locked thread