Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Truga
May 4, 2014
Lipstick Apathy

OSI bean dip posted:

code:
PATCH NOTES FOR 12.0
* Official HTTPS support--it only took Lowtax like a decade to get it to work properly

Finally, :nsa: can't read my shitposts as they fly through the tubes

Or can they? :nsavince:

Adbot
ADBOT LOVES YOU

Truga
May 4, 2014
Lipstick Apathy

Parallel Paraplegic posted:

Yeah i was thinking of blocklist.de but decentralized and web of trust and

You know what never mind this is a dumb idea

Just make sure you call it blockchainlist.de

Truga
May 4, 2014
Lipstick Apathy

Shaggar posted:

I don't block lets encrypt either but I was thinking about it cause idk anyone legitimate who would use them over a real CA.

I'm moving all my poo poo to let's encrypt from a "real CA", because real CAs are just as bad, but far less flexible.

Truga
May 4, 2014
Lipstick Apathy

Snapchat A Titty posted:

how do i encrypted web???

Truga
May 4, 2014
Lipstick Apathy
I was thinking what was going on during the last couple pages and then I remembered this and it all made sense.

Truga
May 4, 2014
Lipstick Apathy

hackbunny posted:

oh lots of DSL routers here in italy were just bridges and you had to configure windows for pppoe.

That's called a modem.

Truga
May 4, 2014
Lipstick Apathy
i'm the pee plug

Truga
May 4, 2014
Lipstick Apathy
I've moved my dumb encrypted mounted volume with text files for passwords to keep rear end finally a couple weeks ago and coupled with keefox its been great

at work, I obviously use sso when I can, but there's things where I need to log into that either don't support ldap auth at all (ipmi access on some boxes, we have some lovely 3rd party billing crap, that won't get replaced because ceo is a friend of the vendor), or needs own passwords alongside sso, because ldap might not be available (switches, esxi hosts, sans...)

in those cases, having a local copy of the password db that easily syncs is great

Truga
May 4, 2014
Lipstick Apathy

OSI bean dip posted:

so i wonder what they lifted their crypto from

very custom openssl fork (unpatched for heartbleed ofc)

I'm enjoying this trainwreck way too much

Truga
May 4, 2014
Lipstick Apathy
I use dactyl and yanking text doesn't yank any extra bullshit sites try to add :shrug:

Truga
May 4, 2014
Lipstick Apathy

at the date posted:

Federal child porn law has been around for 40 years. Would you care to give an example or two of the government using the prosecution of pedophiles as a pretext to trample on the rights of all us normies?

here, let me help

ErIog posted:

"Feds have to disclose how they obtained evidence because otherwise there's no way to know if the evidence is real. The feds don't want to do that."

so what you're saying is that because the defendant is a pedo this is absolutely fine? the post you quoted says *exactly* why it isn't. are you familiar with what legal precedent is at all?

Truga
May 4, 2014
Lipstick Apathy

at the date posted:

also yeah, my position is basically that anything up to lynching is A-OK for pedos but that's just an opinion and not the argument I'm trying to make


Maybe give your next post a good hard 10 second think before making my argument for me.

(USER WAS PUT ON PROBATION FOR THIS POST)

Truga
May 4, 2014
Lipstick Apathy

at the date posted:

I know this is a sensitive topic for you, a known ADTRW poster, but please try to keep the conversation civil.

hmm, yes, they're coming for anime next, that's why i care about basic human rights!!!!!1

Truga
May 4, 2014
Lipstick Apathy
post some content then

remember the hillary mail poo poo? keeps getting better:

quote:

The State Department asked Powell to try to receive relevant emails from his internet provider, but "as of May 2016 the Department has not received a response" from Powell, the audit said.

apparently powell just used his ISP's mail account for super sekret state business, and the spin machine is already working :v:

https://twitter.com/brianefallon/status/735506225375399936

a very nice appeal to tradition there. also I wonder how many people around the world are reading state department mails lmbo

Truga
May 4, 2014
Lipstick Apathy

EAT THE EGGS RICOLA posted:

The NFL's twitter was "hacked". The password was 12345

drat, that's the same combination I have on my luggage.

Truga
May 4, 2014
Lipstick Apathy

apseudonym posted:

It just.. it hurts me.

"It's 1 server 1 domain due to the way certs work"

Jesus Christ SNI is how old.

I had to set up a new server for a domain a month ago, because some shitlord client demanded IE for XP support, and SNI doesn't work on that :v:

Truga
May 4, 2014
Lipstick Apathy

ErIog posted:

Umm.. why's your poo poo logging into a db directly from a client? Isn't that kind of a no no?

Shouldn't the users have their own creds and only access the database via some interface you've put between users and the actual DB?

The place I work at uses direct mssql connections over the internet to connect to some finance software. The user/pass you get is actually your SQL user/pass for "your" database. There is no option for 2FA or anything better. The client is just a SQL client with some custom table layouts skins to be more friendly to a use case, and that's it. This is also the most popular all-in-one-tax&paperwork app in the country by an extremely wide margin. I've been pushing to move away from it, but there's a shitload of inertia behind it, so

Oh, and I have no idea if it does SSL. If MSSQL can even still do unencrypted connections, it probably is.

Truga
May 4, 2014
Lipstick Apathy

Captain Foo posted:

lol has evolved into lmao!

Truga
May 4, 2014
Lipstick Apathy
I had zero issues with keepass2 on lunix, but now I'm trying to get my work onto a chomebook and while most things work the way I want to, keepass obviously doesn't. Does anyone know any password managers that work with chomeos without having to use developer mode?

I'm gonna wait until there's support for android apps, the keepass app for that should work well enough, but if it doesn't I'm going to have to switch (or go back to lunix) I guess

Truga
May 4, 2014
Lipstick Apathy

anthonypants posted:

and if you're on a chromebook you're stuck with your google account passwords, because it's a loving chromebook. install another operation system if you don't want to use chromeos

Sorry yeah, was just gonna ask that, is google passwords good/secure? I'm guessing yes, since google, but I have roughly zero experience with google stuff outside search until very recently.

Truga
May 4, 2014
Lipstick Apathy
https://httpoxy.org/

Yay, another vuln with a name

Truga
May 4, 2014
Lipstick Apathy
speaking of fridges, a friend of mine is working on an internet of thing, and today he found out the process of getting said thing connected to your psk wpa2 wifi:
1. install app on phone
2. connect phone to desired wifi, hit "connect" button in said app
3. thing is now connected to wifi.

the trick for this working is: your phone sends random data to your AP that is the exactly correct length, for the duration 802.11 header to spell out your password to the IoT device, prepended by the magic number that signals the start.

you absolutely cannot make this poo poo up

Truga
May 4, 2014
Lipstick Apathy
iot poo poo is aimed for the end user, you can't tell them to just connect this box and then log into it and holy poo poo what my brain is melting this other device that does the same thing from the competing company has "install app, everything works"

at least, that's what I think the thinking behind it is. said friend is still in shock

Truga
May 4, 2014
Lipstick Apathy
lomarf at the last 3 posts

Truga
May 4, 2014
Lipstick Apathy
holy poo poo.

i'm ffs attack

Truga
May 4, 2014
Lipstick Apathy
best part is definitely

quote:

We have registered all possible domains that are one bit flip away from ubuntu.com and debian.org.

Truga
May 4, 2014
Lipstick Apathy
Why is only illuminati passworded? :tinfoil:

Truga
May 4, 2014
Lipstick Apathy
https://motherboard.vice.com/read/infowars-accounts-hacked-prison-planet-alex-jones

quote:

The dumped data relates to Prison Planet TV, which gives paying subscribers access to a variety of Infowars content. The data includes email addresses, usernames, and poorly hashed passwords.

lol

Truga
May 4, 2014
Lipstick Apathy
Thank god for letsencrypt

Truga
May 4, 2014
Lipstick Apathy
process to get a passport in my stupid EU country: go to the local govt office, apply for a passport, show any document that shows you as you (anything is fine, including a driver's license or an expired passport), receive said passport via snailmail a week later

it's us, we're the secfuck in the schengen zone

vvv: I can pay a nominal 5 euro fee to have it ready for pickup on the next day's evening lmao.

Truga fucked around with this message at 15:01 on Sep 6, 2016

Truga
May 4, 2014
Lipstick Apathy

Wheany posted:

top 10 passwords of the last fm leak
123456
password
lastfm
123456789
qwerty
abc123
abcdefg
12345
1234
music

ugh these people keep stealing my luggage combinations goddammit

Truga
May 4, 2014
Lipstick Apathy
https://twitter.com/Angry_Voice/status/772816083065659392

Owns

Truga
May 4, 2014
Lipstick Apathy

URL grey tea posted:

I received an URGENT EMAIL to update my SanrioTown password (no shame).

Just for kicks I fill in the needed information on their password reset page and!

they send me the new password in plain text via email, and the site login page is http

I don't know what I expected

I'm the

quote:

'=''or' Says:
December 23rd, 2015 at 5:33 am

‘=”or’

Truga
May 4, 2014
Lipstick Apathy

quote:

VERY VIP

such mail much secure :shibe:

Truga
May 4, 2014
Lipstick Apathy
sshpass exists

and is a recommended package for ansible in ubuntu :cripes:

also, how do you type a sudo password if none of the users on the machine have a password

Truga
May 4, 2014
Lipstick Apathy

b0red posted:

Why even bother with a package? It can be done from the sudoers file.

Subjunctive posted:

same as ssh.

was replying to this

I thought it was normal, in tyool 2016, to not auth into ssh with passwords, especially for automation, until I typed apt-get install ansible on my laptop and saw sshpass under recommendations

now I just don't know anymore what's even real

Truga
May 4, 2014
Lipstick Apathy

Notorious b.s.d. posted:

see confusing users makes it more secure :smug:

security through confusity

Truga
May 4, 2014
Lipstick Apathy
if a user account is compromised, they have the password already, that's how they logged in (don't use passwords)

if your web service has sudo privileges, then lomarf

Truga
May 4, 2014
Lipstick Apathy

spankmeister posted:

They could have gotten in with an RCE of some kind and popped a shell.

ok sorry, let me fix that


Truga posted:

if your web service has sudo privileges, then lomarf

Adbot
ADBOT LOVES YOU

Truga
May 4, 2014
Lipstick Apathy
tbh, fde can sometimes be counterproductive

my last laptop, some now-ancient vaio z, shipped with gps and gsm/3g. so I only had the homedir encrypted (since fde wouldn't boot fully without the passphrase), and if there was an incorrect login attempt, or no login attempt for more than 30 seconds after boot, it'd send me an SMS with its coordinates, either via direct gps, or the google location service, whichever was available

I tested it a couple times, and it worked great, but nobody actually ever tried stealing it :(

  • Locked thread