Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Midjack
Dec 24, 2007



hackbunny posted:

why wouldn't you just download the official iso. did you know? if you don't activate windows 10, a few features are locked out but it mostly works?

a lot of people discover torrents and immediately forget that there's any other way to acquire software.

Adbot
ADBOT LOVES YOU

Midjack
Dec 24, 2007



Carbon dioxide posted:

http://www.bbc.com/news/technology-38521973

Folks scanned for non-password protected mongoDB databases exposed to the open internet and if there was any useful data in them, encrypted them with ransomware. Nice.

the best one i've seen so far is a bootleg website for playing the cyberpunk card game Netrunner got their poo poo wrecked :ironicat:

Midjack
Dec 24, 2007



zen death robot posted:

look the NRC is gonna come down on my rear end if i expose the public to that much radium

:laffo:

Midjack
Dec 24, 2007



DuckConference posted:

SA got banned from paypal a long time ago, the bittorrent forums or chargebacks or the katrina donation drive or something I don't really remember anymore.

Katrina.

Midjack
Dec 24, 2007



Powerful Two-Hander posted:

*nods sagely*

therefore my messaging app that discards all messages on any attempt to send is the best

arguably has a slightly lower signal to noise ratio though not by much

Midjack
Dec 24, 2007



Thanks Ants posted:

arent most luggage locks going to be garbage enough that you can just shim them open anyway

or just slice the bottom of your luggage open, why waste time defeating the lock when you can simply defeat the container?

Midjack
Dec 24, 2007



Shaggar posted:

stuxnet was so cool.

shaggar was right

Midjack
Dec 24, 2007



Trabisnikof posted:

Physically cutting the cable is pretty cheap for 100% effectiveness

so is unplugging the power NOW WHAT BITHC

Midjack
Dec 24, 2007



Powaqoatse posted:

i wipe my butt with your mac

not the paper around it

your rectum is rekt

Midjack
Dec 24, 2007



spankmeister posted:

the latest innovation in wizardsecurity: just use regular locks

this is almost always the right answer. electronic locks are always expensive, complex, and lovely; the only reason to use them is a massive facility with huge turnover, like a hotel where you can replace a lost magnetic key for a nickel and don't have to touch the door to invalidate the old one rather than pay $25 to install a new cylinder

Midjack
Dec 24, 2007



spankmeister posted:

I agree but you have to appreciate the irony and sheer ridiculousness of the fact that using regular old door locks is considered "innovative"

everything old is new again, and just because everything is different doesn't mean anything has really changed!

Midjack
Dec 24, 2007



fisting by many posted:

or you could just have standalone pcs for your keycard stuff and have it completely segregated from the internet, probably for a fraction of the cost of reinstalling locks on hundreds of rooms

but no, computers are wizard poo poo, let's go back to security by "do not copy"


i dearly want to assume this is just bad journalism but who knows anymore :iot:

a lot of systems pull information from the property management system (that folio number the twit at defcon was so proud of discovering on the card last summer), which is tied into the online reservations. it's cheaper and easier to just stick it all on the Internet, and now that many manufacturers offer zigbee or other internet of poo poo communication to the front desk, there you go

fisting by many posted:

i went to paris a few years ago and at my hotel you weren't allowed to take the key outside, you had to return it when you went out

then when you came back you'd just go to the desk and they'd recognize you and return the key

i thought it was the most ridiculous backwards-rear end thing at the time but maybe they were on to something

this is actually one of the best ways to secure hotel rooms but scales somewhat poorly

Midjack
Dec 24, 2007



uncurable mlady posted:

that was aggressively terrible

edit: i'm the guy in the rabbit mask who immediately takes it off and walks away at the end

Midjack fucked around with this message at 02:10 on Jan 30, 2017

Midjack
Dec 24, 2007




come and play my lord

Midjack
Dec 24, 2007




a similar attack happened in vegas years ago. the attackers bought a slot machine, determined the prng, then had to cruise for a machine in one of a few known states before they could start calling the patterns in. it took a bunch of trips to the pay phone with a synchronized watch and a partner to keep people off the machine while they conditioned it and the window to press the button was like 150 milliseconds. they got away with it for a while and quit before the heat came down on them. i'll look for the references when I get home tonight.

Midjack
Dec 24, 2007



Wiggly Wayne DDS posted:

is that a different contractor than the one taking home TBs of material for years? story was up a few weeks ago when they were raided

same guy that they raided in october

a lot has happened since then

Midjack
Dec 24, 2007



Perplx posted:

microsd cards are the densest, let's assume he's using 128GB, 256 is too new

50TB/128GB =390.625

a microsd card is 1mm so that 39cm or 15.4in

if you can get 2 stacks side by side thats 7.7in up your butt

it's physically possible

Midjack
Dec 24, 2007



Meat Beat Agent posted:

universal serial butt

Chris Knight posted:

any port in a packet storm

Midjack
Dec 24, 2007



apseudonym posted:

What did I just read?

haha oh man this is even better than his cryptocurrency scheme Ethereum

Midjack
Dec 24, 2007



pr0zac posted:

how does this thread have 90 pages of discussion i am so loving confused

eripsa is loving insane is how

Midjack
Dec 24, 2007




link here, it's long and this is a derail anyway

Midjack
Dec 24, 2007



keep loving that chicken in the secfuck thread, it's not like we don't have an entire loving forum to listen to this

Midjack
Dec 24, 2007



boy howdy i sure am enjoying watching this chicken get hosed

Midjack
Dec 24, 2007



anthonypants posted:

i've never heard of wickr before but they just went open sores https://github.com/WickrInc/wickr-crypto-c

they're yet another secure messaging thing that does who knows what with your data

Midjack
Dec 24, 2007



Jewel posted:

continuing on from the bitcoin CI, a great one i just saw on twitter

https://github.com/auchenberg/volkswagen

lol

conceptually similar to the eyepyramid vm detection; should we just call environmental detection and subsequent behavior modification "vdubbing" from now on?

Midjack
Dec 24, 2007




Hello, Yospos Bitch

apseudonym posted:

I would have accepted "most Security Experts suck rear end at building real things" as a response instead of "OMG NSA".

eripsa is loving insane

Midjack
Dec 24, 2007



dragon enthusiast posted:

has anyone said cloudfart yet

buttfart

Midjack
Dec 24, 2007



Thanks Ants posted:

re: access fobs, a bunch of the systems work by just reading the serial number off the 125khz token which is shamefully bad. i think the hid systems are actually able to interrogate the card bt they cost more than some apartment developer is going to pay.

also fob + pin pad readers should be more common than they are.

the card standard in use matters less if you can just smash the reader off the wall and deliver the data straight to the controller, though: http://blog.opensecurityresearch.com/2012/12/hacking-wiegand-serial-protocol.html

not really, most LF systems just read the number off the fob. there are a ton of custom formats running around but the LF systems don't typically have enough sophistication on the credentials to do any sort of authentication

newer HF stuff can get fancy as you describe

Midjack
Dec 24, 2007



Munkeymon posted:

is the reward a shirt that confirms that your uncle does indeed work for Nintendo?

Volmarias posted:

Well, that's easy to solve, just have one of them click on a phishing email and all of their emails will be encrypted.

two in a row

Midjack
Dec 24, 2007




i intensely dislike uber and their ilk for a variety of reasons but that's still pretty great

Midjack
Dec 24, 2007



cloud2butt remains a pro plugin

Midjack
Dec 24, 2007



Rooney McNibnug posted:

keep rear end x :wink:

this ain't a password manager xxx

Midjack
Dec 24, 2007



redleader posted:

homegrown crypto question: how bad is it if you can narrow down the range of possible values for the IV based on, say, the current date/time?

real bad

Midjack
Dec 24, 2007



bump_fn posted:

hey sec thread how easy would it be to make a USB "charging" station that compromises every device that gets plugged into it because this is what I assume every USB port charging station is

there's been one set up in the hall at defcon for the last few years

Midjack
Dec 24, 2007



Zero One posted:

It's lovely

Midjack
Dec 24, 2007



infernal machines posted:

holy poo poo. this seems like it should be bigger news

there might have been another disclosure right around then

Midjack
Dec 24, 2007



Midjack
Dec 24, 2007




lol

Midjack
Dec 24, 2007



cinci zoo sniper posted:

alphabetamines would suggest literacy though

Adbot
ADBOT LOVES YOU

Midjack
Dec 24, 2007




it seems like this stunt gets rediscovered every few years

  • Locked thread