Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Dylan16807
May 12, 2010

Flagrama posted:

windows 10 clean install was never free. upgrade from win7/8/8.1 was free and then would activate on your hardware even if you installed again clean.

and that upgrade still is free. the 'deadline' was only there to fight procrastination

Adbot
ADBOT LOVES YOU

Dylan16807
May 12, 2010

BangersInMyKnickers posted:

I am yet to see a way to shink a virtual disk and actually reclaim the space without spending a huge amount of ops doing it. Growing is no problem and can happen on the fly, you're much better setting smaller disks and dealing with people bumping in to the limits and cleaning up at that point before expanding allocations than letting idiocy or a malfunctioning application brim a drive with garbage which then cascades in to your storage replication and backup sets.

in virtualbox at least it's easy to set it so guest OS TRIM commands cause the disk file to shrink.

Dylan16807
May 12, 2010
chrome thing requires a PIN that you set on the computer, so it's probably secure but I couldn't find any real description of its security when I looked

Dylan16807
May 12, 2010

Winkle-Daddy posted:

MitM SSL strip isn't just about security, it's also about liability. In that regard it does what it needs to.

go ahead and MitM if you need to, but doing it on the end device with a self-signed cert seems like a terrible way to get there

Dylan16807
May 12, 2010

spankmeister posted:

Yeah but then you need to know the size of the colliding blocks beforehand because when you add blocks the filesize changes so the preamble changes so the hash changes so you need more/different colliding blocks so the filesize changes so the hash changes etc..

Not impossible, just a lot harder.

you just set the filesize to 10KB or whatever. once you have the collision you add identical data to both files until the size is right.

Dylan16807
May 12, 2010

Lutha Mahtin posted:

anyone use the Firefox sync feature? supposedly it works the same as a good password manager, where mozilla can't look at your data, but i never investigated it fully :effort:

I can tell you that it used to generate a random key that required an existing device to participate in authorizing a new device

but then they changed it to just use the password https://blog.mozilla.org/services/2014/04/30/firefox-syncs-new-security-model/

it's probably fine if you use a good password?


oh amazing, they have conflicting documentation up for both versions https://support.mozilla.org/t5/Sync-and-Save/How-do-I-add-a-device-to-Firefox-Sync/ta-p/21091 https://support.mozilla.org/t5/Sync-and-Save/How-do-I-set-up-Sync-on-my-computer/ta-p/21417

Dylan16807
May 12, 2010

anthonypants posted:

https://twitter.com/cczona/status/846859875854487553

there's a bunch more tweets in that thread too

the second sentence on that article sure got mangled. "out of all of them" and then it doesn't say what percent have malware

going by https://arstechnica.com/security/2017/01/majority-of-android-vpns-cant-be-trusted-to-make-users-more-secure/ it's a bit over a third

but a full 84% screwed up with IPv6 and 66% screwed up with DNS

at least a handful seem to be competent.

Dylan16807
May 12, 2010

Wheany posted:

Today in the secfuck thread: "if you suddenly get weird new popups in your browser, be sure to click on them"

clicking inside a web page can't really do anything that the web page couldn't already do

Dylan16807
May 12, 2010

spankmeister posted:

Nice way to make yourself not look like an idiot because you had a bog-standard DLL hijacking vulnerability.

I don't think there was actually a vulnerability, they were just replacing the DLL inside program files and the signing is more of a "gently caress you" than an increase in security

Dylan16807
May 12, 2010

infernal machines posted:

yeah, there are both. there are two scenarios where one but not both of the required components for IME may be present. the original claim was that this was irrelevant and it was exploitable regardless.

a bunch of people here posted screenshots of device manager on boards that do support it. there are boards that do not support IME and don't have that device. you can still install an i5 or an i7 that has vPro support in them.

likewise you can install a celeron, pentium, or i3 that does not support vpro in one of those boards they took the screen shots from. in either case, IME should not be active because it requires both chipset and cpu support.

this is not difficult

the issue is that going by what other people are saying the board support is very common

which would imply that a hell of a lot of consumer systems with i5 and i7 processors are vulnerable, maybe even most of them, not the relative rarity you're making it out to be

Dylan16807
May 12, 2010

ErIog posted:

1password not having Linux support is killing me right now and I think I'm going to just bite the bullet and switch back to Keepass like I was using 9 years ago.

The one thing I find absolutely infuriating about Keepass, though, is that it doesn't auto-save the vault when you add a new password or change passwords. I lost data on an encrypted sparse volume due to that before. That sucked poo poo and drove me over to 1password. Is that issue taken care of by any of the KeePass forks?

there's a very obtuse way of doing it. create a trigger on user interface state change, condition unsaved changes, action save

it fits the KeePass ethos of unnecessary extra work to set it up followed by working fine

Adbot
ADBOT LOVES YOU

Dylan16807
May 12, 2010

vOv posted:

i mean i don't see how it'd be any worse, it's not like the source of the light affects how harmful it is

the problem is that if the laser stops moving you have an entire screen's worth of brightness focused on a single pixel

  • Locked thread