Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
AggressivelyStupid
Jan 9, 2012

Tayter Swift posted:

Security
Hardware for the
Internet of
Things

Adbot
ADBOT LOVES YOU

AggressivelyStupid
Jan 9, 2012

Jewel posted:

oh my God, furbies have an accessible debug menu and it shows up in their eyes and the future owns



http://hackaday.com/2017/01/21/taking-control-of-your-furby/

"[Jeija] is able to add custom audio to the official DLC files and upload them into the Furby.

[Jeija] points out the all this was done without taking a Furby apart, only by sniffing the Bluetooth communication between the robot and the controlling app"

I can't wait to see furbies get remotely hacked

This rules but I can't believe this is the fourth furby

AggressivelyStupid
Jan 9, 2012


The Cyber Realm

AggressivelyStupid
Jan 9, 2012

Wheany posted:

keep rear end

AggressivelyStupid
Jan 9, 2012

Just use lynx, op

AggressivelyStupid
Jan 9, 2012

My Linux Rig posted:

why does anyone still use LastPass, KeePass and SpiderOak are literally all you need and it's actual secure

AggressivelyStupid
Jan 9, 2012

I rolled my own cloud storage

AggressivelyStupid
Jan 9, 2012


why

AggressivelyStupid
Jan 9, 2012

Bernstein is a wild rear end in a top hat jesus loving christ

AggressivelyStupid
Jan 9, 2012

On a scale of 1 to 10 how bad is storing SSNs in plaintext? I'm asking for a friend.

E: along with pretty much every other piece of PII

AggressivelyStupid
Jan 9, 2012

For clarification, I'm not the one storing them. If it were up to me I'd not touch that poo poo because I don't want to get owned and have it be my fault for being a big dumb idiot.

I'm just looking at my own unencrypted ssn right now and am kinda annoyed but resigned to the fact that I already am owned

AggressivelyStupid
Jan 9, 2012


Not wrong tho

AggressivelyStupid
Jan 9, 2012


:eyepop:

AggressivelyStupid
Jan 9, 2012


I need this in my life right now

AggressivelyStupid
Jan 9, 2012

im so excited

AggressivelyStupid
Jan 9, 2012

https://twitter.com/kennethlipp/status/849684722150256648

AggressivelyStupid
Jan 9, 2012

Cocoa Crispies posted:

unless you mean "cops" in which case you can just say "pigs"

AggressivelyStupid
Jan 9, 2012

Powerful Two-Hander posted:

security fuckup megathread: /* should we even bother? */.

AggressivelyStupid
Jan 9, 2012

wiper no wiping

AggressivelyStupid
Jan 9, 2012

https://twitter.com/mikko/status/869539641090867200

AggressivelyStupid
Jan 9, 2012

spankmeister posted:

I should point out that in this case it's the crappy implementation of Blackboard that the University of Amsterdam did that causes most of these issues, not Blackboard itself...

they're probably not alone in crappy blackboard implementations though

AggressivelyStupid
Jan 9, 2012

Let's Play/Walkthrough

For the sake of this walkthrough, we assume you are a paranoid user who does not trust any one keystore with your credentials. You decide to spread your secrets across three keystores (at least two are required to use Horcrux) across three distinct datacenter regions in Amazon Web Services (AWS). You then plan to make a Facebook account with Horcrux and successfully login.


:thunk:

Adbot
ADBOT LOVES YOU

AggressivelyStupid
Jan 9, 2012

Lain Iwakura posted:

What is the worst that can happen? I am sure it has the highest quality code.


JavaScript code:

     // unique salt?
     const key = crypto.pbkdf2Sync(auth, '0945jv209j252x5', 100000, 512, 'sha512');

     console.log("Super secret auth key is: " + key.toString('hex') + "\n"); // '3745e48...aa39b34'

i'm the unique salt?

  • Locked thread