Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Truga
May 4, 2014
Lipstick Apathy

Migishu posted:

Security Fuckup Megathread - v13.0.1 - looks like them secfuck boys are at it again

Adbot
ADBOT LOVES YOU

Truga
May 4, 2014
Lipstick Apathy

This is great, I hope it happens.

Truga
May 4, 2014
Lipstick Apathy


center for strategic and int'l studies wizard policy task force. has the wizard glasses to prove it

2017 is going to be a very good year for wizard security, i can tell already

Truga
May 4, 2014
Lipstick Apathy

Segmentation Fault posted:

you can still get a free upgrade if you jump through some sort of user accessibility hoop, I don't know anything about that specifically

You have to pinky swear you'll use accessibility features (like, say, hotkeys) when using windows, and you can still install it from here: https://www.microsoft.com/en-us/accessibility/windows10upgrade That's it.

Also, lol that microsoft themselves don't offer a torrent of their iso, it's a much better protocol for downloading large files than http if your internet isn't very fast (so, majority of the world that doesn't have win10 yet). Are there even any browsers out there that can resume http downloads today?

Winkle-Daddy posted:

Hey sec fuckup thread! I know I've seen some awesome posts about what cipher suites should be enabled...does anyone have a config or can link to an ideal nginx SSL config? Specifically for ssl_protocols and ssl_ciphers?

My personal procedure is to use https://www.ssllabs.com/ssltest/analyze.html until it shows A or A+. It says what the problematic ciphers are if you have them enabled.

Truga
May 4, 2014
Lipstick Apathy

however, if you have to

pr0zac posted:

no one should be running windows 7 when win10 is a free upgrade
this, and installing 7 and upgrading isn't needed either.

windows 10 installer will take a windows 7 product key even on a fresh install in my experience, even after the period ended.

Truga
May 4, 2014
Lipstick Apathy

ratbert90 posted:

Random question:

Is there a way for me to NOT have a self-signed certificate on an production embedded device that may not be connected to the internet?

Get a 50 year certificate:v:

But no, I don't think you can. What you can do is allow the customer to add their own certificate, and they can either suck or get one from their own internal CA

E: welp i can't scroll

Truga
May 4, 2014
Lipstick Apathy
And enjoy your house fire when the fridge decides it's time to set its temperature to 2 billion degrees because it couldn't resolve dumbfridge.samsung.co.kr.

No, the way of going about this is to buy dumb appliances. They're probably still cheaper at this point, even.

Truga
May 4, 2014
Lipstick Apathy

honestly, this is great

brb dumping all blu ray encryption keys

LastInLine posted:

for now thats an option but just like tvs what will happen is that "premium" sizes or featuresets will eventually be smart only then ones with relatively mundane features like everything with an ice maker or a timer on the oven and then it will just be the lovely rental unit ones that arent smart and everything else will be smart

i'll be the idiot paying idiot hipster tax for dumb fridges in 2030, if (lomarf) iot is still a shitshow.

Truga fucked around with this message at 13:57 on Jan 10, 2017

Truga
May 4, 2014
Lipstick Apathy
and thus begins the fall of ransomware

Truga
May 4, 2014
Lipstick Apathy
security pissup megathread - much hacking, hacking is bad, shouldn't be done

Truga
May 4, 2014
Lipstick Apathy
trump's obercybergrandpa

Truga
May 4, 2014
Lipstick Apathy

Powaqoatse posted:

goddamn youre amazing

Truga
May 4, 2014
Lipstick Apathy

Ur Getting Fatter posted:

waSSHing machine

Truga
May 4, 2014
Lipstick Apathy

OSI bean dip posted:

Isn't there a limit to the number AD users and groups?

depends, which samba version is it running on?

Truga
May 4, 2014
Lipstick Apathy
guess i'm safe, all my paths contain anime

Truga
May 4, 2014
Lipstick Apathy
snowden died in vain https://www.whitehouse.gov/the-press-office/2017/01/25/presidential-executive-order-enhancing-public-safety-interior-united

quote:

Sec. 14. Privacy Act. Agencies shall, to the extent consistent with applicable law, ensure that their privacy policies exclude persons who are not United States citizens or lawful permanent residents from the protections of the Privacy Act regarding personally identifiable information.

if you're not a us citizen get your poo poo out of us services. probably if you're us citizen too :v:

Truga
May 4, 2014
Lipstick Apathy

Subjunctive posted:

How so? Legal residents and visitors to the US enjoy the full protection of law.

Well, yeah, but now it's also legal. Until now there was that safe harbour replacement thing: http://fortune.com/2016/02/02/looks-like-data-will-keep-flowing-from-the-eu-to-the-u-s-after-all/

Truga
May 4, 2014
Lipstick Apathy

Subjunctive posted:

So how is this the same as it's been then?
difference is, now it's legal for nsa to read my mail
it's the same since i'm pretty sure they'd do it if they wanted to do it

in other words:

flakeloaf posted:

to the extent that the law can be flexed, for compelling reasons like "because we can" and "gently caress you"

also, this fuels my paranoia nicely, and it feels good.

my antivirus anecdote is that windows defender runs in the background automatically and users don't know it's av since it's windows and thus don't complain about av slowing their pc. probably might as well not exist, but it satisfies the antivirus requirement some people give so i'll take it

e: oh, i also run clamav on mail gateways for the same reason and get a few mails every year about it catching this or that 10 year old infected .doc or troyan

Truga
May 4, 2014
Lipstick Apathy
oh, that's even worse then

Truga
May 4, 2014
Lipstick Apathy
nah, you're right

hijacking a browser or the iot poo poo is great and all, but there's a lot of things they can't do. obviously you don't bother attacking av when making your kickass anime botnet because the potential amount of targets is an order of magnitude smaller

but if you're going to do espionage, sabotage, that sort of poo poo, figuring out what av your target office uses (often just telneting to their mail server and sending to a bogus address will send you a reply with SCANNED BY OUR SUPERSCANNER 9000) and attacking that is probably one of the better courses of action, because 2 posts up

Truga
May 4, 2014
Lipstick Apathy
your operating system is printing owned sheets.

Truga
May 4, 2014
Lipstick Apathy

Subjunctive posted:

I also somewhat doubt that we have clean backups.

nice av/post combo there

Truga
May 4, 2014
Lipstick Apathy
denuvo isn't always online, but it does stop working if it can't get online for more than 5 days, presumably to get new keys.

Truga
May 4, 2014
Lipstick Apathy

The_Franz posted:

so it's likely that the cracking group just has it figured out at this point

either that or it has something to do with

https://twitter.com/alt_kia/status/818609521928998912?ref_src=twsrc%5Etfw

if you have full debug access to your cpu, hahahaha drm? lol nope.

Truga
May 4, 2014
Lipstick Apathy

LeftistMuslimObama posted:

the grey forum sure is mad that firefox is getting rid of the older more insecure extension framework. how will they get a "sane" tabs-under-url ui without classic theme restorer?

the old firefox extension framework is also real loving good though, and allows for a lot of things the lovely js one can't do

i don't give a poo poo where the url bar is, because my url bar doesn't exist, but if the only extensions that are keeping firefox users on firefox break, most will just use chome instead. i'm sure google would love that, but i'm not sure mozilla will.

Truga
May 4, 2014
Lipstick Apathy

cheese-cube posted:

NPAPI support : firefox :: register_globals : PHP

nobody is bothered by NPAPI being gone, it's never worked in 64bit firefox anyway

people are bothered with the webextensions framework being a shitshow, though at least they seem to be working hard on extending it finally

hopefully they'll have most of the functionality down by the time they force xul off for everyone

e;fb

and no, it's nothing like npapi at all.

Truga
May 4, 2014
Lipstick Apathy
yeah, I'm not going to defend xul in any way because it's a gigantic mess, and i purposefully avoided writing poo poo in it even though i've used firefox since the first beta releases. writing applications with xml ughhhh

but webextensions right now can't replace quite a bit of things xul extensions do for firefox. webextensions is very good though and mozilla has been working hard on extending it to the point where it'll hopefully do most of the things xul does now. there's some things that won't ever be possible I'm sure, but I don't know any extensions that would need more than webextensions is theoretically capable of providing

plus, it's more secure, since it runs inside the browser sandbox afaik. if you install a malicious firefox extension it probably can do some real damage right now

Truga
May 4, 2014
Lipstick Apathy
gonna be a lot of bits when that condom ruptures

Truga
May 4, 2014
Lipstick Apathy

Meat Beat Agent posted:

universal serial butt

Truga
May 4, 2014
Lipstick Apathy
https://arstechnica.com/security/2017/02/a-rash-of-invisible-fileless-malware-is-infecting-banks-around-the-globe/

owns

quote:

Now, fileless malware is going mainstream, as financially motivated criminal hackers mimic their nation-sponsored counterparts. According to research Kaspersky Lab plans to publish Wednesday, networks belonging to at least 140 banks and other enterprises have been infected by malware that relies on the same in-memory design to remain nearly invisible. Because infections are so hard to spot, the actual number is likely much higher.

Truga
May 4, 2014
Lipstick Apathy
https://www.vusec.net/projects/anc/

:rip: aslr

Truga
May 4, 2014
Lipstick Apathy
just download some lovely windows 7 pro iso and upgrade to windows 10, jeez

Truga
May 4, 2014
Lipstick Apathy
https://wycd.net/posts/2017-02-21-ibm-whole-cluster-privilege-escalation-disclosure.html

quote:

This is a disclosure of a privilege escalation vulnerability I found in the IBM Data Science Experience product, which was patched on Feb 15th, 2017. It was a misconfiguration vulnerability with very severe consequences. In short, they left all the Docker TLS keys in the container

...

What was at stake:
* Root access across whole compute cluster
* R/W to 100s of TBs of customer data

Conditions required:
* Web browser
* Free trial account



ayyyy lmao

Truga
May 4, 2014
Lipstick Apathy
i'm currently in the process of deploying openshift through our infrastructure and butts and it's going to own and be the best thing ever, but yes, i agree

Truga
May 4, 2014
Lipstick Apathy
the main problem of docker is the ease of access i bet. you click or paste a few things and are developing the app in a production like environment! another few clicks and it's running on production in a ha cluster! it's like magic

you're supposed to have a sysadmin and/or devops guys handling all the configuration poo poo, but lol if a manager will hire a dude he doesn't explicitly need to push his project into production, when he could raise his own salary by pushing out more project faster, cheaper

if a secfuck happens, the dev will be the one getting hosed anyway

Truga
May 4, 2014
Lipstick Apathy

OSI bean dip posted:

a year now will be a month in few years

case in point, from the amd thread:

:v:
maybe amd will finally be good again and the rate of progress will increase, as intel/nvidia get off their collective butts

tangentially related, there's bound to be good bugs in early zen, a completely new arch waiting to be exploited. especially seeing how they're basically soc now, there's barely anything off the package. can't wait

Truga
May 4, 2014
Lipstick Apathy

ate all the Oreos posted:

christ you have a lot of plugins why you got so many plugins plugin man

that's what my chome looked like when i had chomeos

Truga
May 4, 2014
Lipstick Apathy
some password manager did send their passwords in the clear through cloudflare tho.

was it lastpass again? those guys just keep loving up

Truga
May 4, 2014
Lipstick Apathy
no, over https. just not, you know, like normal people do password managers - in an encrypted container that only you know the secret to unlock

Adbot
ADBOT LOVES YOU

Truga
May 4, 2014
Lipstick Apathy
in other news:
https://www.wired.com/2017/02/malware-sends-stolen-data-drone-just-pcs-blinking-led/

first disk clicking, then fan speeds, now blinken lights, lmao

  • Locked thread