Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
duTrieux.
Oct 9, 2003


what the gently caress

Adbot
ADBOT LOVES YOU

duTrieux.
Oct 9, 2003

reminder that you can download a variety of preconfigured HyperV machines with various versions of windows' directly from microsoft for free at modern.ie,

duTrieux.
Oct 9, 2003

run a crack on them

or just save state and refresh every now and again

duTrieux.
Oct 9, 2003

COACHS SPORT BAR posted:

the windows 10 download page can be coerced into showing download options for windows 7 and 8 as well with a little js :ssh:

i used this to downloaded and archive 32 and 64 bit win 7 isos as a 'just in case'

windows 10, too. gently caress windows 8.

duTrieux.
Oct 9, 2003

Fuzzy Mammal posted:

my latest flight was delayed because they overloaded the plane and we needed to sit there and burn off exactly 140l of fuel.

i was traveling this week and i noticed a small wheeled tank on the runway labeled "USED FUEL"

duTrieux.
Oct 9, 2003


duTrieux.
Oct 9, 2003

Shaggar posted:

ive never used teamviewer for persistent remote access but id put it in the same category as opening rdp or ssh to the world.
you spe
the problem with teamviewer isn't technical, it's social. rdp or ssh or whatever is specific to that machine, meaning somebody would have to specifically target you. teamviewer (and other 3rd-party services) create a single point of failure. what's easier, doing a mass port scan and targeting individual machines or breaching a single system with direct access to hundreds or thousands of machines?

duTrieux.
Oct 9, 2003

wyoak posted:

i dunno saying something as general as "never trust a 3rd party" seems a bit paranoid and the endgame there is actively vetting crypto algos and only using software that you've compiled yourself using those algos (also using a compiler you wrote yourself)

do you use lastpass

duTrieux.
Oct 9, 2003

Shaggar posted:

mass port scans are way way easier especially w/ access to botnets.

botnets :argh:

duTrieux.
Oct 9, 2003

chaotic good as gently caress

duTrieux.
Oct 9, 2003

just use one of those popomatic trouble dice domes for your rng seed, problem solved

duTrieux.
Oct 9, 2003

Jimmy Carter posted:

9/11 mayor getting made chief of cyber.

one of these days i'm going to give enough of a poo poo to edit in giulianiilini and a cloud service logo

Only registered members can see post attachments!

duTrieux.
Oct 9, 2003


this is pretty fuckin' bad

duTrieux.
Oct 9, 2003

Ur Getting Fatter posted:

loving lol at that secret service agent leaving her backpack in her car in her driveway while she was inside the house.

for real, tho

duTrieux.
Oct 9, 2003

Pryor on Fire posted:

Hmm someone was just able to break out of a VM and compromise the host in VMWare, I think that will cause some rethinking of things

why pay for the whole exploit when you only need the edge

https://twitter.com/thezdi/status/842788469923442689

duTrieux.
Oct 9, 2003


Kuvo posted:

brb testing this out

Kuvo posted:

hahah what


duTrieux.
Oct 9, 2003

JawnV6 posted:

top notch Siren Matter Expert on the way

boo. boooooo!

duTrieux.
Oct 9, 2003

Midjack posted:

i'm the pearl clutching about an internet of poo poo device having security problems

some people still have illusions to be shattered.

duTrieux.
Oct 9, 2003

funny Star Wars parody posted:

that dudes twitter handle is worth a fortune

at least 15k. this is based on having sold a five-character twitter handle for 10k.

duTrieux.
Oct 9, 2003

MononcQc posted:

On top of gunshot locators, there's other fancy stuff, like tracking car motions through the RFID chips in EZcard in NYC. Tinfoil hatters worry about RFID chips tire manufacturers embed in there to track their inventory since they could also be used there.

There's also references to using license plate recognition (p.23-24) to do geo-fencing and correlation of traffic patterns in some areas with crimes such as drug trafficking, and similarly correlating with social media. There's some pretty fancy stuff out there.

data mining can surface a lot of interesting stuff. unfortunately, it's all developed and utilized by people with their own implicit biases

duTrieux.
Oct 9, 2003

cinci zoo sniper posted:

circumvents pin-protected lockscreen

why is this even possibleandroid

duTrieux.
Oct 9, 2003

Subjunctive posted:

why does it matter if it's full-screen or not?

cinci zoo sniper posted:

as ive said, im not sure how much this actually matters. i just have never seen a lockscreen interaction other than a widget before, and it feels shortsighted that the app authorizing bank payments does circumvent some portion of security measure on the phone

artists representation of android security:

Only registered members can see post attachments!

duTrieux.
Oct 9, 2003

gotta have 2fa to protect my digital hats

duTrieux.
Oct 9, 2003

lol at using games in order to gamble and launder money

duTrieux.
Oct 9, 2003

cis autodrag posted:

imagine a pressure sensitive toilet seat.

user-configurable delay between standing up and flushing to account for people who may lift fully off of the seat when wiping and also to allow for appropriate poop-inspection time

duTrieux.
Oct 9, 2003

PCjr sidecar posted:

add facial recognition, kuerig toilet paper, and a neural net to monitor dwell time and you've got storytime

instead of facial recognition, include multiple sensors so that it can determine who is sitting on it based on their weight distribution

duTrieux.
Oct 9, 2003

tangential, but ebola isn't a death sentence. like most diseases, it depends on local infrastructure and medical resources

duTrieux.
Oct 9, 2003

BlueBlazer posted:

Too true, been using the medical analogies all day on this one.

You could kill it but would need the resources to flash every piece of hardware on the network. A daunting feat for even the strongest of sourcerers.

I've also managed to make the analogy between available healthcare and infosec today. Only rich people have it and everyone else will be wiped out in the coming plague.

this makes me think the ebola metaphor fits a lot better than i had first thought.

also re: sourcerers, maybe that's why so many tech companies are having trouble with hiring women; they're all after seventh sons of seventh sons. must investigate further.

duTrieux.
Oct 9, 2003

i just received a company-wide email about the HP audio keylogger fiasco. all issues PCs are HP machines, so I've been wondering if the company would say or do anything about.

duTrieux.
Oct 9, 2003

mod saas posted:

re:keep rear end, is there an acceptable version for macos?

...you aren't running windows in a vm?

duTrieux.
Oct 9, 2003

haveblue posted:

that is not dead which can eternal buffer

duTrieux.
Oct 9, 2003

goddamnedtwisto posted:

i'm the multi-billion dollar international arms company with a free blogspot account

that's how they got to be so rich! scrimp and save. why, if it weren't for all of that avocado toast you'd be a millionairian already! those millennials.

duTrieux.
Oct 9, 2003

my understanding was that if you're on the same network it's much easier to force other devices on the network to do another handshake, allowing you to capture what you need (from watching the handshake) to decrypt traffic from that device.

i'm an idiot so that may be entirely wrong.

duTrieux.
Oct 9, 2003

spankmeister posted:

Yeah Why do they Do that AnyWay?

https://en.wikipedia.org/wiki/Word_salad

duTrieux.
Oct 9, 2003

whatever happened to body area networks, anyway

duTrieux.
Oct 9, 2003

Jewel posted:

keepass

why do people keep asking and not learning

use the one that doesnt have the database in some ~magic autosync cloud~ and don't download stupid poo poo to your computer and execute it. that's all you have to do

duTrieux.
Oct 9, 2003

Volmarias posted:

:science: "Use the system where you have to keep track of things yourself if anything changes and you get to copy paste things in manually for each website and you sync your key file across your computers using dropbox"

:downs: "drop what? Key who? Look, why can't I just keep using this thing I'm already using, it works great and I'm used to it and I don't have to do any extra work. I don't have to type a password in whenever I want to use a website, why are you making this harder?"

How does this thread continue to not understand that usability is a larger, more immediate, and more visible concern for end users than a nebulous concept of good security practices? This is the same thread that understands "making strict password change rules means people will just add 1 to the end each time"

usability is important, but shouldn't also significantly undermine the entire point of the thing that you're using

if knowing what a file is is too complicated, then one should just use a pen and paper and then keep the paper somewhere secure

"remembering where i kept my piece of paper with passwords on it is too hard! i'm going to give it to somebody in my neighborhood and then have him shout my paswords at me wheneve ri need them. so much more usable!"

duTrieux.
Oct 9, 2003

the solution is to educate people on basic digital security, not to dumb everything down so as to be worse than nothing

duTrieux.
Oct 9, 2003

also i don't think using pen/paper is patronizing; if somebody is uncomfortable with digital solutions then having a written record that they can mentally classify witht he same security as, idk, a checkbook or a social security card works fairly well.

Adbot
ADBOT LOVES YOU

duTrieux.
Oct 9, 2003

anthonypants posted:

when i paid for lastpass, keep rear end was still an open sores nightmare where you needed third-party plugins for anything you actually wanted to use it for, and a lot of plugins weren't compatible between keep rear end v1 and keep rear end v2. i've since switched to 1password but i don't believe keep rear end has gotten any better. like, if i wanted to get chrome integration with keep rear end, i'd go to their plugins page, ctrl+f chrome, the first result is a plugin called KeeForm, here is their website, whoops it doesn't actually work with chrome

um

i use keepass with chrome and i didn't have to install any plugins? i just go to keepass and press ctrl+v on the entry and it auto-types into chrome for me?

  • Locked thread