Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Thanks Ants
May 21, 2004

#essereFerrari


an internet connected consumer electronics device to protect your internet connected consumer electronics

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


:psyduck:

there's reinventing the wheel and then there's this

Thanks Ants
May 21, 2004

#essereFerrari


has anyone got any pointers on what to look for when hiring a firm/consultant to do penetration testing? it seems there's a ton of charlatans in the industry.

im currently looking at ones that publish their own research and show up at cons rather than simply blogging about things, but would be interested to hear about how this is usually approached.

Thanks Ants
May 21, 2004

#essereFerrari


arent most luggage locks going to be garbage enough that you can just shim them open anyway

Thanks Ants
May 21, 2004

#essereFerrari


Captain Foo posted:

I am very interested in that hackbunny post, cool stuff!

Thanks Ants
May 21, 2004

#essereFerrari


was there anything special about october?

Thanks Ants
May 21, 2004

#essereFerrari


fibre cut talk from a few years back
https://www.theguardian.com/world/2011/apr/06/georgian-woman-cuts-web-access

quote:

An elderly Georgian woman was scavenging for copper to sell as scrap when she accidentally sliced through an underground cable and cut off internet services to all of neighbouring Armenia, it emerged on Wednesday.

Thanks Ants
May 21, 2004

#essereFerrari


if your phone usually only required a fingerprint to unlock past the first boot/period of non-use, but if it were possible to 'hey siri' it into a state of requiring a pin/password again, would that legally count as obstruction?

Thanks Ants
May 21, 2004

#essereFerrari



:vince:

Thanks Ants
May 21, 2004

#essereFerrari


ate poo poo on live tv posted:

Supermicro is a shitshow, BUT they are a cheap shitshow.

they oem for a gently caress ton of other people though - like about a billion people trying to get into storage market. i don't know how much firmware development happens by those users of supermicro gear, or if the only change they make is to put a different badge on the front.

Thanks Ants
May 21, 2004

#essereFerrari


re: access fobs, a bunch of the systems work by just reading the serial number off the 125khz token which is shamefully bad. i think the hid systems are actually able to interrogate the card bt they cost more than some apartment developer is going to pay.

also fob + pin pad readers should be more common than they are.

the card standard in use matters less if you can just smash the reader off the wall and deliver the data straight to the controller, though: http://blog.opensecurityresearch.com/2012/12/hacking-wiegand-serial-protocol.html

Thanks Ants fucked around with this message at 01:07 on Feb 28, 2017

Thanks Ants
May 21, 2004

#essereFerrari


Thanks Ants
May 21, 2004

#essereFerrari


i once had a discussion with a developer who claimed that he was going to 'bolt the security on at a later date', maybe he works for you guys now?

Thanks Ants
May 21, 2004

#essereFerrari


cheese-cube posted:

i hope that dev is now dead. loving ignorant bastard. it's exactly that attitude which is the cause of all our problems. pissssssss

he's still alive and has since become the sort of person who wears odd socks on purpose to prove how laid back he is

Thanks Ants
May 21, 2004

#essereFerrari


anthonypants posted:

cjs: talking to a new lady in marketing who is super concerned that b2b emails from surveymonkey are getting flagged as spam when they're sent to herself. i think they're getting flagged because we don't do javascript in emails and i would very much like to keep that setting the way it is

i'd be surprised if surveymonkey emails had javascript in, since their delivery rates would be pretty horrific. can you see them in a message trace? it might be something simple like they're being sent with your domain set as the from, and you have policies in place to drop them if they originate from outside your exchange environment.

Thanks Ants
May 21, 2004

#essereFerrari


its a lot of effort running around making your environment more vulnerable by hand

Thanks Ants
May 21, 2004

#essereFerrari


Powerful Two-Hander posted:

clever marketing i guess because you'll never forget it

:pusheen:

Thanks Ants
May 21, 2004

#essereFerrari


he's got giuliani and his son or whoever it was so everything will be fine

Thanks Ants
May 21, 2004

#essereFerrari


spankmeister posted:

new thread title pls

Thanks Ants
May 21, 2004

#essereFerrari


apple does the same thing, fyi http://captive.apple.com/hotspot-detect.html

i dont know how often it checks, each time connectivity changes at a guess?

Thanks Ants
May 21, 2004

#essereFerrari


except for that guys uncle

Thanks Ants
May 21, 2004

#essereFerrari


i think impact mitigation tends to just be checking for credit applications in your name and acting accordingly, take a look at https://www.consumer.ftc.gov/articles/0235-identity-theft-protection-services

Thanks Ants
May 21, 2004

#essereFerrari


are the 1password apps any good on windows yet?

Thanks Ants
May 21, 2004

#essereFerrari


Thanks Ants
May 21, 2004

#essereFerrari


Storysmith posted:

also I cannot stop reading that brand name as "slime eye" which is a really crass name for a cervix

Thanks Ants
May 21, 2004

#essereFerrari


welp

https://twitter.com/DEYCrypt/status/852974162138337280

Thanks Ants
May 21, 2004

#essereFerrari



less a skid mark, more a full-on brick

Thanks Ants
May 21, 2004

#essereFerrari


welp

https://www.theguardian.com/society/2017/may/12/hospitals-across-england-hit-by-large-scale-cyber-attack

Thanks Ants
May 21, 2004

#essereFerrari


im imagining the network guys doing a full boris in goldeneye and pulling modems out to stop the hack

Thanks Ants
May 21, 2004

#essereFerrari


haveblue posted:

breaking: chief of NHS IT authorizes deployment of spike, declares self "invincible"

runs at wall, disappears

Thanks Ants
May 21, 2004

#essereFerrari


BangersInMyKnickers posted:

maximum penetration

call me

Thanks Ants
May 21, 2004

#essereFerrari


Thanks Ants
May 21, 2004

#essereFerrari


https://www.youtube.com/watch?v=CTWwrO9XjaE

Thanks Ants
May 21, 2004

#essereFerrari


theres also the possibility that its been on his system for a while and purposely activated today

Thanks Ants
May 21, 2004

#essereFerrari


that's great, the act of firewalling the subnet it's on activates it.

Thanks Ants
May 21, 2004

#essereFerrari


vOv posted:

yeah there exists malware out there that will do nasty poo poo to your BIOS/EFI/ring -2 but i don't think standard ransomware will do it. just swap the drives and you're good

i am anal about keeping secure boot on for this reason

Thanks Ants
May 21, 2004

#essereFerrari


probably not because they'd know exactly what system you were running and could target it specifically, but for drive-by stuff trying to lodge itself into uefi i can see the uses

Thanks Ants
May 21, 2004

#essereFerrari


are they the thinkpads with that auto-loading rootkit in the bios?

Thanks Ants
May 21, 2004

#essereFerrari


i just clicked on the first page of this thread and i would like to give more exposure to the content of the first post. it also seems appropriate today.

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


comparing writeups of this wannacrypt outbreak to the reports in the press is pretty eye-opening as to how much of it is just pure guesswork or extrapolation way past a point that is rasonable

  • Locked thread