Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

quote:

Hello,

It has come to our attention that in 2013 there was an undetected breach of the RedFlagDeals.com user database. The contents of this breach were posted online on Monday, January 9th 2017. No personal information was obtained in this breach, only RedFlagDeals usernames and encrypted passwords.

As a matter of best practice, we regularly conduct security testing of our sites to minimize the chance of this type of leak reoccurring. As a precautionary measure, we have logged all affected users out of the RedFlagDeals system and are implementing a mandatory password reset. We encourage affected users to take the time to reset their password, when prompted, by clicking 'Forgot your password?' and following the subsequent steps. It is also important to change your password on any sites where the same password may have been used.

We apologize for any inconvenience this may cause you. Please email support if you have any further questions.

RedFlagDeals.com

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/andryou/status/818946765684670468

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

spankmeister posted:

Theo is annoying

i threw an egg at his house once

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/Viss/status/819685780247298048
https://twitter.com/Viss/status/819686452002861056

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

fins posted:

Shadowbrokers taking their toys and going home:
https://onlyzero.net/theshadowbrokers.bit/post/messagefinale/

quote:

So long, farewell peoples. TheShadowBrokers is going dark, making exit. Continuing is being much risk and bullshit, not many bitcoins. TheShadowBrokers is deleting accounts and moving on so don’t be trying communications. Despite theories, it always being about bitcoins for TheShadowBrokers. Free dumps and bullshit political talk was being for marketing attention. There being no bitcoins in free dumps and giveaways. You are being disappointed? Nobody is being more disappointed than TheShadowBrokers. But TheShadowBrokers is leaving door open. You having TheShadowBrokers public bitcoin address 19BY2XCgbDe6WtTVbTyzM9eR3LYr6VitWK TheShadowBrokers offer is still being good, no expiration. If TheShadowBrokers receiving 10,000 btc in bitcoin address then coming out of hiding and dumping password for Linux + Windows. Before go, TheShadowBrokers dropped Equation Group Windows Warez onto system with Kaspersky security product. 58 files popped Kaspersky alert for equationdrug.generic and equationdrug.k TheShadowBrokers is giving you popped files and including corresponding LP files. Password is FuckTheWorld Is being final gently caress you, you should have been believing TheShadowBrokers.

lol so whiny

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

apseudonym posted:

Ah yes, the good ol' "I don't trust my OS but somehow don't think Im completely hosed"

makes me think of that medium article that came out around christmas telling people to make windows stop calling home because microsoft could watch what you're doing

if you're paranoid about an os calling home, don't use that os

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Volmarias posted:

Installing Linux isn't a realistic option for most end users, and buying a MBP costs a lot of money said user may not have.

if you have the mindset that windows is filled with backdoors and that the only solution to protect yourself from them is to make changes to the registry or block items via the firewall, then use linux. if linux is somehow not an option then you're a lost cause

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/kaepora/status/820030127102795776

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
I guess we're back?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Subjunctive posted:

I want to know Backhoe's score.

when i worked at an isp, three years in a row and approximately in the same spot affecting the same fiber line, we'd have a backhoe dig up our link between our data centre in edmonton to a town in northern alberta. it happened like clockwork around the beginning of october

backhoes are a menace

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

I have had my Samsung washer leak from having a sock in the gasket. I cannot wait to have it gush all over the floor when it gets owned or gets a faulty update.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Wiggly Wayne DDS posted:

germany ...

really though you wouldn't show large-scale capabilities of that nature publicly unless you were effectively at war, like ukraine

yep

https://www.wired.com/2015/01/german-steel-mill-hack-destruction/

quote:

I’m referring to the revelation, in a German report released just before Christmas (.pdf), that hackers had struck an unnamed steel mill in Germany. They did so by manipulating and disrupting control systems to such a degree that a blast furnace could not be properly shut down, resulting in “massive”—though unspecified—damage.

[...]

The report doesn’t name the plant or indicate when the breach first occurred or how long the hackers were in the network before the destruction occurred. It’s also unclear if the attackers intended to cause the physical destruction or if this was simply collateral damage.

even though details have always been a bit vague about the incident, this is one of the primary reasons why i have been spending the past year dealing with industrial control poo poo

want to know what scares me the most?



a fully-automated haul truck

combine this with lack luster security in a lot of natural resource companies and you end up with a vehicle that can cause a lot of damage.

the upside to these things is that typically nobody is going to try and get air in these suckers

https://www.youtube.com/watch?v=8iYj4WJvcB0

which was this truck:



or try and drift them:

https://www.youtube.com/watch?v=5kdrtOgJ6OA

but it not out of the question that one could do some harmful poo poo with them

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
pls no more washing machine talk

i had to do a load of laundry last night and this is causing me to have flashbacks

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

McGlockenshire posted:

if he can't even figure out that SuperMicro makes servers not routers and that those devices exposing IPMI to the world also has nothing to do with routers being hacked, I'm not really sure I trust anything else in that article to be factually correct

same thing with crediting Microsoft for Minecraft

Microsoft paid 2.5 Instagrams for Mojang and Minecraft.

Also that's a fuckup on the SuperMicro part but they make more than just servers.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
you can still compile current openssl source for nextstep and beos (well haiku really)

code:
Configuring OpenSSL version 1.1.1-dev (0x10101000L)
BS2000-OSD
BSD-generic32
BSD-generic64
BSD-ia64
BSD-sparc64
BSD-sparcv8
BSD-x86
BSD-x86-elf
BSD-x86_64
Cygwin
Cygwin-i386
Cygwin-i486
Cygwin-i586
Cygwin-i686
Cygwin-x86
Cygwin-x86_64
DJGPP
MPE/iX-gcc
OS390-Unix
QNX6
QNX6-i386
UEFI
UWIN
VC-CE
VC-WIN32
VC-WIN64A
VC-WIN64A-masm
VC-WIN64I
aix-cc
aix-gcc
aix64-cc
aix64-gcc
android
android-armeabi
android-mips
android-x86
android64
android64-aarch64
android64-mips64
android64-x86_64
bsdi-elf-gcc
cc
darwin-i386-cc
darwin-ppc-cc
darwin64-debug-test-64-clang
darwin64-ppc-cc
darwin64-x86_64-cc
debug
debug-erbridge
debug-linux-ia32-aes
debug-linux-pentium
debug-linux-ppro
debug-test-64-clang
dist
gcc
haiku-x86
haiku-x86_64
hpux-ia64-cc
hpux-ia64-gcc
hpux-parisc-cc
hpux-parisc-gcc
hpux-parisc1_1-cc
hpux-parisc1_1-gcc
hpux64-ia64-cc
hpux64-ia64-gcc
hpux64-parisc2-cc
hpux64-parisc2-gcc
hurd-x86
ios-cross
ios64-cross
iphoneos-cross
irix-mips3-cc
irix-mips3-gcc
irix64-mips4-cc
irix64-mips4-gcc
linux-aarch64
linux-alpha-gcc
linux-aout
linux-arm64ilp32
linux-armv4
linux-c64xplus
linux-elf
linux-generic32
linux-generic64
linux-ia64
linux-mips32
linux-mips64
linux-ppc
linux-ppc64
linux-ppc64le
linux-sparcv8
linux-sparcv9
linux-x32
linux-x86
linux-x86-clang
linux-x86_64
linux-x86_64-clang
linux32-s390x
linux64-mips64
linux64-s390x
linux64-sparcv9
mingw
mingw64
nextstep
nextstep3.3
purify
qnx4
sco5-cc
sco5-gcc
solaris-sparcv7-cc
solaris-sparcv7-gcc
solaris-sparcv8-cc
solaris-sparcv8-gcc
solaris-sparcv9-cc
solaris-sparcv9-gcc
solaris-x86-gcc
solaris64-sparcv9-cc
solaris64-sparcv9-gcc
solaris64-x86_64-cc
solaris64-x86_64-gcc
tru64-alpha-cc
tru64-alpha-gcc
uClinux-dist
uClinux-dist64
unixware-2.0
unixware-2.1
unixware-7
unixware-7-gcc
vms-alpha
vms-alpha-p32
vms-alpha-p64
vms-ia64
vms-ia64-p32
vms-ia64-p64
vos-gcc
vxworks-mips
vxworks-ppc405
vxworks-ppc60x
vxworks-ppc750
vxworks-ppc750-debug
vxworks-ppc860
vxworks-ppcgen
vxworks-simlinux

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/kaepora/status/821981816139747328

his lebanese passport was handwritten until early 2016

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i was going to make a joke about conscription coming to cyberwar but it's already a thing

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/stevebiddle/status/822190488505589760

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Shaggar posted:

my bro was telling me about some of the PLCs at a plant he was managing and he was telling me they have a separate internet connection (DSL, lol) for letting the vendor on to do work. It didn't occur to him that leaving this open all the time was a bad idea cause he didn't realize that theres effectively no security on the PLCs.

this is far from uncommon

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
Isn't there a limit to the number AD users and groups?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

BiohazrD posted:

lol hosting an entire country's worth of people on ms azure ad what would that cost like $1 bil/mo?

australia has 23 million people so unless they get special pricing microsoft would charge anywhere between $23 mn USD to $138 mn

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
$30 mn to $180 mn AUD

Chalks posted:

I imagine they would be offered quite the discount for something like that.

well yeah. it could be a negative discount too all things considered

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

quote:

Canadians feel that online voting in federal elections would have a positive effect on voter turnout. They support online voting in principle, but their support is contingent on assurances that online voting would not result in increased security risks.

i have no idea how to respond to this other than... "yay"?

this was via some study the government is doing on electoral reform

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
here's some anecdotes about av:
https://news.ycombinator.com/item?id=13489100

quote:

Except AV started out like how Carbon or Cylance did (lean, effective, buzzworthy, etc) and other popular applications started out. It was decades of feature creep, poor competition, out of control pricing, etc that killed the AV industry.

quote:

Windows 8/10 with the MS built-in protection or Linux + clamav
Sometimes I used CClenaer and/or Spybot to deal with something really nasty, but the MS stuff really does a good job (Someone checked if the hell is frozen now ?)

quote:

I have 150 ish machines on eset across a few different clients, obviously my experience with it has been very good over the years in all aspects. Eset don't offer the biggest margins but I stick with them because it doesn't cause support issues and I can count the number of infected eset machines I've had to deal with on one hand.

quote:

I have the impression that the AV business is some kind of mixture of scam and mafia.

quote:

Who writes all these viruses ?
I mean, I've experimented with assembler when I was a teenager and I may have developed some kind of program which could replicate itself.. but I highly doubt today's viruses are written by teenagers...
Who and why do people write viruses ? Is this a thing at all or are all the viruses written by the Antivirus makers themselves ?
More 'threats' is good news for the A/V makers so why not have a separate department which develops them ?
I wouldn't be surprised at all, given that much crazier things are happening in this world..
Can anyone confirm or disprove this ?

quote:

If you need AV, consider F-secure. They do quality products and take security seriously.

quote:

Defender has the nasty habit of aggressively scanning new games I download off Steam. There are two occasions where it'll do it:
- While it's downloading it seems to scan each chunk. I have a gigabit connection, with defender off I can download at nearly full speed. With it on I can download at about 1MB/s.
- While the game loads a level. For example, the intro level to the new Deus Ex took over 10 minutes to load the first time. At that point I disabled defender entirely and just promised myself I would be careful. Naive, I know, but at least I can play my video games.

quote:

In principle, I agree with the article.
Personally, on Win7 I use a combination of 3 things:
- MSSE - TinyWall as a lightweight firewall - heavily modified HOSTS file
Never had malware/virus problems and sometimes I do visit shady webistes or download quirky software.

quote:

Any relevant information about Avast? I'm using their free version for 10 years and don't have any major complains.

quote:

While many AV companies are really bad, AV per say is still an extra layer of security. Telling people to remove a layer of security is bad advice. There's a problem though and if I knew how to solve it I'd be rich!

quote:

Most people forget the malware on hacked website. Browsers won't give you a warning. (OK. Chrome will show you a RED screen but not for all) They need not hack into your system. But they collected your login info, credit card. I even want to install one on my MacOS.
MS AV still too slow at the moment. In Windows 10, you could turn on Defender to run both AV at the same time.

:allears:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
pls do not d&d this thread

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

LastInLine posted:

its cute that you think the trump administration will last four years and also laughable that you think the following administration will change these policies

the thing about surveillance policies is every government believes they are the only ones moral enough to have such power so no one ever walks them back

shut the gently caress up and go post in d&d

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
if you want to talk about how trump is loving up his opsec or whatever, sure

if you want to talk about how trump won't last four years, go post in d&d

if either of these two points are unclear then don't post at all

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
http://www.zdnet.com/article/breach-site-leakedsource-raided-by-feds/

quote:

Breach site LeakedSource apparently raided by feds
The site obtained a massive hack of over 400 million AdultFriendFinder accounts last year.
Zack Whittaker
ByZack Whittaker for Zero Day | January 26, 2017 -- 18:13 GMT (10:13 PST) | Topic: Security

LeakedSource, a for-profit breach notification site that helped break the news of some of last year's largest data breaches, has apparently been raided by law enforcement.

News of the raid, which can't be confirmed at the time of writing, first broke on Thursday through a note posted on a vritual markets forum earlier in the day.

LeakedSource's website appears to have been pulled offline.

The note reads:

quote:

"Yeah you heard it here first. Sorry for all you kids who don't have all your own Databases. Leakedsource is down forever and won't be coming back. Owner raided early this morning. Wasn't arrested, but all SSD's got taken, and Leakedsource servers got subpoena'd and placed under federal investigation. If somehow he recovers from this and launches LS again, then I'll be wrong. But I am not wrong. Also, this is not a troll thread.

The location of LeakedSource members isn't known, nor which law enforcement agency was allegedly involved.

LeakedSource shot to prominence last year for providing reporters, myself included, access to some of the largest data breaches and hacks in living memory, including AdultFriendFinder, Russian internet giant Rambler.ru, and millions of accounts associated with Twitter.

But the service drew controversy and criticism for allowing users to subscribe to the site in order to get access to raw data, including passwords.

Critics said -- rightfully -- that this could make hacking of other sites with similar user credentials much easier.

LeakedSource was just one of many breach database sites founded in the mold of non-profit service, Have I Been Pwned, which is considered the gold standard in breach notification because founder Troy Hunt deliberately doesn't store passwords.

"Handling data of this nature is a sensitive business," Hunt said in a message.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Wiggly Wayne DDS posted:

when the hell did twitter support text->tweet and why the gently caress are those accounts using it

twitter originally was conceived as an sms-based service hence its limit on characters

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/gcluley/status/824972776675082245

clueless

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

redleader posted:

have there been any reports of malware taking advantage of av vulnerabilities?

does it matter?

https://www.zerodium.com/program.html

quote:

Others / Techniques

Any other innovative research or techniques related to:

- Mitigation Bypass (e.g. ASLR)
- Mobile Baseband RCE
- Tor De-anonymization
- AntiVirus RCE/LPE

people will pay for them

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
it doesn't matter if it is fragmented: the problem with av isn't really that

the problem is that the methodology of preventing malware from executing worked great back in 1995 when at worst you could get infected by a floppy diskette

once the internet became a mainstream thing and e-mail proliferated, the idea of having someone going through each sample and coming up with a signature was over. it was manageable for a long time only because the internet had yet to become something we need but the writing on the wall was there with the iloveyou virus back in mid-2000

the av industry's solution to this problem is to just add more "value" and rebrand themselves as endpoint solutions. this has resulted in them adding holes to their garbage and demonstrates an overall sloppiness in their approach

av is dead because it's worthless; install windows 10 and use the av that it comes with or use a mac

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Chalks posted:

I guess it depends a lot on what you're protecting. If you're talking about a large business that may be subject to sophisticated and targeted attacks that's one thing, but if you're talking about a small to medium business your biggest worry isn't some obscure AV exploit being used because the attacker analysed your network, it's some idiot executing a 12 month old ransomware attachment and that poo poo will get caught by an up to date antivirus. Big name AV seems to be garbage but I wouldn't personally recommend against using AV on business machines because nobody is getting infected with 0-day poo poo in that environment anyway.


OSI bean dip posted:

av is dead because it's worthless; install windows 10 and use the av that it comes with or use a mac

there is absolutely no reason to use third party av

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Chalks posted:

It's not specifically my area but we use Microsoft Intune - does that count as third party? I assume the main benefits are centralised monitoring and control so that you actually get told about users trying to execute viruses on the system, but I can't say I'm an expert in Microsoft AV features.

that's just a device manager. it doesn't change anything about what is running on the desktop

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
please no more talk about paper

This is the weirdest derail ever :psyduck:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://www.youtube.com/watch?v=FUyaItsRInQ

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/whitequark/status/825944162180677633

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
this needs to be on security snake oil

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Cocoa Crispies posted:

not once you add in kicksharter delays

six months of saying it's coming
four months of delays
four months of delays with promises that it'll come next month
two months of photos while still delaying with promises of it coming within six weeks
200 units shipped in one month while 15,000 units promised still pending
7,000 units shipped across three months
remaining units never shipped or produced and the founders run off citing that a business partner squandered the money

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Security Fuckup Megathread - v13.2 - car go bep bep

  • Locked thread