Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Achmed Jones
Oct 16, 2004



I'm a founding member of my company's new security team. A week ago, I was a hobbyist with an OSCP certification. We're starting on risk assessment, prioritization, and all that, but I'd love any links y'all might have (or books to read) that'll help us out.

Adbot
ADBOT LOVES YOU

Achmed Jones
Oct 16, 2004



pr0zac posted:

lastpass doesn't use cloudflare and even if it did it wouldn't have affected security of their product either

1password is what you're referring to but they weren't sending passwords through cloudflare, they just used it for their website

are there seriously people in this thread that think a prominent password manager company would have an implementation that would involve sending plaintext passwords over http to cloudflare?

How to get a password from Okta:
1. Ask its API (providing credentials)
2. Look at password on the wire

It's HTTPS, but it still ain't good.

Their browser plugin uses this, though it may be limited to sites that don't support SAML and/or don't have it enabled.

Achmed Jones fucked around with this message at 04:14 on Feb 25, 2017

Achmed Jones
Oct 16, 2004



Re: the equation group files, changing quotes to fancy directional quotes strikes again.

Achmed Jones
Oct 16, 2004



Subjunctive posted:

allowing inverted case is fine, people have done the math

If they're taking the given password on login, generating both normal and inverted-case hashes, and then comparing both of these to the hash generated from a case-sensitive password in the database, sure.

If they're downcasing new passwords and saving that hash, much less so.

  • Locked thread