Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Shaggar
Apr 26, 2006
any exploits in wordpress or javascript are working as expected. when I think virus I think code that gets onto a user's machine without their interaction and replicates to other machines without user interaction.

Adbot
ADBOT LOVES YOU

Shaggar
Apr 26, 2006
yeah that's a better differentiator. either way, imo, they require no human interaction to spread.

Shaggar
Apr 26, 2006
we have a lot of policies that say you cant allow other people (including internal) to use your credentials. it comes from the hipaa side of things but it applies to all accounts.

Shaggar
Apr 26, 2006

well atleast its negligence instead of someone sneaking malicious code into a signed driver.

Shaggar
Apr 26, 2006

this is cause they're using samba. I found another bug in that same component that was supposed to be patched this week.

Shaggar
Apr 26, 2006

redleader posted:

wouldn't surprise me to learn that amazon are simply big enough to negotiate special deals with cc processors and banks that let them get away with not requiring a cvv

pretty sure you have to provide it for your first payment and then once you save the payment deets amazon is storing a special token that's represents your card when being processed by amazon. if its stolen its useless without being able to send thru amazons payment processing system.

Shaggar
Apr 26, 2006

BangersInMyKnickers posted:

Apparently a new worm called Bluedoom is propagating but not yet activating a payload and its using 6 different SMB vulns and one other from the NSA dump. Fun times. Turn off SMB1.

are these new vulns or already patched?

Shaggar
Apr 26, 2006
I would like to see what someone like tavis would do to an EHR. they'd probably try to sue him into the dirt.

Shaggar
Apr 26, 2006

BangersInMyKnickers posted:

So is Microsoft dropping EMET because they're rolling all the features in to the base OS at some point or because they have some idiotic dream that all apps in a year will come through the Windows store and enforce opt-in for all the security features that EMET enforces? Because there's still going to be decades of legacy applications that could benefit from it

iirc lots of emet was already made native as part of defender in win10

Shaggar
Apr 26, 2006

Wiggly Wayne DDS posted:

they make it hard to follow any emet news in particular

hmm, looks like its EOL https://technet.microsoft.com/en-us/security/jj653751

I was not aware

Shaggar
Apr 26, 2006

Volmarias posted:

I'm getting hard just thinking about the idea of a lovely EHR company trying to sue Tavis and unexpectedly slamming into a wall of Google lawyers, then furiously trying to back pedal out of danger.


they have the money and connections to take google on and i'd love to see it happen

Shaggar
Apr 26, 2006

vOv posted:

it's the former, because you can't send jesus over tcp

he was free from SYN :haw:

Shaggar
Apr 26, 2006

pseudorandom name posted:

it isn't a shell script in this case, its a proc file serializing data as plain text with fields delimited by spaces and one of the fields is a file name

it is literally impossible to safely parse

and this is ignoring the fact that nobody ever bothered to define the format or how it should be parsed in the first place

parsing random string output is the foundation of the unix philosophy

Shaggar
Apr 26, 2006
an excel document in a one drive 365 folder.

Shaggar
Apr 26, 2006

Subjunctive posted:

the extra step is "Open in Instagram?", and equivalent (but more terribly worded) on Android, for which the cancel rate is non-trivial in other scenarios

it's the same broken model used by every site on the web, assuming they bother to confirm at all. the failure mode here is loss of a new, low-value-to-user account. the failure mode of a more complex system is more users locking themselves out of older, high-value-to-user accounts because they didn't complete confirmation

I will pass your thoughts on to the account access team, though, so you can save the world with untried approaches!

show them a banner in the app that's like "Don't lose access to your account! confirm your email address now!" or something to encourage them to confirm it. if they don't, then gently caress 'em.

Shaggar
Apr 26, 2006

Munkeymon posted:

today I got PII emailed to me from a random Austin woman (insurance info) and the Army Corps of Engineers (dam permit I guess?)

I occasionally get PHI faxed to me.

Shaggar
Apr 26, 2006
pinewood derby owned

Shaggar
Apr 26, 2006
its probably full of profanity and hacks for 3rd party poo poo.

Shaggar
Apr 26, 2006
well yeah, the usps gets paid to deliver that garbage and the mail carriers aren't allowed to not deliver it.

Shaggar
Apr 26, 2006
i emailed them to ask about that and you cant. the flyers and stuff aren't addressed and they get paid to deliver to all boxes in a region so they don't have lists of who to deliver or not deliver to. if you're on the route, you get a flyer.

for a little bit our mail carrier would leave them in a stack on a table by the boxes instead of sticking them into the boxes which i thought was a great compromise but they had to stop.

Shaggar
Apr 26, 2006
eventually we'll get to the point where the only thing in your mailbox is trash and the key to the parcel box and then you can just dump it all directly into the trash instead of having to sort.

Shaggar
Apr 26, 2006
to get the key for the parcel box.

Adbot
ADBOT LOVES YOU

Shaggar
Apr 26, 2006

Volmarias posted:

I know, I would just love a "we'll pay you to stop, please, please stop" arrangement. The marketers get "targeted" advertisements so it looks better, the USPS gets an extra cash flow, I don't get loving garbage in my mailbox. It should be a win win all around, but the same group that brought us CAN SPAM would kill even a hint of this.

a better solution would be to charge businesses more for delivery of properly addressed items and then eliminate delivery of non-addressed mail.

  • Locked thread