Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
get ready for drm on html5 video https://www.eff.org/deeplinks/2017/07/amid-unprecedented-controversy-w3c-greenlights-drm-web

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Mr SuperAwesome posted:

obviously SMS 2FA is bad, but if you're using gauth/totp whatever and lose your phone, what then?
just use the gauth recovery code when you set up gauth on your new phone

like how is this even a question

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

oh yeah then you'd be hosed. same as if you didn't copy down your recovery keys for a non-sms 2fa. altho depending on the account they probably have a way to remove the 2fa which is an easier target than your SMS was in the first place.
yeah you just ask nicely

Chalks posted:

My phone broke so I emailed the company and asked them to turn off 2fa and they did it no questions asked. lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Munkeymon posted:

am I the only one who keeps the old phone and sets up the 2fa app on old and new at the same time in order to have a backup?
statistically no, but you are doing a dumb thing

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lmao https://thehackerblog.com/the-io-error-taking-control-of-all-io-domains-with-a-targeted-registration/

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
regarding an oracle exploit from the equation group leak https://twitter.com/nicowaisman/status/884507246096519168

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
if we use asas is there a good alternative to anyconnect or should we be using anyconnect

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

RISCy Business posted:

i'm wondering this too, because i bought a couple grey market ASAs for personal use and i'm not sure how the vpn stuff will shake out

i found this: http://www.infradead.org/openconnect/

might be useful?
can't say i'm thrilled with the idea of building the package myself, but it's something to look into

e: nevermind, i found the windows installers

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

anyconnect enforces policies that other clients may not (ex: split tunneling). the biggest thing is keeping it all up to date.
we are currently using Cisco Systems VPN Client v5, i am extremely aware that we need an up-to-date client. but anyconnect licenses cost money, and this vpn client is free :qq:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Wrath of the Bitch King posted:

Too bad the OpenVPN client is garbage for the average user to use. Is it even worth using from a security perspective or are there problems with it?
it's not an ikev2 client

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/og_tjg/status/884756210267893761

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Lain Iwakura posted:

this font poo poo while hilarious is best suited for the opsec thread
are you telling them to go gently caress themselves

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cinci zoo sniper posted:

old was closed, new one opened and also died i think? not sure, but i've pm'd graph about this a few mins back, ill make one if he says it's ok
iirc graph shut down the second thread. both threads were closed. there is no opsec thread.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Deep Dish Fuckfest posted:

isn't tizen the project where everything is a void pointer and a hosed up variant type with a bunch of casting everywhere because everyone working on it is literally insane?

if so i imagine a static analyzer would just explode if it touched that code
yeah reportedly it's pretty bad
https://motherboard.vice.com/en_us/article/xy9p7n/samsung-tizen-operating-system-bugs-vulnerabilities
there's also this post about enlightenment which tizen uses https://what.thedailywtf.com/topic/15001/enlightened

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
it's called security through obscurity, nobody would ever think to check for the private key in a webserver-readable directory

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
http://www.bbc.com/news/world-europe-40583718

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
they weren't really bricked, you could go into a linux and undo it

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
making the first word in a recursive acronym the acronym seems like both cheating and a misunderstanding of what recursive means

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
if i said i wrote a 500-line recursive algorithm and the first line called itself it would be pretty stupid

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ate poo poo on live tv posted:

Depends on the situation. Most military bases in the southwest US like in the middle of cities etc, are pretty chill about people coming on them. Lots even have public spaces for people to actually come have a picnic and visit on-base housing.

Kirtland, Holloman, and Lackland are the ones I went to fairly often. I suppose if you are an idiot you could be charged with espionage or something.
lackland is boot camp for all enlisted trainees so they see a lot of family members for airmen, not really a fair example. but like ate all the Oreos said, post-9/11 a lot of things changed

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
we're going to get pentested this weekend by some local infosec firm and i don't know which i would rather get to see: a printout of nessus scan results we already have, or for my boss to bug out over getting serious about security

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Powaqoatse posted:

remember to embarass them by filling out the phishing email wrong
one of the guys assigned to this pentest is an owasp member, and the one who will be doing the actual work is some guy who's only worked with them for about a month, so i'm very looking forward to how this is going to go

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Powaqoatse posted:

that sounds super professional haha
well like the email says they'll both be doing the pentest but, cmon

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Powaqoatse posted:

why tell you the guy is a newbie though??
i looked up his linkedin profile and it says he started with them june 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Subjunctive posted:

is the person new to pentesting or just that company? pentesters cycle through companies all the time.
previous jobs per linkedin are systems administrator at a private university (8 months), undergrad independent research (8 months), teaching assistant (5 months), air force (8 years)

maybe he's just real good at opsec lol

anthonypants fucked around with this message at 21:30 on Jul 14, 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Powaqoatse posted:

those are in reverse chronological order right?

to me that could describe a natural talent finding their way (unless the last 3 are all the same employer)
yes; newest first, oldest last. all those academic jobs were at the same private christian college outside of LA

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/CNN/status/885692095616487424

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

https://twitter.com/taviso/status/886989661049995264

e: lol

quote:

I pinged mozilla security team to let them know that they may need to prioritize an upcoming addon review (Mozilla manually approve all addons).

I don't know how webex works in IE and Edge, but dealing with Microsoft is such a huge pain that I'm just going to plead ignorance and let them figure it out themselves.

anthonypants fucked around with this message at 17:48 on Jul 17, 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
how bad are the infosec books currently in the humble bundle https://www.humblebundle.com/books/cybersecurity-wiley

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Grace Baiting posted:

Noticed what? ❔❓:confused:❓❔

mrmcd posted:

whoooooooosh
also does anyone else hear that whooshing sound

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

mrmcd posted:

Oh well no fair editing the quoted image. :mad:
also changed the quoted user's name, no fair looking at their post

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Volmarias posted:

Given that they can just take accounts from whoever, wouldn't they just have it 302?
it's really dumb that they would just blackhole every previous @support post but That's Twitter

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Avenging_Mikon posted:

Does this affect devices using the iOS 11 beta?
it probably has a different patch schedule, and if you're in the public beta i don't even think you get patch notes

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Migishu posted:

the gently caress is alphabay?
it's an online marketplace for drugs, like silk road was

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lol http://money.cnn.com/2017/07/19/technology/fish-tank-hack-darktrace/index.html

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/john_lam/status/888442492051259392

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
didn't someone internet poker get legalized because lobbyists got it classified as a game of skill instead of a game of chance or something like that

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/VickerySec/status/886290921381179392 https://twitter.com/VickerySec/status/886351694459584512

  • Locked thread