Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

syscall girl posted:

they also had possibly one of the worst fighting games

https://www.youtube.com/watch?v=-_Ya4mSkDMI

itym best
the environmental fatalities are unironically good imo

Adbot
ADBOT LOVES YOU

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

MononcQc posted:

the worst part about vim being from the 70s is all the hot takes from the 70s you get to hear for using it

RFC2324 posted:

It's not that they are the best.

It's that no one has come up with anything better.
we get it, you vape

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Lain Iwakura posted:

it's just another example of why sms 2fa is dumber than poo poo

is that seriously the thing that worries you the most in "my phone provider reassigned my phone number to someone else"

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Powerful Two-Hander posted:

yes and yes. logins are behind an rsa 2 factor so even if my actual logon was swiped it wouldn't be useful though

it was for the dumbest loving thing as well. i forgot to do some bullshit mandatory training before i went away and me and my manager (who was also on holiday) would both get in the poo poo if i didnt because it is obviously critically important that i spend 30 minutes clicking through a presentation about disaster recovery right this second.

every single thing on it was animated, it took forever on a lovely connection and lol at whoever decided to embed a video that then ran at 1fps

bonus: a picture of an email notifcation which had 'this is a test email' in bold on it with a comment underneath saying "note: this is not a phishing mail"

lol when we had to do that but on workplace safety we all independently set up a script to cheat on the mandatory viewing time

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

BattleMaster posted:

reminds me of like 15 years ago and using IE and getting sketchy activex controls with long names saying they're totally cool and safe and begging to be installed

not unlike vampires trying to convince you to invite them in

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
I'm pretty sure shovelware is the only thing that makes consumer pcs remotely profitable

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
question: we use openssl in our product, as a dependency of a dependency that would be hugely expensive to replace. is the switch to libressl worth it, and is it painless?

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

spankmeister posted:

use polarssl op

but is it source compatible with openssl? otherwise it's just more work for me which I'd rather expend on something else e.g. rewriting the openssl-dependent code to use native os ssl support

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
and years ago, microsoft was forced to document a ton of windows internals as part of a settlement, which may have lead to them eventually documenting all their internal protocols and file types

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
has this been posted?

https://twitter.com/codelancer/status/890620840080941056

twitter moderation always on point :thumbsup: "won't you think of the feelings of the war profiteers :qq:"

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
shadowhawk could you explain why the gently caress does a thumbnailer need to access the product version of an installer package, in the first place?

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
a bash script
that uses wine
to run windows script host
to run a vbscript script
to run a sql query on an msi file
to embed a very minor metadata label in a thumbnail icon

Cybernetic Vermin posted:

vbscript.exe is entirely innocent here, it is, say it with me ~~~a bash script where arbitrary user data is syntactically escaped into a string by haaaaand~~~

windows script host shares part of the blame though, as

code:
		# Workaround wine bug #19799: cscript crashes if you call WScript.Arguments(0)
		# [url]http://bugs.winehq.org/show_bug.cgi?id=19799[/url]
if it wasn't for working around that bug, the filename could have been passed as an argument, automatically quoted by bash and wine

blame wine too but especially wsh for being a fragile pos that requires external and easily corrupted metadata for something as simple as retrieving the command line arguments

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
are the cards collectible?

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

maskenfreiheit posted:

"UK model kidnapped by Polish national who reportedly planned to auction woman on dark web"

https://www.theguardian.com/uk-news/2017/aug/05/uk-model-kidnapped-and-held-captive-in-italy-for-six-days

politely tittering at them using the name of the town in the local dialect

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

mrmcd posted:

Wasn't there a bgp fuckup a couple years ago where a huge chunk of traffic for Europe got routed to some nobody university in Pakistan or something?

I'm honestly surprised bgp fuckups aren't more common.

I remember the time all internet was routed through Iceland, which IIRC would later be revealed by whistleblowers to have been a Tor deanonymization attack by the NSA

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

maskenfreiheit posted:

oooh interesting... got a source i'd like to read more about that

there were several separate incidents of bgp hijacks in 2013, where traffic was variously redirected to iceland, belarus, iran
an academic paper from 2014, and a 2015 followup describe how to attack tor with bgp

apparently though there's no hard, proven link between the bgp hijacks and nsa's long campaign against tor

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Schadenboner posted:

I'm the Moka pot.

a 3-cup pot by the looks of it, too. that's a lot of coffee for one person

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
use tor whonix

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Phobeste posted:

also one big threat with the facial recognition stuff for people who absolutely have pictures of you is your parent who thinks you're gay or your partner who thinks you're cheating or whatever. those are just as valid threats as mugging.

for all the talk of "have a threat model" some people sure love to throw up their hands and jump to the "blackbagged to cia black site" scenario

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Volmarias posted:

If that's a euphemism for "my girlfriend is screaming and crying about how I cheated on her in a dream she had and I long for a CIA kill team to end me" I guess that makes sense.

I mean that "phsyical access is game over :smug:" was and is used as a debate ender by people who really should know better

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Shinku ABOOKEN posted:

if i was the eu i would be digging for reasons to sue us companies. free money y'all.

lol if you think any digging is required

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Trabisnikof posted:

sneakers is the best hacking movie

I think I read it here: the least believable part of sneakers is mainframes that use strong crypto

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

ludicrous premise: identity theft as a life threatening tragedy vs a depressingly common occurrence

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
I think the device in sneakers was a prime factorizer, so asymmetric crypto specifically

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Max Facetime posted:

Encryption is not a human right and neither is downloading apps, in fact both could well be illegal in some places, so where's the human rights violation?

could you be any dumber (edgier?). "illegal" isn't in the ballpark of "not a right", it's not even the same game

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

surebet posted:

i mean if you want to have a thing that'll spy on you and make shopping lists that's fine, but why in the hell would you give it authoritative access to your money

ask the many, many yosposters who own one

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Max Facetime posted:

modern encryption is something computers do, not humans. ergo it's not a human right

communicating with other people is something people do you gigantic boob

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Farmer Crack-rear end posted:

honestly my plan for all future international travel is to just take my work phone and leave my personal phone at home.


fine, keep my phone, i don't give a poo poo. i'll just get another one for 99c.

failure to provide sensitive data to border control is grounds for refused entry, foreigner

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Cocoa Crispies posted:

gg on shipping the debug symbols

they didn't ship the debug symbols, just the link to the debug symbols: a UUID and the original path to the PDB file. what's worrying is that they apparently compromised one of the developer machines, because it appears the malware was built there

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
on the other hand: that looks like the symbols for the installer itself, not the malware part, which is probably just a self-contained .obj dropped somewhere on the build machine and sneakily added to the linker's command line. from how it's described to work, it's trivial to make it self-contained: the payload is saved in a big static array, and the bootstrap function is registered as a TLS constructor by declaring a pointer to it in one of the specially named sections that the linker merges to form the array of TLS constructors

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Mr. Nice! posted:

or if you're really worried about customs digging through your phone, make a backup beforehand, wipe your phone, and hand it to them to look over.

like that won't get you detained, interrogated and refused entry

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Optimus_Rhyme posted:

the real option is a shadow os on phones/laptops.

thegrugq works or is otherwise involved in a company making shadow os phones. for obvious reasons they don't advertise a lot, the photos on the site are completely unbranded devices, and they aren't mass marketed. iirc they don't even list prices

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
my bank is about to roll out an improved internet banking platform. among the security improvements, I can choose to irrevocably disable my current otp key and rely on one time codes sent by sms instead

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Carbon dioxide posted:

SAN FRANCISCO (Reuters) - An international group of cryptography experts has forced the U.S. National Security Agency to back down over two data encryption techniques it wanted set as global industry standards, reflecting deep mistrust among close U.S. allies.

https://www.reuters.com/article/us-...t-idUSKCN1BW0GV

the algorithms in question are block ciphers SIMON and SPECK. did we really need two new block ciphers, anyway?

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

spankmeister posted:

Speck has been optimized for performance in software implementations, while its sister algorithm, Simon, has been optimized for hardware implementations.

So... Yes?

and aes rounds are now cpu instructions. so?

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

akadajet posted:

I miss being able to swipe my card. It just worked without delays and angry buzzing noises.

nfc cards are hella fast

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

The_Franz posted:

nfc cards in the us are a chicken/egg thing. some cards had it 10 years ago and dropped it since almost no terminals had support for it and now that the terminals do support it the cards don't. not that it matters these days since apple pay makes that irrelevant.

how does apple pay make that irrelevant, do you want to make idevices mandatory or what

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
is it this guy? https://en.wikipedia.org/wiki/Morgan_Marquis-Boire

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Midjack posted:

thought he was a piece of poo poo anyway.

that's all itsec people though

Adbot
ADBOT LOVES YOU

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

itsec is important, it's necessary, and it's an assembly line of entitled assholes

and I don't believe this correlates in any way with being a rapist

  • Locked thread