Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
hobbesmaster
Jan 28, 2008

if you have a microcontroller without a trng is any tls implementation doomed to being terribly broken?

Adbot
ADBOT LOVES YOU

hobbesmaster
Jan 28, 2008

Luigi Thirty posted:

are you telling me my Amiga's openssl implementation is broken

i was told the low bits of the difference between two independent hardware clocks (like say a 1khz-ish oscillator and the system clock) is not good enough for encryption

hobbesmaster
Jan 28, 2008

Meat Beat Agent posted:

i bet that dude will WannaCry after he gets fired lol

hobbesmaster
Jan 28, 2008

I'm at a training for amongst other things selling iot solutions

one of the main talking points was how to sell solutions without talking to IT departments :nsavince:

hobbesmaster
Jan 28, 2008

BangersInMyKnickers posted:

the supported cipher list from a major industrial controls vendor's monitoring and remote access platform:

TLS_RSA_WITH_NULL_MD5 (0x1) INSECURE 0
TLS_RSA_WITH_NULL_SHA (0x2) INSECURE 0
TLS_ECDHE_RSA_WITH_NULL_SHA (0xc010) ECDH sect571r1 (eq. 15360 bits RSA) FS INSECURE 0
TLS_ECDH_anon_WITH_NULL_SHA (0xc015) INSECURE 0
TLS_RSA_EXPORT_WITH_DES40_CBC_SHA (0x8) INSECURE 40
TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA (0x14) DH 512 bits FS INSECURE 40
TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA (0x19) INSECURE 40
TLS_RSA_WITH_DES_CBC_SHA (0x9) INSECURE 56
TLS_DHE_RSA_WITH_DES_CBC_SHA (0x15) DH 1024 bits FS INSECURE 56
TLS_DH_anon_WITH_DES_CBC_SHA (0x1a) INSECURE 56
TLS_RSA_WITH_3DES_EDE_CBC_SHA (0xa) WEAK 112
TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA (0x16) DH 1024 bits FS WEAK 112
TLS_DH_anon_WITH_3DES_EDE_CBC_SHA (0x1b) INSECURE 112
TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA (0xc012) ECDH sect571r1 (eq. 15360 bits RSA) FS WEAK 112
TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA (0xc017) INSECURE 112
TLS_RSA_WITH_AES_128_CBC_SHA (0x2f) 128
TLS_DHE_RSA_WITH_AES_128_CBC_SHA (0x33) DH 1024 bits FS WEAK 128
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013) ECDH sect571r1 (eq. 15360 bits RSA) FS 128
TLS_DH_anon_WITH_AES_128_CBC_SHA (0x34) INSECURE 128
TLS_ECDH_anon_WITH_AES_128_CBC_SHA (0xc018) INSECURE 128

just give up and punch in TLS_NULL_WITH_NULL_NULL :wtc:

hobbesmaster
Jan 28, 2008

Peachfart posted:

My company provides a solution for a large online retailer that owns half of Seattle, and they wanted to deploy a newer physical product. So they tested the product on the client side and it didn't work! This was because their server software was out of date.
Well, they refused to update the software due to 'downtime', even though we said we would do the update overnight or any other time they chose. We are talking about maybe 30 minutes max, and certainly nothing mission critical.
Instead, they demanded every version of software that had been released for the newer product so that they could test every combination and try and make something work.
Engineering back east told them to gently caress off. Locally, they asked me and I said 'lol no'. This is a huge account so eventually they found someone to send them the files, and somehow killed the product.
They had to update anyway.

theres something to be said for letting customers go with their plan that won't work after explaining why it won't work and that it'll break in this way

that way when they do it they'll actually believe you next time






:lol:

hobbesmaster
Jan 28, 2008

Wrath of the Bitch King posted:

from what I've experienced, they don't. Every PM I've worked with barely knows what a keyboard is.

always remember: PMs are all that stand between you and sales

hobbesmaster
Jan 28, 2008

mrmcd posted:

Google literally has a (completely different) EU antitrust investigation going on right now because they tried to tell manufacturers and telcos they couldn't ship Android phones with 10 GB of crapware and security holes.

telling computer manufacturers what they could and could not install on their computers was one of things Microsoft got hit with in the US antitrust suit.

The antitrust concern is that google is using android to advance their advertising business and disallowing others from doing the same.

google should probably come up with some sort of certification for crapware free like microsoft's "signature edition" laptops.

hobbesmaster
Jan 28, 2008

Shaggar posted:

winphone ftw

even Microsoft employees don't use windows phones

they all have crazy expensive surfaces of course

hobbesmaster
Jan 28, 2008

Subjunctive posted:

yeah, pagerank was a long con

:rolleyes:

as soon as google decided they wanted to make money they became an advertising company

hobbesmaster
Jan 28, 2008

you're supposed to haggle them down, duh

hobbesmaster
Jan 28, 2008

like my dad was once shaken down by Indian customs for about $100. his host's reaction was "wow you're bad at haggling"

hobbesmaster
Jan 28, 2008

i assume he means a lack of centralized updates leading to orphaned insecure peripherals?

lol if you think Linux is better though

hobbesmaster
Jan 28, 2008

ThePeavstenator posted:

In my college Real-Time Systems class we did projects on BeagleBones running Debian. One of my classmates decided that he was too smart to use such a poo poo OS even though it was distributed by the professor and required for the class. Instead he decided to use Gentoo.

he should've used yocto

that way he'd still be loving around with bitbake recipes

hobbesmaster
Jan 28, 2008


so does Microsoft have a "ten loving years" policy?

hobbesmaster
Jan 28, 2008

Trabisnikof posted:

id like to know more about owning my own network

well, no rng on this hardware, guess we'll just need to put a seed in eeprom

*seed is always 0000000000000000*

hobbesmaster
Jan 28, 2008

ate poo poo on live tv posted:

I'm not a crypto/gambling expert, but even the pokemon games have a prng that is based on the embedded clock and doesn't reset on power-loss. So if that keno machine is reseting on power-loss, I doubt they do anything that "sophisticated".

Also thanks Pokespergs. This is cool information :
https://bulbapedia.bulbagarden.net/wiki/Pseudorandom_number_generation_in_Pok%C3%A9mon

a prng based on the clock isn't very good at all

at least use the LSBs from an adc to see a prng or something

hobbesmaster
Jan 28, 2008

JewKiller 3000 posted:

wanna go to a precheck interview wearing a giant potleaf tshirt

there is no real interview for precheck, they just take your fingerprints and scan your passport.

hobbesmaster
Jan 28, 2008

there absolutely are speed limits in the air, what are you talking about

hobbesmaster
Jan 28, 2008

ate poo poo on live tv posted:

There are areas where there are speedlimits. There isn't a general speed limit. What are you talking about?


If you are outside of FCC controlled "airspace" like most of the US up to 1200ft AGL is outside of FAA controlled airspace, then yea it would be similar. However FAA and FCC controlled airspace aren't the same. In fact beyond both being federal agencies, they aren't really comparable at all.

in absence of other applicable restrictions the speed limit below 10,000ft asl is 250kias. class b airspace is 200kias

the FAA claims jurisdiction on everything that's above the ground, likewise the FCC has jurisdiction over the entire EM spectrum

hobbesmaster
Jan 28, 2008

Truga posted:

there's open sores implementations of gps though, which allow you to remove any lockouts super easily :v:

there's also radio firmware you can flash that will let you violate FCC limits. you still need those limits in software to sell the things in the US without a giant "FOR DEVELOPMENT ONLY" sticker on it

all of that said, the specific speed and height limits on dji's drones are probably to limit the number that break

hobbesmaster
Jan 28, 2008

Microsoft: denied service is a feature!

hobbesmaster
Jan 28, 2008

cheese-cube posted:

i'm pretty sure any instance of them loving you up for attempting disclosure would be prosecutable.

:lol:

what country do you live in?

hobbesmaster
Jan 28, 2008

anonymous tweet?

hobbesmaster
Jan 28, 2008

flakeloaf posted:

copyright infringement as a service isn't a great business model but maybe you shouldn't let corporations execute search warrants

keep reading - it wasn't a search warrant and the judge was pissed

they get to hold onto his poo poo pending appeal though

hobbesmaster
Jan 28, 2008

no like they weren't allowed to do that stuff they did in the first place

hobbesmaster
Jan 28, 2008

what if he knew what the domain would do because he wrote it in the first place! :tinfoil:

hobbesmaster
Jan 28, 2008

Daman posted:

he probably did some weev poo poo, b4 he was popular the guy was pretty skiddy

according to the twitter thread some black hats reported wire fraud or something he supposedly did?

hobbesmaster
Jan 28, 2008

Diva Cupcake posted:

this? i can't imagine a high-profile vanning for this.

https://twitter.com/delevrything/status/877687311487705088

i bet he put in a month larger than 12!

hobbesmaster
Jan 28, 2008

Bhodi posted:

Yeah, if I make malware and gave it away, and someone later incorporates it to do harm, am I liable?

e: they're indicting a co-conspirator who is is being accused of everything else other than making it? I hate breaking-news-via-twitter

https://twitter.com/demize95/status/893184139679211520

yes, I'm assuming that guy is from Wisconsin or else this case is going to be eventually dismissed like the weev thing

they say that Hutchins created it and then later updated it, then this other guy sold it

hobbesmaster
Jan 28, 2008

lol forever if they built this case on private messages sent in the clear and preserved by alphabay

hobbesmaster
Jan 28, 2008

so either these hacker forum guys successfully framed him or he did write it and had a falling out with the guy he did it for?

edit: https://twitter.com/chmod007/status/893208559629901825

hobbesmaster
Jan 28, 2008

Trabisnikof posted:

Thank goodness California has a SLAPP statute. I wish popehat wasn't on twitter probation so I could read his musings on this

it's federal though

hobbesmaster
Jan 28, 2008

good news they're going to dramatically cut back their donuts and go all in on being starbucks

(USER WAS PUT ON PROBATION FOR THIS POST)

hobbesmaster
Jan 28, 2008

Wiggly Wayne DDS posted:

the transcript for malwaretech's august 4th proceeding is up: https://www.documentcloud.org/documents/3923335-USA-v-Marcus-Hutchins-August-4-2017-Hearing.html

there's a bunch of absurd parts in there, but crucially the prosecution's claiming there's another co-defendant at large conveniently excusing why kronos is still getting updates

also the tale has now evolved to sold software that later became the malware

it's apparently illegal for an alien on a non immigrant visa to take possession of a firearm?

that explains the prosecutions strange obsession with pointing out he fired a gun but :wtc:

hobbesmaster
Jan 28, 2008

FAT32 SHAMER posted:

this is probably one of the first times in history that has been applied against a white man lmao

well at least the judge agreed with the defense that it doesn't matter since there were ads in the airport for it and he showed his real passport

hobbesmaster
Jan 28, 2008

Jimmy Carter posted:

you're doing it wrong http://www.ursaminorvehicles.com/campers/element-camper.html


lol wasn't the Iran thing them trying to block Youtube by null-routing their IP block via BGP and they hosed up and advertised the route to the entire world

seems kinda expensive for not all that much extra space?

hobbesmaster
Jan 28, 2008

something might actually happen to them for that one

hobbesmaster
Jan 28, 2008

welp I guess it makes sense that identity theft is so easy

Adbot
ADBOT LOVES YOU

hobbesmaster
Jan 28, 2008

PyPy posted:

Those qualifications....her LinkedIn is gone now, ofc.



she had at the very least 11 years experience in something or other - she's blocked details of previous jobs. she could be extremely qualified we don't know

edit: more disk space and computing power could just be trying to get them to finally pay for new hardware but that entire answer does not instill confidence

  • Locked thread