Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Arcsech
Aug 5, 2008

ate all the Oreos posted:

wife just linked me this:



brilliant :allears:

Adbot
ADBOT LOVES YOU

Arcsech
Aug 5, 2008

Shaggar posted:

tl;dr: the primary benefit of lets encrypt was avoidance of key-reuse and wildcards and now they're gonna end that so w/e. its stupid but i guess just don't use them yourself.

the biggest benefit of LE was always easy free ssl certs that auto-renew

avoidance of key reuse and wildcards was also good

Arcsech
Aug 5, 2008

why doesnt this guy ever find earthshattering oh-poo poo vulns on like, monday morning or something

always like thursday or friday afternoon

Arcsech
Aug 5, 2008
got my poc||gtfo bible today, it looks loving fantastic.

time to read a bunch of papers about doing cool poo poo with computers that I'm too dumb to understand

Arcsech
Aug 5, 2008

not actually amazon, just a scammer pretending to be:

https://twitter.com/Chris_Vivier/status/890304520105762816

Arcsech
Aug 5, 2008

fishmech posted:

corporations have literally existed for hundreds of years.

also people do have the right to store personal information of other people. it's called being conscious. you may not be familiar with it.

people may, corporations do not, because corporations are not people

in some places they are legally people, because those places have braindead laws

Arcsech
Aug 5, 2008

Rufus Ping posted:

Well i'm bored in vegas

what the gently caress is this post about and why does anyone care

Arcsech
Aug 5, 2008

quote:

Instead of parsing an MSI file to get its version number, this code creates a script containing the filename for which a thumbnail should be shown and executes that using Wine. The script is constructed using a template, which makes it possible to embed VBScript in a filename and trigger its execution.

why

Arcsech
Aug 5, 2008

BattleMaster posted:

I feel like that's an entirely avoidable situation even if you're green or gullible

yep

however, don't underestimate the number of people who think "what happens in vegas stays in vegas" is a real thing and a good excuse to be terminally stupid

Arcsech
Aug 5, 2008
apparently sales force fired a couple of their security folks at defcon for giving a talk at defcon, because some exec sent them a text half an hour before the talk telling them to abort which they didn't see in time

http://www.zdnet.com/article/salesforce-fires-red-team-staffers-who-gave-defcon-talk/

Arcsech
Aug 5, 2008

anthonypants posted:

which didn't have anything to do with salesforce specifically, it was just to show off a cool thing they made and were using internally and want to give to the world. it should go over well

also they had exec approval since february

Arcsech
Aug 5, 2008

spankmeister posted:

My loving god shut the gently caress up about donuts

Arcsech
Aug 5, 2008

ate all the Oreos posted:

my man have you heard of the dd command


pre:
dd if=/dev/👻 of=/dev/sdX bs=4096

Arcsech
Aug 5, 2008
google says amd is vulnerable as well, and also arm: https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html?m=1

quote:

These vulnerabilities affect many CPUs, including those from AMD, ARM, and Intel, as well as the devices and operating systems running them.

rip all modern cpus, i guess

e: project zero blog confirms: https://googleprojectzero.blogspot.co.uk/2018/01/reading-privileged-memory-with-side.html

e2: looks like amd is less vulnerable at least?

Arcsech fucked around with this message at 00:11 on Jan 4, 2018

Arcsech
Aug 5, 2008

Shifty Pony posted:

crossing from the tech bubble thread

good security idea: deploy something that lets you instantly remotely lock and encrypt any system and train overseas office managers on how to quickly trigger it if a bunch of unauthorized people force their way into the office to gain access to sensitive data.

bad security idea: defining "police with a search warrant" as unauthorized.

I mean if your business is literally “operate an obviously illegal unlicensed taxi service” and therefore your threat model explicitly includes law enforcement, this doesn’t seem like that bad a security idea

at least until local law enforcement gets wise and just takes bolt cutters to the ISP lines into your building before raiding you and/or decides to prosecute for obstruction

Arcsech
Aug 5, 2008
yeah don’t rely on nordvpn to keep you safe if you’re trying to dodge a government or whatever but if you just want to torrent Linux ISO’s or dodge an overly restrictive firewall or use public WiFi more safely it’s fine

also the pre shared key isn’t an issue if you use their app or OpenVPN instead of the trash fire built into old android/windows

Arcsech
Aug 5, 2008
pay-with-bitcoin fuckup results in coinbase and overstock.com giving out bitcoins basically for free: https://krebsonsecurity.com/2018/01/website-glitch-let-me-overstock-my-coinbase/

e: whoops, this is a couple days old, so it might have been posted already. still hilarious

Arcsech
Aug 5, 2008

pseudorandom name posted:

Apparently they're actually blindly assuming you can just overwrite the window.u2f property because they're bad at coding and didn't read their own spec.

chome is the new internet explorer

Adbot
ADBOT LOVES YOU

Arcsech
Aug 5, 2008

Truga posted:

you'd need govt sponsored pentesters that continuously hack your poo poo, because that's what they had to do to get food/fire safety laws to work (inspectors showing up at random and closing down your buildings if they don't conform)

jail time for ceos/executives in cases where data breaches are deemed sufficiently negligent by an appropriate regulatory body could maybe work

except lol that will never ever happen because rich people never face consequences for anything

  • Locked thread