Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Workaday Wizard
Oct 23, 2009

by Pragmatica
its high performance art

Adbot
ADBOT LOVES YOU

Workaday Wizard
Oct 23, 2009

by Pragmatica

M_Gargantua posted:

now do the same, but social media and government records too

wasnt this the plot of catwoman?

Workaday Wizard
Oct 23, 2009

by Pragmatica

Bulgogi Hoagie posted:

god i so so hope that the kaspersky bullshit doesn’t mean the fsb have infiltrated jetbrains too

my code will give them aids lol

Workaday Wizard
Oct 23, 2009

by Pragmatica

Workaday Wizard
Oct 23, 2009

by Pragmatica

ffs its 2017 just throw your app behind nginx and take 2 minutes to add the three lines needed for tls :argh:

Workaday Wizard
Oct 23, 2009

by Pragmatica

Volmarias posted:

Enjoin Ex

:divorce:

too soon lol

Workaday Wizard
Oct 23, 2009

by Pragmatica

Ciaphas posted:

good point. this might be workable (technically against the rules to download and run anything even if there's no install but oh loving crackers i'm tired of these rules

lastpass is just easier though because I know at least dropbox is proxied off to inaccessibility on the 'net machines at work, i don't know what other cloud storage services are (probably all of them)


Ciaphas posted:

i desperately want a new job because of bullshit like this (ok this time it's not impacting my work but 99% of the time you bet it does)

but i'd miss all the tiny little bennies of working at this stupid place, like flexible schedule and being totally ok with t-shirt and jeans and boat shoes or whatever

why are you accessing clown hosted poo poo at work from a work machine? :thunk:

could you perhaps be.... the security fuckup? O_o

Workaday Wizard
Oct 23, 2009

by Pragmatica

minato posted:

I don't know if this counts as a security fuckup, but I was talking to an Uber engineer today who told me a couple of interesting scams they encountered the past couple of years.

Apparently Uber got heavily scammed in China by people exploiting the subsidies used to incentivize drivers to cruise around waiting for fares.

The first scam involved phone emulators and fake GPS units to organize fake trips. When scammers tried to parallelize the system with multiple fake driver accounts, Uber caught on when they saw "snakes" of cars moving around the map.

The second scam involved the drivers deliberately putting up scary profile pictures, making the driver look like a vampire or a ghost. The hope was that the customer would be so put off that they'd cancel the ride before pickup, which would give the driver a few yuan as compensation for the cancelled ride. Uber had to implement a facial recognition system that ensured profile pictures closely matched their owner.

edit:

ahhh... the entrepreneur spirit :allears:

Workaday Wizard
Oct 23, 2009

by Pragmatica
stay safe noob ghost


i'd personally avoid any chinese or russians :tinfoil:

Workaday Wizard
Oct 23, 2009

by Pragmatica
there are already systems for detecting nudes with a very high detection rate. just buy the ones the chinese use or something.

Workaday Wizard
Oct 23, 2009

by Pragmatica
is facebook sending requests for nudes? can we lock fuckerberg up for soliciting nudes from minors?

Workaday Wizard
Oct 23, 2009

by Pragmatica
am i the only one who feels phishing tests are worthless. the way i see it used is mainly secops being shitheads. “haha gotcha u dummy”. it sucks rear end for morale and the tools don’t care if the user didn’t interact with the phish.

the only thing phishing tests prove is that people whose job is to click emails click emails.

Workaday Wizard
Oct 23, 2009

by Pragmatica

infernal machines posted:

Maybe they don't convey it too well, but you really do want to train users not to click on links in unexpected emails. If you've had meetings/training telling people not to do that, and they still do it, I'm not sure how exactly to get the message across.

the days of unexpected emails are long past. nowadays phishing is super specific.

the phishing exercise im complaining about is both timing and subject specific. the users 120% expect the kinds of emails that were sent.

Workaday Wizard
Oct 23, 2009

by Pragmatica

Jabor posted:

So the anti-phishing exercise is mimicking exactly what a spearphisher targeting your organisation is going to try?

This is a bad thing why?

because the management is using it as a performance indicator which is the dumbest poo poo. have fun telling management that people clicked because they have a billion emails to process and not because they are “bad” employees.

e: i didn’t click btw

Workaday Wizard
Oct 23, 2009

by Pragmatica

Truga posted:

i know posting about video games is cheating but

https://forums.enmasse.com/tera/discussion/18877/status-of-potential-chat-vulnerability

apparently there's an rce floating around the tera community where you can post malware into chat, and it'll execute(???) for people.

tera is the pedorpg right? if so good gently caress em

Workaday Wizard
Oct 23, 2009

by Pragmatica

Cocoa Crispies posted:

or the drunkenly speed changing nokia ringer from "Crank"

so *thats* where that annoying ringtone came from

Rufus Ping posted:

classic Mr Hands

lomarf

Workaday Wizard
Oct 23, 2009

by Pragmatica

Just-In-Timeberlake posted:

we prefer that lube be used

Workaday Wizard
Oct 23, 2009

by Pragmatica
let he without breach cast the first lol

Workaday Wizard
Oct 23, 2009

by Pragmatica
two talks on intel me already 😰

Workaday Wizard
Oct 23, 2009

by Pragmatica

Kuvo posted:

i hope you continue to do the write ups/recomendations for these because the ones last year were real good

Workaday Wizard
Oct 23, 2009

by Pragmatica

bicycle posted:

https://twitter.com/Viss/status/935681868845932544

@viss touching the poop like a loving idiot

mycrimes.txt

Workaday Wizard
Oct 23, 2009

by Pragmatica

please be real :evilbuddy:

Workaday Wizard
Oct 23, 2009

by Pragmatica

BangersInMyKnickers posted:

lol I have a SEP client that is detecting its own IPS sig updates as malicious and stuck in an endless loop of deleting the files its update routine is writing

lmao

Workaday Wizard
Oct 23, 2009

by Pragmatica
wait client cert auth is bad? i only used it to authenticate clients with servers that i control (a toy project)

what's so bad about client cert auth?

Workaday Wizard
Oct 23, 2009

by Pragmatica
ripgrep is fast 💨

Workaday Wizard
Oct 23, 2009

by Pragmatica

Optimus_Rhyme posted:

I was gonna reply to a link to his awesome DEFCON talk but NOOOOOPE youtube took it down

https://www.youtube.com/watch?v=PfbMZJsb1cQ&hd=1

youtube suck balllllllllllllls and not in the good way 🤬🤬🤬🤬🤬🤬

Workaday Wizard
Oct 23, 2009

by Pragmatica

thanks :tipshat:

Workaday Wizard
Oct 23, 2009

by Pragmatica

dats a c00l cyberpunk

Workaday Wizard
Oct 23, 2009

by Pragmatica

Jabor posted:

you need an iot id to sign into an id:iot account

heh

Workaday Wizard
Oct 23, 2009

by Pragmatica

quote:

replace her with me, an operator 100x better that she is oppressing

of course its a 4chan incel retard

Workaday Wizard
Oct 23, 2009

by Pragmatica

BangersInMyKnickers posted:

lmbo Microsoft's Mac and Linux system center endpoint protection is just a licensed and reskinned eset agent this owns

innovation through capitalism

Workaday Wizard
Oct 23, 2009

by Pragmatica
no one from equifax got hurt for selling stocks during a loving breach that they knew about and were investigating. why do you think they will touch intel's ceo?

Workaday Wizard
Oct 23, 2009

by Pragmatica

mrmcd posted:

As long as you don't execute based on pure speculation you should be fine.

https://www.youtube.com/watch?v=kJaM8qJNx8M

Workaday Wizard
Oct 23, 2009

by Pragmatica

:discourse:

Workaday Wizard
Oct 23, 2009

by Pragmatica

Volmarias posted:

I immediately uninstalled WhatsApp when it refused to work without being able to read all of my contacts, am I just being overly paranoid?

that ship already sailed when truecaller etc. harvested your contact from your contacts.

it's the facebook problem: you can hide as much as you want but the idiots around you will tag you and publish your details anyway.

Workaday Wizard
Oct 23, 2009

by Pragmatica

Max Facetime posted:

cool, I can’t wait to experience more random slowdowns because Apple can’t control what code gets executed on their platform

thanks Apple, dapple

i wish ios didn’t run javascript but alas cest la vie

Workaday Wizard
Oct 23, 2009

by Pragmatica

Cocoa Crispies posted:

the security theater is that .net mvc doesn't validate the csrf token automatically like the much better framework it's a knockoff does

which framework would that be?

Workaday Wizard
Oct 23, 2009

by Pragmatica

Truga posted:

yeah macos is on a roll lately

more like infosec people slightly turned their heads in its direction 😜

Workaday Wizard
Oct 23, 2009

by Pragmatica

Mr.Radar posted:

Someone found another string of Unicode that causes Apple products to lock up (and generally seems to cause most Unicode rendering libraries to choke or crash). You can find it here (:siren: warning: don't open if you're not okay with your browser crashing, even on non-Apple platforms :siren:).

i clicked on awful app and nothing happened :confused:

Adbot
ADBOT LOVES YOU

Workaday Wizard
Oct 23, 2009

by Pragmatica
what's keybase and who uses it?

  • Locked thread