Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
apseudonym
Feb 25, 2011

Did we touch the poop again?

Adbot
ADBOT LOVES YOU

apseudonym
Feb 25, 2011

Subjunctive posted:

does he do mobile? apseudonym? he should do mobile

Some of the p0 folks do mobile things, the last iOS security bulletin thing had a lot of hilariously bad sounding bugs credited to them and they find some cool Android ones from time to time but not as much as I'd like.


Tavis does what Tavis wants, he cannot be aimed.


E: wildcard certs are good Subjunctive is correct as to why y'all crazy sometimes.

apseudonym fucked around with this message at 17:51 on Jul 7, 2017

apseudonym
Feb 25, 2011

CmdrRiker posted:

I never thought about it before, but Google does a poo poo ton of data mining with all of their products. For example, when you get an email about your flight schedule and it magically appears on your calendar and at the top of your inbox app on the day of your departure. I became more aware of this poo poo when a colleague of mine got a job at Google and then promptly stopped using his Gmail account and wouldn't tell me why.

Can anyone else speak to this weird privacy business when it comes to Google and datamining emails?

I still use mine and I doubt that's why he switched ¯\_(ツ)_/¯.

apseudonym
Feb 25, 2011

goddamnedtwisto posted:

i'm really not sure why anyone thinks anything google has ever done has ever been about anything other than this

:jerkbag:

apseudonym
Feb 25, 2011

Notorious b.s.d. posted:

well, that would work, i guess

or microsoft could just insist that OEMs not gently caress with the operating system in their contracts. but they don't. because microsoft doesn't really care if OEMs are fuckups.

Because they could do that

apseudonym
Feb 25, 2011

:confused:

I'm also at defcon and no one cares it's not exciting.

apseudonym
Feb 25, 2011


:cripes: DEFCON what happened to you claiming to be against repressive governments.

apseudonym
Feb 25, 2011

Subjunctive posted:

changing the system from inside!

That's why they all went into working for government contractors or selling vulns.

apseudonym
Feb 25, 2011


That'll go well in court

apseudonym
Feb 25, 2011

James Baud posted:

Android - on Nexus/Pixel, at least - recently figured out that it would be good to let manual update checks bypass the staged rollouts since determined people were just going to get it another way more complicated way, maybe Firefox will be nice enough to do that too... I was annoyed at having to hit the website and download the (no visible sign of a version number, run it blindly) stub installer the day the update came out too. I think Mozilla took down/are taking down the ftp site, so didn't try that route.

Incidentally, I don't know what happened in the last year but Chrome's resource utilization has blown up making it unusable on machines that it formerly on ran just fine. (So I switched to Firefox on those work PCs after returning from an extended parental leave.)

Probably a bit of Chrome and a lot of websites, people keep bloating and bloating websites to a painful degree.


Also gently caress the web.

apseudonym
Feb 25, 2011

CommunistPancake posted:

it wasn't that she didn't understand tires, it was that she expected that everyone else would believe she had her tires slashed so she could get internet nazi points

No one would ever post lies for internet points

apseudonym
Feb 25, 2011

Cocoa Crispies posted:

unlike modern ios, android doesn't really have a standardized safari/chrome thing that lets apps launch web pages in a app-specific instance of the OS browser, instead they get to use a shittier browser view that google can't relaly fix because android

https://developer.apple.com/documentation/safariservices/sfsafariviewcontroller

Ur wrong also that looks like a Chrome Custom Tab

apseudonym
Feb 25, 2011

wolrah posted:

This one's always struck me as a matter of what threats you're trying to secure against.

If you're trying to stop someone who wants to break in to your phone specifically, yeah any of the one-camera facial recognition systems are pretty much junk.

If you're trying to stop some random who found/stole your phone from being able to get in to your poo poo, they're pretty effective.

The point of a lockscreen is the first.

apseudonym
Feb 25, 2011

cis autodrag posted:


fingerprints might be more trustworthy on an iphone, but surely not in Android land where the most popular OEM stored the finger prints as high resolution raw files in world readable storage.
Besides one OEM doing this before aosp support this isn't a thing and never really was.

Also focusing on the storage completely misses the point where fingerprint sensors fail in a security context and Apple's is no better than anyone else's.

apseudonym
Feb 25, 2011

ate poo poo on live tv posted:

Interesting. So you basically hit the button on the side 5x, and it disables fingerprints?

Also what do people think about a keypad with randomized nmber locations? Instead of it looking like 1, 2, 3, etc. It's 0-9 in a random location on the screen. Then after every number input, or maybe every 2 numbers, idk, all the numbers randomize again and you put the rest of the PIN in.

Way back in the 80's or so when the first LED keypads were a thing, some DoE keypads were designed that way. The passcode would be 1,2,3,4 but looking at someone putting in that keycode from far away their hand would have to move all over the keypad to put in the code. Seems like that would eliminate shoulder surfing, at the expense of taking longer to unlock the phone.

Not sure if that would be an acceptable trade off for usability or not.

Means you type in your pin a lot slower and I worry about that increasing the risk of screen surfing not decrease it since you have to think so long, you'll probably also make your pin shorter as a result of it sucking rear end

apseudonym
Feb 25, 2011

I don't understand why you'd sell your stock because of a breach though, breaches never seem to have much of a lasting impact on price.

What am I missing?

apseudonym
Feb 25, 2011

Shinku ABOOKEN posted:

lol the broadpwn bug is a plain-old 90's style buffer overflow

Bugs in 2017 aren't different than bugs in 1990.

apseudonym
Feb 25, 2011

anatoliy pltkrvkay posted:

who is this 'fip' character and why do people like their mode so much.

i prefer toris mode myself

:bsdsnype:

Fips is the jar jar of security

apseudonym
Feb 25, 2011

anthonypants posted:

yeah and a hundred years ago the swastika didn't have anything to do with nazis but guess what

Yikes even this dead comedy forum can't stand a joke anymore in the fuckup thread

apseudonym
Feb 25, 2011


I always rant that you shouldn't trust the network in any capacity but this gonna be fun

apseudonym
Feb 25, 2011

Honestly if in 2017 you rely on wifi encryption alone you're doing it really wrong.

If you're worried about your devices getting into hostile networks I sure hope you've never paired to any open networks since thats the way we've setup mitms forever.

apseudonym
Feb 25, 2011

M_Gargantua posted:

so should I be finding a way to wipe all prior key exhange material from all my devices or should they have been doing that well enough through routine garbage collection?

Keys wouldn't really be stored afaik

Cybernetic Vermin posted:

there have been quite a few of those posts already though, and i keep wondering whether they should be read "99.99% of users are loving idiots and should get off the internet", and whether you actually have been advicing your friends and family to not use wifi

The exact opposite? If you're using tls and friends the network doesn't matter (and the network is always hostile). This doesn't noticably change the security posture for any device that has an open network in it's pairing list (e.g. Starbucks) aka just about all of them.

Normal people shouldn't get off the Internet, though sometimes I wish parts of the security community would.

apseudonym
Feb 25, 2011


Top figure of the year

apseudonym
Feb 25, 2011

hobbesmaster posted:

title: “Microsoft is good? :psyduck:

Good compared to that TPM vendor at least.

apseudonym
Feb 25, 2011

BangersInMyKnickers posted:

Please don't construe OpenSSL's one instance of doing something right with an endorsement of that garbage fire

Openssl sucks but everything else sucks more

apseudonym
Feb 25, 2011


Did anyone actually read this because it's the stupidest scare mongering thing I've read in a while.

apseudonym
Feb 25, 2011

Proteus Jones posted:

Adress space randomization. Makes it harder to take advantage of buffer overflows.

Specifically it makes it harder to know addresses, it's not particularly about buffer overflows (just as applicable to many attack primitives).

It means you don't know, short a leak, the address of the function or ROP gadget you want to jump to or struct in memory you wish to mess with isn't known to you at runtime as an attacker.

apseudonym
Feb 25, 2011

ate all the Oreos posted:

the last time it came up in this thread i bought one and now i own one, i guess it's not actually that interesting a story :sigh:

the actual app for it is complete garbage, like it crashes or randomly disconnects, and it requires you to do everything over it (including its own hand-made chat program and other terrible ideas).

there's also a group of hobbyists who have written an entire generic buttplug control protocol that can federate between heterogenous teledildonic systems and then translate down into the particular protocol each actual device speaks on the client which is, uh, neat i guess?

like XMPP for your butt

Not the cyberpunk future I expected but buttpunk has a ring to it.

apseudonym
Feb 25, 2011

Wasabi the J posted:

Butt rock is already a thing. E.g.: Nickelback.

Wrong kind of buttplay

apseudonym
Feb 25, 2011

suffix posted:

i've noticed crapware asking for it
afaict you cant turn it off, and it will keep pushing updates even when the app is closed
so i figure google are happy with apps abusing it as long as they have an excuse to log the data, "the user installed our music app, so clearly they want their activity uploaded to our servers 24/7 in order to select a fitting playlist"

:jerkbag:

bump_fn posted:



i hate this so loving much

What a clever way to reduce the entropy of a password to almost nothing.

apseudonym
Feb 25, 2011

Bulgogi Hoagie posted:

https://twitter.com/lukasstefanko/status/926084558273044481

either pixel security is really good or no one targeted the pixel?

Adrian is right and iOS security is overblown :colbert:.

apseudonym
Feb 25, 2011


Scotty is a super cool dude, I'm glad he didn't totally burn out.

hobbesmaster posted:

so this will be named PSNV?

Doubt it, they don't get traction these days without dedicated PR people being involved and he isn't trying to sell you anything. Its too complicated and doesn't have a clever name and so wont be noticed compared to a lot of the far less interesting bugs that have lit up the press this year.

apseudonym
Feb 25, 2011


This is not the buttpunk future I wanted.

apseudonym
Feb 25, 2011

fishmech posted:

its good that no one uses bing.

apseudonym
Feb 25, 2011

haveblue posted:

I'm curious how much the phone's owner participated in that, the writeup and video don't make it clear. high rez face photos and 3D scans would not be easy to do on the sly and would be totally infeasible if you don't know who the owner is in the first place (phone obtained through street crime etc)


With two OK photos of someone's face you can order 3d printed masks online that are pretty good, I've been able to do it just off my public Facebook photos. Realistically your face at any level of detail is public information, it's 2017 high res data is everywhere.

Face is a stupid unlock mode and Apple users are gonna get bit in so many terrible ways but people will keep defending it :smithicide:.

apseudonym
Feb 25, 2011


I wish WikiLeaks actually delivered what it used to promise and wasn't just a weak sauce mouthpiece for Russian poo poo.

apseudonym
Feb 25, 2011


:smug:

apseudonym
Feb 25, 2011

Brings new meaning to sanitize your inputs

apseudonym
Feb 25, 2011

SmokaDustbowl posted:

I like your avatar

Thanks :unsmith:


Security Fuckup Megathread - v14.1 - I caught a virus from my unsanitized blowjob

Adbot
ADBOT LOVES YOU

apseudonym
Feb 25, 2011

Ur Getting Fatter posted:

gonna ddos the blowjob machine until I get a buffer overflow iykwim


vOv posted:

distributed denial of service

dick denial of service

  • Locked thread