Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
cinci zoo sniper
Mar 15, 2013




cheese-cube posted:

oh yeah actual secfuck: today i found a couple of standalone windows servers in our environment that had their local Guest accounts enabled and they'd been added to the local Administrators group :stare:

oh and they also weren't being patched but that pales in comparison. pretty sure it was a former coworker who is responsible for that fuckery but he left about 3 months ago so i cant tear his trachea out.

:staredog:

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013





https://www.youtube.com/watch?v=vfl33Tn0pYc

cinci zoo sniper
Mar 15, 2013




Maximum Leader posted:

i think someone hacked my poo poo, someone tried to log into (with correct username and password) my steam account from brazil and my spotify password just got changed

sounds like that ye

cinci zoo sniper
Mar 15, 2013




please use password manager from now on

cinci zoo sniper
Mar 15, 2013




FAT32 SHAMER posted:

or if you're like me, dont use the same password everywehre

password managers are for the unburned

what

cinci zoo sniper
Mar 15, 2013




FAT32 SHAMER posted:

the unburned are those who havent been hacked yet

yeah im trying to make sense of your advice to ditch password managers and implication of single password for everything with the use of password manager

cinci zoo sniper
Mar 15, 2013




Angela Merkle Tree posted:

people aren't hacking your password manager, they're hacking that unpatched counterstrike forum you posted on 10 years ago with the same password

e: wait i think that's what you're saying

yeah that what I'm saying

FAT32 SHAMER posted:

nonono

i said i use a pw manager (safari's) and at the very least dont use the same pw everywhere because
yeah i saw that you use pw manager, it's just that the first two lines rub sleepy me the wrong way but im dumb foreigner. either way i see now that at least the first line poses you as a bad example. still not getting second line though, password managers are pretty good after you've been owned too

cinci zoo sniper
Mar 15, 2013




but yeah just ignore me whenever i stumble in english, i should've known better by now unless you are making some obscure regional references

cinci zoo sniper
Mar 15, 2013




Raluek posted:

i think cinci's confusion stems from these being basically opposites
exactly, unless it's meant to say "password managers are meant to prevent getting owned"

cinci zoo sniper
Mar 15, 2013




mrmcd posted:

lol if there's scrubs itt not using password managers and 2fa

to be honest i am too lazy to use 2fa for most things. one day thatll get me in trouble, but for now ive just had chinese guests in my c-tier nth gmail account i accidentally remembered after never using it, and my guild wars 2 account i barely ever used too

cinci zoo sniper
Mar 15, 2013




Wrath of the Bitch King posted:

is lastpass still unacceptable to use these days or what? I'm using keepass with my dropbox account to house the pw database, but it's a little more cumbersome than I'd like and I wouldn't mind moving to a centralized platform like LP.

lastpass still not great at the specific part that makes it different from standalone cloud storage keepass, yes

cinci zoo sniper
Mar 15, 2013




maskenfreiheit posted:

I prefer to use KeePass.

There's a nice shiny OSX client - KeePassXC.

If you want your DB synced across devices you can get a Spideroak account.

i use keepass too, "official" windows client with key file in onedrive

cinci zoo sniper
Mar 15, 2013




Truga posted:

I hope you mean password vault? Key file should be local.

And yeah, same, except I sync via SCP.

the database file, im not fluent with terminology

cinci zoo sniper
Mar 15, 2013




maskenfreiheit posted:

you use a keyfile? don't you worry that if that's compromised?

US government wrote it's privacy laws in the goddamned 80s, so files older than something like 30 days don't even require a warrant for government to grab. (And that's if you're a US citizen)

Personally I use a passphrase I've memorized. It's kind of a pain to type but no one can steal it or compel it with a court order.

database file locked under a password.

cinci zoo sniper posted:

the database file, im not fluent with terminology

cinci zoo sniper
Mar 15, 2013





i opened the thread on phone and seeing twitter/taviso made me reflectorily go "oh poo poo"

cinci zoo sniper
Mar 15, 2013




Arcsech posted:

why doesnt this guy ever find earthshattering oh-poo poo vulns on like, monday morning or something

always like thursday or friday afternoon

i imagine he gets lame work poo poo out of the way, although he should have a p interesting for himself job, and then just hobbies away at whatevers the target

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

I don't know if this user1 has any infosec knowledge or anything but it seems to me they dont actually know what an 0day is.

0day is becoming one of those terms that gets thrown around without people knowing what it really means, just yesterday I was talking to some non-techies about wannacry and nyetya and one of them thought and 0day was a backdoor and persistence mechanism.

an app idea - 0dayr, crashes your phone on activation

cinci zoo sniper
Mar 15, 2013




The fidget spinner of prosumer cyber.

cinci zoo sniper
Mar 15, 2013




communism bitch posted:

You could probably find a venture capitalist ready to invest 10 mil into this. Just change "crashes" to "disrupts", make some vague noises about monetisation strategy, and you're golden.

what if we pay users if they can actually load into it, but they pay us for each disruption suffered to make for an immersive ransomware experience?

cinci zoo sniper
Mar 15, 2013




Cocoa Crispies posted:

seems like a good way to know who even knows what a 0day is is people who call it an "oh-day" vs. "zero day"

if you ever say it "zero day" to a british person you'll be laughed out into the loving oblivion. do you also "zero" when dictating a phone number with 0 in it?

cinci zoo sniper
Mar 15, 2013




james bond, agent double zero seven

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

what weird european country are you from where they call them "handsets" i've only ever heard that in relation to landline phones

standard english m8

cinci zoo sniper
Mar 15, 2013




gonadic io posted:

I'm British and say zero day :shrug:

you're not supposed to just go and blow up my cover like that :argh:

cinci zoo sniper
Mar 15, 2013





that's what ive heard in europe the few times ive got to hear it,, and most of countries here stick to british english :shrug:

cinci zoo sniper
Mar 15, 2013




FAT32 SHAMER posted:

when you say "oh-day" i think of his brother qusay hussein
but enough about american sense of "humour"

cinci zoo sniper
Mar 15, 2013




jre posted:

People saying oh-day ?

yea

cinci zoo sniper
Mar 15, 2013




BattleMaster posted:

it had never even occurred to me that "oh day" was a possible way to say it especially when phrases like "zero hour" have existed for a long time

its always pronounced oh hour thouhg?







ok im kidding.

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

I use antifa on all my accounts

preparing for imac pro eh?

cinci zoo sniper
Mar 15, 2013




Mr SuperAwesome posted:

i am a british person who says "zero day"

zero really? :downsrim: but yeah thread opinions and my limited experiences are different things. not that it matters much, im just more and more curious how oh-day hasn't seen broader, i guess, adoption due to being easier and shorter to say while retaining the clarity of meaning

cinci zoo sniper
Mar 15, 2013




geonetix posted:

if you say anything else than "zero day" you should probably not be in this kind of business

thankfully im a financial analyst :v: just interested in reading and talking about dangerous computers

cinci zoo sniper
Mar 15, 2013




Mr SuperAwesome posted:

obviously SMS 2FA is bad, but if you're using gauth/totp whatever and lose your phone, what then?

i mean, how different is it from loosing phone with sms 2fa, or do your carriers restore stolen numbers?

cinci zoo sniper
Mar 15, 2013




Subjunctive posted:

where are you, if I might ask, that losing your phone means getting a new phone number?

latvia. a significant portion of population uses prepaid for which im far from certain about the possibility to restore number in the case of theft. with contract plans that should of course be possible

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

By the way the plural is zeroes day

argh

cinci zoo sniper
Mar 15, 2013




guys has anyone seen the op, by the way.i think we may have killed her :ohdear:

Shaggar posted:

you just get a new phone and the same account w/ same number. the old phone/sim are deactivated. the reason SMS is so common for 2fa is because the user doesn't have to manage their own key recovery when their 2fa mechanism is lost. For example
i get that for contract numbers, yes. here that would gently caress up considerable portion of population, and i imagine it is similar in other poorer countries

cinci zoo sniper
Mar 15, 2013




Shaggar posted:

oh yeah then you'd be hosed. same as if you didn't copy down your recovery keys for a non-sms 2fa. altho depending on the account they probably have a way to remove the 2fa which is an easier target than your SMS was in the first place.
the removable 2fa is double-edged sword. with google you are hosed, with steam you can email your id and unfuck the account, but then you can also be identity-theft owned

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

I'm not going this year :(

may your kapsalons be especially tasty

cinci zoo sniper
Mar 15, 2013





/r/programmerhumor checking in

cinci zoo sniper
Mar 15, 2013




COACHS SPORT BAR posted:

lol



coworker had this hanging on his wall for years after being hassled on his day off to complete phishing training

thats a cool coworker :laffo:

cinci zoo sniper
Mar 15, 2013




WAR DOGS OF SOCHI posted:

i saw that the petya decryption key was released just the other day

practically speaking, how are they obtaining the keys to these ransomwares? i mean, they must be using a crap algorithm in order for this to be possible, right?

sometimes, people reverse engineer the ransomware enough to figure exactly what's happening, and how. this time, similarly to teslacrypt, the author released the private key in public

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




WAR DOGS OF SOCHI posted:

i must be missing something because even if you reverse engineer something that implements something like rsa encryption, you aren't decoding that thing in a few months without the private key -- as you point out, the author would need to release that
i was more of leading to the idiots who hardcode the encryption key into their code, that sometimes happens. otherwise sure, you might be fairly hosed if it's a properly executed implementation of a well known and tested modern encryption algorythm, and not some artisanal hand-crafted crypto based on a quadratic function

  • Locked thread