Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

ate all the Oreos posted:

wife just linked me this:



brilliant :allears:

Magnificent



Lain Iwakura posted:

ayyy lmao

but yeah. i came out in april and sort of disappeared for a while because of it. will be kicking rear end soon enough!

Congrats!

Adbot
ADBOT LOVES YOU

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

:golfclap:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Helianthus Annuus posted:

libraries are good and cool

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

maskenfreiheit posted:

Maybe they will ban McAfee? 🤔

Inshallah


The hero infosec deserves.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

cheese-cube posted:

he left about 3 months ago so i cant tear his trachea out.

Look at this Pessimistic Pete over here, all I'm seeing is that he had a 3 months head start and probably didn't even realize that he needed to run.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

For those of us who don't know, what COULD possibly go wrong?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Lain Iwakura posted:

code:
15:44 < user1> company doing pentest on us is pissed at us.. one of our engineers uploaded
                their 0day exploit to virustotal and MSFT picked it up and tweeted about it
15:45 < user2> lmao
15:46 < user3> hahahahaha rekt.
15:46 < user4> Oops
15:46 < user4> Where's the tweet?
15:46 < user3> Of all the poo poo ways to burn an 0day.
15:46 < user3> That's probably the worst
15:49 < user1> [link to tweet]
15:49 < user1> MSFT picked it up from virustotal
15:49 < user1> and tweeted about it.. all in a span of about 25 minutes
https://twitter.com/JohnLaTwC/status/883057609023959040

:perfect:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Text me

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Shifty Pony posted:

idk, there's probably enough wiggle room for them to set up some sort of quarantine for all preinstalled apps until they are actually launched by the user. they would just have to include their own apps in it too.

Several years ago, a feature was added to Android so that garbage preload apps could be uninstalled. Apps that are required for phone functionality (Dialer, Settings, etc) could have a flag set that would mark them as "critical" and thus not allowed to be uninstalled.

Guess how long it took for the garbage to be marked "critical" as well?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Shifty Pony posted:

and if they cracked down and actually applied standards for what is critical functionality the manufacturers would simply pool the dialer and settings app with the bloat apps into a single package such that the former depend on code from the latter for operation, similarly to how MS deeply integrated IE into windows.

The open source nature of Android means that Google can recommend and strongly suggest, but ultimately cannot fully control what OEMs do, which is unfortunate for end users.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

pray for my aunt posted:

exploit indexing begins at 1day

:catstare:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

COACHS SPORT BAR posted:

lol



coworker had this hanging on his wall for years after being hassled on his day off to complete phishing training

A good response

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

fishmech posted:

Plug this Web key into the USB drive on your computer.

what is with this copy

Any person that would actually plug this in is the kind of person who would call it a "web key"

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

surebet posted:

How the Calibri font could take down Pakistan’s prime minister
Microsoft’s default font is at the centre of an ongoing corruption investigation



Microsoft’s Calibri is a fairly innocuous font, used by default on countless numbers of Word, Excel and Powerpoint documents. The inoffensive lettering could soon topple Pakistan’s prime minister, however, after being placed at the heart of a corruption investigation.

Pakistan’s supreme court is currently deliberating a case against Nawaz Sharif, the head of the country’s government. As Al Jazeera reports, a Joint Investigative Team (JIT) encompassing police, military officials and financial regulators has been gathering evidence about the prime minister’s family’s assets.

This follows a judgment by investigators that there were "significant gap[s]" in Sharif's family's ability to explain their assets and means of income. The investigation stems from the 2016 Panama Paper leak, which named three of Sharif's children as beneficiaries of offshore companies. Sharif’s political opponents claim that his properties in London were obtained through corrupt means.

Okay, so where does Calibri come in? Well, to prove her father’s innocence, Sharif’s daughter Maryam Nawaz Sharif has produced a document – allegedly from 2006 – which claims to show certain declarations of income.

The JIT report, however, notes that the documents are written in Calibri, which was not made commercially available by Microsoft until 2007. The investigators say this means that the declarations are therefore incorrectly dated, and were likely created at some later point in time.

https://twitter.com/frooq/status/884494782306889730
The investigation is ongoing, so it’s too soon to tell if a misused font is enough to undermine Sharif’s case, but it certainly isn’t going to do the precariously placed politician any favours. Still, at least it wasn’t Comic Sans.

:haw: Well I tried to use the original document, but word told me that it was too old so it converted it to a new one, I'm not sure I'm not good at computers

:doink: Neither am I, that sounds plausible. Case dismissed!

Seriously though, I love that there's always some new way for Microsoft's font handling to screw people over.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

my bitter bi rival posted:

Calibri more like Sans Sharif

:popeye:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
The irony is that they originally always showed ads, but so many people complained about how they spent money for a thing that was going to advertise at them, that Amazon relented and added a no-ads model afterwards for $10 extra.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

ratbert90 posted:

He will probably become a serial murderer.

Excuse me, I believe you mean GNU serial murderer

Carbon dioxide posted:

25 eur gift card attached.

I'm guessing you have functional privacy laws and they would have lost a lot more than 25EUR if someone found out.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Call up Brian Krebs claiming to be Brian Krebs from a terrible future where Bitcoin is the world currency but the security situation hasn't improved. Say that Tavis is the ruler of the world and ask whether this is actually pretty ok all things considered.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

cinci zoo sniper posted:

government

reason

encryption

Found the fatal flaw in your argument.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

bobfather posted:

I was really hoping "what security question did you choose" picked twice would pop up a third drop down box.

cinci zoo sniper posted:

I was really hoping "what security question did you choose" picked twice would pop up a third drop down box.

:golfclap:

Subjunctive posted:

yeah, without hdr there's a simple rainbow table attack

Everyone's just going to pick a corner anyway.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
I'm guessing your password is "I'm a huge ding dong" so that no one realizes when it happens?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Chris Knight posted:

that's because the real one is @twittersupport

Given that they can just take accounts from whoever, wouldn't they just have it 302?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

cinci zoo sniper posted:

hackers can turn your segway into a bomb

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Oh, I thought it was a pun about a segue.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
An uninterrupted transition from one topic (or song or whatever else) to another.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

My PIN is 4826 posted:

best part isn't even mentioned in this article - the STA database is public domain information, so it's passed around to advertisers as a service. however, this one time they all got an un-redacted database that included things like people in the witness protection programs.

the obvious solution would be to send out the redacted version and tell recipients to destroy the old one, but instead they sent out a list of who to remove from the first database :smithicide:

:piss:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Powerful Two-Hander posted:

do u have a skul gun?

This

Dodoman posted:

What happened to your 💀?

but mostly this

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

PCjr sidecar posted:

ur dogs on a no flea list

A terrier watch list

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

maskenfreiheit posted:

i look forward to a future where we are sedated, stripped naked, and stacked like cordwood when flying

As a tall person, this would actually be a significant improvement. At least then my legs would be unfurled and I wouldn't have to sit through the flight.

cinci zoo sniper posted:

no, you are not. you would land too rapidly etc, and regulators have their own opinions on it all too

It's probably easier for them to be able to say that they're self regulating than to have the FAA decide that drones constantly appearing in class B airspace buzzing the tower really isn't worth the hassle and to ban them all.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

cheese-cube posted:

patriot pac-3 has drone shoot-down capability within a very broad altitude envelope. you better be packing some badass ruskie EW/traditional countermeasures fdriend

fake edit: holy lol, this bit from the patriot wiki article is a proper fuckup (https://en.wikipedia.org/wiki/MIM-104_Patriot#Failure_at_Dhahran):

And as always, it was user error.

quote:

Two weeks earlier, on February 11, 1991, the Israelis had identified the problem and informed the U.S. Army and the PATRIOT Project Office, the software manufacturer.[46] As a stopgap measure, the Israelis had recommended rebooting the system's computers regularly. The manufacturer supplied updated software to the Army on February 26.

The rest of the Wikipedia article doesn't inspire a lot of confidence, listing a number of misses, and instances of drones being missed.

There's a number of anti-drone weapons, including lasers, being developed and actively used. It'll be interesting to see what happens in the near future with them.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

cinci zoo sniper posted:

https://security.gerhardt.link/RCE-in-Factorio/

Factorio is a very popular multiplayer factory management and automation game. It supports modification though the use of Lua scripts. For security and determinism (in a multiplayer game all clients process the game state separately, any client difference would result in desyncronization and crashing) access to certain Lua core libraries is disabled. This includes OS, debug and package. Factorio supports a Lua REPL that can be used by administrative users in multiplayer games and will also autorun Lua provided by the server on joining in a less widely used system called “scenarios”.

Finally, a bigger gently caress up in Factorio than my base layout!

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

quote:

It also helped that Seleznev didnt use encryption at all.

Why did they need the password at all then?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Why not both?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
e: misread, nevermind

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

flakeloaf posted:

unless it is a festering landfill of diapers you cannot improve it with the addition of blockchain technology

How would blockchains improve festering diaper landfills? :confused:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

French Canadian posted:

To be fair, it was partially the "authenticity" of the DropBox-esque email that screwed me over.

Gone are the days of Nigerian emails and poor grammar.

They're still there, phishing is just another attack strategy. 419 emails look like garbage on purpose.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

ate all the Oreos posted:

today my friend managed to catch in code review one of our shittier devs' "solution" to running tasks remotely.

anyone wanna guess what it was doing?

it was literally just netcat piped to sh of course!

this was going to be installed on a customer's corporate network :stonk:

:murder:

Adbot
ADBOT LOVES YOU

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

geonetix posted:

nist has some very cynical people in their copywriting department



... Nice?

  • Locked thread