Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
maskenfreiheit
Dec 30, 2004
so i heard defcon is cancelled

Adbot
ADBOT LOVES YOU

maskenfreiheit
Dec 30, 2004

spankmeister posted:

You don't go to def con for the talks tbqh

Vegas will have dispenaries open by Defcon so that should be... interesting.

maskenfreiheit
Dec 30, 2004

ratbert90 posted:

Taking a shower at the gym I realized that anybody flushing the toilets makes the water temp go up by 10F.

MitM attack if I have ever seen one.

real question is if you flush all the stalls at once will you roast somebody

edit: drat, foiled by communism bitch

maskenfreiheit
Dec 30, 2004
there was some magic going on in grad school that if we searched google scholar on the university network, we'd get free access to stuff. we'd also see a link to the library's page for the item, in cause you're some weirdo who wanted the physical journal.

maskenfreiheit
Dec 30, 2004

ThePeavstenator posted:

Well this morning certainly has been interesting.

I work at a large global company that makes lawn equipment and engines. Our manufacturing line computers were infected with ransomware last year and had to be shut down until hundreds of thousands of dollars were payed out.

I work in the equipment testing lab. The lab manager (who btw owns) and I are the people that maintain and develop software that handles all the test requests and test data, among other things.

I go into his office this morning and we notice that a folder in the network drive where all of our test data is stored had a bunch of [document in the folder filename].locky files. We immediately wrote a ticket, which immediately got escalated to the head of global network security. I then noticed that all the locky files were 0 bytes and I right clicked on the properties to see the owner. Every file was owned by the same guy and we work fairly closely with him so we messaged him right away. He tries being all coy saying he had no idea what we're talking about *wink*. Turns out they're all just empty and it was just a "prank".

Our IT sends out almost daily memos reminding people what to look for in a phishing attempt after we had production shut down last year. They were making GBS threads themselves this morning and wanted to speak with him right away. We told him this and his defense was "well I was just trying to check up on you guys, IT sends out phishing tests to employees all the time too!!"

tldr: A genius at work this morning decided to put a bunch of blank [filename].locky files on a network drive where all of our test data is stored as a "prank".

Robert Hanssen also claimed to be merely testing his employers' information security

maskenfreiheit
Dec 30, 2004

anthonypants posted:

it is my understanding that this is how cylance works

vim is a notorious hacking tool.

maskenfreiheit
Dec 30, 2004

Wrath of the Bitch King posted:

We enforce 45 days here. It sucks.

The FTC put out a great blog on this subject:
https://www.ftc.gov/news-events/blogs/techftc/2016/03/time-rethink-mandatory-password-changes

TL;DR: more frequent forced changes == frustrated users == weaker PWs

maskenfreiheit
Dec 30, 2004

Maybe they will ban McAfee? 🤔

maskenfreiheit
Dec 30, 2004
i like vim because i don't do a ton of coding and i'd rather know the features I use are on pretty much any system vs coming up with some elaborate emacs setup that i need to replicate on every machine i administer

maskenfreiheit
Dec 30, 2004
NSA AGENT: Well, you'd be working on the cutting edge. You'd be exposed to the kind of dank memes that you wouldn't see anywhere else - because we've classified them.

maskenfreiheit
Dec 30, 2004

this song really speaks to me

maskenfreiheit
Dec 30, 2004

spankmeister posted:

Hmm slight chance I might be going to def con after all

we should have a defcon goon meet

maskenfreiheit
Dec 30, 2004
"cyber" was an eyeroll term on k street long before donald trump came to dc

maskenfreiheit
Dec 30, 2004

ate all the Oreos posted:

i assume the only reason why anyone would buy a pastebin pro account is so they could write messages on it to prove they owned the bits coin?

it's so they can leak winrar keys

maskenfreiheit
Dec 30, 2004

cinci zoo sniper posted:

please use password manager from now on

and set up two factor on the accounts that support it

maskenfreiheit
Dec 30, 2004

cinci zoo sniper posted:

lastpass still not great at the specific part that makes it different from standalone cloud storage keepass, yes

I prefer to use KeePass.

There's a nice shiny OSX client - KeePassXC.

If you want your DB synced across devices you can get a Spideroak account.

maskenfreiheit
Dec 30, 2004

cinci zoo sniper posted:

i use keepass too, "official" windows client with key file in onedrive

you use a keyfile? don't you worry that if that's compromised?

US government wrote it's privacy laws in the goddamned 80s, so files older than something like 30 days don't even require a warrant for government to grab. (And that's if you're a US citizen)

Personally I use a passphrase I've memorized. It's kind of a pain to type but no one can steal it or compel it with a court order.

maskenfreiheit
Dec 30, 2004
Speaking of certificate errors:

maskenfreiheit
Dec 30, 2004

flakeloaf posted:

not that 2fa over sms isn't still poo poo but maybe the telco oughta be picking up on the fact that someone's tried to reset your password 219 times in the last hour and a half

physically going to the rogers store to unlock my phone is simple because the drat things are everywhere, i wonder if i can just have them forbid anything over the phone other than "i lost my phone cause i'm a moron, brick it pls"

you can set a verbal password on most carriers so that if someone were to be like "lol cancel my service" then "lol i'm op and now i use this other service send me lovely 2f texts", they'd have to give the verbal password or show an id at the carrier's store.

maskenfreiheit
Dec 30, 2004
why would you jump through hoops to set up nonshitty 2 factor on fb when u can just delete account

maskenfreiheit
Dec 30, 2004

Powaqoatse posted:

wish you would delete your SA account

maskenfreiheit
Dec 30, 2004
instead of facebook try face to face book

[dad laugh]

maskenfreiheit
Dec 30, 2004

ate all the Oreos posted:

serious question: is your threat model "someone could break into my house and steal a piece of paper and then use it to post terrible things to my facebook account"



i'm a privacy fundementalist, models want nothing to do with me

maskenfreiheit
Dec 30, 2004
you haven't lived until in house counsel, who is traveling to moscow, wants to know how to "compute securely" and finds vpns (click to run) too complex complains to your supervisor that you are VERY unhelpful

maskenfreiheit
Dec 30, 2004

Chris Knight posted:

lawyers suck

:yeah:

maskenfreiheit
Dec 30, 2004

mrmcd posted:

"I mean we clearly state at the bottom of the man page that calling do_thing() without first calling dont_shoot_own_dick() will result in the users dick getting shot off. We can't be expected to handhold every single user of our library." --a C programmer, probably.

read this in bunk's voice

maskenfreiheit
Dec 30, 2004

maskenfreiheit
Dec 30, 2004

LP0 ON FIRE posted:

never mind your magstrip credit cards, don'tt even bring your iphone to DEFCON

not only am i bringingmy phone to defcon im gonna shitpost in yospos from defcon :c00l:

maskenfreiheit
Dec 30, 2004

mrmcd posted:

Also once you issue a "smart contract" you can never patch it. Hope you coded everything perfectly the first time!



there's going to be an entire :airquote:smart:airquote: contract hacking talk at defcon that should be hilarious:

https://www.defcon.org/html/defcon-25/dc-25-speakers.html#Karagiannis

maskenfreiheit fucked around with this message at 03:07 on Jul 20, 2017

maskenfreiheit
Dec 30, 2004
all that password talk a few pages back reminded me that amex requires usernames to have numbers in them (because... entropy?)

maskenfreiheit
Dec 30, 2004

hobbesmaster posted:

well, no rng on this hardware, guess we'll just need to put a seed in eeprom

*seed is always 0000000000000000*

i read a story somewhere about a casino or bar or something w/ a keno machine that they kept turning off at night, every morning it would reset w/ same seed

(someone noticed)

maskenfreiheit
Dec 30, 2004

ate poo poo on live tv posted:

Aren't gambling machines with real money one of the least likely to be a sec gently caress up since the company that provides them, and not the casino, are responsible for the payouts?

apparently the manual said don't shut it off but they didn't read it

[shrugging intensifies]

maskenfreiheit
Dec 30, 2004

hobbesmaster posted:

a prng based on the clock isn't very good at all

at least use the LSBs from an adc to see a prng or something

maskenfreiheit
Dec 30, 2004

A Pinball Wizard posted:

obviously exploiting oversights in the code but the article keeps calling it cheating and I fail to see how it's cheating

using a device to aid you is cheating

card count using autism = 👍
card count using phone = 👮🏻

maskenfreiheit
Dec 30, 2004

jre posted:

The 88% is over all players not individual players, so it doesn't mean you'll lose 12%. You can easily lose 100% or gain 100%

When I worked as a bar man the regulars complained about one of the other staff playing the machine because he would be able to watch it all day, see them losing their money and then jump on and clean it out. It is possible to make bank if you are able to watch the machine for hours, learn the behaviour so that you know when it's going to pay out a jackpot.

i don't get this logic

isn't it pretty well established that random events are independent of each other?

so like, just because a roulette wheel has been black 50 times that doesn't mean the 51st is "due" to be red... in the long run (millions and millions of spins) this is just a blip

https://en.wikipedia.org/wiki/Gambler's_fallacy

maskenfreiheit
Dec 30, 2004

defcon party tricks dot txt

maskenfreiheit
Dec 30, 2004

My PIN is 4826 posted:

best part isn't even mentioned in this article - the STA database is public domain information, so it's passed around to advertisers as a service. however, this one time they all got an un-redacted database that included things like people in the witness protection programs.

the obvious solution would be to send out the redacted version and tell recipients to destroy the old one, but instead they sent out a list of who to remove from the first database :smithicide:

jesus

also, i'm kind of suprised something like a witness protection db isn't paper based

then again i'm here in the us where it would be paper based due to deep dysfunction of state and local government rather than a measured choice on the costs to productivity vs the benefits to security

maskenfreiheit
Dec 30, 2004
http://kstp.com/news/wisconsin-company-to-implant-microchips-in-employees-three-square-market/4549459/

quote:

A Wisconsin company is about to become the first in the U.S. to offer microchip implants to its employees.

Yes, you read that right. Microchip implants.
Advertisement

"It's the next thing that's inevitably going to happen, and we want to be a part of it," Three Square Market Chief Executive Officer Todd Westby said.

The company designs software for break room markets that are commonly found in office complexes.

Just as people are able to purchase items at the market using phones, Westby wants to do the sam thing using a microchip implanted inside a person's hand.

"We'll come up, scan the item," he explained, while showing how the process will work at an actual break room market kiosk. "We'll hit pay with a credit card, and it's asking to swipe my proximity payment now. I'll hold my hand up, just like my cell phone, and it'll pay for my product."

More than 50 Three Square Market employees are having the devices implanted starting next week. Each chip is about the size of a single grain of rice.

Along with purchasing market kiosk items, employees will be albe to use the chip to get into the front door and log onto their computers.

Each chip costs $300 and the company is picking up the tab. They're implanted between a person's thumb and forefinger. Westby added the data is both encrypted and secure.

"There's no GPS tracking at all," he said.

No one who works at Three Square Market is required to get the chip implant.


oh boy, encrypted AND secure? what could possibly go wrong!

maskenfreiheit
Dec 30, 2004

mrmcd posted:

Employee ID implant chips + a company so cheap you have to pay for your lovely coffee and potato chips at work = Charlie Booker sighs wistfully and shreds another Black Mirror script draft.

OTOH, this was arguably already done in Fifteen Million Merits.

I have a friend who's an employment loler lawyer I'll have to see if you can argue religious discrimination or something if they fire you for refusing

i suspect his response will be lol employment at will

Adbot
ADBOT LOVES YOU

maskenfreiheit
Dec 30, 2004

Cocoa Crispies posted:

magnets that apparently wear out in a matter of years lol

loving magnets how do they work

  • Locked thread