Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Pile Of Garbage
May 28, 2007



Lain Iwakura posted:

https://twitter.com/KateLibc/status/958478170604290048

"Performing Your Own Dentistry -- Challenges, Unknowns, and What is Overlooked in Security Log Collection"

that is all i'll say on the talk for now

noice. also sorry for making GBS threads up the last thread

Adbot
ADBOT LOVES YOU

Pile Of Garbage
May 28, 2007



Doccykins posted:

Whilst the forums were down Matt Hancock, the guy responsible for the Department of Digital, Culture, Media and Sport in the UK released his own social media platform called 'Matt Hancock MP' It is, of course, full of privacy issues


https://twitter.com/MattHancock/status/958988393748357121

https://twitter.com/PrivacyMatters/status/959016936494522369

lol so that app download landing page has this as allow in robots.txt:

https://matt-hancock.disciplemedia.com/user/sign_in

fuckin why?

Pile Of Garbage
May 28, 2007



geonetix posted:

is anyone going to RSA2018 or is it worth going at all?

only if you can mass-goatse the con

Pile Of Garbage
May 28, 2007



ahaha holy poo poo. surely that violates the apple store tos or something?

Pile Of Garbage
May 28, 2007



just checked and yeah that's deffo what google does. the images are cached and then loaded via something like https://mail.google.com/mail/u/0/?u...38b17&zw&atsh=1

edit: that link is from one of my e-mails but it disnae matter as they require auth

Pile Of Garbage
May 28, 2007



from what i observed google only fetches when you open the message. there's zero reason for them to retrieve and cache images upon message receipt because i'm pretty sure the gmail app doesn't download messages by default so why bother when the user may immediately archive/delete the message?

Pile Of Garbage
May 28, 2007



secfuck: i joined a union recently and upon receiving my membership details i found i was unable to login to their website. reset password wasn't working so i e-mailed my rep who changed my password to "<SURNAME>.123!" and e-mailed it to me in the clear. then when i logged in it did not force me to change it. a shameful display

Pile Of Garbage
May 28, 2007



Wiggly Wayne DDS posted:

see if you can organise the userbase into convincing them to fix this

yeah that's a good idea, thanks. i already replied to my rep advising how their current poo poo is garbage but if they don't improve things i'll start reaching out to membership.

CHANGE FROM WITHIN, MOTHERFUCKERSSSSS

Pile Of Garbage
May 28, 2007



infernal machines posted:

as someone who provides services to a couple of union locals, let me assure you, unless you stop them from doing so the average member will make their password <surname><membership number>

lol great, the two things readily available on your membership card

Pile Of Garbage
May 28, 2007



p sure that dingus is a troll or a legit shill

Pile Of Garbage
May 28, 2007



what the gently caress is "Brave" in the context of that greydingus?

Pile Of Garbage
May 28, 2007



work secfuck: just discovered that some idiot hell fucker has configured ACEs at the root of the AD domain which allows auth users (aka almost everyone) to write properties on all computer objects and join computers to the domain :downsgun:

Pile Of Garbage
May 28, 2007



CareyB posted:

That was my suspicion. It would be good to know if the enterprise version is in fact as vulnerable as the free version. We've got 1password on our shortlist too however it looks to be a fair bit more work to maintain our end which is where lastpass seems to have it beat, but obviously day to day productivity isn't the only factor here....

i'd bet dollars to donuts that the free and enterprise versions of lastpass share the same codebase and have the same vulnerabilities. of course that's besides the point because the primary problem is the organisation behind the software. as others have already mentioned they have an abysmal track record when it comes to security and have not really shown any improvements. basically they cannot be trusted to handle things properly.

Pile Of Garbage
May 28, 2007



Soricidus posted:

“shut up haters I loving wrote the wiki on the thermal properties of wax” - icarus

Pile Of Garbage
May 28, 2007



just gonna put my garbage tweet(s) here. tl;dr my bank is garbage

https://twitter.com/GarbageDotNet/status/971327709170167808

Pile Of Garbage
May 28, 2007



Lysidas posted:

i give it a 50 50 chance they "fix" it by also opting out of the ssl labs scan

actually my bad i should have linked further down the thread. they're embedding JS from a third-party ad server on the fuckin internet banking login page lol

https://twitter.com/GarbageDotNet/status/971330728645443584

Pile Of Garbage
May 28, 2007



put on your 3d glasses now

Pile Of Garbage
May 28, 2007



the fact that they do it on every page including ones where you enter or view sensitive info is pretty fuckin greasy

Pile Of Garbage
May 28, 2007



spankmeister posted:

Insufficient Bank Security

Pile Of Garbage
May 28, 2007



i pay nothing to use my bank and pretty much always have (only fee i've ever had to pay was the FID tax that was a couple of cents a year but they got rid of the FID tax aeons ago). sure i've only got a single savings account but it suites my needs and i get a chip+pin mastercard debitcard that has that NFC stuff in it and ive never encountered any fees p much ever.

Pile Of Garbage
May 28, 2007



sadus posted:

anyone ever mess with disabling specific TLS Extensions in SChannel like Session Ticket, is that even a thing (I'm guessing not)? Yay auditors thinking it would be a great use of time nickpick Microsoft's TLS implementation beyond just locking down specific ciphers and protocols.

pretty sure we have one resident schannel pro, i shamefully cannot remember but they posted nice cipher suite lists plus recommended ECC curve combos, was very handy

Pile Of Garbage
May 28, 2007




ty bangers and sorry for forgetting you!!!

infernal machines posted:

holy loving poo poo!


..people actually use samba as an AD DC?

no (well maybe but how?) but samba operates it's own LDAP server to interface with an AD DC and this is where the issue occurs (correct me if i'm wrong).

from what i understand the issue is that in AD "change password" and "reset password" privileges are secured differently for obvious reasons however the samba LDAP server conflates the two and fucks up the extended right security checks.

Pile Of Garbage
May 28, 2007



i'd never trust anything other than a windows server DC to provide domain services, simply because everything else out there seems to fail in spectacular ways at things which are very simple. for example, the AD schema clearly outlines object and attribute associations as well as the typing of the values for attributes. attributes which accept integers are either typed as "Integer" (int32) or "LongInteger" (int64). CA (the company) provides an entire suite of software which integrates with AD as an IAM solution. however in their infinite wisdom they've ignored the schema and just decided on arbitrary types for attribute values. this really fucks poo poo up when you want to say set an exchange recipient type value which is an int64 but the CA garbage only accepts int32 for some idiotic reason.

Pile Of Garbage
May 28, 2007



yeah if your linux doesn't do SSSD then whatever samba can do would be an acceptable fall back seeing as NIS is deprecated

Pile Of Garbage
May 28, 2007



infernal machines posted:

yes, AD sync to azure cloud actually works pretty well

can confirm, AADC sync is smooth as gently caress. however if you want to enable password change in the cloud with federation then you'll need to pay for an AAD P1 subscription, that's how they get you (probably, idk just buy ECS which is Enterprise E3 plus EMS E3 for gently caress all)

Pile Of Garbage
May 28, 2007



Shaggar posted:

yeah its such bullshit that password change and security auditing is in P1 and not included in E1 or E3

i like how they put the really useful security features in E5. our sec ops lead is always asking "hey can we use this?" and my answer is usually "no we're not licensed for it lollll"

NEED MORE MILK posted:

isnt their a free azure tier?

"azure" and "azure AD" are two different beasts. afaik there's no AAD P1 or EMS E3 trial.

Pile Of Garbage
May 28, 2007



yep that will work fine.

Pile Of Garbage
May 28, 2007



Shaggar posted:

it really feels like extortion when they hide basic security stuff behind a higher plan level. I'm implementing some of it myself (poorly) cause I refuse to pay the absurd price to get a P1 for everyone.

it's funny our customer recently outsourced SOC (Security Operations Centre) to a BPO (lol yeah i know) and the first complaint i got from them was that the on-prem SIEM appliance wasn't getting logs from O365. the dudes at the BPO just assumed we were using the actual "SIEM integration" feature with Cloud App Security but yeah i had to tell them "lol nope, we're not licensed for that and are just smashing APIs for logs".

kind of a critique on how garbage BPOs are but also how microsoft try to make you pay for stuff. if you google "office 365 siem integration" the first results are for the E5 feature so the whole thing's a rort.

Pile Of Garbage
May 28, 2007



the new Graph API looks p sw8, been meaning to find time to gently caress with that for a while now. apparently that's where microsoft are going to push all o365+services and seccom reporting to. also looks like a faster method of querying some of the more expensive exchange cmdlets (Get-MailboxStatistics, Get-MailboxFolderStatistics, etc.)

sorry im making GBS threads up the sec gently caress thread with msft stuff i'll stop now


:getout:

Pile Of Garbage
May 28, 2007



break a leg!!!

Pile Of Garbage
May 28, 2007



nvm

Pile Of Garbage
May 28, 2007



yeah logs are still available via syslog from azure, just the auth is a bit more involved.

Pile Of Garbage
May 28, 2007



wd cari for surviving the talk, excellently presented imo.

Pile Of Garbage
May 28, 2007



that's a good fishmech, two pages late and no one cares

Pile Of Garbage
May 28, 2007



no i actually like a lot of fIshmech's posts, like in the transport thread. that post i had to quote because it was so bad

Pile Of Garbage
May 28, 2007



NEED MORE MILK posted:

im a big fan of how ntfs and windows can have file paths of like 2.5 trillion characters but explorer is still limited to 255

not to over use this but :getout:

Pile Of Garbage
May 28, 2007



dumb nerds are just using words they saw in video games and lazy portmanteaus

Pile Of Garbage
May 28, 2007



the MO of anyone allowed to post content to a sharepoint site really. also uploading images that don't have a 1:1 aspect ratio and then get squished all up and poo poo/

Pile Of Garbage
May 28, 2007



BangersInMyKnickers posted:

DH implementations aren't looking so hot these days so I'd probably drop them entirely for ECDH, there are very few clients that support DH that don't also support ECDH and if its legacy RSA is still an ok fallback. We'll see what's going on with curve availability, hopefully MS starts adding some additional modern curves instead of just x25519

i disabled DH on several of our servers because as i understand you can't change DH params with schannel so disabling DH is the only way to mitigate that DH vulnerability whose name escapes me.

Adbot
ADBOT LOVES YOU

Pile Of Garbage
May 28, 2007



ate all the Oreos posted:

as far as i know:

- keepass is One Of The Good Ones, though it's a bit clunky and you have to janitor your own files
- 1password is also One Of The Good Ones, has an actual design team so is nice to use but costs money
- Lastpass is a garbage fire
- Windows / OSX built in trust stores are Fine if you're into that sort of thing
- Everything else is worse than lastpass

did I get that right?

what about password safe? it doesn't get mentioned much because honestly it has little in the way of features compared to keepass but i use it because i'm a simpleton and apparently it's not terrible?

  • Locked thread