Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender


code:
PATCH NOTES FOR 16.0
* Tavis is taking a vacation so we're making a new thread
* This thread is not a place for discussing rape apology, mens rights activism, how much you want to talk about MRAs, Wikileaks, how Wikileaks is not a wiki, and Julian Assange

PATCH NOTES FOR 15.0
* Thread now has a 30% slowdown

PATCH NOTES FOR 14.0
* New thread because I was tired of seeing my old forums name in the bookmarks
* True origins of DEFCON have been made clear

PATCH NOTES FOR 13.0
* Avoids slamming car doors into genitals
* Removed conversation that belongs in D&D

PATCH NOTES FOR 12.0
* A whole new version to reflect the ever-changing threat landscape
* Official HTTPS support--it only took Lowtax like a decade to get it to work properly

PATCH NOTES FOR 11.4
* Added details at end of OP for why the thread is called "You're busted, dude"

PATCH NOTES FOR 11.3
* POP POP of unsigned ints

PATCH NOTES FOR 11.0
* new version with less bloat
* all anime removed and hopefully forever

PATCH NOTES FOR v10.1
* no patch notes required

PATCH NOTES FOR v10.0

* decided that 8 and 9 were bad numbers and skipping to '10' would make us look cooler.
* js crypto added in for the sake of an internet argument

PATCH NOTES FOR v7.69

* Added 1.2 billion passwords from Russian hacker forums

PATCH NOTES FOR v7.2 "BoringSFM"

* The name is aspirational and not yet a promise

PATCH NOTES FOR V1.0.1g

* changed version number

PATCH NOTES FOR V0.9.8

* once again removed LF and Fishmech corruption from the last thread
* added a new feature that enables the mods/admins to go ahead and probate/ban as necessary if LF'n poo poo happens
* added heartbeat feature to non-existent SSL layer on the forums

PATCH NOTES FOR V69

* removed LF and Fishmech corruption from last thread
* new "hello" service for conference attendees
* blocking of js crypto through message relay services like twitter

PATCH NOTES FOR V1.2

* made more efficient for version 1.2 after having removed fishmeching and talk about credit card contracts

PATCH NOTES FOR V1.1

* don't loving use any of these goddamn exploits you dumbshits


join us on irc: irc.synirc.net #yossec

useful news resource for information security professionals: http://reddit.com/r/netsec/

risky business podcast is worth listening to and yospos has been mentioned in it before

here are some old threads that haven't been archived:

Security Fuckup Megathread - v15.1 - Stop!!! I Kill You Researcher (jan-apr 2018)
Security Fuckup Megathread - v14.1 - Hello, is this a delivery order? (jun 2017-jan 2018)
Security Fuckup Megathread - v13.69 - plugins may violate privacy (jan-jun 2017)
Security Fuckup Megathread - v12.2 - you have slammed your dick in the car door (apr 2016-jan 2017)
Security Fuckup Megathread - v11.4 - who u gonna snitch to pussy bitch gently caress u (apr 2015-apr 2016)
Security Fuckup Megathread - v10.1 (Hackers can turn your gas station into a bomb) (nov 2014-apr 2015)
Security Fuckup Megathread - v7.69 (stay safe security ghost) (aug-nov 2014)
Security Fuckup Megathread - v7.2 "BoringSFM" (jun-aug 2014)

Alereon posted:

seriously though people dont post anything that would allow a lurker from gbs to gently caress with anything


just a reminder: this is for sec gently caress ups. if you want to talk about telecoms or politics (including wikileaks), make a new thread

Adbot
ADBOT LOVES YOU

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Lain has spoken.

edit for content: I don't get the Tavis shower joke :(

Proteus Jones
Feb 28, 2013



ChubbyThePhat posted:

Lain has spoken.

edit for content: I don't get the Tavis shower joke :(

I think it re: LastPass. He had a flash of inspiration while taking a shower and discovered a major exploit.

EDIT:

YEP

https://twitter.com/taviso/status/845717082717114368?s=20

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


glad i finally got around to switching to 1password :v:

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
in the interest of disclosure, i should point out that i didn't remember the exact context of it either and so now i have "tavis ormandy shower" in my google search history

flakeloaf
Feb 26, 2003

Still better than android clock

ground floor, ecuador

i like the advisories we get that start with four pages of fluff before vaguely alluding to some threat i read about on twitter two days ago

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
github was apparently doing plaintext logging of some passwords https://twitter.com/SwitHak/status/991416974252167169

Illusive Fuck Man
Jul 5, 2004
RIP John McCain feel better xoxo 💋 🙏
Taco Defender
Someone in the previous thread asked if you can use dns challenges with let's encrypt. The answer is yes. I've done it a bunch of times and it works great.

I think the original question was something about getting certs for a not-internet-exposed host. Let's encrypt with dns challenges should work fine.

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp
security is hilarious

i am here for this

thank god i have no actual duties or accountability in my job, all i gotta do is point + laugh

EssOEss
Oct 23, 2006
128-bit approved
How do you automate LE with DNS challenges, though? What sets the DNS record in response to the challenge?

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
Ground floor postin'

cinci zoo sniper
Mar 15, 2013




oh-floor posting

Phone
Jul 30, 2005

親子丼をほしい。
we did it, we solved security

Illusive Fuck Man
Jul 5, 2004
RIP John McCain feel better xoxo 💋 🙏
Taco Defender

EssOEss posted:

How do you automate LE with DNS challenges, though? What sets the DNS record in response to the challenge?

Yeah you'll have to write the automation yourself. I'm only dealing with one domain so I just do it manually every few months.

OldAlias
Nov 2, 2013

ground

Schadenboner
Aug 15, 2011

by Shine
:sherman:

Bulgogi Hoagie
Jun 1, 2012

We

Ciaphas posted:

glad i finally got around to switching to 1password :v:

keychain is the only good password manager because it signals to the world you dont have to touch the bad operating systems in any capacity

Bulgogi Hoagie
Jun 1, 2012

We
speaking of signals, I dont recall this being posted - amazon and google are both dictator lovers and threatened to drop signal unless they stop censorship circumvention

https://twitter.com/josephmenn/status/991408871955513344?s=21

necrotic
Aug 2, 2005
I owe my brother big time for this!
AWS told them to stop domain fronting using domains they don't own through cloudfront. not really a surprise if its adding risk to other AWS customers.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Bulgogi Hoagie posted:

keychain is the only good password manager because it signals to the world you dont have to touch the bad operating systems in any capacity

No, they still make me poop-touch through parallels

necrotic
Aug 2, 2005
I owe my brother big time for this!

EssOEss posted:

How do you automate LE with DNS challenges, though? What sets the DNS record in response to the challenge?

you need an internet connection to request a cert from LE so presumably from that same host?

Wiggly Wayne DDS
Sep 11, 2010



necrotic posted:

AWS told them to stop domain fronting using domains they don't own through cloudfront. not really a surprise if its adding risk to other AWS customers.
yeah the current thought going around is getting a bunch of customers to approve signal using their domains since it'd abide by amazon's guidelines

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp

Bulgogi Hoagie posted:

speaking of signals, I dont recall this being posted - amazon and google are both dictator lovers and threatened to drop signal unless they stop censorship circumvention

https://twitter.com/josephmenn/status/991408871955513344?s=21

amazon and google are in the right here, despite this being useful and convenient for signal

Bulgogi Hoagie
Jun 1, 2012

We

necrotic posted:

AWS told them to stop domain fronting using domains they don't own through cloudfront. not really a surprise if its adding risk to other AWS customers.

I wonder if there are any discussions going on about evolving the TLS/SNI standard to be censor proof

Zamujasa
Oct 27, 2010



Bread Liar
obligatory "0 day, 1 floor, 2 towers" comment


also keep rear end suits my password management needs

AggressivelyStupid
Jan 9, 2012

i hope vacation tavis means more good tweets from him

Midjack
Dec 24, 2007



AggressivelyStupid posted:

i hope vacation tavis means more good tweets from him

i hope it means nothing for a month and then some bomb rear end tweets shortly afterwards

wolrah
May 8, 2006
what?

EssOEss posted:

How do you automate LE with DNS challenges, though? What sets the DNS record in response to the challenge?
A popular solution is this: https://github.com/Neilpang/acme.sh

Supports the APIs of many popular DNS providers as well as screen scraping solutions for others, and can automatically install certs in to many popular servers. Also sets up a cron job to automate renewals.

Bulgogi Hoagie
Jun 1, 2012

We

Jonny 290 posted:

amazon and google are in the right here, despite this being useful and convenient for signal

thats the essence of whats wrong with modern tech corps tho

https://twitter.com/filosottile/status/991775401340035072?s=21

https://twitter.com/filosottile/status/991776382719025153?s=21

Schadenboner
Aug 15, 2011

by Shine

I mean: yes. But on the other hand, if your security model requires that your :butt: providers don't enforce RFCs then that's probably not a great long-run strategy?

E: Obviously, gently caress AWS and GCloud for :a2m:ing for goddamn Russia ("Upper Volta Italy with rockets") though.

Schadenboner fucked around with this message at 21:38 on May 2, 2018

Shaggar
Apr 26, 2006

lmao @ its gonna get people killed. amazon is correct and signal should never have relied on a hack to make their system work.

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp
you do not gently caress with the rozkomador

Midjack
Dec 24, 2007



Jonny 290 posted:

you do not gently caress with the rozkomador
you must obey the rozkomador

giving out the orders for fun

spankmeister
Jun 15, 2008






Don't be frontin

CrazyLittle
Sep 11, 2001





Clapping Larry

Jonny 290 posted:

you do not gently caress with the rozkomador

rozkomador me amadaeus

Tiny Bug Child
Sep 11, 2004

Avoid Symmetry, Allow Complexity, Introduce Terror
picking up a thing from the closed thread

ErIog posted:

I got passed some code for security audit, and now the dev is arguing he doesn't need to validate this user input at all (for what should be an all-caps alphanumeric string) because the framework is making sure it's safe. It doesn't matter that this is being passed to things outside the dependency which don't check input at all. I should just sign off on it because, you see, this web framework said it was good input and that means you can drop it to the shell or just put it in a SQL query or do whatever with it.

I just want him to write like 10 lines of code to protect poo poo, but I guess that makes me an insane person.

that's 9 more lines than you should need but this dude is still completely in the right. you do not need to re-validate things the framework has validated for you. this is half the value of a web framework. if you insist on doing things that the framework has already done for you, why even bother using it

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp
https://landave.io/2018/05/7-zip-from-uninitialized-memory-to-remote-code-execution/

cool

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

necrotic posted:

AWS told them to stop domain fronting using domains they don't own through cloudfront. not really a surprise if its adding risk to other AWS customers.

what risk is it adding to other aws customers exactly

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp

Rufus Ping posted:

what risk is it adding to other aws customers exactly

losing 150 million potential browsers and their accompanying revenue?

Adbot
ADBOT LOVES YOU

Tiny Bug Child
Sep 11, 2004

Avoid Symmetry, Allow Complexity, Introduce Terror

Rufus Ping posted:

what risk is it adding to other aws customers exactly

i assume it's that the agencies in question are perfectly willing to block all of aws or google or whoever if they don't comply, and their other customers who don't give a poo poo about signal don't want to get blocked

  • Locked thread