Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Pile Of Garbage
May 28, 2007



Wiggly Wayne DDS posted:

[pre-watch disclaimer]
before i begin going from the schedule i don't expect lots of outstanding talks, or any really bad ones, so don't expect any major criticism. these are my opinions, so make your own assessments and say when a talk's poo poo that i think is good and vice versa
[/pre-watch disclaimer]

35c3 day 1 talks:

good stuff! thanks as always

Adbot
ADBOT LOVES YOU

Pile Of Garbage
May 28, 2007



LMFAOOOO good poo poo adlords

Pile Of Garbage
May 28, 2007



EssOEss posted:

Turns out that no, Chromecast is fine and this is just lovely routers being lovely: https://twitter.com/SwiftOnSecurity/status/1081000904688656386

fyi swift is just an unaccomplished CJ who obsessively tweets about infosec and because of their gimmick they got popular so now they punch above their weight as some kind of authority.

consumer routers having UPnP enabled on the WAN interface (or at all) by default: secfuck
chomecast having UPnP enabled by default: secfuck

hurr:

https://twitter.com/SwiftOnSecurity/status/1081003077912719362

Pile Of Garbage
May 28, 2007



EssOEss posted:

No, not necessarily. What you say about Switft is true but he does address this - UPnP is a wide-ranging suite of standards and he says Chromecast does not use the "open a port" variant that the lay audience might normally associate with UPnP. Unless he is flat out wrong in his facts, Chromecast is in the clear here.

Other uses of UPnP are "media player" features. The Windows "Play To Device" function is UPnP, for example. I bet Chromecast does something in that style (Swift mentions SSDP, which is for finding devices).

UPnP is straight garbage and i thought i was already dead in tyool 2019. i don't care how chomecast uses UPnP, the fact that it uses it at all is a huge loving red flag, even if it apparently "doesn't use it in a bad way."

Shame Boy posted:

"adobe flash player for windows server" is the best worst thing I've heard of all week

it's for RDS sessions, not unusual at all.

Pile Of Garbage
May 28, 2007



BangersInMyKnickers posted:

its a large protocol suite designed to do broadcast discovery and happens to have some ability to request port forwards from a upstream NAT. some kind of discovery protocol is a requirement for any kind of soho environment without proper DNS infrastructure. you're tilting at windmills and being an idiot. the problem are the routers enabling the port forward functionality by default, implementing in a shoddy manner, and not updating/supporting their poo poo in the field.

i don't see how i'm an idiot for calling poo poo what it is: poo poo. upnp is straight garbage, i accept that it has been adopted and exists and that the majority of problems are due to lovely implementation but that aside it's dumb trash!

Pile Of Garbage
May 28, 2007



BangersInMyKnickers posted:

christ you are stupid

fine gently caress you then cheers

Pile Of Garbage
May 28, 2007





Edit: good job dunking on me ozymandOS, fellow white noise poster charlatan.

Pile Of Garbage fucked around with this message at 18:25 on Jan 4, 2019

Pile Of Garbage
May 28, 2007



yah this will end well and not be a thing that no one uses: https://github.com/SwiftOnSecurity/OrgKit

Pile Of Garbage
May 28, 2007



Shame Boy posted:

i noticed on google maps that there's a (branch?) office of GENERAL DYNAMICS INFORMATION TECHNOLOGY near where I work, so i poked around their website and found some fun stuff

https://gdit.com/what-we-do/cyber



i love cyber :allears:



i want to get a job in "cyber engineering" or work at the "cyber range"

MIC "cyber" programs/initiatives are part hand-waving bs and part cringe inducing marketing wank. all the major corps have them however lockheed and boeing seem to give them far less prominence than others. comparatively thales and raytheon can't go a day without talking about the size of their cyber wangs.

these corporations are also really keen about inserting themselves into higher education and sometimes even K-12 to teach "cyber" which i find quite disconcerting:

https://www.youtube.com/watch?v=FS3vp3WxTCw

Pile Of Garbage
May 28, 2007



i'm the one dingus still using password safe how does it rate?

Pile Of Garbage
May 28, 2007



ZeusCannon posted:

We legit dont have calc anymore on our end points and im pretty sure its because someone was like they cant confirm calc.exe if they dont have it :pseudo:

i cannot believe this but i know it to be true

Pile Of Garbage
May 28, 2007



not sure how much of a secfuck this is but it seems kinda dumb: earlier this month the notepad++ dev posted about how he had tried to get a new code signing cert but in the end he gave up because apparently it was too hard and code signing is just an "overpriced masturbating toy" and everything has been fine for years so why even? https://notepad-plus-plus.org/news/notepad-7.6.4-released.html

quote:

When you install Notepad++ version 7.6.4, You might notice there's no more blue-trusted UAC popup. Here's the explanation for the reason that we remove code signing from Notepad++ :

3 years ago DigiCert donated a 3 years code signing certificate to the project, and every good thing has its end, the certificate has been expired since the beginning of this year.

I was trying to purchase another certificate with reasonable price. However I cannot use "Notepad++" as CN to sign because Notepad++ doesn’t exist as company or organization. I wasted hours and hours for getting one suitable certificate instead of working on essential thing - Notepad++ project. I realize that code signing certificate is just an overpriced masturbating toy for FOSS authors - Notepad++ has done without certificate for more than 10 years, I don’t see why I should add the dependency now (and be an accomplice of this overpricing industry). I decide to do without it.

It doesn’t mean there’s no more security in Notepad++, but it will be less flexible for sure:
  • SHA256 hash of Installer and other packages will be provided for every release as usual. Too bad for ugly yellow-orange UAC popup while installation.
  • Notepad++ will check the SHA256 of all the components (SciLexer.dll, GUP.exe and nppPluginList.dll) used by the program.

i mean sure certificate pricing is a fuckin rort but it kinda sounds like he hosed up trying to get one issued so just gave up and is making excuses

Pile Of Garbage
May 28, 2007



i didn't know it was closed-source. loving lol

Pile Of Garbage
May 28, 2007



Boiled Water posted:

i mean its nice until you find out about our lord and savior: vscode

yeah i've been using vs code since i started doing dev full-time. that said one of our senior devs was using np++ exclusively up until at least at least 4 months ago lol

Pile Of Garbage
May 28, 2007



Midjack posted:

motherfuckers act like they forgot about jre

Pile Of Garbage
May 28, 2007



Chris Knight posted:

no token ring

it's right there on the left (c/o Soricidus)

Pile Of Garbage
May 28, 2007



:lol:

Pile Of Garbage
May 28, 2007



CommieGIR posted:

You'll get a VDI and you'll like it.

lol that reminds me of the last gig I was at. the customer decided to outsource a bunch of BPO stuff to Accenture (massive bastards btw, look em up re Philippines) in order to automate and streamline processes. Accenture decided to implement this with Automation Anywhere, a software package that just records and plays-back mouse+keyboard inputs, but enterprisey (why spend time and money understanding APIs and building scripted orchestration poo poo for whatever product your dealing with when you can just simulate the user interaction).

despite the automation poo poo Accenture were putting in they were still employing a team of poor Filipinos working remotely to operate Automation Anywhere for some reason, probably mad profit min-maxing or some poo poo. anyway to use the AA software front-end it has to run as administrator in the context of the user executing it. at first they wanted to just put it on the Citrix environment to which we said "lol gently caress know"

after weeks of back and forth with us saying "this poo poo is hosed, get it outta here" and the customer saying "yeah but we need it kay" we ended up designing and deploying an entire VDI solution solely for the Accenture drones to run AA from remotely.

basically gently caress BPOs

Pile Of Garbage
May 28, 2007



Accenture has +469k employees, they've min-maxed the fuckin numbers on the automation game and know exactly how much they need to do and how to make a profit. poo poo is hosed...

Adbot
ADBOT LOVES YOU

Pile Of Garbage
May 28, 2007




this is particularly funny because last year i helped transition one of our now former customers to their new provider, namely wipro. their poo poo is wildin i tell you whut

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply