Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Raere
Dec 13, 2007

why are computer model numbers so bad. like, what happened to gateway 2000 etc

Adbot
ADBOT LOVES YOU

Raere
Dec 13, 2007

Sorry I mentioned computer model numbers.
Hey, how about them viruses?

Raere
Dec 13, 2007

Shame Boy posted:

lmao what is this bullshit fedex:



WARNING: YOU HAVE ENTERED A STRONG PASSWORD!!!!

taking their cue from the error sounds POS terminals make when it’s ok to remove your card

Raere
Dec 13, 2007

You can't forget or lose your creds if you hardcode them :smugdog:

Raere
Dec 13, 2007

The least surprising part of the bitcoin hardware wallet talk was that it has a hardcoded value of F00DBABE in the code. A bitcoiner's dream girl

Raere
Dec 13, 2007

Lot of good talks this year! Gonna take me a long time to watch them all.

Raere
Dec 13, 2007

What's the consensus on running AV on Macs (for myself)? Do they just increase the attack surface like they tend to do on PCs, or is it actually a useful extra layer of defense?

Raere
Dec 13, 2007

This isn’t the cyberpunk cool billboard future I was promised in Blade Runner

Raere
Dec 13, 2007

Say you're designing an authentication backend (I'm not) and are storing passwords as salted hashes. Where do you store the salts, if properly designed?

Raere
Dec 13, 2007

security through obscenity

Raere
Dec 13, 2007

Sometimes I'm glad the networks I manage aren't connected to the internet

Raere
Dec 13, 2007

osint is being intellegent about operating systems

Raere
Dec 13, 2007

in soviet russia file uploads to you

Raere
Dec 13, 2007

BangersInMyKnickers posted:

It's a plenty good idea and why I'm trying to enable it, I'm just worried that it will poo poo itself when I have 20k clients all jabbering it at once. If they were less-poo poo this would have a secure out of box config with some kinda of cert validation of the server instead of blind-tls and some kind of rpc endpoint mapper to handle the socket limits that are loving obvious for any large-scale deployment. I have to assume that most products have something similar for optimization, though probably doing some kind of cloud lookup to the vendors servers by deferring the actual scan of the file until it get can a verdict back on the file from the cloud or it times out and fails back to a local scan.

wouldnt randomizing scan times alleviate this problem? is that even possible in SEP?

Raere
Dec 13, 2007

looks like everything's going pear shaped

Raere
Dec 13, 2007

oiler or yewler?

Raere
Dec 13, 2007

BangersInMyKnickers posted:

ISC2 is jacking their annual dues from $85 to $125 so that’s cool

If your work doesn't pay your maintenance fees for CISSP find a job that will

Raere
Dec 13, 2007

cut the app into pieces, this is my last resort

Raere
Dec 13, 2007

Facebook more like Farcebook

Raere
Dec 13, 2007

admin@kremlin.ru is a little bit on the nose

Raere
Dec 13, 2007

no, logs

Raere
Dec 13, 2007



Ok cool an extra 8 bits

Raere
Dec 13, 2007

ThePeavstenator posted:

Today I found two stored procedures called "encrypt" and "decrypt" in an old applications database. Turns out the "encryption" algorithm for passwords was ROT128 (ASCII is the alphabet) and then reversing the string.


Yes this application was 99% stored procs why do you ask

Not as secure as ROT26

Raere
Dec 13, 2007

Proteus Jones posted:

Yeah, that was some really suspicious timing.

what did lowtax call him out about?

Raere
Dec 13, 2007

I love lowtax but in the 2 decades it's been around has he ever hired a single person for the site that hasn't stabbed him in the back?

Raere
Dec 13, 2007

this thread itself is one of my favorites. it was even cited on risky business podcast

Raere
Dec 13, 2007

Park benches are a vital part of security because they encourage people to sit and be snitches if they see crime going on

Raere
Dec 13, 2007

Shifty Pony posted:

three small square stickers on the pavement were all it took to make autopilot recognize a "lane" and send the car in the wrong direction. lol you could kill dozens with one roll of white duck tape.

otoh I was fairly impressed that remote control is relatively difficult. The exploit chain is rather long and it looks like they have reasonable mitigations in there. As long as they keep up with patching flaws it won't be too bad. I was expecting Linux kernel 2.4 with 10 year old unpatched vulns

Raere
Dec 13, 2007

The Scientist posted:

I found a huge repo of old Blackhat zines, phreaking box schematics and leaked security documents.

morehouse.org

All the Cult of the Dead Cow and Phrack articles, some very cool stuff.

beto going above and beyond just releasing his tax returns

Adbot
ADBOT LOVES YOU

Raere
Dec 13, 2007

is anyone turning away from cisco given their nonstop pants on head stupid vulns or are they still worth it?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply