Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
spankmeister
Jun 15, 2008






New year, new thread

Adbot
ADBOT LOVES YOU

spankmeister
Jun 15, 2008






flakeloaf posted:

hi I'm calling from Microsoft there's a security virus problem on your thread and it's hacking your computer

Please do the needful

spankmeister
Jun 15, 2008






Raere posted:

why are computer model numbers so bad. like, what happened to gateway 2000 etc

It was bad

spankmeister
Jun 15, 2008






Or that it was being fishmeched again

spankmeister
Jun 15, 2008






cinci zoo sniper posted:

do you guys really have difficulties understanding intel and nvidia model numbers

The numbering systems change between generations so you can have a higher number with lower performance (say 2060RTX vs 1080Ti) or vice versa. Usually Nvidia stays within their 50 60 70 80 system but sometimes they change that too.

spankmeister
Jun 15, 2008






cinci zoo sniper posted:

well yeah that's a generation thing, 2080 Ti is more powerful than 1080 Ti. generation leaps on nvidia usually are 1 model relative shift, e.g. 2060 is equal to or better than 1070. still, both for nvidia and intel there seldom are reasons to buy previous generation consumer products

Now imagine you're a normal person.

spankmeister
Jun 15, 2008






Whiskyleaks is good

spankmeister
Jun 15, 2008






Krankenstyle posted:

its like how yall still used checks way past 2015 even.

i remember seeing a check being cashed at one of my first shifts at the grocery in 1995, and that one time was literally also the last time i saw a check used

holy lmao im almost 40 and i only learned about crossing checks from books. you all had to depend on that for decades

"had"

spankmeister
Jun 15, 2008






Let's not pick on the Americans and their archaic banking system again guys.

spankmeister
Jun 15, 2008






Nobody's checking the FAA's inbox at the moment anyway.

spankmeister
Jun 15, 2008






Happy new year yossec!

spankmeister
Jun 15, 2008






BangersInMyKnickers posted:

Did they actually sign their code because it would be pretty trivial to kill it if they did and if they didn't then you're going to have to click through a lot of warnings to get it to launch.

AV software on Mac is a blight on an otherwise reasonably secure platform and you should not install it.

e: lol of course they're leveraging lovely Java security for persistence

Mac users are conditioned to click to give root rights to everything anyway.

spankmeister
Jun 15, 2008






BangersInMyKnickers posted:

considering who it is, I wouldn't hold your breath

spankmeister
Jun 15, 2008






Wiggly Wayne DDS posted:

okay this is where you look past the tweet and at the paper and presentation not involving dragos

I'm sorry I usually only read dragos tweets if I want to laugh at a crazy person and then feel bad about myself for laughing at a person with obvious mental illness.

spankmeister
Jun 15, 2008






Wiggly Wayne DDS posted:

its probably because outside of his random bursts he's well versed and still a good source? there's a difference between other people's research he's highlighting and the times he's digging into something that isn't there

now anyone care about that 7 month old bug in a wifi chipset covering a ton of consumer appliances in the wild with no known public patch yet? the one with a private poc for an unauthed rce?

Yeah I'm sorry I should have looked at it more carefully. Like I said I saw it was dragos and my eyes glazed over and I didn't even see the source. My bad.

spankmeister
Jun 15, 2008






Pile Of Garbage posted:



Edit: good job dunking on me ozymandOS, fellow white noise poster charlatan.

BARONS LAST STAND

spankmeister
Jun 15, 2008






You forgot Diginotar Root CA X3

spankmeister
Jun 15, 2008






Kazinsal posted:

what the actual gently caress



Ah the Pine Gap CA

spankmeister
Jun 15, 2008






This might be a fun list to keep tabs on:

http://www.firemountain.net/mailman/listinfo/dumpsterfire

spankmeister
Jun 15, 2008






Lain Iwakura posted:

boy i could talk endlessly about rsa if i wasn't bound by ndas

bsafe infosec ghost

spankmeister
Jun 15, 2008






https://twitter.com/pwnheadcom/status/1084810903969824774?s=19

80% against people rankings, guess the internet isn't all bad.

spankmeister
Jun 15, 2008






Main Paineframe posted:

also, personal secfuck news: i got an email containing one of my passwords and a blackmail note saying that they hacked my webcam and my facebook, and that if I don't send them eight hundred bucks in bitcoin they'll send nudes of me to all my contacts

except I don't have a webcam and my facebook uses a different password. the password they had was an old one that I never use on anything remotely important. so they probably got their hands on passwords from some crappy old forum or something, then decided trying to scam password-reusers with fake blackmail threats was more time-efficient than trying to break into people's accounts directly

Recently this has been a common tactic. They use passwords from leaked dumps that are available all over the internet to make the threat look credibile. It's also a very clever threat because it works on people's shame and most aren't savvy enough to figure how the scam works.

spankmeister
Jun 15, 2008






fisting by many posted:

yeah apparently the mirai guy got rich operating a booter/extortion racket solely for minecraft servers (krebs did a huge exposé on it)

that's crazy

Yep. The biggest DDoS in history was done by Minecraft kids.

spankmeister
Jun 15, 2008






Unironically tho, it's gonna be fine.

spankmeister
Jun 15, 2008







Nuh uh! Sometimes I use Bing!

spankmeister
Jun 15, 2008






Schadenboner posted:

I didn’t understand any of the sponsor interview from the most recent Risky Business. And not for the usual reason (:australia:). Like it was all about math and modeling selectric typewriters in a can of La Croix in Second Life?

:psyduck:

Funny because the trail of bits guy CTF one was one of the very few sponsor interviews that I listened to and actively enjoyed. I usually skip them after a couple of minutes.

This one was absolutely great. It's because I like to play CTF's and it's cool to hear from someone who designs these absolutely insane challenges.

It's also nice that they used their sponsor spot to just tell a story about a cool CTF challenge, instead of actively trying to push some product.

spankmeister
Jun 15, 2008






cinci zoo sniper posted:

huh, our nation-wide bank 2fa app system has github https://github.com/SK-EID/smart-id-documentation

Estonia is pretty good at the cybers imo

spankmeister
Jun 15, 2008






Cocoa Crispies posted:

trail of bits is a contractor doing fairly intensive research; what they're pushing is that it's cool to let them reap the difference between the fruits of your labor and your paycheck

(by all reports they're a nice place to work)

Of course, it's pretty obvious that it's a recruiting bit but they do it in a very chill way.

spankmeister
Jun 15, 2008






Schadenboner posted:

Non-commutative arithmetics legit freak me the gently caress out.

quaternions are some crazy poo poo, let alone the higher dimension ones.

If they weren't so useful I would say they are an abomination.

spankmeister
Jun 15, 2008






ZeusCannon posted:

Im sure this is a dumb question and maybe not specific to this thread but i dont know where else to ask it. Does anyone have any resources/courses for reverse malware and digital forensics? Looking to brush up a bit

The SANS series of courses are pretty decent and sort of the industry standard.

spankmeister
Jun 15, 2008






ZeusCannon posted:

Yeah i was looking into those but unlikely to have the wherewithal to pay for something like that so figured id ask if there was anything else that would be suitable to give basics.

Oh I see. Well in that case you're probably better off with self-study, by buying a couple of books and starting to reverse-engineer malware samples.

Basically if you can't get an employer to pay for them, I wouldn't do it. They're not valuable enough to pay for them yourself imo.

Here are two good books about reverse engineering
https://nostarch.com/malware
https://nostarch.com/idapro2.htm

spankmeister
Jun 15, 2008






Cocoa Crispies posted:

how are you supposed to use the contact part of the smart card with that poo poo on it lol

You take it out.

spankmeister
Jun 15, 2008






salted hash browns posted:

Unpopular opinion: Apple giving away iCloud encryption keys in PRC is going to cause far more human harm than Facebook or Google will ever do.

I think this is especially egregious considering their attitude in the San Bernardino case. You can argue about whether or not they did the right thing there, but making a stand against US government agencies there, and then just handing over keys to the Chinese government without even blinking tells you all you need to know about Apple.

spankmeister
Jun 15, 2008






Methanar posted:

The San Bernardino thing was a PR stunt

Yes, exactly. Corporations only care about privacy as long as it affects their bottom line. In the western hemisphere you can differentiate your product by claiming to provide privacy for your users.

In China, caring about privacy means no sales at all, and with a rapidly growing middle class being able to afford iPhones, privacy becomes irrelevant.

spankmeister
Jun 15, 2008






Google was working on a Chinese version of their search engine (supporting all of the censorship requirements) until late last year when a bunch of engineers revolted and didn't want for work on it anymore.

None of these companies have any kind of morals or ethics.

spankmeister
Jun 15, 2008






LastInLine posted:

you say it as a joke but if facebook starting raising an army of the dead i feel like thered be some complaints about that too

Looking forward to zombie Stamos whiteknighting it

spankmeister
Jun 15, 2008






rjmccall posted:

ugh i seriously don’t get our resistance to run a bounty program across the product line

It takes a LOT of effort to run a good bounty program, and running a lovely one is a lot worse than not running one at all.

I'm sure that's not the reason though :v:

spankmeister
Jun 15, 2008






Suuuure.

spankmeister
Jun 15, 2008






Maybe they hired some ex-TAO peeps to karma his phone. :v:

Adbot
ADBOT LOVES YOU

spankmeister
Jun 15, 2008






Jeff got horny on main

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply