Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Shame Boy
Mar 2, 2010

fins posted:

Nobody touched the epoop?

i assume the only reason there's a new thread is that lain came up with a thread title she liked and wanted it right now

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

lmao what is this bullshit fedex:



WARNING: YOU HAVE ENTERED A STRONG PASSWORD!!!!

Shame Boy
Mar 2, 2010

oh my god the fedex signup process keeps getting better



of course i want to take a fun exam about me :allears:



what great questions! anyway time to submit and see how I did...



:bravo:

Shame Boy
Mar 2, 2010

actually i cut out two of the questions because i thought they were boring but i just realized something: one was "what car have you owned" and the options were like "porsche" and "lamborghini" and... "nissan"

gosh i wonder which one it could be :thunk:

Shame Boy
Mar 2, 2010

duz posted:

thats a service that i believe expirian runs, other companies can use it to verify identity
as you can see it works as well as the rest of their it

yeah i've run into it when getting a credit report before, but this is the first time it's had questions and answers that were quite this stupid

also the first time it failed on submit lmao

Shame Boy
Mar 2, 2010

geonetix posted:

me, trying to get some NIST references into some documentation.



thanks US Government. at least the banner works great with amberpos

anyone know of copy of all the NIST documentation?

i hope the atomic clock is still running and they paid their power bill for the month :ohdear:

Shame Boy
Mar 2, 2010

Krankenstyle posted:

secfuck-adjacent, i used to be able to overdraft my debit card without prior agreement until like 2007ish (no credit, see) --- trick was to run between the various banks' machines because they didnt sync immediately. Then hungover me has the problem

(i also remember abusing the days longer ch-chunk machine delay but it was made illegal here in like 1997ish)

now everything has been synced for a decade+

here it took the economic meltdown and a federal law to make it so your bank couldn't just let you overdraft and then charge you insane fees for it.

the law doesn't bar them from doing it, it just makes it opt-in, so now the banks repackaged it as some kind of service, like "gee if your account is out of money your card will be declined, but with Super Account Protection Plus the purchase will still go through and you can just pay us a $50 overdraft fee for the privilege, isn't that great???"

Shame Boy
Mar 2, 2010

PCjr sidecar posted:

this would be a really good post in the international banking trivia thread

i think you're being sarcastic but now i want to read the international banking trivia thread dammit

Shame Boy
Mar 2, 2010

Jimmy Carter posted:

I'm not aware of any Mac AV that's anything other than snake oil which causes kernel panics. Maybe get yourself a Little Snitch license if you want to increase your paranoia. Install software updates, don't disable SIP and that's about it.

we had to install them at work for PCI compliance because our auditor's an idiot so i had it installed for all of a week until he went away and then promptly removed it

...and it's loving root certificate that it left behind

Shame Boy
Mar 2, 2010

James Baud posted:

Junior devs and interns, sometimes people even let them review each other's code without additional oversight.

lmao that you think they do code review

i mean i hired you [interns / lowest bidder contractors] to write the drat code, why should we have to have another one of you read the code???

Shame Boy
Mar 2, 2010

rjmccall posted:

i had just never considered that some non-american might watch south park and not recognize the running joke that everything associated with cartman is at least subtly and often unsubtly racist

ah yes, that "running joke", not "intentional design reflective of the writers"

Shame Boy
Mar 2, 2010


heard about this on the radio this morning. apparently everyone except the nazis got their data released :thunk:

Shame Boy
Mar 2, 2010

"adobe flash player for windows server" is the best worst thing I've heard of all week

Shame Boy
Mar 2, 2010

wait they force you to use the web version these days? christ i'm glad i don't have to manage VM's anymore

Shame Boy
Mar 2, 2010

Lain Iwakura posted:

this is good

ahh yes the advanced hacking technique of "hard-coded credentials"

Shame Boy
Mar 2, 2010

Kazinsal posted:

what the actual gently caress



it's the interoperability certificate so we need to have it signed by everyone we interoperate with, duh

Shame Boy
Mar 2, 2010

Jewel posted:

UK gov.org revenue and taxes registration page :gonk:



too many characters make it loop back around to not strong

Shame Boy
Mar 2, 2010

Mustache Ride posted:

Some real SOAD fans at Qualys. I haven't heard CUBErt in like 20 years.

there's a joke about leaving SSL keys up on a table here but i can't really make it work :effort:

Shame Boy
Mar 2, 2010

Penisface posted:

i did google for 10 seconds and i believe this is because bcrypt embeds the salt in the digest/hash, and if you want them separately then you have to do some extra motions

if you want them separately for literally any reason you are doing it wrong and should be ashamed

Shame Boy
Mar 2, 2010

Daman posted:

outrage begins on Twitter. Kennedy bans one of his oldest volunteers in response, who all of his staff were friends with. The con is then harassed continuously for not being swift or vicious enough, as everyone associated with the con is purported to be misogynist Hitler.

huh, how dare he blame quitting on outrage culture... huh, this guy is clearly against inclusion...

now tell us your opinions on anita sarkeesian

Shame Boy
Mar 2, 2010

i love it when people who haven't posted in a thread ever suddenly show up to defend the honor and dignity of random internet dudes in the face of slanderous lies from BITCHES :argh:

Shame Boy
Mar 2, 2010

Diva Cupcake posted:

the proliferation of infosec cons and the idea of a community in general is pretty loving weird. it’s a job.

are there corporate finance conferences and speaking engagements that people take way too seriously? are there project management Twitter rockstars?

oh man there's dumb cons for everything my man, right now most of my company's upper management and the entire sales department is at the yearly National Retail Federation retail sales technology conference, something we spend at least a quarter of the year every year preparing for

Shame Boy
Mar 2, 2010

it's great because the whole show is half meaningless buzzwords and half terrifying orwellian future spying and data-mining technologies

come see the next generation of fully integrated line-busting single-channel/single-swipe virtual point of sale customer stalking platforms!

Shame Boy
Mar 2, 2010

Trabisnikof posted:

macafee is still a kinda cool dude

reading these words made me twitch and grimace slightly out of instinct before i managed to get through the rest of the post

Shame Boy
Mar 2, 2010

Loky11 posted:

alright, so I'll share some personal info, something I don't do on social media or forums.

Maybe it'll help with why I don't understand your attitude and why I'm curious about what I'm missing and why I'm asking you, who obviously gets "it" for some understanding why I "don't get it".

I'm a gay guy, who joined the Army under DADT in the late 90s. I worked and lived under that system until I got out to work in security where I still see the same poo poo just with less protection now that the Army finally changed over where private sector hasn't in many ways. I've worked in a field dominated by straight dudes all through my life and worked against stereotypes and helped inform others. I really thought I understood. However, you have some kind of secret sauce or info I don't have.

Obviously I'm still the problem personnel in the field and a fuckup.

edited:

TLDR; your attitude is poo poo and part of the problem.

i get the feeling you're pretty genuine, but when people say "please explain to me why i'm wrong" with regard to LGBT issues (especially in places not really about LGBT topics) they almost always mean "please argue with me about why i'm right". this is a big reason why people are very apprehensive about engaging you with anything other than "go figure it out yourself"

Shame Boy
Mar 2, 2010

sadus posted:

the java autoupdater now shows this handy dialog - why yes, don't mind if I do



lmao i think this is the first time i've seen a company admit you're better off without their product

Shame Boy
Mar 2, 2010

maybe we should have a queer questions thread explicitly for exploring this poo poo? idk i get why people should put in a little effort to figure stuff out on their own and not expect others to have to explain it to them and all, but sometimes you do genuinely wanna ask / talk it through with others. it's just the security thread isn't the best place, and the yosqueer thread isn't the best place since it's meant to be safe / relaxing... i know a bunch of people were wandering into the yosqueer thread a while ago asking earnestly how they should go about doing [x] better and we kinda shuffled them out since it's not really the place for it, so maybe there should be a place explicitly for it?

(i realize this isn't really a queer issue specifically, more of a feminist issue, but i think it still applies :shrug:)

Shame Boy
Mar 2, 2010

Main Paineframe posted:

also, personal secfuck news: i got an email containing one of my passwords and a blackmail note saying that they hacked my webcam and my facebook, and that if I don't send them eight hundred bucks in bitcoin they'll send nudes of me to all my contacts

except I don't have a webcam and my facebook uses a different password. the password they had was an old one that I never use on anything remotely important. so they probably got their hands on passwords from some crappy old forum or something, then decided trying to scam password-reusers with fake blackmail threats was more time-efficient than trying to break into people's accounts directly

yeah those have been going around, i posted a few in the last thread. did it say you have ~UNBRIDLED FANTASY~ 'cuz that's my favorite one :allears:

Shame Boy
Mar 2, 2010

spankmeister posted:

Recently this has been a common tactic. They use passwords from leaked dumps that are available all over the internet to make the threat look credibile. It's also a very clever threat because it works on people's shame and most aren't savvy enough to figure how the scam works.

on top of that all the ones i've gotten set the From header (or similar) to make it look like it was sent from your own account, which they point out multiple times in the text, because obviously you can only do that if you've hacked the account for real!!!

Shame Boy
Mar 2, 2010

Lain Iwakura posted:

yeah. i got one of those e-mails and it had my password from the lastfm breach. it shook me to my bones :laugh:

oh poo poo that's where they got mine from i bet too, thinking about it that was the last time i used that password...

Shame Boy
Mar 2, 2010


did someone write NEDM? is this from loving 2005?

Shame Boy
Mar 2, 2010

chemosh6969 posted:

Flakes on the non-toxic side of the issue don't help matters. I don't follow this stuff on social media enough to remember names, so I don't know who all the insane people are.

I stopped going to one conference because each year the keynote speaker would be an old white lady that just talked about how forward, non-toxic, and unbiased she was. Sometimes they'll also have a Native American ancestor, and then tell us a story from their tribe.

The one that made me give up on the conference was a lady that took this online test https://implicit.harvard.edu/implicit/ She said she would tell minorities about how high her scores were, after doing the test multiple times until she'd get the score she wanted, some people would get mad and she didn't understand why. The only thing that made things worse was when you get to the Q&A and the both the speaker and the person asking the question are the types that always have to be the last person to speak in a conversation and nobody is willing to step in and stop things when there's that tiny gap before one of them starts talking again. 45 minutes for two people in the audience.

I also work in a female dominated industry and it took me awhile to notice how sexist a lot of the men are. I started picking up on it with incidents like a co-worker (female) explaining to a consultant (male) that the idea they have, isn't going to work. The consultant just kept pushing it via email for around a month, until I jumped in and said the same thing as her. Then all of the sudden he magically understood.

at least it's not steve bannon

he was giving a speech about economic opportunities for minorities in tech, presumably that he thought there were too many and should be harder to get

Shame Boy
Mar 2, 2010

jit bull transpile posted:

so when people start whining about "crazy loud sjws", they're really saying "I tortured you until you couldn't do anything but scream and I think that's your fault".

well either that or "this problem doesn't exist/isn't really that bad because i'm not personally affected by it, therefore you're making it up for attention, wouldn't it be better if we all just got along and left the politics out of it???"

Shame Boy
Mar 2, 2010

Optimus_Rhyme posted:

It wasn't even a white board, so they couldn't wipe anything away (sec fuckup #2). Instead someone put BrakeingSec podcast stickers on it

https://twitter.com/deborahlindseyl/status/1048401909353209856

my new favorite is the one that just says "hedgehog" :yayclod:

Shame Boy
Mar 2, 2010

chemosh6969 posted:

anyone that does things like putting their hands on their head to sync up their heartbeat with their head, is a flake for that reason.

wait what? is this a thing people do? what does it have to do with anything else?

Shame Boy
Mar 2, 2010

Shaggar posted:

they make keys with active elements to make them even harder to copy, but I would be surprised if the manufacturer actually claimed the key was uncopyable.

look what thread you're in, are you sure you'd be surprised?

Shame Boy
Mar 2, 2010

BONGHITZ posted:

As for DSA, it is weak indeed, because you can brute-force decrypting, but to create a valid fake message is a different task.

... unless i'm mistaken, no it literally is not

Shame Boy
Mar 2, 2010

Lutha Mahtin posted:

is PEAR uh, the main package repository for PHP? :stare:

it's the big one yes, though generally the package repository for php is "whatever your system package manager is"

Shame Boy
Mar 2, 2010

necrotic posted:

i think composer has all but replaced pear these days. i havent touched php in years and im not going to check now.

doesn't composer do the gentoo thing of recompiling everything all the time? that's what it did the one time i had to use it...

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

Truga posted:

it's not anymore, everyone wants the latest and greatest now.

i get real bad looks at work when i insist on using only distro packages for php, and trying to avoid composer at all costs, but it's got us safely past a couple of these idiocies entirely unaffected so i guess it's not the worst idea

i've never encountered someone who uses loving php who wants the "latest and greatest" of anything

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply