Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Schadenboner
Aug 15, 2011

by Shine
I think you can do PiHole in teh :butt:, you can also make an open resolver that way.

:v:

E: I'm actually thinking of building this (High Apple Pie In The Sky Hole, not open resolvers) as a service for the customers of the MSP I work for where there's a lot of :yayclod: paranoia around. This might be a way to help "talk them down off the ledge" (as the kids say these days)?

Schadenboner fucked around with this message at 01:41 on Dec 27, 2018

Adbot
ADBOT LOVES YOU

Schadenboner
Aug 15, 2011

by Shine

MLYP

Schadenboner
Aug 15, 2011

by Shine
Wait, you mean normal people don’t spend time staring at Intel Ark?

Am, am I not ...normal?

:ohdear:

no, it’s the consumers who are wrong...

Schadenboner
Aug 15, 2011

by Shine
I remember using a zip-zap machine on my credit card once in like 1999?

Schadenboner
Aug 15, 2011

by Shine

fritz posted:

florida lan

Schadenboner
Aug 15, 2011

by Shine
:stare:

...Ok, who had (checks notes) “UPnP” for the “What 2019’s first meltdown will be about” pool?

Schadenboner fucked around with this message at 05:50 on Jan 7, 2019

Schadenboner
Aug 15, 2011

by Shine

That girl looks like one of my cousins’s kids and every time I see it I go all :3:.

Schadenboner
Aug 15, 2011

by Shine

Cybernetic Vermin posted:

free private repos can only have three collaborators, so it is pretty drat limited anyway

besides there is a bunch of enterprise features they still charge for, just microsofts modern realization that you want to rope in hobbyists with free tools to the extent possible, the real money is with cost-insensitive companies

I mean, tbf hasn’t this been their strategy with universities as well?

Schadenboner
Aug 15, 2011

by Shine

:stare:

Schadenboner
Aug 15, 2011

by Shine

Boiled Water posted:

in sec-gently caress fun: I saw a defcon video describing an interesting attack vector: Windows Defender. Turns out it scans almost anything you come into contact with in its own container, like if you view an email in gmail with an attachment it downloads it and scans and runs it in the container. You can escape this container, and its supposedly a good time.

:justpost::posthaste:

:ohdear:

Schadenboner
Aug 15, 2011

by Shine

haveblue posted:


three winters from now
fallen leaves under snow and
your cert expires


:ck5:

Schadenboner
Aug 15, 2011

by Shine

EMILY BLUNTS posted:

YOSPOS › Security Fuckup Megathread - v18.0 - the thread title says “security fuckups” not “insecurity fuckups”

Mods, plz do the needful &c. &c.

Schadenboner
Aug 15, 2011

by Shine

Carbon dioxide posted:

Anyway, the hardcoded key is 1024-bit DSA.

So the police are in on it too, then?

:crossarms:

Schadenboner
Aug 15, 2011

by Shine

BangersInMyKnickers posted:

lol ok symantec here we go again

they have this thing called a shared insight cache, which at its core is just a big memory lookup table of process hashes, the definition rev, and the number of clients that voted it clean. so when things are doing disk scans, they can call back to this server and get a verdict on the file without doing the full scanning poo poo locally and expending those cycles. they sell it as a vdi optimization thing, but really you could use it for any system so long as they have a low latency connection to the server and .5mbit network overhead to spare.

the documentation is garbo with some kind of cert-less TLS implementation they you can intercept and then creds being passed inside that tunnel, but I guess you can increase the vote threshold before a hash is marked clean to minimize the risk of cache tampering. there's not any scaling guidelines to speak of so I'm profiling this thing to figure it out what I have to throw at it and I see the client start spamming hundreds of new sockets against the cache instance. at one point in the scanning process, the client opens 100+ sockets to the cache listener, and it seems to happen at around the same point at the beginning of every scan, which means I can have 650 clients doing this at once before this stupid things starts running off the rails for a failure mode I'm sure they didn't validate for.

for a company that claims to be an enterprise security vendor they sure do loving suck at it

This seems like a poor implementation of a good idea though? Does anything do this well/correctly/less-potato?

Schadenboner
Aug 15, 2011

by Shine
I didn’t understand any of the sponsor interview from the most recent Risky Business. And not for the usual reason (:australia:). Like it was all about math and modeling selectric typewriters in a can of La Croix in Second Life?

:psyduck:

Schadenboner
Aug 15, 2011

by Shine

spankmeister posted:

Funny because the trail of bits guy CTF one was one of the very few sponsor interviews that I listened to and actively enjoyed. I usually skip them after a couple of minutes.

This one was absolutely great. It's because I like to play CTF's and it's cool to hear from someone who designs these absolutely insane challenges.

It's also nice that they used their sponsor spot to just tell a story about a cool CTF challenge, instead of actively trying to push some product.

He never said what flavor it was though. I’m going to be so loving mad if it turns out not to have been Pamplemousse.

Schadenboner
Aug 15, 2011

by Shine

spankmeister posted:

Funny because the trail of bits guy CTF one was one of the very few sponsor interviews that I listened to and actively enjoyed. I usually skip them after a couple of minutes.

This one was absolutely great. It's because I like to play CTF's and it's cool to hear from someone who designs these absolutely insane challenges.

It's also nice that they used their sponsor spot to just tell a story about a cool CTF challenge, instead of actively trying to push some product.

Non-commutative arithmetics legit freak me the gently caress out.

Schadenboner
Aug 15, 2011

by Shine

Blinkz0rz posted:

a product manager literally just asked me if i have any concerns about allowing paid users to upload selenium jars and exes which our product will process

trying to figure out a diplomatic way to say "absolutely not why would you think this is a good idea?"

“Have you run it by the auditors?”

Schadenboner
Aug 15, 2011

by Shine

EMILY BLUNTS posted:

8 dildos seems like a lot tho

For you...

Schadenboner
Aug 15, 2011

by Shine

Midjack posted:

ol dirty bastard lives!

This is probably a transpositional error, they probably meant to name it “OBD II” meaning “On Board Diagnostic II” which is the standard used to communicate engine data. It seems likely that the wireless network is from an “OBD dongle” and connecting to it would not provide access to broader information networks (e.g. the Internet)?

H
T
H
!

Schadenboner
Aug 15, 2011

by Shine

Snitches get stitches.

:toughguy:

Schadenboner
Aug 15, 2011

by Shine

Cocoa Crispies posted:

*felix voice* the best part of waking up… is kashoggi got cut up

:catstare:

Schadenboner
Aug 15, 2011

by Shine
:laffo: if you let your laptop "sleep" or "hibernate". Pull the battery, hold down the power button to discharge the capacitors, turn 360 degrees and walk the gently caress away.

Not for any security reason, mind you. Just because: gently caress you laptops! If "on" and "off" is good enough for every other computer you don't get special power states just because you're skinny.

Schadenboner
Aug 15, 2011

by Shine

:laffo: if you're not just constantly moonwalking everywhere. Like, how can you expect people to take you seriously if you can't even manage that?

Schadenboner
Aug 15, 2011

by Shine
It probably was a state actor, just not the Saudis.

The brother is Trumpy, he’s probably being paid by one of the fuckers.

Schadenboner
Aug 15, 2011

by Shine

geonetix posted:

I have a feeling that investigation should be done by a third party instead

I mean, not if you want the investigation to reach the conclusion Facebook wants it to reach?

Schadenboner
Aug 15, 2011

by Shine

abigserve posted:

Security Fuckup Megathread: not so fast hot stuff

Schadenboner
Aug 15, 2011

by Shine

Proteus Jones posted:

Security Fuckup Megathread - v17.2 - your gender is broadcasting an IP address

Schadenboner
Aug 15, 2011

by Shine
Has anyone else heard someone pronounce it as “Too-fah” (as in the sponge)?

I recently did and it was :chloe: as gently caress.

E: Versus the obviously correct “Two-eff-ay”.

E2: and god help you if I don’t hear a correctly formed w in the “two”! :toughguy:

Schadenboner fucked around with this message at 16:36 on Apr 6, 2019

Schadenboner
Aug 15, 2011

by Shine

flakeloaf posted:

i was a loving dismal interrogator but that part even i could get right

Wait, what?

Schadenboner
Aug 15, 2011

by Shine

Krankenstyle posted:

e: nm, misread

:justpost::posthaste:

Schadenboner
Aug 15, 2011

by Shine

haveblue posted:

BARRENS SHAPED CHARGES

Schadenboner
Aug 15, 2011

by Shine

D. Ebdrup posted:

In case you're using seemingly any of the ad-blockers but uBlock Origin (why would you?), you probably want to switch.

Also note that uBlock and uBlock Origin are different, Origin is the good one.

Schadenboner
Aug 15, 2011

by Shine

D. Ebdrup posted:

Very different, yes - that's pretty well-known by now, though. But I suppose someone might not know it?

Comic book nerds have a saying that “every issue is someone’s first issue”.

:shrug:

Schadenboner
Aug 15, 2011

by Shine

MononcQc posted:

my employer produces those, among other things.

They're still expensive and require data access so many police forces have only a few car running with them at any given time.

Pigs out of YOSPOS.

Schadenboner
Aug 15, 2011

by Shine

flakeloaf posted:

wait so integrating xss into the desktop of an operating system (and probably into a process with god rights) is.... um... bad?

:monocle:

Adbot
ADBOT LOVES YOU

Schadenboner
Aug 15, 2011

by Shine
Is 9.9.9.9 good?

:ohdear:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply