Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Thread remounted -rw

Adbot
ADBOT LOVES YOU

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

hobbesmaster posted:

the good news is that if you were a hacker you'd have no trouble answering those questions because the possible answers are all part of complete identities they sell!

borat voice my life

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Vanadium posted:

naively I would expect that this couldn't happen, but after all I've heard about unexpected dangers in date/time handling, I wouldn't really be surprised anymore if a neglected atomic clock somehow goes critical and makes large swaths of the calendar uninhabitable

lmao

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Jabor posted:

it's exactly the same reason calling your package manager a racial slur is a bad idea. no-one cares that you got there by shortening "raccoon"

heh

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

BattleMaster posted:

did this happen I don't want it in my google history

Russian erlang Dev posts about doing this
Mononcqc advises him that it's a bad idea
A horrible fucker decides that it's a good idea to die on the hill that the Dev should be able call it whatever he wants

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Chris Knight posted:

speaking of publicly facing things with web interfaces
https://twitter.com/mikko/status/1080223116197019648

lmao

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

haveblue posted:

hey guys I wrote this daemon to re-verify tape archives in the background, what do you think

took me a minute

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

graph posted:

well yeah you need it to use the more recent vcenter web interfaces

lol

the most recent versions are html5 and are so much better

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

graph posted:

oh it finally came out? which version is it now

html5 client is first available on 6.0u3, mostly feature complete on 6.5, and i think standard on 6.7

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

EssOEss posted:

I wonder how they'll react when they realize what IPv6 does to this situation.

Edit: Oh, is this what is holding IPv6 adoption back?! :tinfoil:

ipv6 succs

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

BangersInMyKnickers posted:

okay welcome to the loving dumbest pki implementation I have ever seen:

wwww.disa.mil exp 11/18/19
DOD ID SW CA-38 exp 9/23/21
DoD Root CA 3 exp 2/17/19 <-- lol
DoD Interop Root CA 2 exp 8/15/19 <-- lolè
Federal Bridge CA 2016 exp 5/15/20
TSCO SHA256 Bridge CA exp 2/19/19 <-- who the gently caress is this?
Alexion Pharmaceuticals Issue 2 CA exp 8/2/27 <-- WHO THE gently caress IS THIS??

Why the gently caress doesn't this stop at DoD Root CA 3 is beyond me but even that they hosed up your root should always have the last expiration date

what in fuckin tarnation

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

jit bull transpile posted:

I don't think you trust
in my
self signed web certify
i
cry
when thinking 'bout PKI

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

haveblue posted:

"secfuck megathread: I don't think you trust in my self signed web certify" is 3 chars under

graph plz

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

One of my coworkers thought that password salting was doing things like p4$$w0rD 5@L+inG

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

ratbert90 posted:

If I ever caught a coworker not using a salt and hash with bcrypt I would be so loving upset. Every modern language has a canned library to do that in usually one or two lines.

He wasn't rolling his own or anything, just misinformed on technical details

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Carbon dioxide posted:

At least make it a haiku.

I don't think you trust
My self-signed certificate
The key looks nice though


ban

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Loky11 posted:

obviously not which is more than fine with me.

if you're not trying to learn things you don't belong in this thread

you probably don't belong here for other reasons, but maybe you understand this one

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Loky11 posted:

just saying things like "you don't get it" and then not trying to educate or inform might possibly have elicited a glib response.

i will fully admit i used to have this attitude and point of view; i hope at some point you figure out why it's not other people's jobs to educate you

you've been told you're the security personnel fuckup, work with that

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

CRIP EATIN BREAD posted:

unfettered write access to a publicly available display seems like a infosec fuckup imho

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

EMILY BLUNTS posted:

the thread title says “security fuckups” not “insecurity fuckups”

holy poo poo lmao

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Powerful Two-Hander posted:

-----BEGIN PGP PUBLIC KEY BLOCK-----
loving HELL
-----END PGP PUBLIC KEY BLOCK-----

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Chris Knight posted:

ugh at trying to do math on a palm pilot

big lomarf

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

NFX posted:

shaggar for business

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Jabor posted:

more like should-be-in-prison book.

not even joking, lock up whoever made the decision, and also their entire management chain including zuckerberg (they all knew exactly what was going on).

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

well, here we go?

https://twitter.com/alexeheath/status/1090618327502897152

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Salt Fish posted:

I looked it up and they wrote their own processing code that read the DNA and translated it into machine code and then deliberately ran it. So basically they proved that DNA can encode information.

...

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Cocoa Crispies posted:

we already knew malware could be encoded in DNA or RNA because viruses exist and kill people

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Notorious b.s.d. posted:

it's a question of ingress vs egress filtering

lol

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

there's a different thread for faking your own death lmao

also bitcoins et al are dumb

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

haveblue posted:

the best phish training email I've seen was one that claimed to be from our security team containing a list of people who fell for the last phish training email

unbelievably savage

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

LastInLine posted:

you say it as a joke but if facebook starting raising an army of the dead i feel like thered be some complaints about that too

lmao

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Last Chance posted:

yeah facebook's definitely trying to fix their PR problem.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Chalks posted:

i wish facebook the best of luck in fixing the problem that people are pretty poo poo and probably shouldn't be allowed to communicate ever

feel free to take yourself to the leper's colony lol

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

salted hash browns posted:

i am putting apple on blast for following Chinese regulation and law because it will result in human harm.

many other companies (incl. Fb/goog) have done the right thing and chose not to operate in China.

but you have such a boner for Apple you don’t care

I'm the potential harm to Chinese being equated to actually-happened genocide

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

GWBBQ posted:

i was shodan surfing and came across someone with an unsecured NAS that has enormous amounts of personal information on it. i kind of feel like i should contact them and let them know, but i also don't want to creep them out by being some random guy contacting them about computer security. thoughts?

the official position of this thread is "do not touch the poop"

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Grace Baiting posted:

ⓑⓛⓞⓒⓚⓒⓗ🅐🅘ⓝ

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

hackbunny posted:

ooxml was ostensibly released to stop people from doing that, which has never been an officially supported way to use office [of course I, too, have driven word through its ole api to programmatically generate documents. for fun. from windows scripting host]

hackbunny.txt

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

pseudorandom name posted:

the sad thing about https://text.npr.org/ is that they could've spent slightly more effort and used the appropriate HTML tags instead of <p> everywhere and gotten so much more structure and formatting for free

v<p>n

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'


ayyyyyy

Adbot
ADBOT LOVES YOU

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Carbon dioxide posted:

Several password managers leave traces of their master password or individually accessed passwords in the Windows 10 memory, sometimes even after they've been locked. Someone with access to the computer could potentially extract those passwords from memory.

https://www.securityevaluators.com/casestudies/password-manager-hacking/



Dashlane and Keepass seem to be doing relatively well on this test.

Note: this is a rather esoteric way of attack and is not at all a reason to not use password managers. If someone installs a keylogger to your computer they can get access whether you have a password manager or not.

physical access trumps everything

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply