Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
ozymandOS
Jun 9, 2004
ground floor security posting

Adbot
ADBOT LOVES YOU

ozymandOS
Jun 9, 2004

Pile Of Garbage posted:

i don't see how i'm an idiot for calling poo poo what it is: poo poo. upnp is straight garbage, i accept that it has been adopted and exists and that the majority of problems are due to lovely implementation but that aside it's dumb trash!

lol take a look at this guy

ozymandOS
Jun 9, 2004

Raere posted:

Say you're designing an authentication backend (I'm not) and are storing passwords as salted hashes. Where do you store the salts, if properly designed?

if not using a library that automatically embeds the salt with the hash, you put it alongside the hash value -- salts to do not need to be secret.

ozymandOS
Jun 9, 2004
it seems that if the upgrade can't be verified with the built-in key, vlc downloads a new key from their server




over http

lol

ozymandOS
Jun 9, 2004

Rufus Ping posted:

i think it then checks this key is signed by a hardcoded one. this makes sense (ish) because it allows the signing key to be rotated without locking old exe's out of the auto update mechanism

yeah it's very possible i don't have the whole story, i am repeating what i heard

Adbot
ADBOT LOVES YOU

ozymandOS
Jun 9, 2004
otoh, if the box can unlock its own encryption on boot, so can an attacker

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply