Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
haveblue
Aug 15, 2005



Toilet Rascal
the last time I used one of those it asked me to pick an address I had previously lived at. all the possibilities were hundreds of miles away and it took me a while to remember that one of them was my college apartment from 15 years ago

Adbot
ADBOT LOVES YOU

haveblue
Aug 15, 2005



Toilet Rascal

Midjack posted:

it's not useful unless you are specifically trying to disinfect some old rear end file from 1996 that isn't available without the malware anymore.

if it’s from 1996 the malware won’t run under X anyway

haveblue
Aug 15, 2005



Toilet Rascal

quote:

> I could easily see this being a viral front page reddit kind of thing.

That actually would be the best thing could ever happen to a niche public
project.

loool

haveblue
Aug 15, 2005



Toilet Rascal

spankmeister posted:

Mac users are conditioned to click to give root rights to everything anyway.

a revoked cert won't give you the choice to run it from the finder. you have to turn off code signing entirely and the option to do that isn't surfaced on demand, you have to go rooting through system prefs if you even know how to turn it off

it also won't offer to run an unsigned app through the fast/easy path (double click), you don't get the run anyway button. you have to use the open command from a menu for it to present that

haveblue
Aug 15, 2005



Toilet Rascal
hey guys I wrote this daemon to re-verify tape archives in the background, what do you think

haveblue
Aug 15, 2005



Toilet Rascal

CmdrRiker posted:

It's recording a public space so it should be available to the public. :kiddo:

"A second source, with direct knowledge of Ring’s video-tagging efforts, said that the video annotation team watches footage not only from the popular outdoor and doorbell camera models, but from household interiors."

weird that this only comes up so far down the article but it should be a way bigger deal that watching the front yard

Cybernetic Vermin posted:

the article is phrased weirdly though, it lists people the videos are available to 'without access control', if it is just publicly available why aren't they just saying that?

what they seem to be trying to say is that within the ring backend it's possible to be exempted from all self-imposed access controls and granted carte blanche to browse any video from any customer on demand. so the "access control" is that you have to be a high-ranking employee of ring but beyond that there is no oversight or audit capability

haveblue
Aug 15, 2005



Toilet Rascal

Heavy_D posted:

is this too long for the title?

"secfuck megathread: I don't think you trust in my self signed web certify" is 3 chars under

haveblue
Aug 15, 2005



Toilet Rascal

ratbert90 posted:

Haikus have to be about the seasons. :colbert:


three winters from now
fallen leaves under snow and
your cert expires

haveblue
Aug 15, 2005



Toilet Rascal
https://twitter.com/DCFurs/status/1087663240421593089

haveblue
Aug 15, 2005



Toilet Rascal
I thought we had already discovered furries thanks to the "oopsie woopsie we made a fucky wucky" tweet

haveblue
Aug 15, 2005



Toilet Rascal

Volmarias posted:

:piss:

Sounds like Apple would be within their rights to nuke all of their certs at this point

yeah it’s a blatant rule violation. the cert they used here will absolutely be yanked, the main apps may be protected by being too popular

haveblue
Aug 15, 2005



Toilet Rascal

Phone posted:

I fail to recognise the “bad practice” here. Researchers clearly asked for consent, in case of teens they have required parental consent as well, they have had clearly worded policy, they have generously paid for participation.

There is no other way to see the user experience in the whole without using VPN and custom root SSL certificate since every app is sandboxed and traffic is sent over HTTPS most of the times.

did you paste this from a comment somewhere

the first bad practice was violating apple's terms with regards to who apps signed with that certificate may be given to, that made this open and shut. the second bad practice was using this to circumvent an app store ban, that made this open and shut with extreme prejudice. on top of that there are all the arguments to be had over whether the level of disclosure was sufficient, whether the users really understood the full implications of what they were doing, whether they did due diligence as to verifying parental consent was actually obtained, whether it's appropriate to make that sort of offer to teenagers in the first place, and the ethics of turning users' phones into bugging devices to obtain data on competitors

facebook is exactly the sort of malicious actor that apple's heavy handed walled garden poo poo is meant to protect users from

haveblue
Aug 15, 2005



Toilet Rascal

my bitter bi rival posted:

does this mean they yanked all of facebooks development certs or that Facebook was using the same cert for all of this

what they yanked was the "enterprise certificate", which is different from the "developer certificate". there's only these two, really

the developer cert is used to sign apps for submission to the app store. this is the cert that signs public releases of the official app, messenger, etc. this cert has not been touched so far was we know and the apps are still up on the store

the enterprise cert is used when you have to put an app on a device as part of your internal operations. you can't put an entirely unsigned app on an ios device unless you jailbreak it, there always has to be some level of credentials/trust involved. so this cert is used to e.g. give a build to your QA department that they can put on all their devices. or to make small in-house apps that don't need to go through the app store because anyone and everyone who uses them works for you to begin with. this cert was used for a bunch of those things and was also abused for this VPN research program, so when apple killed it a ton of internal facebook utilities went with it

haveblue
Aug 15, 2005



Toilet Rascal

Potato Salad posted:

Not knowing what action apple took here specifically, it would make sense that entities that existed before FB acquisition have their own apple certs.

I agree, maintaining the old certs/dev accounts is the only way (that I know of) to retain the original store listings for instagram.app/whatsapp.app and the ability to deploy updates to installs of those listings

haveblue
Aug 15, 2005



Toilet Rascal

wyoak posted:

seems unfair imo, if facebook is paying a 13 year old 20 bucks a month they're clearly an employee and therefore sideloading this dodgy app to monitor their employee's usage is good and cool

clearly they're independent contractors

haveblue
Aug 15, 2005



Toilet Rascal

CmdrRiker posted:

Yeah. And I would dare say Apple had its fair share of privacy fuckups over the last year as well.

but apple's response is "oops, we'll fix it" rather than "oops we got caught"

apple doesn't make money from selling your info and doesn't need to. the others do

haveblue
Aug 15, 2005



Toilet Rascal
maybe the sequencer is making assumptions about naturally occurring sequences? did dna evolve length encoding and terminator characters?

haveblue
Aug 15, 2005



Toilet Rascal

Midjack posted:

a condom is a firewall for your dick. also vag depending on your attitude wrt safe sex.

the pill is an NX flag

a fleshlight is a sandbox

haveblue
Aug 15, 2005



Toilet Rascal
the best phish training email I've seen was one that claimed to be from our security team containing a list of people who fell for the last phish training email

haveblue
Aug 15, 2005



Toilet Rascal
I didn't click it :smugdog: and it was auto-deleted once I used the outlook report phishing button

usually the documents just have boilerplate "this was phishing, you're a dumbass, now read these guides" text

haveblue
Aug 15, 2005



Toilet Rascal

salted hash browns posted:

at least FB is trying to fix poo poo

lol

haveblue
Aug 15, 2005



Toilet Rascal

ban this sick filth

haveblue
Aug 15, 2005



Toilet Rascal

Cybernetic Vermin posted:

we didn't really know what rules apple had in place for facebooks use of the certificates

the terms of the generic enterprise cert program agreement are public and were cited as the reason for the revocation, I don't think they had a special private contract since apple removed ios's built-in facebook integration

haveblue
Aug 15, 2005



Toilet Rascal
looks like they think "physical threat model" is the guy manning their booth at the convention

haveblue
Aug 15, 2005



Toilet Rascal
glassbox's selling point is that they take the recorded taps and keystrokes and combine them with a mockup of your app/site to reconstitute what the screen looked like during the session. whether this counts as "screen recording" is a semantic argument so expect it to go on for another five pages

haveblue
Aug 15, 2005



Toilet Rascal
I'm the offensive cyber

haveblue
Aug 15, 2005



Toilet Rascal
people would accept phone/computer 2fa more if you told them they've already been using 2fa systems for years atm/debit cards

haveblue
Aug 15, 2005



Toilet Rascal
I guess there's info disclosure there? although I can't spot what it is, all I see are internal IPs and half of an aws subdomain

haveblue
Aug 15, 2005



Toilet Rascal
if you live in an area where brownouts are common it's not a bad idea for electronics

haveblue
Aug 15, 2005



Toilet Rascal

Meat Beat Agent posted:

love to perform a special command move and shoryuken my way into a complete stranger's medical records

are you the hacker in my mandated online security training who tries to hack our network by powering up to super saiyijin and throwing fireballs at the server

haveblue
Aug 15, 2005



Toilet Rascal

quote:

For example, in Year 1 that useless letter `c' would be dropped to be replased either by `k' or `s', and likewise `x' would no longer be part of the alphabet. The only kase in which `c' would be retained would be the `ch' formation, which will be dealt with later. Year 2 might reform `w' spelling, so that "which" and "one" would take the same konsonant, wile Year 3 might well abolish `y' replasing it with `i' and Iear 4 might fiks the "g/j" anomali wonse and for all.

Jenerally, then, the improvement would kontinue iear bai iear with Iear 5 doing awai with useless double konsonants, and Iears 6-12 or so modifaiing vowlz and the rimeining voist and unvoist konsonants. Bai Iear 15 or sou, it wud fainali bi posibl tu meik ius ov thi ridandant letez `c', `y' and `x' - bai now jast a memori in the maindz ov ould doderez - tu riplais `ch', `sh', and `th' rispektivli.

Fainali, xen, aafte sam 20 iers ov orxogrefkl riform, wi wud hev a lojikl, kohirnt speling in ius xrewawt xe Ingliy-spiking werld.

--Mark Twain

haveblue
Aug 15, 2005



Toilet Rascal

Shame Boy posted:

is it just me or are these "i've got your old password via hacking and definitely not just using a big list" emails getting less and less understandable

I forced a neural net to read 1,000 threatening emails, and

haveblue
Aug 15, 2005



Toilet Rascal

Lain Iwakura posted:

time to create some new calc.exe payloads that load calc.exe

https://www.youtube.com/watch?v=SVt4XsTvWXY





in other news, now that we're all done turning off branch prediction, we have to turn off the other clever microcode optimization trick

http://nebelwelt.net/blog/20190306-SMoTherSpectre.html

tldr: a thread running on an SMT core can figure out what threads on the other virtual core are doing

haveblue
Aug 15, 2005



Toilet Rascal
figure out who did it with a blockchain explorer, shame them on slack

haveblue
Aug 15, 2005



Toilet Rascal
everyone is better off with fewer bitcoins so yes

haveblue
Aug 15, 2005



Toilet Rascal

florida lan posted:

gently caress that poo poo, use a proper hardware credential system:



that subtitle is all wrong, it’s “leeloo dallas multipass.“, a three-component proper name

haveblue
Aug 15, 2005



Toilet Rascal

ewiley posted:

I once encountered a T1 card with very similar behaviors. a ping packet padded with all 0's (or any other packet with a large 0's payload) would reset the connection due to some odd signal encoding fuckery. In-band metadata is the worst thing to happen to communications protocols.

remember when certain models of modem would obey the hayes hangup command if it was delivered through the phone line port? good times

haveblue
Aug 15, 2005



Toilet Rascal

duz posted:

gave him $4k

:staredog:

haveblue
Aug 15, 2005



Toilet Rascal

Soricidus posted:

i feel sorry for the guy at the nsa who had to buy an account to carry on reading my posts

*looks at camera* it’s a living!

Adbot
ADBOT LOVES YOU

haveblue
Aug 15, 2005



Toilet Rascal

Cybernetic Vermin posted:

during trumps second term they're going to pour his brain into glados and he'll run things forever fyi

if you pour his brain into a computer he turns into wheatley

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply