Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Luigi Thirty
Apr 30, 2006

Emergency confection port.

I'm the goo girl

Adbot
ADBOT LOVES YOU

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
i don't understand how they could possibly have a big enough problem to need to block some of these, like 'dendrophilia'

e: 'women rapping'

Pile Of Garbage
May 28, 2007



Aleksei Vasiliev posted:

i don't understand how they could possibly have a big enough problem to need to block some of these, like 'dendrophilia'

e: 'women rapping'

i think that's code for rape

Shame Boy
Mar 2, 2010

spankmeister posted:

it's funny because I expected these machines to run Windows but this runs some flavor of red hat and the most old-skool looking version of X11.

my old cable company had this one channel you could only tune to with a third-party receiver that showed nothing but an old Red Hat login screen 24/7. i did some research and apparently it's like their flavor of the emergency alert system or something like that.

Panty Saluter
Jan 17, 2004

Making learning fun!

Luigi Thirty posted:

I'm the goo girl

text me

spankmeister
Jun 15, 2008






Parallel Paraplegic posted:

my old cable company had this one channel you could only tune to with a third-party receiver that showed nothing but an old Red Hat login screen 24/7. i did some research and apparently it's like their flavor of the emergency alert system or something like that.

couple years ago I was in a motel and one of the channels was a fedora 8 text console login. (i suppose it was still fedora core back then)

DOG AT THE DOOR
Aug 29, 2007

bwha
https://www.blackhat.com/docs/us-15/materials/us-15-Zhang-Fingerprints-On-Mobile-Devices-Abusing-And-Leaking-wp.pdf

HTC One Max stores saved fingerprints in the /data/ folder as a .bmp with full read/write permissions

lol

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
http://blogs.bis.gov.uk/exportcontrol/files/2015/08/Intrusion-Software-Tools-and-Export-Control1.pdf
uk wassenaar rules
exploit that just pops calc: "unlikely to be controlled"
explaining that exploit to a vendor: need an export license (according to @i0n1c)

Nerdlord Actual
Apr 14, 2007

Awaken to your true self with Wisconsin Potatoes
Grimey Drawer

froward posted:

im gay & hungry for cum

please dont post my bank challenge answers

Pinterest Mom
Jun 9, 2009

Wiggly Wayne DDS
Sep 11, 2010



Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Aleksei Vasiliev posted:

http://blogs.bis.gov.uk/exportcontrol/files/2015/08/Intrusion-Software-Tools-and-Export-Control1.pdf
uk wassenaar rules
exploit that just pops calc: "unlikely to be controlled"
explaining that exploit to a vendor: need an export license (according to @i0n1c)

how does wassenaar work wrt poo poo like exhibition/competitive hackers?

and does hosting the software at home and just accessing/running it remotely sidestep it at all?

Luigi Thirty
Apr 30, 2006

Emergency confection port.

Parallel Paraplegic posted:

my old cable company had this one channel you could only tune to with a third-party receiver that showed nothing but an old Red Hat login screen 24/7. i did some research and apparently it's like their flavor of the emergency alert system or something like that.

the real estate listings channel here in the 90s was an Amiga guru meditation screen half the time

I stayed in a hotel in TN once and the public access channel was a Commodore Plus/4 boot screen

the other government channel was a cable company headend "unable to acquire signal" error screen that rebooted every 180 seconds

Pile Of Garbage
May 28, 2007



Aleksei Vasiliev posted:

http://blogs.bis.gov.uk/exportcontrol/files/2015/08/Intrusion-Software-Tools-and-Export-Control1.pdf
uk wassenaar rules
exploit that just pops calc: "unlikely to be controlled"
explaining that exploit to a vendor: need an export license (according to @i0n1c)

jfc what a boondoggle. the whole thing is just a means of legitimising intrusive DRM and "Commercial Malware Toolkit for Law Enforcement" by making them "export controlled", right?

Panty Saluter
Jan 17, 2004

Making learning fun!

DOG AT THE DOOR posted:

https://www.blackhat.com/docs/us-15/materials/us-15-Zhang-Fingerprints-On-Mobile-Devices-Abusing-And-Leaking-wp.pdf

HTC One Max stores saved fingerprints in the /data/ folder as a .bmp with full read/write permissions

lol

:stare:

triple sulk
Sep 17, 2014



lmao

graph
Nov 22, 2006

aaag peanuts

DOG AT THE DOOR posted:

https://www.blackhat.com/docs/us-15/materials/us-15-Zhang-Fingerprints-On-Mobile-Devices-Abusing-And-Leaking-wp.pdf

HTC One Max stores saved fingerprints in the /data/ folder as a .bmp with full read/write permissions

lol

anroid lol

Sharktopus
Aug 9, 2006

i got a lot of catching up to do, just got back from a week vacation. Anyone got any highlights other than the elevator hacking video?

Squeezy Farm
Jun 16, 2009
All of you guys like to have sex with animals

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Squeezy Farm posted:

All of you guys like to have sex with animals

you and me baby ain't nothin but mammals

Dylan16807
May 12, 2010

cheese-cube posted:

what use-case is there for the variable-length output modes (SHAKE128/256)?

you can use the same core as both a hash and a CSPRNG / keystream, I think that's neat

Panty Saluter
Jan 17, 2004

Making learning fun!

Captain Foo posted:

you and me baby ain't nothin but mammals

OHMIGOD FUCKYOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOUUUUUUUUUUUUUU

apseudonym
Feb 25, 2011

graph posted:

anroid lol

Biometrics lol

Korean Boomhauer
Sep 4, 2008
biometri.cx

suffix
Jul 27, 2013

Wheeee!

cheese-cube posted:

what use-case is there for the variable-length output modes (SHAKE128/256)?

hashes are often used for key derivation: take a bunch of data in whatever length and format is convenient, and make one or more secure keys of the required length

this has come up in the cfrg's work on elliptic curve signatures (the current ECDSA standard is kind of crap, see http://blog.cr.yp.to/20140323-ecdsa.html for an explanation of why it was pretty dated even in the 90s when it was made (by the nsa))
depending on the curve strength they'll need to generate numbers with an upper bound of anywhere between ~2256 to 2521, so even sha-512 isn't big enough, and they'd like to use the same method for all the curves. SHAKE is great for that use case


Wheany posted:

it makes the implementation more complex and error prone. :nsa:

eh. keccak is a pretty neat design called a sponge. there's one simple function in the middle that just needs to act as a 1600 bit fixed random permutation, no keys or nothing
that's where most of the cryptoanalysis happens, and also any optimization and hardware acceleration
then you can build other constructs on top - a hash, a mac, a kdf, etc. and prove that they're secure assuming properties of the base function

the main problem with sha3 is that software implementations are pretty slow compares to the alternatives, even sha2, so it's not very attractive for developers
but if sha3 hardware acceleration became common i bet you'd see the core function reused for other things

Shame Boy
Mar 2, 2010

Segmentation Fault
Jun 7, 2012

Luigi Thirty posted:

I'm the goo girl



:eyepop:

Dodoman
Feb 26, 2009



A moment of laxity
A lifetime of regret
Lipstick Apathy
eyyy girl

oh no blimp issue
Feb 23, 2011

thank god i work at the slime girl anime factory!

oh no blimp issue
Feb 23, 2011

keep up the good work says my supervisor as i read the yospos security gently caress up thread

Shaggar
Apr 26, 2006
text me (an application)

Shame Boy
Mar 2, 2010

wtf is a "blumpkin," some silly brit thing like tallywacker or fanny?

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

DOG AT THE DOOR posted:

https://www.blackhat.com/docs/us-15/materials/us-15-Zhang-Fingerprints-On-Mobile-Devices-Abusing-And-Leaking-wp.pdf

HTC One Max stores saved fingerprints in the /data/ folder as a .bmp with full read/write permissions

lol

dammit i came here to post this

graph posted:

anroid lol

Shame Boy
Mar 2, 2010

i would also like to point out that the naughty words list includes "yaoi" but not "yuri" and this bothers me :spergin:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
it was chill to meet you all. i have some photos to share later including a very special one

in other news

http://www.theregister.co.uk/2015/08/07/sophos_anti_muslim_name_filter

ErIog
Jul 11, 2001

:nsacloud:

Parallel Paraplegic posted:

i would also like to point out that the naughty words list includes "yaoi" but not "yuri" and this bothers me :spergin:

As it loving should be. They're providing a public service by signalling that if you're looking for it to beat off then you're barking up the wrong tree.

Yaoi is for beating off. Yuri is for weeping to yourself in your apartment as you read it while drinking the cheapest chu-hai.

ErIog fucked around with this message at 22:04 on Aug 10, 2015

oh no blimp issue
Feb 23, 2011

yuri is also a name, so i imagine they dont block it because of that?

Segmentation Fault
Jun 7, 2012

OSI bean dip posted:

it was chill to meet you all. i have some photos to share later including a very special one

in other news

http://www.theregister.co.uk/2015/08/07/sophos_anti_muslim_name_filter



TRWTF is Sophos

also antivirus for mac

eonwe
Aug 11, 2008



Lipstick Apathy
I set up 900 users each with unique permissions and a unique password and the account manager wants me to set all of their passwords to one thing so she doesn't have to send individual emails

Lol, nope

Adbot
ADBOT LOVES YOU

ErIog
Jul 11, 2001

:nsacloud:
Did you offer to help her automate the e-mail process?

  • Locked thread