Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
2nd floor

Adbot
ADBOT LOVES YOU

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

JawnV6 posted:

dont u mean 1st

fucker

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
why would you ever assume that any sort of messaging using a cell phone is "secure" for a very very strident definition of the word

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
i guessed that the password to the admin account for the tech lab macs was the name of our school and got in-school suspension for it. i had to watch a really cheesy 80s video from att about hackers.

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

Winkle-Daddy posted:

this sounds rad as hell

i'm trying to find it on the internet but not having a lot of luck

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

do you wanna build a botnet

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

jre posted:

GET of death, nice.

#GETrekt

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
http://blog.ammaraskar.com/minecraft-vulnerability-advisory/

quote:

Around 2 years ago, I was enthusiastically working on Spigot and Bukkit along with a couple of fairly popular plugins. During my poking around within the networking internals of Minecraft, I came across a fairly substantial problem that allowed anyone to send certain malformed packets and crash a server by running it out of memory.

Following the defacto standard procedure, I responsibly and privately disclosed the problem to Mojang on 10th July, 2013. That’s nearly 2 years ago. I asked for updates in one month intervals over the course of 3 months and was ignored or given highly unsatisfactory responses. I kept my hopes up that the problem would be patched and checked the source code on new releases whenever I could.

The version of the game when the vulnerability was reported was 1.6.2, the game is now on version 1.8.3. That’s right, 2 major versions and dozens of minor versions and a critical vulnerability that allows you to crash any server, and starve the actual machines of CPU and memory was allowed to exist.

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
yeah but it's funny

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

Parallel Paraplegic posted:

the only way to start it if the fob battery dies is to rub the fob against the START button for a few seconds.

text me

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

Aleksei Vasiliev posted:

http://arstechnica.com/security/2015/04/1500-ios-apps-have-https-crippling-bug-is-one-of-them-on-your-device/
iOS networking library accidentally disabled HTTPS validation, 1500 apps with ~2m installs still vulnerable

only the apps have hosed security, the rest of the system is fine

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
do they still run bofh

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

Shaggar posted:

the thing that didn't exist?

looks like someone can dish it out but can't take it

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
eve is fantastic to observe

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

Bloody posted:

goonfleet sec is certainly many standard deviations better than average

gf probably has better opsec than the militaries of several small nations, combined

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

anthonypants posted:

remember when vilerat threatened to offline core stations in illum because someone leaked his awful tattoo pic

good times

rip vr shoot blues erry day

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
wordpress is loving horseshit

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

so this is obviously a scam but I'm getting some poes law vibes too

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
like, it's bullshit just so

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

OSI bean dip posted:

http://www.telegram.com/article/20121222/APN/312229943/0


this is the guy who wants to speed up your internet and make your bits encrypted

so much for poes law then

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
ur doing the cryptolords work osi

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

Winkle-Daddy posted:

And also putting more thought into their product than the devs are. I'm not sure their thought process went beyond "get funded, cash out"

given the sort of people who back kickstarters can you blame them

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

Aleksei Vasiliev posted:

well if your internet connection is shittily routed for some reason then going through a server can make it better
i've done this using a nearby vps during times when TWC had decided to poo poo itself

in the general case it's bullshit though, and it's definitely bullshit when it's p2p

e: i hope this project succeeds and releases a product because i want to see the fallout

this is one crazy dude with a copy of premier and blender I don't think they're gonna ship even if it does hit its goal

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

Subjunctive posted:

unconsidered question: what's the relevant fact-pattern difference between the analyst firm guessing the URL for the Twitter earnings report and what weev did?

'bout 2 mil in net worth

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison



working as advertised, they no longer exist online

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
lync is a handful of good ideas mired in a swamp of bad ideas that hides the desiccated corpses of a few incredibly awful ideas

and the client is loving garbo

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

Bloody posted:

is that nadim or just one of his intellectual rivals

i think this is better than js crypto

maybe

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

vOv posted:

Hackers can turn your home computer into a BOM!

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

VaaS

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

syscall girl posted:

he also hosed someone's kitchen floor during a party, iirc

sounds like a good party

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
innguest 1 day ago | parent | on: Over 30% of Official Images in Docker Hub Contain ...

Tell me about it!
Gotta love those security experts that your company hires when they say to you "your app has a security issue right here" and I say "alright then prove it, hack it, let's see if there really is a security issue" and they can't do it.
If I don't want to worry about deployment, there's Heroku. If I don't want to worry about testing, there's Circle CI. If I don't want to worry about scaling, there's AWS EC2. If I don't want to worry about security, there's... nothing. Because it's not a real product. At least not real in the way databases, deployment, testing and scaling are.
So when people say "programmers don't care about security" I honestly don't understand what they mean since I've never seen a secure app. It's like there's this mob of believers that want to convince you security is the salvation. OK, teach me by showing. Show me a bunch of secure apps and we'll learn from it. But those don't exist, so no one ever learns, but that doesn't keep "security experts" from blaming programmers building real things in the real world for not caring about their imaginary friend.
I'll believe security experts care when they create a service and sell it for money to people like me.
reply

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

anthonypants posted:

that's my alt

@afreak
yospos security researcher @hilare_belloc just discovered one weird tip at the guardian's online bookstore, librarians hate it

i would suggest taking a closer look at the url in that tweet before you click on it tho
[/quote]

this was pretty funny because I clicked it on my phone

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
CNN reporting that 'basically every federal agency' got popped

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
hail chinese hacker satan

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

lmfao

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
if he made over 5 grand then he's looking at 10 years in jail at least

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
plus civil violations

plus mycrimes.txt

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

hobbesmaster posted:

I refuse to believe that isn't a troll

my head tells me it's fake

but my heart wants to believe

Adbot
ADBOT LOVES YOU

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

the book he wrote about this is a really good read

  • Locked thread