Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Carbon dioxide
Oct 9, 2012

So, Facebook felt it was necessary to "correct" some Belgian security report which showed that Facebook sucks.

https://newsroom.fb.com/news/h/setting-the-record-straight-on-a-belgian-academic-report/

It's quite funny, really, lots of weaseling.

quote:

Facebook does receive standard “web impressions,” or website visit information, when people visit sites with our plugins or other integrations. The authors misleadingly call this “tracking.”
Misleadingly?

quote:

Claim: Facebook wants to use Social Plugins to add cookies to the browsers of people who don’t use Facebook.

Fact: We don’t, and this is not our practice. However, the researchers did find a bug that may have sent cookies to some people when they weren’t on Facebook. This was not our intention – a fix for this is already under way.
Ah. It was not their intention that the 'bug' would be found. They're fixing it so the 'bug' can't be found by outside researchers any more.
Additionally, they say nothing about tracking non-Facebook users using other methods, without cookies. Such as IP-based tracking, which certainly happens.

quote:

Fact: You can opt out of having your social actions paired with ads.
Fact: they'll randomly opt you back in without telling you whenever they update their systems.

This Richard Allan figure would make a very good politician.

Adbot
ADBOT LOVES YOU

Carbon dioxide
Oct 9, 2012

Cocoa Crispies posted:

somebody almost got expelled for clicking around in the Network Neighborhood

Back in my high school, it was fine to play browser games or do whatever on the library computers, as long as there weren't any kids waiting to use the computers for actual school work. They usually didn't even mind if you hacked it somewhat, because that allowed the IT guy to see where he could improve the system security.

I got detention once, for subverting their block on chat protocols. I think I managed to log in to MSN Messenger or somesuch. I got detention because chatting from the school computers was absolutely banned. They said the reason was that online communities are full of rapists and the school didn't want any possibility of being held responsible if someone meets their future rapist online.

Carbon dioxide
Oct 9, 2012

Reminds me, one time I got a mail on my university students mail account, but it was sent to some kind of old 'allthepeople@science...' address that everyone had forgotten about or something. It was some message from the univ's central administration to the folks running the science department.

Some other student replied that it wasn't meant for them... and this message appeared into my account too. After that people figured out quickly that anyone could send messages to that address and they would be received by all students, and possibly by staff too.

So a bunch of students started posting memes and stuff, it quickly devolved into some FYAD-like poo poo, with the occassional person asking if everyone would PLEASE STOP. It got to multiple messages per second. I quickly made a mail filter, dumping it all in some separate folder. The tsunami of mails suddenly stopped after an hour and a half or so and we never heard anything about it anymore.

Carbon dioxide
Oct 9, 2012

minivanmegafun posted:

"keyboarding" was a requirement to graduate high school (I graduated in 2002). you could test out of it, but I flunked the test three times.

know why?

because they required you to format a table in Word using tabs instead of the table feature, and having never been trained on a typewriter I had nfc how to do that :mad:

You can't even do that in Word unless you manually make a bunch of tab stops. Without that, tabs seem to be somewhat random in Word.

Carbon dioxide
Oct 9, 2012

I'd like you to 'edit' a 'batch file' at my place

Carbon dioxide
Oct 9, 2012

The coming two days, the city of The Hague will be hosting the "Global Conference on Cyberspace 2015". It's basically a massive meeting of politicians that are responsible for internet regulations and stuff in their respective countries. Other than politicians from most countries, there will be folks from tech companies and a bunch of NGOs.

It's treated like quite a big deal.

A few examples from their programme:

- Lunch panel on 'Cyber warfare and jus in bello'
- FOCUS SESSION : International peace and security in cyberspace
- Parallel Session : Rethinking the social impact of new cyber technologies
- Parallel Session : Exploring the best (and most fun) tools in cyber security education

And so on.

The city government of The Hague is saying they did all they could to make sure the cybersecurity during the cyberspace conference will be up to cyberstandards, because they're afraid people are going to test their security during the conference.

Another, more important piece of news, is that the folks on the conference will officially announce the formation of a "Global Forum on Cyber Expertise". The idea is that countries are scared their confidential data will leak when third world governments with worse cyber security get hacked and are used as a point of entry to secure information. So this global forum will share tips on how to secure government systems with countries that have less cyberexpertise.

:words:, but I'm interested to see how many gently caress-ups will happen in The Hague tomorrow.

Carbon dioxide
Oct 9, 2012

In case you care... Wikileaks published a whole lot of Sony hack stuff.

Carbon dioxide
Oct 9, 2012

http://www.devttys0.com/2015/04/what-the-ridiculous-gently caress-d-link/

quote:

...their patch to prevent an unauthenticated sprintf stack overflow includes a new unauthenticated sprintf stack overflow.

But here’s the kicker: this patch does nothing to prevent unauthenticated users from executing completely valid administrative HNAP actions, because all it does is ensure that the HNAP action is valid. That’s right, their patch doesn’t even address all the bugs listed in their own security advisory!

Carbon dioxide
Oct 9, 2012


That post was like 5 pages ago.

Carbon dioxide
Oct 9, 2012

Subjunctive posted:

isn't that sort of a problem if you get pulled over? can you just say "well, the police recommended that I not have my registration in the car, sorry officer"?

The idea is you keep it on your person. So you can show it when you get pulled over, but it's never in your car when it's parked.

Carbon dioxide
Oct 9, 2012

This bug severely reduces the maximum possible 'uptime' of a plane.

Carbon dioxide
Oct 9, 2012

Oh come on, the folks on the ISS just use regular Dell laptops or something.

Carbon dioxide
Oct 9, 2012

See THESE VERY LETTERS?

They radiate at you.

Carbon dioxide
Oct 9, 2012

Boeing also said they are working on a software update to fix this bug. The update will be distributed later this year. It is, as of yet, unclear whether it will be distributed over-the-air.

Carbon dioxide
Oct 9, 2012

spankmeister posted:

i know exactly where you stole that joke from buddy

Original content do not steal

Carbon dioxide
Oct 9, 2012

Yeah, if they don't hire me because I don't have a facebook, I don't want to work there either.

Remember, the more accounts Facebook has, the more money they get from advertisers. I don't want them to get any money through me, so I won't make an account. Not even a fake or empty one.

Carbon dioxide
Oct 9, 2012

Carbon dioxide
Oct 9, 2012

Not sure if everyone sees this but...



Good job.

Carbon dioxide
Oct 9, 2012

OSI bean dip posted:

what browser/os?

Win 7 Firefox here.

Carbon dioxide
Oct 9, 2012

minato posted:

Wonder what happens when they visit this account: https://twitter.com/glitchr_
♡╰̩̩̩̩̩̻̍̍̍̍̍̊●̩̩̩̩̩̩̩̻̍̍̍̍̍̍̍̊ᴗ̩̩̩̩̩̩̩̩̩̩̪̺̍̍̍̍̍̍̍̍̍̍̆̑●̩̩̩̩̩̩̩̻̍̍̍̍̍̍̍̊╯̩̩̩̩̩̩̻̍̍̍̍̍̊♡

Edit:
𝐆𝐋𝐈𝐓𝐂𝐇𝐑 ᏀᏞᎥᎢᏟᎻᎡ 𝗚𝗟𝗜𝗧𝗖𝗛𝗥 𝖦𝖫𝖨𝖳𝖢𝖧𝖱 𝔊𝔏i𝔗𝔠𝔥𝔯 𝙶𝙻𝙸𝚃𝙲𝙷𝚁 ɢʟɪᴛᴄʜʀ 𝔾𝕃𝕀𝕋𝕔𝕙𝕣 ᴳᴸᴵᵀᶜᴴᴿ ᴳˡᴵᵗᶜ.ͪᵣ

Carbon dioxide fucked around with this message at 10:39 on Jun 6, 2015

Carbon dioxide
Oct 9, 2012

Mr.Radar posted:

lol samsung found a way to put an rce in the loving stock keyboard of their android skin


the article contains a list of affected devices and carriers (since carriers customize the firmware); pretty much all of the galaxy s devices since the s4 are affected and probably more.

Phew, I still got an S3 nothing can hurt me.

Carbon dioxide
Oct 9, 2012

I got that once. Oldish lady I knew through some forum and had shared contact info with at one point. Started getting spams from her e-mail address. So I notified her in an IM and added some basic tips on how to reset passwords and 'secret questions' poo poo (hotmail...).

She got angry at me, I didn't understand why, but I kinda wanted her to stop sending spams to me. So I pressed on, trying to stay polite despite her anger, but she only got more and more angry.

After a while it became clear what was going on. She claimed she already knew about it and had reset her password, and she knew what she was doing and she certainly didn't need no insolent kid tell her what to do, she could've been my mother and yadayada. A bit after that she let slip that some 'tech guy' (I think it was some neighbourhood kid) helped her out.

I don't know what they did but I still get spams from that same account every month or so. Oh well, my spam filter works perfectly fine.

Carbon dioxide
Oct 9, 2012

Aleksei Vasiliev posted:

if you DOS the entertainment system do the pilots lose contact with the tower or is that off-plane thing just internet or whatever

I might be wrong, but I believe the pilots have access to some ancient analog system called a... what's the word again? Rodeo? Radio!

Carbon dioxide
Oct 9, 2012

Remember, there's no penalty for submitting a false DMCA claim. Or millions or false DMCA claims. It's up to the webhost receiving the claims to sort them out.

Not removing copyrighted materials in time does have a penalty: you get sued by powerful and rich companies. The law is rather imbalanced.

I think in theory it wouldn't be illegal for a company to ask for a processing fee for every single DMCA claim... but as long as Google and the other big ones don't do that, doing so would put you in a bad position too.

Carbon dioxide
Oct 9, 2012

Speaking of buttcoins

https://twitter.com/MikeTyson/status/624986928690036737 wtf??

Carbon dioxide
Oct 9, 2012

We're in luck!

To turn off the microsoft thing, the SSID has to include _optout
To turn off the google maps thing, the SSID has to end on _nomap

So, SSID_optout_nomap is valid, while SSID_nomap_optout isn't.

:eng99:

Carbon dioxide
Oct 9, 2012

Jabor posted:

The dirty secret about wifi scanning is that your device will happily tell anyone who's listening about all the wifi networks it wants to automatically connect to :ssh:

Yep. Tiny devices such as the wifi pineapple will listen in and go: "Oh, you're looking for Pentagon_guest? That's cool. I am actually Pentagon_guest. Password please?" and I don't know if security has improved, but I know that older devices would happily give up all information required to login to that wifi network.

Carbon dioxide
Oct 9, 2012


Carbon dioxide
Oct 9, 2012

Unhackable, like the Titanic was unsinkable.

Carbon dioxide
Oct 9, 2012

See, if I *were* to kill myself in Nevada, I'd make sure to do it in such a way that the sensors of all the UFO spotters around area 51 go crazy, making them think the War of the Worlds has begun.

Carbon dioxide
Oct 9, 2012

I can't find an English report yet, but according to a Dutch tech news site, someone at Black Hat talked about an intel cpu vulnerability that allows installation of rootkits, that among other things can gently caress up your energy management and heat up your computer until it catches fire.

https://tweakers.net/nieuws/104636/architectuurfout-in-oudere-x86-cpus-intel-maakt-rootkit-mogelijk.html

Carbon dioxide
Oct 9, 2012

JumpinJackFlash posted:

DND is filled with stupid assholes

Very true. The map thread is the only good thread in that whole forum. It's mostly non DND-folks nerding about maps. Doesn't really belong in that subforum but it's there so meh. I can reach it through my bookmarked threads without ever having to enter DND itself.

Carbon dioxide
Oct 9, 2012

So, the free wifi aboard Dutch trains is open and unsecured. Not a surprise, and it's stated in the terms you have to agree with whenever you connect.

Someone living near a railway decided to listen in, and keep stats of what phones are used to access what servers/websites. Tuesday at 5 pm is the busiest time of the week, and there are twice as many apple phone connections than android connections.

Live updates here: http://trainwatch.u0d.de/

Carbon dioxide fucked around with this message at 15:38 on Aug 9, 2015

Carbon dioxide
Oct 9, 2012

This might be useful to someone. https://github.com/shutterstock/List-of-Dirty-Naughty-Obscene-and-Otherwise-Bad-Words/blob/master/en

Carbon dioxide
Oct 9, 2012

pr0zac posted:

this is probably the best talk to come out of blackhat so far this year: https://github.com/xoreaxeaxeax/sinkhole/blob/master/us-15-Domas-TheMemorySinkhole.pdf

i understand approximately 15% of the content and am still blown away

"The memory sinkhole" is an appropriate name. That embedded pdf viewer in github manages to crash both Firefox and Chrome after filling up a crapload of RAM.

E: Alright, downloaded it. Interesting, if complicated, read. How the gently caress can anybody make sense of assembly code at all?

Here's a short article about the vuln: https://techreport.com/news/28784/vulnerability-in-older-intel-cpus-gives-away-the-keys-to-the-kingdom

Carbon dioxide fucked around with this message at 08:33 on Aug 11, 2015

Carbon dioxide
Oct 9, 2012

scottch posted:

lol post is gone. is there a copy anywhere?

https://web.archive.org/web/20150811052336/https://blogs.oracle.com/maryanndavidson/entry/no_you_really_can_t

Bunch of news sources also picked it up.

E: vvv lol

Carbon dioxide fucked around with this message at 13:20 on Aug 11, 2015

Carbon dioxide
Oct 9, 2012

Aleksei Vasiliev posted:

https://twitter.com/lorenzoFB/status/631151628436000769
apparently the opinions of oracle's CSO do not represent oracle's views, so they removed the post


e: how do i install security updates without accidentally upgrading to win10, it keeps trying to trick me into it

Bigger problem, I would upgrade to Win10 but can't because their installer doesn't have proper error handling (yes, I looked in the error logs for the problem, tried the possible solutions from the internet, nothing worked). But it still keeps showing up in the Win Update thing, taking priority over Win 7 updates. Microsoft, fix your poo poo.

Carbon dioxide
Oct 9, 2012

computer toucher posted:

<bigger sigh> yes, dear, but that's not the problem with the article. <sighs again, covers face with hands, slumps a little bit>

<sigh>

Is that CSO a zombie?

Carbon dioxide
Oct 9, 2012

Nintendo Kid posted:

no, the fbi filters are the most effective way to keep cp off of the site, other than using another government's filters if you really wanted to.

Do non-american sites use fbi's filters?

Adbot
ADBOT LOVES YOU

Carbon dioxide
Oct 9, 2012

Triglav posted:

um why does the fbi have child porn? dont they know its bad and illegal?

There are people out there who investigate everything on the internet that's illegal, horrible, and disgusting, in order to get the people creating that stuff locked up.

A lot of those people develop PTSD-like problems after a while. There's an article and a youtube clip out there about people in Latin America that're hired by Facebook and the like to check reported images and delete the illegal stuff. They get a rather low wage... and most can't keep it up for more than a few months or so, it's more traumatizing than you'd think.

I respect those folks.

  • Locked thread