Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Tad Naff
Jul 8, 2004

I told you you'd be sorry buying an emoticon, but no, you were hung over. Well look at you now. It's not catching on at all!
:backtowork:
Well this has all been educational. I was just about to throw in something that would obfuscate the id's in the injected HTML, but using caller.toString() is ... pretty devastating since there would always be some signature. Can't think of a way around that without going into extension territory, yeah. The reason I didn't go with extensions was because of the polymorphic "feature", it would be hard to distribute an extension that's different for every user through standard means.

Ah well. Don't roll your own crypto, folks.

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

CLAM DOWN posted:

poo poo, I definitely can't make anything this week, then I'm at SANS the following. How often do these happen?

On the 2nd Thursday of each month.

nem
Jan 4, 2003

panel.dev
apnscp: cPanel evolved
What are the downsides, apart from signer key compromise, to issuing software licenses as X509 certificates and encoding license capabilities as OIDs in its extended attributes? I'm moving forward with licensing the panel shortly and everything in my head clicks to use X509 to handle panel licensing:
  • serial numbers
  • expiry dates
  • tamper proof
  • revocation
  • unable to reproduce without signer key
  • ability to store license-specific data

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Rufus Ping posted:

i mean seriously, if there are people out there who don't trust proper password managers but do trust some pile of poo poo w3schools-quality javascript bookmarklet written by local helpdesk janitor Tod McRetard, then your response shouldn't be to indulge their stupidity

brutal, but fair

ming-the-mazdaless
Nov 30, 2005

Whore funded horsepower

Dex posted:

brutal, but fair

Honest is not brutal.
This kind of poo poo is the curse of IT and Info Sec.

PBS
Sep 21, 2015

ming-the-mazdaless posted:

Honest is not brutal.
This kind of poo poo is the curse of IT and Info Sec.

It's definitely brutal. It being honest or a curse to IT/InfoSec doesn't change that.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


ming-the-mazdaless posted:

Honest is not brutal.
This kind of poo poo is the curse of IT and Info Sec.

It's literally called "brutal honesty" you dork

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

ming-the-mazdaless posted:

Honest is not brutal.
This kind of poo poo is the curse of IT and Info Sec.

I like to think I provided a decent amount of actual feedback and criticism before taking the piss out of him

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Rufus Ping posted:

I like to think I provided a decent amount of actual feedback and criticism before taking the piss out of him

Your wind-up was exemplary.

jre
Sep 2, 2011

To the cloud ?



ming-the-mazdaless posted:

Honest is not brutal.
This kind of poo poo is the curse of IT and Info Sec.

If you unironically post awful home made crypto in a thread with "DONT ROLL YOUR OWN CRYPTO" in the title, you are going to get lit up :shrug:

Tad Naff
Jul 8, 2004

I told you you'd be sorry buying an emoticon, but no, you were hung over. Well look at you now. It's not catching on at all!
:backtowork:
I think for all the fun I have provided I at least deserve a red text. Also, the project lives on, with hazard warnings, because I am a) a dumbass and b) it's useful for other ideas (no crypto). I'd also like to thank all of you for your mostly helpful and not at all calling me an idiot feedback. Special thanks for the PoC and explanation which I have understood. As my username implies, I do get ideas that are not quite rational from time to time.

So. If the bookmarklet calls a secure service to obtain a salt

Absurd Alhazred
Mar 27, 2010

by Athanatos

FeloniousDrunk posted:

I think for all the fun I have provided I at least deserve a red text. Also, the project lives on, with hazard warnings, because I am a) a dumbass and b) it's useful for other ideas (no crypto). I'd also like to thank all of you for your mostly helpful and not at all calling me an idiot feedback. Special thanks for the PoC and explanation which I have understood. As my username implies, I do get ideas that are not quite rational from time to time.

So. If the bookmarklet calls a secure service to obtain a salt

How about you pay for your own red text? :ms:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

FeloniousDrunk posted:

I think for all the fun I have provided I at least deserve a red text. Also, the project lives on, with hazard warnings, because I am a) a dumbass and b) it's useful for other ideas (no crypto). I'd also like to thank all of you for your mostly helpful and not at all calling me an idiot feedback. Special thanks for the PoC and explanation which I have understood. As my username implies, I do get ideas that are not quite rational from time to time.

So. If the bookmarklet calls a secure service to obtain a salt

Please come out to this sometime:
http://vansec.org

CLAM DOWN
Feb 13, 2007




OSI bean dip posted:

Please come out to this sometime:
http://vansec.org

I'll definitely be at the next one, mainly because discussion of CSOX is discouraged.

Tad Naff
Jul 8, 2004

I told you you'd be sorry buying an emoticon, but no, you were hung over. Well look at you now. It's not catching on at all!
:backtowork:

OSI bean dip posted:

Please come out to this sometime:
http://vansec.org

Kind of afraid I'm being set up for a huge embarrassment. But hey, I just did this, so how much worse could it be. I shall attempt to be there. I will be likely trying to lurk, unnoticed.

CLAM DOWN
Feb 13, 2007




FeloniousDrunk posted:

Kind of afraid I'm being set up for a huge embarrassment. But hey, I just did this, so how much worse could it be. I shall attempt to be there. I will be likely trying to lurk, unnoticed.

You got rightfully poo poo all over in this thread, but if you have a desire to learn more about crypto, don't stop experimenting (just don't pretend you'll publicly release anything) and definitely meet and talk to others in the same industry! Just don't use any open wifi networks in the same meetup spot though.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
It helps to ask questions. I don't invite people to these events to have them embarrassed as I'd rather see people learn than anything else.

That said, I have had to walk away from a conversation at this event because some dimwit tried to talk me up into this idea of rewriting Wi-Fi drivers so he could implement a paywall wireless network solution.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


OSI bean dip posted:

It helps to ask questions. I don't invite people to these events to have them embarrassed as I'd rather see people learn than anything else.

That said, I have had to walk away from a conversation at this event because some dimwit tried to talk me up into this idea of rewriting Wi-Fi drivers so he could implement a paywall wireless network solution.

:psyduck:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
Oh. It involved Bitcoin too.

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

FeloniousDrunk posted:

Also, the project lives on, with hazard warnings, because I am a) a dumbass and b) it's useful for other ideas (no crypto)

Just take it down. You might have realized being wrong, but someone else might get the wrong idea, even if you have a warning on the page.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

keseph posted:

My limited understanding of it is:
Copy-On-Write writes against deduped memory are (sometimes, potentially) slightly slower than writes against non-deduped memory. If you can measure that difference successfully on memory entirely inside your VM, you can privately deduce that it's enabled on the host. You can then load up the public key you're interested in and check if it ever hits the same slowdown, implying that some other VM has the same key loaded and deduped with yours. Since the key is much bigger than a single dedupe block, you can test against one chunk of the key and establish a high degree of confidence that the remainder of the key is aligned with and has been deduped against yours. Since you're allowed to read that deduped block, you can see exactly what bits were flipped, attempt a connection to the victim and see if its public key now matches your flip.

A big thing to keep in mind is that the code checking and trying to exploit this doesn't have to get it right on the first shot. If it checks a hundred times and fails 99 times, it still got a successful alignment and exploit on that hundredth time and up until the very end there is no sign on the victim that anything is happening. If attacking SSH, your victim's public keys would suddenly change to unrecognized values which could be detected by the victim's monitoring tools, but this has most of the typical benefits of an offline attack and is really only relying on a more surreptitious final attack and improvements to its probability of success.

De-dupe isn't real-time though. New writes in VMware go against free pages and then a background host process generates hashes asynchronously for possible hits and does a final comparison before dropping and remapping the duplicate pages. Write latency is going to be further impacted by large vs small pages being allocated (depending on host load, dedupe only kicks in by default at 80%+ host utilization) and by that threshold you're dipping in to the memory balloon, mem compression, and potentially swapping which would further make write latency a useless metric.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

FeloniousDrunk posted:

Also, the project lives on, with hazard warnings

Delete it. It's literally a danger to people's security to have it exist, even with warnings. Hopefully after your experience here you understand why.

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

FeloniousDrunk posted:

Kind of afraid I'm being set up for a huge embarrassment. But hey, I just did this, so how much worse could it be. I shall attempt to be there. I will be likely trying to lurk, unnoticed.

It's probably hard to believe but security nerds are generally a lot nicer in real life than online.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


pr0zac posted:

It's probably hard to believe but security nerds are generally a lot nicer in real life than online.

No way computer geeks talk tougher on the Internet than face-to-face.

taqueso
Mar 8, 2004


:911:
:wookie: :thermidor: :wookie:
:dehumanize:

:pirate::hf::tinfoil:

Squeegy posted:

No way computer geeks talk tougher on the Internet than face-to-face.

What the gently caress did you just loving say about me, you little bitch? I’ll have you know I graduated top of my class in the Navy Seals, and

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

pr0zac posted:

It's probably hard to believe but security nerds are generally a lot nicer in real life than online.

At work, I have to deal with certain people who don't see security with any semblance of importance and in turn end up creating barriers that impede me or my team's ability to make improvements or determine problems. This is a common problem with any security operations team, but when it comes up during incident response scenarios, it's incredibly grating. With all of that frustration, it doesn't make things better to go and piss off those individuals so usually you have to build up social capital and then expend it when you run across these things. It's something I have the patience for at work because I get paid enough to not make it a problem.

On the Internet I don't need to worry about that. However, I won't chew someone out unless it is deserved.

Cowboy Mark
Sep 9, 2001

Grimey Drawer
A vendor pitched this 1million bit encryption thingy to us:

http://www.cubeitz.com/next-level-security/

:raise:

FlyingCowOfDoom
Aug 1, 2003

let the beat drop

flosofl posted:


You can PM me as well. I've had the GCIH, GPEN, GCFA since around 2005 and GAWN since 2010. I did let the GPEN and GCFA bunch lapse recently (I've only kept the GAWN), but I'm going to be doing some challenges next year and take some of their newer courses as well.


Thank you guys for the info and offering help, it is greatly appreciated!!

Thanks Ants
May 21, 2004

#essereFerrari


Cowboy Mark posted:

A vendor pitched this 1million bit encryption thingy to us:

http://www.cubeitz.com/next-level-security/

:raise:

https://beta.companieshouse.gov.uk/company/08045866

Let's start there

And seriously, what vendor decided that is something to try and pitch to their customers?

Thanks Ants fucked around with this message at 21:52 on Sep 7, 2016

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

OSI bean dip posted:

Please come out to this sometime:
http://vansec.org

Need one of these in Edmonton, yarr.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Thanks Ants posted:

https://beta.companieshouse.gov.uk/company/08045866

Let's start there

And seriously, what vendor decided that is something to try and pitch to their customers?

https://securitysnakeoil.org/

It'll likely be posted about here.

apropos man
Sep 5, 2016

You get a hundred and forty one thousand years and you're out in eight!
Quote:

"CubeiTz does not use ANY of this underlying technology... "

Underneath mentioning vulnerabilities in C.

Impressive that they've written a whole secure OS that doesn't use anything from the Windows/NT stack, Linux kernel OR Mac kernel! Way to go, guys.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

apropos man posted:

Quote:

"CubeiTz does not use ANY of this underlying technology... "

Underneath mentioning vulnerabilities in C.

Impressive that they've written a whole secure OS that doesn't use anything from the Windows/NT stack, Linux kernel OR Mac kernel! Way to go, guys.

It's written in RealBASIC

Tad Naff
Jul 8, 2004

I told you you'd be sorry buying an emoticon, but no, you were hung over. Well look at you now. It's not catching on at all!
:backtowork:
At least I'm not that guy.

On another note, "2nd Thursday" being tomorrow?

I have trouble with 0 and 1 apparently

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

FeloniousDrunk posted:

At least I'm not that guy.

On another note, "2nd Thursday" being tomorrow?

I have trouble with 0 and 1 apparently

Yes.

Tad Naff
Jul 8, 2004

I told you you'd be sorry buying an emoticon, but no, you were hung over. Well look at you now. It's not catching on at all!
:backtowork:

Sweet. I'll be the long haired old guy just trying to fit in, you know the type.

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

FeloniousDrunk posted:

Sweet. I'll be the long haired old guy just trying to fit in, you know the type.

Turns out Felonious is secretly

everyone in this thread just immediately super owned.

Tad Naff
Jul 8, 2004

I told you you'd be sorry buying an emoticon, but no, you were hung over. Well look at you now. It's not catching on at all!
:backtowork:
A little more like



But less attractive

big black turnout
Jan 13, 2009



Fallen Rib

CLAM DOWN posted:

This is about Windows 10 though, why would you still be on 8.1

If you're like me, its because even though the automated update process interrupted me doing things several times on two separate machines, it always ended with it automatically rolling back to 8.1 with a failed install




Unrelatedly, what's the current best practice for identity verification and encryption for email? I know things like this exist for pgp/gpg https://pgp.mit.edu/ but my takeaway from this thread is that those aren't terribly good anymore? Is that true?

Adbot
ADBOT LOVES YOU

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


big black turnout posted:

If you're like me, its because even though the automated update process interrupted me doing things several times on two separate machines, it always ended with it automatically rolling back to 8.1 with a failed install

Personally I'm only on 8.1 because my computer's manufacturer doesn't make drivers for 7.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply