Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

big black turnout posted:

Unrelatedly, what's the current best practice for identity verification and encryption for email? I know things like this exist for pgp/gpg https://pgp.mit.edu/ but my takeaway from this thread is that those aren't terribly good anymore? Is that true?

get a client cert from a CA, set all your emails to sign by default with it, if you need to encrypt the message then have the other end get their client cert and once you've exchanged signed emails the first time you have each others public keys and now you can encrypt poo poo to each other. if you're worried about your private key then password protect it in the keystore.

Adbot
ADBOT LOVES YOU

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Is there anything wrong with Enigmail for Thunderbird?

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Squeegy posted:

Is there anything wrong with Enigmail for Thunderbird?

Apart from that time it had a bug that silently failed to actually encrypt messages when you told it to? And then the dev said it wasn't an issue

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Rufus Ping posted:

Apart from that time it had a bug that silently failed to actually encrypt messages when you told it to? And then the dev said it wasn't an issue

Do tell :allears:

Tad Naff
Jul 8, 2004

I told you you'd be sorry buying an emoticon, but no, you were hung over. Well look at you now. It's not catching on at all!
:backtowork:
Regarding vansec, how long do these meetups last? I'm totally prepped to go but waiting on a thing. This is probably a dumb post since anyone concerned is already there.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

FeloniousDrunk posted:

Regarding vansec, how long do these meetups last? I'm totally prepped to go but waiting on a thing. This is probably a dumb post since anyone concerned is already there.

Usually until 9

Tad Naff
Jul 8, 2004

I told you you'd be sorry buying an emoticon, but no, you were hung over. Well look at you now. It's not catching on at all!
:backtowork:
On my way

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

https://sourceforge.net/p/enigmail/forum/support/thread/3e7268a4/

I'm wrong, it wasn't one of the devs who said people should cut them some slack over this, it was someone else

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

I'm sitting in the corner next to the open window with some guy wearing a burgundy cap

mod saas
May 4, 2004

Grimey Drawer
the media will report it as a gas leak, but we'll know the real cause of the explosion was putting security and antisecurity in such close proximity




realtalk good on you for taking the hits and deciding to learn more instead of hugboxing

Tad Naff
Jul 8, 2004

I told you you'd be sorry buying an emoticon, but no, you were hung over. Well look at you now. It's not catching on at all!
:backtowork:
Cheers Adix, found my guys. They are not currently trashing on me.

Absurd Alhazred
Mar 27, 2010

by Athanatos
The latest SMBC is appropriate:



The Infosec Thread: It's people! The security vulnerability is people!!

Double Punctuation
Dec 30, 2009

Ships were made for sinking;
Whiskey made for drinking;
If we were made of cellophane
We'd all get stinking drunk much faster!

Absurd Alhazred posted:

The latest SMBC is appropriate:



The Infosec Thread: It's people! The security vulnerability is people!!

https://www.youtube.com/watch?v=X4RuB3gT8t0

Pryor on Fire
May 14, 2013

they don't know all alien abduction experiences can be explained by people thinking saving private ryan was a documentary

Can any of you thread readers recommend a good media contact who covers security and technology? Someone who writes about incidents well and hopefully understands at least some of the technical nuance of security/encryption? Mainly looking for good writing examples to show to other people.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Pryor on Fire posted:

Can any of you thread readers recommend a good media contact who covers security and technology? Someone who writes about incidents well and hopefully understands at least some of the technical nuance of security/encryption? Mainly looking for good writing examples to show to other people.

patrick gray of risky business (radio)
matthew green
bruce schneier
joseph cox and lorenzo f-b of vice motherboard
kevin poulsen of wired
kashmir hill of fusion

comedy option: violet blue

Heresiarch
Oct 6, 2005

Literature is not exhaustible, for the sufficient and simple reason that no single book is. A book is not an isolated being: it is a relationship, an axis of innumerable relationships.
Sarah Jeong possibly? Her Twitter is mostly in-jokey stuff but her actual articles are good.

Mustache Ride
Sep 11, 2001



Brian Krebs usually does a good job with technical stuff: http://krebsonsecurity.com/

Cugel the Clever
Apr 5, 2009
I LOVE AMERICA AND CAPITALISM DESPITE BEING POOR AS FUCK. I WILL NEVER RETIRE BUT HERE'S ANOTHER 200$ FOR UKRAINE, SLAVA
For less-serious coverage, @SwiftOnSecurity is pretty amusing and is generally self-deprecating about their actual expertise.

computer toucher
Jan 8, 2012

FeloniousDrunk posted:

On the topic of password managers, I rolled my own crypto! Basically for people who don't trust LastPass etc. It runs entirely in the browser, no local storage, randomized per instance (unless choices have been made by the user).

I'd love to hear about problems it has, I haven't really put it out in the world.

Is this just a coincidence? I made this in february.

https://github.com/AnttiKurittu/pwx

Tad Naff
Jul 8, 2004

I told you you'd be sorry buying an emoticon, but no, you were hung over. Well look at you now. It's not catching on at all!
:backtowork:

computer toucher posted:

Is this just a coincidence? I made this in february.

https://github.com/AnttiKurittu/pwx

I was going to say that this was the worst possible post to make, considering. But since no-one has ripped you apart in a couple of days, I gotta say that's a good choice of name. Just make sure your project doesn't get confused with mine

Trabisnikof
Dec 24, 2005

FeloniousDrunk posted:

I was going to say that this was the worst possible post to make, considering. But since no-one has ripped you apart in a couple of days, I gotta say that's a good choice of name. Just make sure your project doesn't get confused with mine

Lol if that's your attempt at humor

Klyith
Aug 3, 2007

GBS Pledge Week

FeloniousDrunk posted:

I was going to say that this was the worst possible post to make, considering. But since no-one has ripped you apart in a couple of days, I gotta say that's a good choice of name. Just make sure your project doesn't get confused with mine

I think his thing is kinda dumb because it has the same big downside of a standard password manager*, extra restrictions that would be annoying in use**, and no upside that I can see. But it should be secure against anything but someone owning his machine.

*must-have backups of a file or your passwords are 100% gone
**no flexibility in password output if a site is retarded about requiring or rejecting characters, only way to change a password is to change your mnemonic "account name" or master password


The other difference is that he put his thing on github with a disclaimer that people shouldn't use it and probably hasn't told anyone to use it. The thread should maybe be "don't roll your own crypto if anyone is gonna use it besides your dumb self" but that won't fit in a title.

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo
Who's going to derbycon?

If anyone is going to be there tomorrow morning by 8am, me and 10 others are going on a bourbon tour and there is a couple seats open from people not being able to attend. Stopping at 6 distilleries including buffalo trace hard hat tour which I keep hearing as being a really good tour.

computer toucher
Jan 8, 2012

FeloniousDrunk posted:

I was going to say that this was the worst possible post to make, considering. But since no-one has ripped you apart in a couple of days, I gotta say that's a good choice of name. Just make sure your project doesn't get confused with mine

Mine is clearly just a proof-of-concept level programming excercise for fun, though. I did make mine in february, and it's been public since, but you can have the name if you want. I don't really care at all.

Tad Naff
Jul 8, 2004

I told you you'd be sorry buying an emoticon, but no, you were hung over. Well look at you now. It's not catching on at all!
:backtowork:

computer toucher posted:

Mine is clearly just a proof-of-concept level programming excercise for fun, though. I did make mine in february, and it's been public since, but you can have the name if you want. I don't really care at all.

Yup. I can out myself further by saying I've made various prototypes for a couple of years, but a polished turd is still a turd and I accept that. No judgement on your project. I was just making a dad-style joke that hey we both chose the same name. I've denatured my effort to the point that I don't think anyone except me would use it.

Also, trip report on vansec, it was good, I broke my wrist, I'll go again.

Cugel the Clever
Apr 5, 2009
I LOVE AMERICA AND CAPITALISM DESPITE BEING POOR AS FUCK. I WILL NEVER RETIRE BUT HERE'S ANOTHER 200$ FOR UKRAINE, SLAVA

Mustache Ride posted:

Brian Krebs usually does a good job with technical stuff: http://krebsonsecurity.com/
As of this posting, Krebs's site is down thanks to a 665Gbps 'DDoS cannon' (his term), which, I'm told, is a nothing to be scoffed at. Akamai's kicked him off their servers, because that's totally the appropriate response to incipient cyber-terrorism...
https://twitter.com/briankrebs/status/778404352285405188
https://twitter.com/briankrebs/status/779047286043185152

ming-the-mazdaless
Nov 30, 2005

Whore funded horsepower

Cugel the Clever posted:

Akamai's kicked him off their servers, because that's totally the appropriate response to incipient cyber-terrorism...


They were offering him services pro bono.

hobbesmaster
Jan 28, 2008

And Cloudflare already volunteered to be stress tested next.

CLAM DOWN
Feb 13, 2007




That's a pretty nice DDoS.

The Range
Sep 20, 2016

by WE B Bourgeois

CLAM DOWN posted:

That's a pretty nice DDoS.

Behold the face of SATAN!





https://www.youtube.com/watch?v=1eWdbMBYlH4
https://www.youtube.com/watch?v=iXZxipry6kE

slaughtered for a 5.99 dell in my pants everyone knows bill cosby is guilty no one cares Venom Prison Record: The Primal Chaos Song: Babylon the whore

Babylon the seven heads of babylon the whore

Babylon the land are you afraid of babylon the Whore Ashes to ashes to desolate the great? burning Autumn 2015 on Soaked In Torment Records.lyrics Lyrics: Babylon the great? burning the crimson rivers of blasphemy I am vengeance for countless rapes and murders
your children slaughtered for their fathers of discontent and you have no escape see the flames of discontent and you eat from my flesh I'm coming back to desolate the land are you eat from my flesh I'm coming back to desolate the land are you afraid of babylon the Whore
Babylon the Whore


Babylon The Primal Chaos Song: Babylon the whore see the whore see the seven heads of blasphemy I am vengeance for countless rapes and murders
your children slaughtered for their fathers guilt
filling the Whore burn renounced, stripped naked you eat from my flesh I'm coming back to dust witness a woman rising from the great? burning the crimson rivers of blasphemy I am vengeance for countless a woman rising from my flesh I'm coming the Whore 7" coming from my pants everyone knows bill cosby is guilty no one cares Venom Prison rivers of devout stripped naked you afraid of babylon the whore burning the shame of Mother Whore burn - watch it burn renounced, stripped naked you eat from my flesh I'm coming back to desolate the land you afraid of babylon the Whore Ashes to ashes riding upon the great? burning the flames of discontent and you have no escape see the shame of Mother Whore burn - watch it burning from my flesh I'm coming back to desolate the shame of Mother Whore see the shame of Mother Whore
Babylon the shame of Mother Whore
to hell for their father Whore
Babylon the bible is right all ******s of discontent and you have no escape see the flames of discontent and you have no escape see the shame of Mothers guilt
filling the crimson rising from my flesh I'm coming back to desolate the land are you eat from the Whore Ashes riding from my pants everyone knows bill cosby is guilty no one cares Venom Primal Chaos Song: Babylon the great?


all shall see the great? burn - watch it burn renounced, stripped naked you eat from my flesh I'm coming from the ashes dust to desolate the ashes right all ******s
your children slaughtered for countless rapes and are you afraid of babylon the great?



4. When asking a question that is specific to your situation (i.e. "help!"), please complete the following template:
Age:
Sex:
Height:
Weight:
Goals:
Diet: (list either specific meals, guidelines, or your calorie/macronutrient goals)
Exercise: (include details. Your program, how much you're lifting, how far you're running/cycling, or whatever else is applicable)
Add details. The more information, the better.
Question:









Trabisnikof
Dec 24, 2005

I'm the plasmatic scum

CLAM DOWN
Feb 13, 2007




THIS is how I find out about Brangelina?!?!?

Cugel the Clever
Apr 5, 2009
I LOVE AMERICA AND CAPITALISM DESPITE BEING POOR AS FUCK. I WILL NEVER RETIRE BUT HERE'S ANOTHER 200$ FOR UKRAINE, SLAVA

ming-the-mazdaless posted:

They were offering him services pro bono.

Ah. So much for my reading comprehension.

andrew smash
Jun 26, 2006

smooth soul

Yes, I see

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Apparently he got banned for spamming that all over

cr0y
Mar 24, 2005



Does any sort of open source two factor token exist? Or a project that can take advantage of readily available RSA tokens? I know using a cellphone is the most common 'token' but I am curious about fob that have a numerical display on them for TFA.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

cr0y posted:

Does any sort of open source two factor token exist? Or a project that can take advantage of readily available RSA tokens? I know using a cellphone is the most common 'token' but I am curious about fob that have a numerical display on them for TFA.

the standard algorithms are TOTP and HOTP via phone apps like you said

you can't reuse existing RSA fobs for your own application because each one has a shared secret burnt into it during manufacturing that you can't extract

Thanks Ants
May 21, 2004

#essereFerrari


For hardware tokens you have the Yubikey range as well

New Zealand can eat me
Aug 29, 2008

:matters:


It's awesome/terrible/sad that these unprecedented DDoS attacks are coming from hordes of unsecured webcams and such (supposedly?)

The Internet of Things is awesome

Adbot
ADBOT LOVES YOU

Sleeper Pimp
Nov 2, 2006

Ess Jay SCHARKS DAWT COM
I deal mostly with bug bounty submissions. Am I allowed to drink with all you folks? (I need a drink.)

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply