Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

CRIP EATIN BREAD posted:

it’s not a security fuckup (yet) but being asked about how to rebuild a bunch of docker containers to enable the FIPS module for OpenSSL seems like it’s a start in the right direction.

yeah fips is crusty as hell. I'm glad they're thinking about it but you can do a lot better with a little effort

Adbot
ADBOT LOVES YOU

evil_bunnY
Apr 2, 2003

CRIP EATIN BREAD posted:

also had a question from the sysadmin on the other side ask us if we can enable LUKS inside our containers.
time for prodin'

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

CRIP EATIN BREAD posted:

it’s not a security fuckup (yet) but being asked about how to rebuild a bunch of docker containers to enable the FIPS module for OpenSSL seems like it’s a start in the right direction.


BangersInMyKnickers posted:

yeah fips is crusty as hell. I'm glad they're thinking about it but you can do a lot better with a little effort

itym fipsmode is the greatest

evil_bunnY
Apr 2, 2003

Cocoa Crispies posted:

itym fipsmode is the greatest
I made this joke at work and got called names :D

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
its hilarious because not only do they want fips enabled SSL, they want it on a postgres server, but also don't want to be bothered to maintain a CA or anything like that.

they also do not know how x509 works, or how the certificates are used.

Wiggly Wayne DDS
Sep 11, 2010



some interesting malware:
https://twitter.com/matthieu_faou/status/1032256075821666304

https://www.welivesecurity.com/wp-content/uploads/2018/08/Eset-Turla-Outlook-Backdoor.pdf posted:

Turla developers like to use less common or modified encryption algorithms in their backdoors:
  • For Carbon and Snake, they used CAST-128 [11]
  • For Gazer, they used a custom implementation of RSA [12]
  • For Mosquito, they used Blum Blum Shub as the random number generator for their XOR byte stream [13]
  • For the Uroburos rootkit, they used a modified version of ThreeFish [14]
In the Outlook backdoor, they implemented MISTY1 [15], which is a symmetric encryption algorithm created by cryptographers from Mitsubishi Electric in 1995.
...
However, Turla developers have slightly modified the algorithm:
  • They added two XOR operations in the FI function, as shown in Figure 25
  • The 128–bit key is generated from two hardcoded 1024–bit keys plus a 2048–bit Initialization Vector.
  • They changed the s7 and s9 tables. This breaks all the tools that recognize cryptographic algorithms based on the s-table values. Both the modified and original s-tables contain the same values. They were simply shuffled.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I really hope more places start rolling app locker. Unsigned/arbitrary code is a nightmare

hobbesmaster
Jan 28, 2008

Subjunctive posted:

the good news is that on all the embedded poo poo that’s really hard to update there will tend to be fixed and known usernames, so not much is lost there

marketing at a recent presentation to sales: "top issues for iot buyers: 1. lack of a business model 2. lack of funding 3. lack of standards security was not a top issue"

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

BangersInMyKnickers posted:

I really hope more places start rolling crypto locker. Unencrypted/arbitrary files are a nightmare

Shaggar
Apr 26, 2006

lol forever @ open sores "security"

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

they should also include an accuracy bar so you know when you're getting closer to guessing the username or password

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

BangersInMyKnickers posted:

yeah fips is crusty as hell. I'm glad they're thinking about it but you can do a lot better with a little effort

the only people i know* who still insist on fips are banks/financial companies whose csos still love using the words "military grade encryption". like you say, it's not actually a bad baseline but afaik still allows quite a lot of old broken poo poo through while disallowing newer, better stuff (does it still say "yeah 3des is fine"?)

* admittedly i don't deal with us.gov, who i assume still at least pretend to use it?

Soricidus
Oct 21, 2010
freedom-hating statist shill

BangersInMyKnickers posted:

I really hope more places start rolling app locker. Unsigned/arbitrary code is a nightmare

the implementation of applocker is terrible though. luv 2 linearly scan huge directories on every single process start without any form of caching or optimisation. I sure hope the security-related parts of it were designed with more thoughtful attention to detail

ate shit on live tv
Feb 15, 2004

by Azathoth

BangersInMyKnickers posted:

they should also include an accuracy bar so you know when you're getting closer to guessing the username or password

Perhaps the protocol could implement a mastermind like password retrieval system to help people that forget their passwords?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Soricidus posted:

the implementation of applocker is terrible though. luv 2 linearly scan huge directories on every single process start without any form of caching or optimisation. I sure hope the security-related parts of it were designed with more thoughtful attention to detail

do it by validating code signatures and its trivial. make your vendors sign their poo poo

ate shit on live tv
Feb 15, 2004

by Azathoth
Unrelated but since I'm going to australia I'm going to change all my passwords to this: ƐᄅƖpɹoʍssɐd

According to esteemed security checking site https://howsecureismypassword.net it would take 8 quadrillion years to brute force.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

goddamnedtwisto posted:

the only people i know* who still insist on fips are banks/financial companies whose csos still love using the words "military grade encryption". like you say, it's not actually a bad baseline but afaik still allows quite a lot of old broken poo poo through while disallowing newer, better stuff (does it still say "yeah 3des is fine"?)

* admittedly i don't deal with us.gov, who i assume still at least pretend to use it?

the DISA STIGs for windows want it on c.f. https://iase.disa.mil/stigs/gpo/Pages/index.aspx

but idk it's probably 100% dependent on if anyone actually checks the settings, and whatever cert & accreditation process they follow says that someone can sign for it if it's not enabled so w/e

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

goddamnedtwisto posted:

* admittedly i don't deal with us.gov, who i assume still at least pretend to use it?

3DES is still secure from a technical standpoint and about as good as AES128. It's good enough and allows for backwards compatibility with XP/2003 (unless you installed the optional 2003 hot fix to install AES128) so it isn't going anywhere soon. Its slow compared to AES with -NI offload which is why RC4 was the primary backwards compatibility cipher for so long.

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

BangersInMyKnickers posted:

3DES is still secure from a technical standpoint and about as good as AES128. It's good enough and allows for backwards compatibility with XP/2003 (unless you installed the optional 2003 hot fix to install AES128) so it isn't going anywhere soon. Its slow compared to AES with -NI offload which is why RC4 was the primary backwards compatibility cipher for so long.

oh yeah, how could i forget? i wonder how much critical infrastructure around the world is still running on software old enough to vote?

evil_bunnY
Apr 2, 2003

all
of
it

Soricidus
Oct 21, 2010
freedom-hating statist shill

goddamnedtwisto posted:

oh yeah, how could i forget? i wonder how much critical infrastructure around the world is still running on software old enough to vote?

hopefully less than before wannacry


... ok I’m not even fooling myself

Carbon dioxide
Oct 9, 2012

https://www.zdnet.com/article/philips-reveals-code-execution-vulnerabilities-in-cardiovascular-devices/

haveblue
Aug 15, 2005



Toilet Rascal

shame the name heartbleed was taken

James Baud
May 24, 2015

by LITERALLY AN ADMIN

ate poo poo on live tv posted:

Cool security fuckup.

https://www.bleepingcomputer.com/news/security/vulnerability-affects-all-openssh-versions-released-in-the-past-two-decades/

quote:

Username enumeration bug discovered in OpenSSH
This particular bug was discovered last week by security researchers from Qualys who spotted a commit in OpenBSD's OpenSSH source code.

After analyzing the commit, researchers realized that the code inadvertently fixed a security bug lying dormant in the OpenSSH client since its creation.


Inadvertently my rear end. The commit message itself referenced a reasonably well known security researcher. Who decided to use that phrase in this article?

BlankSystemDaemon
Mar 13, 2009



BlackHat is envious of the rest of the industy having secfucks, so it wants its own: https://ninja.style/post/bcard/
Here's a tidbit:

quote:

To my surprise, I was able to pull my attendee data completely unauthenticated over this API.

quote:

The rate at which we were able to brute force the API would mean that we could successfully collect all BlackHat 2018 registered attendees’ names, email addresses, company names, phone numbers, and addresses in only approximately 6 hours.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

D. Ebdrup posted:

BlackHat is envious of the rest of the industy having secfucks, so it wants its own: https://ninja.style/post/bcard/
Here's a tidbit:

black hat is part of the rest of the tech conference industry

abigserve
Sep 13, 2009

this is a better avatar than what I had before

ate all the Oreos posted:

great advice thanks

that advice is actively malicious holy poo poo

"yeah a bug in openssh allows people to brute force usernames, what you should do is turn off the functionality that prevents them from brute forcing passwords as well"

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/hanno/status/1032510153273290754

Proteus Jones
Feb 28, 2013




*Still* with the Ghostscript?

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



James Baud posted:

Inadvertently my rear end. The commit message itself referenced a reasonably well known security researcher. Who decided to use that phrase in this article?

lol yea as I read it, the commit is intended to fix that very issue, like that is its entire purpose

wtf does the article author think was the point

Carthag Tuek fucked around with this message at 12:00 on Aug 23, 2018

Wiggly Wayne DDS
Sep 11, 2010



followup
https://twitter.com/hanno/status/1032612415068889090

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

that is a very distro thing to do

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

with compiled it with the -NoSecurity flag for your benefit

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

is there an easy way in redhat to interrogate if a process is using the nx bit?

Truga
May 4, 2014
Lipstick Apathy

Subjunctive posted:

that is a very distro thing to do

in gentoo i have to --funroll-loops and --no-security to get more juice out of my ricer mods, ubuntu just pre-packages all the rice

Shame Boy
Mar 2, 2010

Truga posted:

in gentoo i have to --funroll-loops and --no-security to get more juice out of my ricer mods, ubuntu just pre-packages all the rice

i mean why wouldn't you want everything compiled with fun roll loops enabled, whee

30 TO 50 FERAL HOG
Mar 2, 2005



BangersInMyKnickers posted:

I really hope more places start rolling app locker. Unsigned/arbitrary code is a nightmare

gonna be great when the new windows comes out and they have a level above enterprise that you have to purchase to use it

cinci zoo sniper
Mar 15, 2013




BIGFOOT EROTICA posted:

gonna be great when the new windows comes out and they have a level above enterprise that you have to purchase to use it

windows 10.1 enterprise pro

Schadenboner
Aug 15, 2011

by Shine

cinci zoo sniper posted:

windows 10.1 enterprise pro

For Business

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




Schadenboner posted:

For Business

365

  • Locked thread