Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://techcrunch.com/2019/05/07/freedom-mobile-data-leak/

nothing like logging passwords in plaintext in a log collector

Adbot
ADBOT LOVES YOU

ewiley
Jul 9, 2003

More trash for the trash fire

Lain Iwakura posted:

https://techcrunch.com/2019/05/07/freedom-mobile-data-leak/

nothing like logging passwords in plaintext in a log collector

quote:

We also found full credit card numbers, expiry dates and verification numbers stored in plaintext.

None of the data was encrypted.

[PCI Compliance Intensifies]

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
fml. they have my credit card number for my mother's phone service.

welp. time for a new card.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/KateLibc/status/1125963290050359301

i'm having fun with this. i wonder what sort of sensitive data exists within

Trabisnikof
Dec 24, 2005

clearly has some bash logs in there too

haveblue
Aug 15, 2005



Toilet Rascal
I put in "butts" and it started talking about the Patriots so score one for machine learning

flakeloaf
Feb 26, 2003

Still better than android clock

Lain Iwakura posted:

https://twitter.com/KateLibc/status/1125963290050359301

i'm having fun with this. i wonder what sort of sensitive data exists within

i would prefer not to touch the poop but man is this one deep kybo maybe

Trabisnikof
Dec 24, 2005

this is probably better in the markov thread but one of my pet peeves about the GPT-2 output is it will give itself an end of text token then happily change topics and styles

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/filosottile/status/1125840275346198529

BlankSystemDaemon
Mar 13, 2009



This is probably the least surprising thing about System500.

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

here's poettering's explanation of why they didn't just use getrandom:

poettering posted:

BTW, the reason we use RDRAND in some cases instead of getrandom() [which we use in many others] is that we need to generate uuids early on (since every service we starts gets one passed, the "invocation ID", and for other stuff too), but getrandom complains in dmesg or blocks if we call it before the pool is initialized. Since systemd is one of the earliest programs that runs and thus very likely comes into contact with an uninitialized pool we attempt to avoid that by using RDRAND when generating uuids, since it should be good enough for that, as the usecase needs a "mid-quality" rng source: not crypt quality and not totally guessable either.

so is this a case of them being lazy and not doing something to get the pool initialized before calling getrandom?

Cybernetic Vermin
Apr 18, 2005

this is definitely more 'lol amd' than 'lol lennart' at any rate

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
https://twitter.com/mayorbcyoung/status/1125826676280188929

pseudorandom name
May 6, 2007

Farmer Crack-rear end posted:

here's poettering's explanation of why they didn't just use getrandom:


so is this a case of them being lazy and not doing something to get the pool initialized before calling getrandom?

ah, yes, the laziness where when the CPU says that it's high-quality random number generator works, you use the CPU's high-quality random number generator for non-cryptographic purposes

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


"please enter a memorable word in case you forget your pasword or username", ok that's dumb so ill mash the keyboard to make it a random string and put it in keepass....



:catstare:

edit: my keyboard mashing is evidently insufficiently random. Also I tried an actual word and it rejected it for having "3 or more sequential letters". Hope your memborable word doesn't contain "nop"!

Shame Boy
Mar 2, 2010

i want that database to get compromised so i can see how many people used "boners" or "weed" or "gently caress"

Potato Salad
Oct 23, 2014

nobody cares


Powerful Two-Hander posted:

"please enter a memorable word in case you forget your pasword or username", ok that's dumb so ill mash the keyboard to make it a random string and put it in keepass....



:catstare:

edit: my keyboard mashing is evidently insufficiently random. Also I tried an actual word and it rejected it for having "3 or more sequential letters". Hope your memborable word doesn't contain "nop"!

What

The

gently caress

Potato Salad
Oct 23, 2014

nobody cares


"please see 800-63b" unfortunately has repeated characters too :smithcloud:

flakeloaf
Feb 26, 2003

Still better than android clock

Powerful Two-Hander posted:

"please enter a memorable word in case you forget your pasword or username", ok that's dumb so ill mash the keyboard to make it a random string and put it in keepass....



:catstare:

edit: my keyboard mashing is evidently insufficiently random. Also I tried an actual word and it rejected it for having "3 or more sequential letters". Hope your memborable word doesn't contain "nop"!

does sequence include sequence on the keyboard? would "powerful" be no good?

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Shame Boy posted:

i want that database to get compromised so i can see how many people used "boners" or "weed" or "gently caress"

flakeloaf posted:

does sequence include sequence on the keyboard? would "powerful" be no good?

yeah i think "PowerfulWeedBoners" is ok, please don't share this though as it's secret!!!!

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
kjs500

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Powerful Two-Hander posted:

"please enter a memorable word in case you forget your pasword or username", ok that's dumb so ill mash the keyboard to make it a random string and put it in keepass....



:catstare:

edit: my keyboard mashing is evidently insufficiently random. Also I tried an actual word and it rejected it for having "3 or more sequential letters". Hope your memborable word doesn't contain "nop"!

https://www.youtube.com/watch?v=H8x6x8enzrk

Sagebrush
Feb 26, 2012

Potato Salad posted:

What

The

gently caress

take every developer and sysadmin who came up with these policies and break them upon the wheel

then replace all former password policies with "must be at least a 30-character sentence"

there, i've solved it forever. if you think typing 30 letters in a row with no mistakes is an undue hardship i hate you.

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

pseudorandom name posted:

ah, yes, the laziness where when the CPU says that it's high-quality random number generator works, you use the CPU's high-quality random number generator for non-cryptographic purposes

i was more replying to the tweet that lain embedded that implicitly criticized systemd for not just calling getrandom

Schadenboner
Aug 15, 2011

by Shine

Sagebrush posted:

take every developer and sysadmin who came up with these policies and break them upon the wheel

then replace all former password policies with "must be at least a 30-character sentence"

there, i've solved it forever. if you think typing 30 letters in a row with no mistakes is an undue hardship i hate you.

I think having to read 30 letters in a row written by you is an undue hardship, hth?

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Sagebrush posted:

take every developer and sysadmin who came up with these policies and break them upon the wheel

then replace all former password policies with "must be at least a 30-character sentence"

there, i've solved it forever. if you think typing 30 letters in a row with no mistakes is an undue hardship i hate you.


"to login, please enter characters 9, 17 and 23 of your password"

pseudorandom name
May 6, 2007

Farmer Crack-rear end posted:

i was more replying to the tweet that lain embedded that implicitly criticized systemd for not just calling getrandom

yeah that tweet was made by an idiot

Celexi
Nov 25, 2006

Slava Ukraini!

Powerful Two-Hander posted:

"to login, please enter characters 9, 17 and 23 of your password"

I really hate banks that do this

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I’m going to abuse my relationship with Lain to post a job description here. I don’t read YOSPOS anymore so PM me or sbjnctv@gmail.com if you’re a loser without plat.

I’m going to need a software developer focused on security soon. Hit me if that’s you.

- I’d be your boss’ boss, and you’ll never have as supportive a management chain as this one. I’m not kidding even a little.
- you need to make good decisions about tooling vs process vs just writing the diffs and tests yourself
- someone else handles all the certification/audit poo poo, you just deal with real problems and getting ahead of them
- our office is attached to a downtown subway station (line 1, west line best line)
- other software developers want to do a good job and will thank you for helping them not gently caress up
- when you tell a PM they shouldn’t ship because of a security issue, they listen
- strong privacy and tech ethics values, and we spend to honour them
- training? conferences? working from Tbilisi for two weeks because you’ve never been there (actual example)? tell your boss how it makes sense and sure. you’re an adult
- more than a year of runway
- actual paying customers
- you should be able to tell me about how you fixed a security fuckup and made sure it stayed fixed
- we have fired recruiting agencies for bringing us only white dudes for leadership and tech positions
- you don’t need to know about AI, but you’ll sure learn about it, including privacy and bias pieces
- talking to people (internal mostly) is part of the job. you can get coached to gently caress and back, but you can’t dodge it
- you’re moving to Toronto or convincing me that you can kick all the rear end if you’re here 1 out of 3 weeks
- your options are meaningfully in the black on day one because Canadian tax accounting is amazing

e: Lain isn’t even OP, well whatever

spankmeister
Jun 15, 2008






Mods, ban this sick filth.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

first, please spank me viciously

Schadenboner
Aug 15, 2011

by Shine
:stare:

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Subjunctive posted:

- I’d be your boss’ boss, and you’ll never have as supportive a management chain as this one. I’m not kidding even a little.
sounds good

Subjunctive posted:

- you need to make good decisions about tooling vs process vs just writing the diffs and tests yourself
keep em coming

Subjunctive posted:

- talking to people
no

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

im not canadian and have no relevant experience but the rest of that stuff sounds pretty good op

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

oh, we can do the visa thing, no question

ewiley
Jul 9, 2003

More trash for the trash fire

Subjunctive posted:

oh, we can do the visa thing, no question

Geez this is what pisses me off most about hiring in the US. "completely qualified and willing to relocate! Ooops sorry you're from outside the US, we can get you a visa in exactly never years" :sigh:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

if you can get the job, we can get you in. and if it takes a long time, we’ll pay you to work remote in the interim. we aren’t animals

Soricidus
Oct 21, 2010
freedom-hating statist shill
how many figgies

Sagebrush
Feb 26, 2012

Celexi posted:

I really hate banks that do this

the little credit union where i first got a bank account when i was a child started doing online banking about 5 years ago

the login is your account number

the password is your ATM PIN, which must be four numbers

:jeb:

i do not keep my money there these days.

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Soricidus posted:

how many figgies

a deece number, most likely

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply