Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Schadenboner
Aug 15, 2011

by Shine

Soricidus posted:

amber stylesheet

:vomarine:

Adbot
ADBOT LOVES YOU

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD

COACHS SPORT BAR posted:

so what's the best E2E encrypted chat with a desktop client not written in electron these days

lol j/k i know there aren't any, ftge

messenger is getting a desktop client shortly

4lokos basilisk
Jul 17, 2008


~Coxy posted:

messenger is getting a desktop client shortly

you can also have messenger run in Franz (https://meetfranz.com/), which is just basically loading the web messenger in an iframe or something similar

ewiley
Jul 9, 2003

More trash for the trash fire
https://twitter.com/ashu_barot/status/1129081068819058688?s=20

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

lmao

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



lol that owns, literally

burning swine
May 26, 2004




goddamn

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

brutal

flakeloaf
Feb 26, 2003

Still better than android clock

hello police a man hacked our gibson and whatsapped me proof

BlankSystemDaemon
Mar 13, 2009



In what may be either news to me or news to someone else, Microsoft apparently doesn't/didn't use AES+HMAC for communicating between the CPU and TPM on systems using BitLocker, which means that it's possible (and easy, since it's a slow datastream) to grab data in-flight.
Has anyone heard about this?

Lightbulb Out
Apr 28, 2006

slack jawed yokel

D. Ebdrup posted:

In what may be either news to me or news to someone else, Microsoft apparently doesn't/didn't use AES+HMAC for communicating between the CPU and TPM on systems using BitLocker, which means that it's possible (and easy, since it's a slow datastream) to grab data in-flight.
Has anyone heard about this?

Yes, you can allegedly get the BitLocker key by tapping into the LPC bus.

haveblue
Aug 15, 2005



Toilet Rascal
they learned nothing from the xbox (the first xbox, which was called the xbox 1)

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

haveblue posted:

they learned nothing from the xbox (the first xbox, which was called the xbox 1)

which was probably designed at the same time as modern tpm poo poo

Miss Mowcher
Jul 24, 2007

Ribbit
Trying to make reservations for a hotel they asked me to send my credit card number and expiry date via e-mail ("Only as a guarantee, payment done in place")

This is a hotel from a big chain, how do they not have some better way for making reservations

Varkk
Apr 17, 2004

Because they don’t need to. After all it costs the company money to implement something new and companies rarely get punished for losing client data.

ewiley
Jul 9, 2003

More trash for the trash fire

ZZZorcerer posted:

Trying to make reservations for a hotel they asked me to send my credit card number and expiry date via e-mail ("Only as a guarantee, payment done in place")

This is a hotel from a big chain, how do they not have some better way for making reservations

We have a DLP notifications mailbox that gets copied every time it detects ssn's and cc's. This is depressingly common

chemosh6969
Jul 3, 2004

code:
cat /dev/null > /etc/professionalism

I am in fact a massive asswagon.
Do not let me touch computer.

ZZZorcerer posted:

Trying to make reservations for a hotel they asked me to send my credit card number and expiry date via e-mail ("Only as a guarantee, payment done in place")

This is a hotel from a big chain, how do they not have some better way for making reservations

One big chain still uses a 4 digit pin instead of a password. Then I searched online and people are always getting their accounts hacked and losing all their points but it looks like customer service restores them after they check things out for a bit. They seem to be more than used to it.

ewiley
Jul 9, 2003

More trash for the trash fire

LOL whats worse loss of confidentiality or loss of availability, CISSP go!

https://www.zdnet.com/article/faulty-database-script-brings-salesforce-to-its-knees/

e: duh didn't mean to quote

jre
Sep 2, 2011

To the cloud ?



ZZZorcerer posted:

Trying to make reservations for a hotel they asked me to send my credit card number and expiry date via e-mail ("Only as a guarantee, payment done in place")

This is a hotel from a big chain, how do they not have some better way for making reservations

Huge amounts of hotel booking websites ultimately fax your card details to the front desk fax machine :shepicide:

The banks are finally making them fix this by hiking the merchant rates if you don't use tokenisation

Cybernetic Vermin
Apr 18, 2005

jre posted:

Huge amounts of hotel booking websites ultimately fax your card details to the front desk fax machine :shepicide:

The banks are finally making them fix this by hiking the merchant rates if you don't use tokenisation

it is sort of key to credit cards precisely that your liability is limited to leave it up to the merchants and credit card company to fight out how to keep things reasonably balanced ease/safety

Potato Salad
Oct 23, 2014

nobody cares


These days, safer is often easier too.

inertia is a property of matter

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Potato Salad posted:

inertia is a property of matter

lol I can't read that without thinking of "bill maher the n-word guy"

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Cocoa Crispies posted:

lol I can't read that without thinking of "bill maher the n-word guy"

but lets not forget who the real n words are folks: the republicans :smuggo:

Carbon dioxide
Oct 9, 2012

Privacy fuckup: https://www.cnbc.com/2019/05/17/google-gmail-tracks-purchase-history-how-to-delete-it.html

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Those sure are some pearls this guy is clutching, having written this well after Inbox shut down.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Volmarias posted:

Those sure are some pearls this guy is clutching, having written this well after Inbox shut down.

It is sort of a bad privacy UI choice that you couldn’t remove the extracted purchases entries without deleting the email. The purchases list is functionally the same as a cached search over the mail store, but how hard it is to retrieve and compute on a piece of data turns out to be a significant practical factor in privacy at scale. People are rightly sensitive to “it’s in there somewhere” vs “it’s easy to access in a structured form”. We need more analysis of privacy elements from widely used products, even if those products have been shut down. People shouldn’t forget the lessons of Beacon either.

I do notice that it’s common for companies like G and FB to say whether they use a given datum to target ads, but don’t speak more generally about whether the data is used for anything other than convenient presentation to the user.

Soricidus
Oct 21, 2010
freedom-hating statist shill

my favorite thing about living in an eu country is going to articles like this that are all "omg google is bad because they track you to sell ads" and then at the bottom of the page there's a popup saying "btw we track you to sell ads"

mystes
May 31, 2006

Subjunctive posted:


I do notice that it’s common for companies like G and FB to say whether they use a given datum to target ads, but don’t speak more generally about whether the data is used for anything other than convenient presentation to the user.
Yeah. It's impossible to tell from their response whether this is a feature they thought would actually be useful and they just forgot to tell anyone, or if it only exists so they can point to it later and say we should already know they're tracking this stuff.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Volmarias posted:

Those sure are some pearls this guy is clutching, having written this well after Inbox shut down.

idk about inbox but my purchases page has a bunch of purchases, newest at 4 days ago and going back to 2013. not nearly all of them though, so hey at least their algorithm sucks

e: also the data for the last "page" (its endless scrolling or whatever its called) shows up twice lol

Carthag Tuek fucked around with this message at 19:24 on May 19, 2019

BlankSystemDaemon
Mar 13, 2009



Sharepoint attacks are starting to happen in the wild.

Midjack
Dec 24, 2007



someone finally found a use for sharepoint

Phone
Jul 30, 2005

親子丼をほしい。

Midjack posted:

someone finally found a use for sharepoint

sharesploit

flakeloaf
Feb 26, 2003

Still better than android clock

Midjack posted:

someone finally found a use for sharepoint

shared point of entry

post hole digger
Mar 21, 2011


lmao

Shame Boy
Mar 2, 2010

oh hey i got a variant of the "i have your password honest!!!" spam emails that assumes i'm a woman, how novel. most of it is the same but some of it is fun:

quote:

Hello, minx!
...
I scanned your hard drive and found enough of your frank and very sexy photos to be surprised.
Oh yeah! You are beautiful and amazing. I would not mind having an affair with you but I need the funds.
...
Be clever girl!

Your respectable observer.

it also goes into more effort than usual to explain how hacking works in simple stupid terms because girls r dum after all

Raere
Dec 13, 2007

Shame Boy posted:

oh hey i got a variant of the "i have your password honest!!!" spam emails that assumes i'm a woman, how novel. most of it is the same but some of it is fun:


it also goes into more effort than usual to explain how hacking works in simple stupid terms because girls r dum after all

E-mail's not believable because affair implies the person is already married and everyone knows hackers are sad incels

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
i bet scamming like that is an entertaining career. just constantly grifting people, you probably run into a different situation every day.

actually thinking about it i envy the person who has that job

LIVE AMMO COSPLAY
Feb 3, 2006

Spam... for women.

Is the spammer doing gender marketing or just being horny?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
those bitcoin extortion messages are gender targeted (presumably based on the email address)

Adbot
ADBOT LOVES YOU

Sereri
Sep 30, 2008

awwwrigami

LIVE AMMO ROLEPLAY posted:

Spam... for women.

Is the spammer doing gender marketing or just being horny?

spam that listens to you and asks you how your day was

I'd prefer that over mails from Brian telling me to buy Bitcoin like his friend Tim who is rich now and drat he missed out.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply