Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Subjunctive
Sep 12, 2006

✨sparkle and shine✨

flakeloaf posted:

"we rolled our own security"

“our developers are very clever”

Adbot
ADBOT LOVES YOU

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
very clever, but it's exploits all the way down

crazysim
May 23, 2004
I AM SOOOOO GAY

taking a page from prince

burning swine
May 26, 2004



quote:

We chose to communicate 😾😾😾 through a visual representation of symbols, rather than “words.” Naming vulnerabilities using emoji sequences instead of other pronounceable natural languages have several advantages. First, emoji sequences are universally understood across nearly all natural languages. Choosing 😾😾😾 instead of a name rooted in any one language ensures that the technical contents of our research can be discussed democratically and without latent cultural or linguistic bias. Second, emojis are indexical to the digital age. Third, clear communication is the foundation of friendship, and such a foundation must begin with proper ontological agreement. Just as the universal language of mathematics is largely expressed through interlinguistic symbology, so too is 😾😾😾. Fourth, cats are seen as almost paradoxical beings. While they exist in our lives as the ultimate creatures of leisure, cats are also fierce predators. “Cats are the most highly specialized of the terrestrial flesh-eating mammals. They are powerfully built, with a large brain and strong teeth. The teeth are adapted to three functions: stabbing (canines), anchoring (canines), and cutting (carnassial molars).” (Lariviere, Serge; Stains, Howard James. “Feline.” Encyclopedia Britannica. Feline). For an incomplete list of felines in various mythologies, see this webpage.

:stare:

I was going to trim this down to just the insane bits but it turned out to be all insane bits

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


idk my cat is kind of a dick but he's never hacked my router


... as far as I know

Kazinsal
Dec 13, 2011



tres gatos enojados posted:

An attacker with root privileges on the device can modify the contents of the FPGA anchor bitstream, which is stored unprotected in flash memory.

wait hold up, you need root access?

so, you need to have already pwned the box?

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
yes but youre still not supposed to be able to do that even as root

Computer Serf
May 14, 2005
Buglord
:tinfoil:

Only registered members can see post attachments!

ate shit on live tv
Feb 15, 2004

by Azathoth

Kazinsal posted:

wait hold up, you need root access?

so, you need to have already pwned the box?

You need root to compromise the box. But once the box is compromised the equivalent of a format and reinstall, won't uncompromise it. So for cisco specifically, you could install untrusted software on the router, then ship it to the target, and they would have no way to detect the software was compromised.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

ate poo poo on live tv posted:

You need root to compromise the box. But once the box is compromised the equivalent of a format and reinstall, won't uncompromise it. So for cisco specifically, you could install untrusted software on the router, then ship it to the target, and they would have no way to detect the software was compromised.

or ever fix it, *kiss noise*

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

COACHS SPORT BAR posted:

:stare:

I was going to trim this down to just the insane bits but it turned out to be all insane bits

that's a lot of words to say there to say "we're trying to downplay this as much as possible so we made the official name ungoogleable"

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slćgt skal fřlge slćgters gang



Perplx posted:

that's a lot of words to say there to say "we're trying to downplay this as much as possible so we made the official name ungoogleable"

you can google emojis tho i think it translates them to their unicode description

https://www.google.com/search?q=%F0%9F%92%A9&ie=UTF-8&oe=UTF-8

post hole digger
Mar 21, 2011


lol

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

NSA <3 Cisco :nsa:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Beautiful

moonshine is......
Feb 21, 2007

i'm looking for a video that was posted in this thread awhile back, it was a pretty funny guy talking about why sockets/IoT was bad iirc, he's also done talks on why blockchain isn't the end all be all solution, and javascript. unfortunately i can't remember his name, or the title of any of the videos. if someone could help me out that would be pretty great.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
James Mickens?

30 TO 50 FERAL HOG
Mar 2, 2005



I love that talk so much

https://twitter.com/omgbeckilee/status/631127484898148353?s=20

moonshine is......
Feb 21, 2007

yeah, that's what i'm looking for. Love his talks, always forget his name.

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

so my executive got a cold call sales email from our current vpn appliance vendor identifying our current firewall mfr and product family (based on ‘research’) helpfully letting us know that gartner doesn’t think the firewall vendor is cutting edge and that they are

im pretty sure they fingerprinted it from the vpn appliance inside my net

bye

Shame Boy
Mar 2, 2010

PCjr sidecar posted:

so my executive got a cold call sales email from our current vpn appliance vendor identifying our current firewall mfr and product family (based on ‘research’) helpfully letting us know that gartner doesn’t think the firewall vendor is cutting edge and that they are

im pretty sure they fingerprinted it from the vpn appliance inside my net

bye

see this is what i always imagined would happen if you don't uncheck that "send anonymous data to help us make our products better" box in every single piece of software

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Shame Boy posted:

see this is what i always imagined would happen if you don't uncheck that "send anonymous data to help us make our products better" box in every single piece of software

yeah that box is unchecked lol

gonna bet there’s one line in the eula that allows it

Wiggly Wayne DDS
Sep 11, 2010



PCjr sidecar posted:

yeah that box is unchecked lol

gonna bet there’s one line in the eula that allows it
ah so you opted out of it being anonymous

Shame Boy
Mar 2, 2010

Wiggly Wayne DDS posted:

ah so you opted out of it being anonymous

:argh:

ewiley
Jul 9, 2003

More trash for the trash fire

Shame Boy posted:

see this is what i always imagined would happen if you don't uncheck that "send anonymous data to help us make our products better" box in every single piece of software

I am certified in checkbox unchecking, or checking in this case.

Midjack
Dec 24, 2007



uncheck yourself before you wreck yourself

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

Midjack posted:

uncheck yourself before you wreck yourself install mcaffee

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Midjack posted:

uncheck yourself before you wreck yourself

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
:rip:

https://twitter.com/briankrebs/status/1132026003386241029

Wiggly Wayne DDS
Sep 11, 2010



what year is it

FMguru
Sep 10, 2003

peed on;
sexually

Wiggly Wayne DDS posted:

what year is it
not much, what year is it with you?

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

today is the first 0day of the rest of your life

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Wiggly Wayne DDS posted:

what year is it

Gonna answer this repeatedly with different years to hear all your replies

power botton
Nov 2, 2011

didn't chase or capital one or some bank let you just type in someone else account number once you were logged in a few years ago

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
i remember a british bank forgot to key their http cache on the logged in userid and customers suddenly started seeing other peoples account details

spankmeister
Jun 15, 2008






iirc steam had the same issue too a couple years back

Proteus Jones
Feb 28, 2013



spankmeister posted:

iirc steam had the same issue too a couple years back

Steam was leaking mortgage information and SSNs? drat.

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Proteus Jones posted:

Steam was leaking mortgage information and SSNs? drat.

valve's coders during the early years of steam were just that good

power botton
Nov 2, 2011

Rufus Ping posted:

i remember a british bank forgot to key their http cache on the logged in userid and customers suddenly started seeing other peoples account details

https://nypost.com/2018/02/22/chase-says-glitch-gave-customers-access-to-wrong-accounts/

apparently that's popular. this is probably what I was thinking of.

Adbot
ADBOT LOVES YOU

LIVE AMMO COSPLAY
Feb 3, 2006

spankmeister posted:

iirc steam had the same issue too a couple years back

Pretty sure it happened on Christmas day too.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply