Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



BIGFOOT EROTICA posted:

to be fair I don't think the button on any smoke detector ive ever owned actually silences the loving thing

the button is for testing, at least is on the one i have

Adbot
ADBOT LOVES YOU

Soricidus
Oct 21, 2010
freedom-hating statist shill

Applebees posted:

Is this default behaviour of cat useful for anything other than tricking people?

it’s kind of what cat is supposed to do, yes? like its primary purpose is to read a series of bytes from a series of files, and output them as a single series of bytes (hence the name, from concatenate). it doesn’t modify those bytes by default because it doesn’t know what you’re using them for and it prefers not to guess.

and there are certain to be people who take advantage of terminal escape sequences to insert colors etc into text files.

cybrancyborg
Jan 24, 2008

How this ends still hasn't been unwritten...

duz posted:

probably, i know i have to keep acknowledging that it is insecure for it to display anything

We're supposed to use the most insecure settings possible, to minimize the inconvenience of using Java 7 on IE 11 on Windows 10.
And the internal Kronos team refuses to update it, and C-suite won't make them, even after having one of my supers present a list of 70+ critical CVEs for JRE 1.7.0u9 at the last security meeting! :thumbsup:

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Krankenstyle posted:

the button is for testing, at least is on the one i have

I've been buying these for my rental, seem to work well enough for a cheapo that dipshit college kids will tamper with and they silence when you press the button.

https://www.amazon.com/gp/product/B0725519PH/ref=ppx_yo_dt_b_asin_title_o01_s00?ie=UTF8&psc=1

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

cybrancyborg posted:

We're supposed to use the most insecure settings possible, to minimize the inconvenience of using Java 7 on IE 11 on Windows 10.
And the internal Kronos team refuses to update it, and C-suite won't make them, even after having one of my supers present a list of 70+ critical CVEs for JRE 1.7.0u9 at the last security meeting! :thumbsup:

If you want to mitigate on the client side, push settings that crank up the JRE default security level to Highest (defaults to either high or medium) which should put it in a mode where it will only invoke jars with user consent or auto-launch if they're in the trusted url list

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

BIGFOOT EROTICA posted:

to be fair I don't think the button on any smoke detector ive ever owned actually silences the loving thing

my Nest Protect's button silences, which is good because by the time the app realizes that it's part of a universe containing my smoke detector the time between warning and bleating has long elapsed. love the "you're too far to silence" when I am literally in physical contact with the smoke detector

Soricidus posted:

it’s kind of what cat is supposed to do, yes? like its primary purpose is to read a series of bytes from a series of files, and output them as a single series of bytes (hence the name, from concatenate).

you are philosophically right, but it's named after catenate, which is the reason that I even know that that word exists

cybrancyborg posted:

We're supposed to use the most insecure settings possible, to minimize the inconvenience of using Java 7 on IE 11 on Windows 10.
And the internal Kronos team refuses to update it, and C-suite won't make them, even after having one of my supers present a list of 70+ critical CVEs for JRE 1.7.0u9 at the last security meeting! :thumbsup:

we had this problem at FB after we banned Java in the wake of a targeted Java zero-day (which I assume cost $0.83 including tax). finance got some VMs issued that were extremely restricted in terms of what they could talk to, and Java was put on there. they got reimaged after every use and so forth.

unrelatedly, a lot of people used Windows VMs just to run the Windows version of Outlook, because the Mac one was so incredibly, bogglingly awful

Shaggar
Apr 26, 2006

BangersInMyKnickers posted:

If you want to mitigate on the client side, push settings that crank up the JRE default security level to Highest (defaults to either high or medium) which should put it in a mode where it will only invoke jars with user consent or auto-launch if they're in the trusted url list

I had to do this for ADP etime cause their poo poo is garbage. last year they finally built an html version of everything so we're totally off of client side java, but it was just so dumb. adp didn't even sign their jars

Shame Boy
Mar 2, 2010

Krankenstyle posted:

the button is for testing, at least is on the one i have

on the ones in my apartment, if you hit the button when it's not going off it tests it, if you hit it when it is going off it silences it except for a periodic chirp to let you know it's still worried...

... for like, 2-3 minutes, and then it resets and if you haven't cleared sufficient amounts of the smoke it starts going again, which is real fun

Vomik
Jul 29, 2003

This post is dedicated to the brave Mujahideen fighters of Afghanistan

BangersInMyKnickers posted:

I've been buying these for my rental, seem to work well enough for a cheapo that dipshit college kids will tamper with and they silence when you press the button.

https://www.amazon.com/gp/product/B0725519PH/ref=ppx_yo_dt_b_asin_title_o01_s00?ie=UTF8&psc=1

looks like we got ourselves a slum lord fellas *rolls out guillotine*

Shame Boy
Mar 2, 2010

BangersInMyKnickers posted:

I've been buying these for my rental, seem to work well enough for a cheapo that dipshit college kids will tamper with and they silence when you press the button.

https://www.amazon.com/gp/product/B0725519PH/ref=ppx_yo_dt_b_asin_title_o01_s00?ie=UTF8&psc=1

guillotine etc but also

amazon posted:

Environment friendly, without smell, radiation or harm

are smoke detectors known for their bad smell?

flakeloaf
Feb 26, 2003

Still better than android clock

"it smells bad" is a common complaint when ordering plastic things from china but i gotta admit that's the first time i've heard it about a smoke detector

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

Subjunctive posted:

my Nest Protect's button silences, which is good because by the time the app realizes that it's part of a universe containing my smoke detector the time between warning and bleating has long elapsed. love the "you're too far to silence" when I am literally in physical contact with the smoke detector


you are philosophically right, but it's named after catenate, which is the reason that I even know that that word exists


we had this problem at FB after we banned Java in the wake of a targeted Java zero-day (which I assume cost $0.83 including tax). finance got some VMs issued that were extremely restricted in terms of what they could talk to, and Java was put on there. they got reimaged after every use and so forth.

unrelatedly, a lot of people used Windows VMs just to run the Windows version of Outlook, because the Mac one was so incredibly, bogglingly awful

if your main job includes outlook, word and/or excel you really just should use a windows machine

Shaggar
Apr 26, 2006
so any job, basically.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

I tried this the day it came out, I'll see if I can get this working in the lab today.

cybrancyborg
Jan 24, 2008

How this ends still hasn't been unwritten...

BangersInMyKnickers posted:

If you want to mitigate on the client side, push settings that crank up the JRE default security level to Highest (defaults to either high or medium) which should put it in a mode where it will only invoke jars with user consent or auto-launch if they're in the trusted url list

Users complained or or declined at the prompt (and then complained the site wouldn't load), so our official procedure is to specifically select all the least secure settings!
As for using trusted URLs, not sure, the decisions were made long before I got here.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

cybrancyborg posted:

Users complained or or declined at the prompt (and then complained the site wouldn't load), so our official procedure is to specifically select all the least secure settings!
As for using trusted URLs, not sure, the decisions were made long before I got here.

lol rip

cybrancyborg
Jan 24, 2008

How this ends still hasn't been unwritten...

My only hope is that MS will someday break compatibility w/ Java 7 on Win10, but since they seem pretty okay with Windows being a sort of Katamari for bugs, it's a very faint hope.

Shame Boy
Mar 2, 2010

there was just a show on the radio talking about how companies and organizations are afraid to come forward and say in public that they got ransomware'd because there's lots of "victim blaming" and people will jump to point out stuff they could have done but didn't, as an example they were talking about baltimore and how they were hit with something that had been patched for over two loving years but also they just couldn't "afford security" so something something

won't someone please think of the innocent corporations and city governments whose feelings are hurt when you mean old security researchers do stuff like "point out that this was trivially preventable" or "demand even basic levels of competence when dealing with something critically important"? you're all monsters :colbert:

Cybernetic Vermin
Apr 18, 2005

weeeell, i don't doubt that local government does indeed struggle with security for reasons not entirely in their control, and in fact agree that the culture around the ongoing security catastrophy we all inhabit is part of the problem.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

cybrancyborg posted:

My only hope is that MS will someday break compatibility w/ Java 7 on Win10, but since they seem pretty okay with Windows being a sort of Katamari for bugs, it's a very faint hope.

edge was sorta that but lol whoops

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


Cybernetic Vermin posted:

weeeell, i don't doubt that local government does indeed struggle with security for reasons not entirely in their control, and in fact agree that the culture around the ongoing security catastrophy we all inhabit is part of the problem.

its purely a cost issue

quote:

Baltimore's information security manager warned of the need for such a policy during budget hearings last year. But the final budget did not include funds for that policy, nor did it include funding for expanded security training for city employees, or other strategic investments that were part of the mayor's strategic plan for the city's information technology infrastructure.

Cybernetic Vermin
Apr 18, 2005

duz posted:

its purely a cost issue

well, that is one read, but there may need to be a larger shift in approach, it might not be reasonable to expect that "security expertise" should be a funded line item in every budget, while e.g. the local school children go hungry

not to lay the blame at the feet of security professionals, but the framing of the problem is not good.

Shame Boy
Mar 2, 2010

Cybernetic Vermin posted:

weeeell, i don't doubt that local government does indeed struggle with security for reasons not entirely in their control, and in fact agree that the culture around the ongoing security catastrophy we all inhabit is part of the problem.

yeah but the actual "victim" usually isn't the company or government or w/e, it's the people who use their services, who now have their information stolen or in baltimore's case can't pay water bills or finalize real estate deals or anything else that requires computer systems.

like yeah if it was just some dude who lost all their poo poo then showing up and being all "well you should have known better :smug:" would be a huge dick move, but I think it's totally fair to criticize companies and governments. frankly if you don't have the budget to [hire a dude that can tell you to] update your 2+ year out of date windows installs that should be auto-updating anyway then you also don't have the budget to offer the online services in the first place. security really needs to be viewed as a non-negotiable part of the cost - you're either paying for the security stuff to be done right or you're paying (in baltimore's case) $20 million to unfuck everything once ransomware hits, but you're paying either way.

Shame Boy
Mar 2, 2010

Cybernetic Vermin posted:

well, that is one read, but there may need to be a larger shift in approach, it might not be reasonable to expect that "security expertise" should be a funded line item in every budget, while e.g. the local school children go hungry

not to lay the blame at the feet of security professionals, but the framing of the problem is not good.

if it comes down to that then you need to shut down the entire system and use the money to feed the kids :shrug:

Shaggar
Apr 26, 2006
there are plenty of other parts in the budget you can take from before taking from kids.

Shaggar
Apr 26, 2006
also in plenty of cases its not even cost, but cold hard incompetence that causes this stuff to happen.

LanceHunter
Nov 12, 2016

Beautiful People Club


Shaggar posted:

there are plenty of other parts in the budget you can take from before taking from kids.

Seriously, we’re talking about Baltimore here. The hundreds of thousands that were getting diverted to purchasing copies of the mayor’s children’s book probably would have covered it.

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Shame Boy posted:

if it comes down to that then you need to shut down the entire system and use the money to feed the kids :shrug:

it might not be exactly what you're looking for, but have your heard of A Song of Wire and Omar, by David R R Simon??

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



the gods will not save you

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Lutha Mahtin posted:

it might not be exactly what you're looking for, but have your heard of A Song of Wire and Omar, by David R R Simon??

:yosnice:

Partycat
Oct 25, 2004

https://twitter.com/bad_packets/status/1135282810938224642?s=21

hackers have taken over instant gram by blue screening google BGP routers with RDP or some bullshit

e: :eyeroll:

Partycat fucked around with this message at 23:22 on Jun 13, 2019

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



got a phishing mail with a weird reply-to field

Only registered members can see post attachments!

WilWheaton
Oct 11, 2006

It'd be hard to get bored on this ship!
im the admin@mudwhole.com

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang




textemail me again

Carbon dioxide
Oct 9, 2012

Krankenstyle posted:

got a phishing mail with a weird reply-to field



Hey, I got that too.
The message body is empty (or stripped by gmail somehow?) and the subject says gently caress YOU!! I HATE YOU....

Oh, I got another one that does have phishing content and doesn't swear.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Krankenstyle posted:

got a phishing mail with a weird reply-to field



late 90s grunge band webring member spotted

evil_bunnY
Apr 2, 2003

Lutha Mahtin posted:

it might not be exactly what you're looking for, but have your heard of A Song of Wire and Omar, by David R R Simon??
:kiss:

namlosh
Feb 11, 2014

I name this haircut "The Sad Rhino".

Krankenstyle posted:

got a phishing mail with a weird reply-to field



that looks like the kind of thing I’d see back when “no-delivery report” dos’ were a thing using smtp servers

evil_bunnY
Apr 2, 2003

duz posted:

its purely a cost issue

duz posted:

Baltimore's information security manager warned of the need for such a policy during budget hearings last year. But the final budget did not include funds for that policy, nor did it include funding for expanded security training for city employees, or other strategic investments that were part of the mayor's strategic plan for the city's information technology infrastructure.

That's 100% a management/politics issue, not a cost issue.

Adbot
ADBOT LOVES YOU

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



carcetti :argh:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply