Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
The Fool
Oct 16, 2003


Lutha Mahtin posted:

you could have the tv connect to a dummy network that is physically disconnected from the internet but then you're just wasting electricity because it probably tries to ping home 1000 times a minute

or, like my phone, sees that it doesn't have internet then disconnects from the network

which makes it really hard to configure devices over wifi

Adbot
ADBOT LOVES YOU

Partycat
Oct 25, 2004

Boiled Water posted:

Disabled hasn't meant disabled in a while.

Only move is to open the tv and remove the chip.

the TV is differently abled

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

i used to work in group homes, and i have a lot of friends who have braniac academic degrees, and the universal response among all these people is "wait... you can FIX that?" when i describe a two-minute fix that will make their internet-connected device be 99% less annoying

Vomik
Jul 29, 2003

This post is dedicated to the brave Mujahideen fighters of Afghanistan

Lutha Mahtin posted:

i used to work in group homes, and i have a lot of friends who have braniac academic degrees, and the universal response among all these people is "wait... you can FIX that?" when i describe a two-minute fix that will make their internet-connected device be 99% less annoying

this is why I tell people don’t try to go to medical school or go into research. instead install Linux during high school so you can troubleshoot with the best of them

Truga
May 4, 2014
Lipstick Apathy
just buy a computer monitor at this point, it's a bit more expensive but you don't get a pile of junk in your display.

well, different pile of junk, anyway. i'm sure g-sync also phones home through the drivers somehow these days

ate shit on live tv
Feb 15, 2004

by Azathoth
Can you even get 4K 55" OLED Monitors? Or even just 4K OLED?

Tankakern
Jul 25, 2007

D. Ebdrup posted:

I did the next best thing; got a small machine to use as a HTPC, and put FreeBSD with kodi and wayland on it. I just wish the PC was passively cooled. :sigh:

why the hell would you use freebsd instead of linux

do you like your fans going 100 % all the time while watching youtube

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Tankakern posted:

do you like your fans going 100 % all the time while watching youtube

Don't you judge how I watch garbage videos

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Tankakern posted:

why the hell would you use freebsd instead of linux

do you like your fans going 100 % all the time while watching youtube

maybe he doesn't own a hair drier

Wild EEPROM
Jul 29, 2011


oh, my, god. Becky, look at her bitrate.
just look at the staggering number of people who still have the iPhone wifi dialog pop up enabled.

every time you’re not connected to wifi and it spots an open wifi, HEY WANNA CONNEXT TO SOME WIFIS

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD

Wild EEPROM posted:

just look at the staggering number of people who still have the iPhone wifi dialog pop up enabled.

every time you’re not connected to wifi and it spots an open wifi, HEY WANNA CONNEXT TO SOME WIFIS

this should default to off now that everyone has 4G with decent data caps

ios has so much jank in it left behind from the 2008 days that they've never revisited

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://www.yubico.com/support/security-advisories/ysa-2019-02/

quote:

An issue exists in the YubiKey FIPS Series devices with firmware version 4.4.2 or 4.4.4 (there is no released firmware version 4.4.3) where random values leveraged in some YubiKey FIPS applications contain reduced randomness for the first operations performed after YubiKey FIPS power-up. The buffer holding random values contains some predictable content left over from the FIPS power-up self-tests which could affect cryptographic operations which require random data until the predictable content is exhausted. This issue occurs only during the power-up of the YubiKey FIPS Series, version 4.4.2 or 4.4.4. After the predictable content in the random buffer is consumed, the buffer will be filled with the intended full random number generator output, and all subsequent use of randomness will not be affected.

For RSA key generation on the YubiKey FIPS Series, the RSA key may be impacted by up to 80 predictable bits out of a minimum of 2048 bits (length will depend on user configuration). We believe 80 predictable bits does not make it imminently possible for an attacker to obtain the private key material or decrypt data that has been encrypted to a key created in this way. During RSA key generation only a portion of these bits may be used, which could further reduce the impact on the algorithm’s output.

For ECDSA signatures, the nonce K becomes significantly biased with up to 80 of the 256 bits being static, resulting in weakened signatures. This could allow an attacker who gains access to several signatures to reconstruct the private key.

For ECC key generation on the YubiKey FIPS Series, the key may be impacted by up to 80 predictable bits out of the minimum 256 bit key length.

For ECC encryption,16 bits of the private key becomes known. For secp256r1 private keys, the key may be impacted by 16 predictable bits, reducing the number of unknown bits in the key from 256 to 240 bits. Similarly, for impacted secp384r1 private keys, the number of unknown bits in the key is reduced from 384 to 368 bits. 240 bit keys are not known to be defeated at the time of this advisory.

Raere
Dec 13, 2007

Thank goodness for FIPS

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

~Coxy posted:

this should default to off now that everyone has 4G with decent data caps

ios has so much jank in it left behind from the 2008 days that they've never revisited

an old boss used to complain about how his Bluetooth discovery thing would constantly pop up. I'm like yeah if only there was a way of turning that off...

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Raere posted:

Thank goodness for FIPS

FIPS mode is the greatest

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

I love everything about hosed up RNGs that leads to hardware recalls, like the previous yubikey 4 vuln

https://crocs.fi.muni.cz/public/papers/rsa_ccs17

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
it's a good thing we have an elaborate and expensive certification process to ensure that cryptographic solutions work correctly and aren't broken.

it would really suck if it was just bureaucratic horseshit that made it very expensive to create compliant implementations while not actually providing any meaningful benefit

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD

Chris Knight posted:

an old boss used to complain about how his Bluetooth discovery thing would constantly pop up. I'm like yeah if only there was a way of turning that off...

I actually got a full-screen popup (is this a special W1 thing?) for a Beats Solo 3 this morning on the train.
Probably just coincidence that someone happened to be pairing right near me at right that moment but a bit annoying nontheless.

Hed
Mar 31, 2004

Fun Shoe
This seems like a good time to ask... are there any winners in the non-smartphone hardware token (like RSA SecurID, not Yubi) that aren't the SecurID? That also integrate with hosted exchange or GSuite for multifactor?

Shame Boy
Mar 2, 2010

Cocoa Crispies posted:

I love everything about hosed up RNGs that leads to hardware recalls, like the previous yubikey 4 vuln

https://crocs.fi.muni.cz/public/papers/rsa_ccs17

it wasn't even really a "recall" in that i didn't have to give back my old one, they just sent me a new one, now i have two :c00lbert:

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

BangersInMyKnickers posted:

they might have stopped when they got caught red handed on this, but some of them completely ignored this so they could still connect to any available network and send usage data back

okay but won't the data be associated with your neighbor in that case?

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

Farmer Crack-rear end posted:

okay but won't the data be associated with your neighbor in that case?

it'll be data like when your tv has watched netflix or possibly your wifi password if you've given the tv this information. Who knows what they might send off.

spankmeister
Jun 15, 2008






Jabor posted:

it's a good thing we have an elaborate and expensive certification process to ensure that cryptographic solutions work correctly and aren't broken.

it would really suck if it was just bureaucratic horseshit that made it very expensive to create compliant implementations while not actually providing any meaningful benefit

It was probably a good idea in like, the 90's

Computer Serf
May 14, 2005
Buglord

spankmeister posted:

It was probably a good idea in like, the 90's

BlankSystemDaemon
Mar 13, 2009



Lutha Mahtin posted:

you could have the tv connect to a dummy network that is physically disconnected from the internet but then you're just wasting electricity because it probably tries to ping home 1000 times a minute
Well, as it is, it's not doing anything other than acting as a display for a device on HDMI1 - so unless they can somehow MITM the HDMI traffic to DPI it and identify it on the fly to see what I'm watching, I'm not worried - and in case they can do that, kudos to them for doing so on a CPU that I'm pretty sure isn't fast enough for that.

Tankakern posted:

why the hell would you use freebsd instead of linux

do you like your fans going 100 % all the time while watching youtube
While the HTPC running FreeBSD is a fairly new thing, it's not like I'm new to FreeBSD.

The choice is between a Linux appliance (LibreELEC; it "helpfully" runs Xorg, kodi, python, and everything else as root, including several listening daemons, as well as sshd allowing root login) - and a FreeBSD appliance I build (using poudriere image; it builds both the OS and packages as well as automatically adding the configuration that runs Wayland, kodi, and python as a normal user).

With FreeBSD, the fans are running slightly slower than Linux when doing the same video decoding using VAAPI; I'm guessing because Wayland might not be as resource intensive as Xorg when there's no window manager decorations, transparency compositing, or anything else being done.

Mind you, even when it was running Linux and also now that it's running FreeBSD, the only time I can tell the difference is if I'm looking at the fan-speeds or standing right next to it - if I'm anywhere else doing anything else, I don't notice it at all.

pseudorandom name
May 6, 2007

D. Ebdrup posted:

Well, as it is, it's not doing anything other than acting as a display for a device on HDMI1 - so unless they can somehow MITM the HDMI traffic to DPI it and identify it on the fly to see what I'm watching, I'm not worried - and in case they can do that, kudos to them for doing so on a CPU that I'm pretty sure isn't fast enough for that.

It doesn't have to MITM anything, it is the TV.

Angela Merkle Tree
Jan 4, 2012

the definition of open: "mkdir android ; cd android ; repo init -u git://android.git.kernel.org/platform/manifest.git ; repo sync ; make"
College Slice

D. Ebdrup posted:

Well, as it is, it's not doing anything other than acting as a display for a device on HDMI1 - so unless they can somehow MITM the HDMI traffic to DPI it and identify it on the fly to see what I'm watching, I'm not worried - and in case they can do that, kudos to them for doing so on a CPU that I'm pretty sure isn't fast enough for that.

they do do that lol why do you think they've been putting quad core cpus in smart tvs ("android" is an understandable answer)

quote:

Samba TV digitally recognizes such content from your TV’s internal tuner or external devices such as set-top box, Blu-Ray player, Roku or Apple TV device, or other video device connected to your TV by HDMI.

Soricidus
Oct 21, 2010
freedom-hating statist shill

BangersInMyKnickers posted:

how do you stop your tv from connecting to the internet when the wifi will automatically attach to any open ssid in range, which is a thing some of them do (samsung)

how many open ssids are you seeing in 2019? I can only see one from my flat, and it’s one of those isp “share your router with other customers” ones that you have to pay to actually use so I don’t imagine smart TVs will get much value out of it.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Hed posted:

This seems like a good time to ask... are there any winners in the non-smartphone hardware token (like RSA SecurID, not Yubi) that aren't the SecurID? That also integrate with hosted exchange or GSuite for multifactor?

they’re all their own flavour of bad

evil_bunnY
Apr 2, 2003

Lutha Mahtin posted:

you could have the tv connect to a dummy network that is physically disconnected from the internet but then you're just wasting electricity because it probably tries to ping home 1000 times a minute
the worst Samsungs would drop that network and then happily join whatever open cesspool

The Fool posted:

or, like my phone, sees that it doesn't have internet then disconnects from the network

which makes it really hard to configure devices over wifi
that’s cellular assist and you can disable it on iOS

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

spankmeister posted:

It was probably a good idea in like, the 90's

as someone who worried about FIPS in the 90s, not really

taiyoko
Jan 10, 2008


Hed posted:

This seems like a good time to ask... are there any winners in the non-smartphone hardware token (like RSA SecurID, not Yubi) that aren't the SecurID? That also integrate with hosted exchange or GSuite for multifactor?

Where I work, users typically have the smartphone soft tokens, but we as outsourced tech support will have hardware tokens for our admin connections. Given that we're more-or-less-T1-helldesk, I can't speak to their integrations. Besides the RSA SecurID, DUO is a pretty common one. Symantec VIP, one that's straight called MFA in our documentation, uses a token that says SafeID on it. Is there something about the RSA SecurID that you dislike? As far as from a troubleshooting/user lockout perspective, the console is fairly straightforward.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
facebook's new blockchain seems to require everyone to verify with a government issued photo id

as if they don't already store way too much data about you

FlapYoJacks
Feb 12, 2009
https://twitter.com/mikko/status/1140597386835877888?s=21

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Tankakern posted:

why the hell would you use freebsd instead of linux

do you like your fans going 100 % all the time while watching youtube

idk about freebsd on the desktop but it is p drat good as a server

flakeloaf
Feb 26, 2003

Still better than android clock


:stonk:

gotta polish my kickin' boot again, i see

i really should sit down some afternoon and set up my yubikey properly (by wiping it and starting over), even though i gave up on ssh-to-home-server long ago cause nordvpn's like $3 and serves the same purpose while abroad

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

my most charitable reading is that the maker of that usb sells a catered seminar about phishing

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



Raere posted:

Thank goodness for FIPS

TGI FIP'S

PIZZA.BAT
Nov 12, 2016


:cheers:


what do you guys recommend for a vpn just to avoid clients from snooping on my personal phone traffic on their guest network?

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

i'd say whichever of expressvpn and nordvpn is cheaper for you in the moment, because your clients are probably nosy simpletons and not some three-letter thingy, so time spent thinking about it beyond that is probably time wasted

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply