Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Lain Iwakura posted:

this thread is great if you're an ex-AV industry person like me or just hate AV like me

https://twitter.com/popepoperet/status/1155545502831845381

“pope pope ret” is a very good name

Adbot
ADBOT LOVES YOU

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

haveblue posted:

why does everything come with web servers these days

is this a side effect of the rise of javascript UIs

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Deep Dish Fuckfest posted:

well gently caress i've been wondering for years why those things were hundreds of MBs like a decade ago but this is the first time someone's provided me with any insight whatsoever about what was actually in there

like i always assumed it wasn't injecting 100 MB worth of ring 0 code up my kernel's rear end, but-

wait please tell me there's something that would preclude shoving all of java and tomcat into the kernel

Not the kernel but they’re absolutely running that poo poo as a service under the system account and binding it to 0.0.0.0

pseudorandom
Jun 16, 2010



Yam Slacker

BangersInMyKnickers posted:

Not the kernel but they’re absolutely running that poo poo as a service under the system account and binding it to 0.0.0.0




I wonder how many people actually change the username/password.

Stabby McDamage
Dec 11, 2005

Doctor Rope

Shaggar posted:

i think its more that applications use services to handle privileged tasks without giving the user UAC prompts. and then if you're gonna have a service why not make it a web service. For a raid controller this might also be useful if its intended for management over a network.

It reminds me of the elaborate poo poo that garbage developers did right after UAC launched to "work around" it, except now it's ~best practice~ among enterprise idiots

abigserve posted:

if you want to write an electron app without writing the entire backend in Node you will need to run a web server at some point


lol I'm pretty sure you only get a uac prompt for this if it's opening a port on an interface other than localhost. might wanna do a cheeky portscan on your machine there buddy

I thought the same thing and uninstalled that poo poo immediately. this system can live without RAID.

pseudorandom posted:



I wonder how many people actually change the username/password.

It makes you change it on login, but it's still 100+MB of code that eats network poo poo on one end and diddles your SATA controller on the other.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I'm just waiting for the first vendor that binds a serial to ip bridge to the jtag interface and presents it to the network

Wiggly Wayne DDS
Sep 11, 2010



that has to have happened already as a feature on a non-dev platform

Potato Salad
Oct 23, 2014

nobody cares


BangersInMyKnickers posted:

I'm just waiting for the first vendor that binds a serial to ip bridge to the jtag interface and presents it to the network

uuuuuuhhhhhhhhhhhh

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Potato Salad posted:

uuuuuuhhhhhhhhhhhh

listen its too early on a monday for me to get this upset

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

BangersInMyKnickers posted:

listen its too early on a monday for me to get this upset

there's a non-zero chance that failing to reset your password at my current work resets it to "Abcd1234"

remember to watch that blood pressure

Schadenboner
Aug 15, 2011

by Shine

Cocoa Crispies posted:

“pope pope ret” is a very good name

Pope Pope horny, George Michael.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Stabby McDamage posted:

100+MB of code that eats network poo poo on one end and diddles your SATA controller on the other.

Please don't cable kink shame

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
so i am failing to read anything on dashlane's website on how it even works and i am guessing it's just a lastpass clone

https://support.dashlane.com/hc/en-us

anyone got a clue? i am trying to avoid installing it before i know what is going on

their release notes give some clue but still vague

https://support.dashlane.com/hc/en-us/articles/206553939-Release-notes

but then there is this other poo poo



so are they scanning the passwords server-side or is your client pinging back?

because then there is this poo poo



i am going to say that this is possibly worse than lastpass and that is impressive

power botton
Nov 2, 2011

... and to my dad, i leave my suicidegirls account

Shaggar
Apr 26, 2006
as far as the identity protection stuff goes some of it is probably done entirely locally (ex: password reuse checking) and some of it they probably send the credentials to their own services for testing. Its possible they have a local db of compromised credentials that they check against, but the remote service thing seems more likely. it would be possible to generate a hash of the credentials and send that for comparison instead of the credentials themselves.

the emergency contacts thing is fine. you may not have a use for it, but plenty of people do.

Shaggar
Apr 26, 2006
you could try contacting their support to get the specific implementation details.

wyoak
Feb 14, 2005

a glass case of emotion

Fallen Rib
1password's newer versions also do a check for compromised PW's against haveibeenpwned, they send the first 5 characters of your hashed password to hibp, get a list back of all matching hashes, and do a local comparison. Dunno if Dashlane's implementation is that but hopefully it's something similar.

power botton
Nov 2, 2011

its probably the same thing as everyone else - checking haveibeenpwned, and will coincidentally break just along with every other vendor once HIBP goes private

crazysim
May 23, 2004
I AM SOOOOO GAY

power botton posted:

its probably the same thing as everyone else - checking haveibeenpwned, and will coincidentally break just along with every other vendor once HIBP goes private

it'll break if they don't pay HIBP.

The Fool
Oct 16, 2003


according to the "dark web" monitoring faq they host the data in house, but have some sort of partnership with SpyCloud

based entirely on the stupid animated console example on spyclouds api website I suspect the client does a query against the api which returns the "dark web" data, including hashed passwords.

The Fool
Oct 16, 2003


power botton posted:

its probably the same thing as everyone else - checking haveibeenpwned, and will coincidentally break just along with every other vendor once HIBP goes private

yeah, 1pass's watchtower service does this

power botton
Nov 2, 2011

crazysim posted:

it'll break if they don't pay HIBP.

so then half these vendors will change it to a susbcription based "identity protection service" for an extra 2 bucks/month or something. 1password is already subscription based and set up nicely for this. lower the cost of the normal version by a dollar or whatever and increase the cool HIBP integration to like 2$/month or whatever.

either way im going to assume a lot of these services will go pay only or break, so you don't have to worry about it unless you actually opt in.

Raere
Dec 13, 2007

Lain Iwakura posted:

so i am failing to read anything on dashlane's website on how it even works and i am guessing it's just a lastpass clone

https://support.dashlane.com/hc/en-us

anyone got a clue? i am trying to avoid installing it before i know what is going on

their release notes give some clue but still vague

https://support.dashlane.com/hc/en-us/articles/206553939-Release-notes

but then there is this other poo poo



so are they scanning the passwords server-side or is your client pinging back?

because then there is this poo poo



i am going to say that this is possibly worse than lastpass and that is impressive

I use Dashlane as my password manager and it suits my needs. They've had a handful of security flaws over the years but nothing outrageous and were quick to fix. Solid 2FA support for my Yubikey. It's your bog standard password manager. Unsure about that emergency contact thing, it's new to me.

Last Chance
Dec 31, 2004

Dashlane has always sketched me the gently caress out and I wouldn't touch it with a ten foot pole

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

lol ran some janky webapp we own's uri through a base64 decoder and

code:
Segment=Login&LoginID=[%username%]&Learner_Password=[hardcodedvalue]&NewUser=1
Can just slap in any valid username and go. Good job, everyone.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Last Chance posted:

Dashlane has always sketched me the gently caress out and I wouldn't touch it with a ten foot pole

that is my logic too. there is nothing about it that really makes me go "yeah that is good"

evil_bunnY
Apr 2, 2003

Lain Iwakura posted:




so are they scanning the passwords server-side or is your client pinging back?
Isn't that hash comparison with hibp?

Lain Iwakura posted:

because then there is this poo poo


I mean having so many is weird but why wouldn't you want your partner able to access your poo poo if you get yourself 6ft under? Does it work differently than I'm assuming?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

evil_bunnY posted:

Isn't that hash comparison with hibp?

I mean having so many is weird but why wouldn't you want your partner able to access your poo poo if you get yourself 6ft under? Does it work differently than I'm assuming?

how do you think it works?

Schadenboner
Aug 15, 2011

by Shine

infernal machines posted:

how do you think it works?

Poorly?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

evil_bunnY posted:

Isn't that hash comparison with hibp?

i am asking if this is server-side or client. my gut says client but i am failing to see any mention of how they manage any of this

quote:

I mean having so many is weird but why wouldn't you want your partner able to access your poo poo if you get yourself 6ft under? Does it work differently than I'm assuming?

there are other, better ways to do this and relying on the server to dictate when to give the keys to someone else is pretty problematic

Vomik
Jul 29, 2003

This post is dedicated to the brave Mujahideen fighters of Afghanistan

Lain Iwakura posted:

so i am failing to read anything on dashlane's website on how it even works and i am guessing it's just a lastpass clone

https://support.dashlane.com/hc/en-us

anyone got a clue? i am trying to avoid installing it before i know what is going on

their release notes give some clue but still vague

https://support.dashlane.com/hc/en-us/articles/206553939-Release-notes

but then there is this other poo poo



so are they scanning the passwords server-side or is your client pinging back?

because then there is this poo poo



i am going to say that this is possibly worse than lastpass and that is impressive

Idgi. what specifically are you investigating dashlane for?

1Password, lastpass, and dashlane all have pretty much the exact same functionality and use.

dashlane costs more but it has a vpn and some other items. included. they all have emergency contacts which you don’t have to setup.

dashlane is also originally (?) from france so I suppose it may have stricter data regulations... depending on if they’re used or if it matters since they have servers in the US who knows.

in terms of a copy... I guess but in the same sense lastpass is a copy of 1password.

you could always use keepassXC which has the EFF seal of approval.

Wiggly Wayne DDS
Sep 11, 2010



source you're posts

xarph
Jun 18, 2001


BangersInMyKnickers posted:

I'm just waiting for the first vendor that binds a serial to ip bridge to the jtag interface and presents it to the network

a supermicro blade server we have contains an integrated 10gig switch. The console connection is serial -> ip -> ethernet -> integrated ethernet to usb adapter -> usb 2.0 type A female connector

Yes it has a DHCP server turned on by default, and bridges you to vlan 1.

BattleMaster
Aug 14, 2000

am I reading that wrong or did they just use a serial to USB bridge with extra steps

Shaggar
Apr 26, 2006

BangersInMyKnickers posted:

lol ran some janky webapp we own's uri through a base64 decoder and

code:
Segment=Login&LoginID=[%username%]&Learner_Password=[hardcodedvalue]&NewUser=1
Can just slap in any valid username and go. Good job, everyone.

it was encrypted with base64!

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



I dated a chick I met on dashlane

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Vomik posted:

Idgi. what specifically are you investigating dashlane for?

1Password, lastpass, and dashlane all have pretty much the exact same functionality and use.

dashlane costs more but it has a vpn and some other items. included. they all have emergency contacts which you don’t have to setup.

dashlane is also originally (?) from france so I suppose it may have stricter data regulations... depending on if they’re used or if it matters since they have servers in the US who knows.

in terms of a copy... I guess but in the same sense lastpass is a copy of 1password.

you could always use keepassXC which has the EFF seal of approval.

this is a garbage response and you don't seem to get the spirit of this thread

i'm saying that lastpass looks like trash and there is little on their website documenting how it even functions

Wiggly Wayne DDS
Sep 11, 2010



and also this dashlane product people speak of

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Wiggly Wayne DDS posted:

and also this dashlane product people speak of

that too. my brain categorized it as the same I guess

Adbot
ADBOT LOVES YOU

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Raere posted:

I use Dashlane as my password manager and it suits my needs. … Solid 2FA support for my Yubikey. It's your bog standard password manager.

how does 2fa work with a password manager

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply