Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Cocoa Crispies posted:

how does 2fa work with a password manager

carefully!

Adbot
ADBOT LOVES YOU

xarph
Jun 18, 2001


BattleMaster posted:

am I reading that wrong or did they just use a serial to USB bridge with extra steps

You read it correctly. I can only imagine there was some completely insane bureaucratic requirement divorced from reality that somehow made it cheaper to do it that way. Supermicro.txt

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Cocoa Crispies posted:

how does 2fa work with a password manager

for ones that sync to the cloud you can enforce 2fa when the user links a new device

The Fool
Oct 16, 2003


Cocoa Crispies posted:

how does 2fa work with a password manager

I can't speak to the others, but 1pass can be set to require a OTP when connecting a new device.

Raere
Dec 13, 2007

I can't speak to Dashlane's security with regards to exploits but in my mind it does all the things right for security-centric app. Standard Windows/Mac/Android/iOS client that lets you set your key derivation function, how often to prompt for your password, 2FA management, etc. Standard browser plugin for Firefox/Chrome/Safari, with things like matching a code between the browser and the app when you install the plugin to ensure it's not fake.

They have a white paper that goes into the internals a bit: https://www.dashlane.com/download/Dashlane_SecurityWhitePaper_October2018.pdf
An analysis was done in 2016 that found some stupid, but not terrible bugs: https://courses.csail.mit.edu/6.857/2016/files/25.pdf
They put out release pretty frequently and have supposedly fixed the bugs in that report and any more that've been disclosed since then: https://support.dashlane.com/hc/en-us/articles/206553939-Release-notes#title3

I'm not trying to defend them I've just been a happy user for a few years.

HAIL eSATA-n
Apr 7, 2007

are the browser addons for lastpass/etc safe? they always seemed more vulnerable than the standalone programs

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

2fa deez nuts

The Fool
Oct 16, 2003


Captain Foo posted:

2fa deez nuts

authentication method not found

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



The Fool posted:

authentication method not found

go deeper, you might need a forceps

Trabisnikof
Dec 24, 2005

Captain Foo posted:

2fa deez nuts

well you are nutz so I guess that works :v:

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


:rip: capital one

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

rafikki posted:

:rip: capital one

what happen

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Capital One data breach compromises tens of millions of credit card applications, FBI says
https://wapo.st/2Kpklw7

Trabisnikof
Dec 24, 2005

Captain Foo posted:

what happen

https://www.bloomberg.com/news/articles/2019-07-29/capital-one-data-systems-breached-by-seattle-woman-u-s-says

Capital One Financial Corp. said data from about 100 million people in the U.S. was illegally accessed after prosecutors accused a Seattle woman of breaking into the bank’s server at a cloud-computing company.

The woman, Paige A. Thompson, was arrested Monday and appeared in federal court in Seattle. The data theft occurred some time between March 12 and July 17, federal prosecutors in Seattle said. The cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers.

“I am deeply sorry for what has happened," said Richard D. Fairbank, Capital One’s chief executive officer, in a statement. "I sincerely apologize for the understandable worry this incident must be causing those affected.”

About 6 million individuals in Canada were also impacted by the breach, Capital One said.

The largest category of data stolen was supplied by consumers and small businesses when they applied for credit cards from 2005 through early 2019, the bank said. It included personal identification data, including names, addresses, phone numbers and dates of birth, and financial data including self-reported income, credit scores and fragments of transaction history.

About 140,000 Social Security numbers were accessed, as well as 80,000 bank account numbers from credit-card customers, the bank said.

Schadenboner
Aug 15, 2011

by Shine
Oh good, I was wondering where my next supply of free credit monitoring would come from!

What's that? "GDPR in the USA"? To that sort of European* nonsense I say: No Sir!

:patriot: Make Mine Freedom. :patriot:

*More like Europoopin, ammirite?

Schadenboner fucked around with this message at 01:04 on Jul 30, 2019

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

quote:

It is unusual in a major hacking case for a suspect to be apprehended so quickly, and in this case, that was apparently due to boasts made online.

Thompson, who authorities say used the name “erratic” in online conversations, is suspected of “exfiltrating and stealing information, including credit card applications and other documents, from Capital One,” according to a criminal complaint filed in federal court. She was ordered to remain in jail pending a detention hearing scheduled for Thursday, according to court records.

A lawyer for Thompson did not immediately respond to a message seeking comment.

Thompson “made statements on social media for evidencing the fact that she has information of Capital One, and that she recognizes that she has acted illegally,” according to the criminal complaint signed by FBI special agent Joel Martini.

In one online posting, “erratic” wrote: “I’ve basically strapped myself with a bomb vest, [expletive] dropping capitol ones dox and admitting it,” according to the complaint.

uh huh

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

:rip:

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Schadenboner posted:

Oh good, I was wondering where my next supply of free credit monitoring would come from!

What's that? "GDPR in the USA"? To that sort of European* nonsense I say: No Sir!

:patriot: Make Mine Freedom. :patriot:

*More like Europoopin, ammirite?

pls dont make fun of shaggar, its not his fault that he is poisoned by capitalism

Trabisnikof
Dec 24, 2005


posted to github but the quote is apparently pulled from a twitter dm, which goes to show the classic truth about opsec

quote:

Thompson then posted about having the data on GitHub, a site where software developers share projects and code. A GitHub user alerted Capital One about the possible breach in mid-July, and the company turned to the FBI to pursue criminal charges.

According to court documents, Thompson posted on Twitter and Slack about trying to get rid of or distribute the data.

"I've basically strapped myself with a bomb vest, f--king dropping capital ones [documents] and admitting it," she wrote in a Twitter direct message to the person who ultimately reported the breach to Capital One, court documents show.


Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



also, is it really true that you have to work up credit by loaning and paying back and if you never use credit you have no worthiness?

its not perfect, but how about current net worth + last couple months paychecks instead (assuming credit is for a mortgage

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Trabisnikof posted:

posted to github but the quote is apparently pulled from a twitter dm, which goes to show the classic truth about opsec





i mean, she was if nothing else aptly named

Raere
Dec 13, 2007

HAIL eSATA-n posted:

are the browser addons for lastpass/etc safe? they always seemed more vulnerable than the standalone programs

No more safe than any other piece of software. There've been exploits in password manager browser addons before. They interact with websites so there's more that can be exploited.

Sagebrush
Feb 26, 2012


that was an awesome game though there wasn't much replay value once you figured out how to cheese the "trace a large transaction" job to get like 10 million dollars right at the beginning

wish they'd made a sequel. lan hacking was fun

Midjack
Dec 24, 2007



Sagebrush posted:

that was an awesome game though there wasn't much replay value once you figured out how to cheese the "trace a large transaction" job to get like 10 million dollars right at the beginning

wish they'd made a sequel. lan hacking was fun

i’d love uplink2 that reflects the intervening 20 years of technical and social changes around hacking.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Midjack posted:

i’d love uplink2 that reflects the intervening 20 years of technical and social changes around hacking.

but how long can you spend on the phone claiming to be the IRS, getting septuagenarians to buy google play gift cards?

Trabisnikof
Dec 24, 2005

id love that zachtronics hacking game plus red string social club put together

Sagebrush
Feb 26, 2012

in that vein Watch_Dogs 2 was pretty great. the hacking was more video-gamey for sure but the context of it all was fantastic. they modeled san francisco well enough that i could pretty much just drive around it like i do for real, the bad guy is essentially jack dorsey, there are perfect copies of google and facebook and nest and such and they're all spying on everyone and selling the data, the first mission has you harassing martin shkreli, etc

e: oh and there are a bunch of missions involving deprogramming someone who sounds exactly like tom cruise from an organization that is definitely not the scientologists

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Trabisnikof posted:

that zachtronics hacking game

Which one

Also seconding watch dogs 2, it was goofy fun, though they definitely just phoned in the second half of the story. The multiplayer seamlessly worked with the single player if you enabled it, so you could play games of "capture the drone"

Trabisnikof
Dec 24, 2005

Volmarias posted:

Which one

Also seconding watch dogs 2, it was goofy fun, though they definitely just phoned in the second half of the story. The multiplayer seamlessly worked with the single player if you enabled it, so you could play games of "capture the drone"

exapunks - http://www.zachtronics.com/exapunks/


also i do recommend red string social club as a relatively short, good game that deals with social engineering

https://store.steampowered.com/app/589780/The_Red_Strings_Club/

https://www.youtube.com/watch?v=IKwKVukDsXQ

Shaggar
Apr 26, 2006

HAIL eSATA-n posted:

are the browser addons for lastpass/etc safe? they always seemed more vulnerable than the standalone programs

anything that uses javascript should be considered insecure.

Hexyflexy
Sep 2, 2011

asymptotically approaching one

Shaggar posted:

anything that uses javascript should be considered insecure.

It's fine, I'm sure one of the many machine local databases that are accessible by a website are totally isolated from any other sites code touching it. Or that I couldn't paste a link here that'd email me your entire html5 web storage. That has never happened.

2nd Rate Poster
Mar 25, 2004

i started a joke
FWIW CapitalOne was a part of the keynote at AWS' security conference last month.

Pile Of Garbage
May 28, 2007



weird the ppl crawling out of the woodwork to defend dashlane itt

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Krankenstyle posted:

also, is it really true that you have to work up credit by loaning and paying back and if you never use credit you have no worthiness?

its not perfect, but how about current net worth + last couple months paychecks instead (assuming credit is for a mortgage

yeah. when your whole business is trusting people to pay off their debt to you it's good to have proof of a history of that and establish a potential for that to keep happening which is the part you're talking about. probably most prospective employers shouldn't be able to run your credit though and before you say that's insane remember which country we're talking about

Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.

Trabisnikof posted:

https://www.bloomberg.com/news/articles/2019-07-29/capital-one-data-systems-breached-by-seattle-woman-u-s-says

Capital One Financial Corp. said data from about 100 million people in the U.S. was illegally accessed after prosecutors accused a Seattle woman of breaking into the bank’s server at a cloud-computing company.

The woman, Paige A. Thompson, was arrested Monday and appeared in federal court in Seattle. The data theft occurred some time between March 12 and July 17, federal prosecutors in Seattle said. The cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers.

“I am deeply sorry for what has happened," said Richard D. Fairbank, Capital One’s chief executive officer, in a statement. "I sincerely apologize for the understandable worry this incident must be causing those affected.”

About 6 million individuals in Canada were also impacted by the breach, Capital One said.

The largest category of data stolen was supplied by consumers and small businesses when they applied for credit cards from 2005 through early 2019, the bank said. It included personal identification data, including names, addresses, phone numbers and dates of birth, and financial data including self-reported income, credit scores and fragments of transaction history.

About 140,000 Social Security numbers were accessed, as well as 80,000 bank account numbers from credit-card customers, the bank said.



(source)

cinci zoo sniper
Mar 15, 2013




Krankenstyle posted:

also, is it really true that you have to work up credit by loaning and paying back and if you never use credit you have no worthiness?

its not perfect, but how about current net worth + last couple months paychecks instead (assuming credit is for a mortgage

yes. i work in the industry, sort of, and “has never paid back on a loan formally registered with a credit bureau” is universally a statistically significant indicator for predicting defaults on loans (mind you, im not doing mortgages or car loans and have no experience with north america north of mexico or africa- literally everywhere else this holds true)

current net worth + current stable income sounds okay for europe, where it’s really hard to fire people and average person has a decent enough safety net (provided your net worth calculation is sane). it would most definitely not be a feasible primary determinant in the states, in 31 of which you can be fired without any notice and any reason given.

for mortgages specifically, having talked to people who do them, age is a major factor because they all are trying to estimate probability of your death before repayment

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



gently caress. thx for the explanation. every day I learn another way that capitalism sucks.

BlankSystemDaemon
Mar 13, 2009



Schadenboner posted:

*More like Europoopin, ammirite?
you are, OP. hth
--an europoopian

about that capital one hack, did erratic basically turn herself in? certainly living up to her nickname :v:

cinci zoo sniper
Mar 15, 2013




D. Ebdrup posted:

you are, OP. hth
--an europoopian

about that capital one hack, did erratic basically turn herself in? certainly living up to her nickname :v:

??

Adbot
ADBOT LOVES YOU

ErIog
Jul 11, 2001

:nsacloud:

cinci zoo sniper posted:

yes. i work in the industry, sort of, and “has never paid back on a loan formally registered with a credit bureau” is universally a statistically significant indicator for predicting defaults on loans (mind you, im not doing mortgages or car loans and have no experience with north america north of mexico or africa- literally everywhere else this holds true)

This is kind of the racket in America. How are you supposed to have paid the loan registered with the credit bureau if in order to get the loan you need to have paid off a loan registered to the credit bureau?

They discriminate by age. If you have a certain income by a certain age they don't care. They call it a "score" so they don't get called out for not giving people a chance.

ErIog fucked around with this message at 11:56 on Jul 30, 2019

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply