Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Harry Lime
Feb 27, 2008


Krankenstyle posted:

ew did anyone use it

I think I only saw one person who was working the booth get in any of the times I was walking by. Definitely wasn't anything approaching a line to get in.

Adbot
ADBOT LOVES YOU

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Harry Lime posted:

I think I only saw one person who was working the booth get in any of the times I was walking by. Definitely wasn't anything approaching a line to get in.

lmao i bet it was in their contract "enter the ballpit at least once per half hour"

Midjack
Dec 24, 2007



shades of dashcon

Agile Vector
May 21, 2007

scrum bored



Krankenstyle posted:

lmao i bet it was in their contract "enter the ballpit at least once per half hour"

dev manager job description sounding unreasonable

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

:eyepop:

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
nvm

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Subjunctive posted:

the alerts are stored in the balls

this post needs to get more love

The Fool
Oct 16, 2003


Subjunctive posted:

the alerts are stored in the balls

You have some alerts on your face

pseudorandom
Jun 16, 2010



Yam Slacker
If they had a sign that said "wouldn't you rather drown in drinks than alerts" and then had a liquor pit, then I'd be interested.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

pseudorandom posted:

If they had a sign that said "wouldn't you rather drown in drinks than alerts" and then had a liquor pit, then I'd be interested.

to be honest it would be an even worse toxic waste pit

redleader
Aug 18, 2005

Engage according to operational parameters

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Lain Iwakura posted:

to be honest it would be an even worse toxic waste pit

for a Second I thought you were talking about your balls :v:

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



toxicity is stored in the balls

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
I feel like I’ve heard a million people talking about splunk and elk stack all weekend

either I’m finding a pattern where none exists or I’m lucky to not have to store and search logs

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Captain Foo posted:

for a Second I thought you were talking about your balls :v:

Lain's a dudette, dude.

Harry Lime
Feb 27, 2008


MITRE attack framework was also the free space on the Blackhat vendor hall bingo card this year

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Cocoa Crispies posted:

I feel like I’ve heard a million people talking about splunk and elk stack all weekend

either I’m finding a pattern where none exists or I’m lucky to not have to store and search logs

tbh it's a good chunk of my job and something that have gotten pretty adept with in the past decade

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Subjunctive posted:

Lain's a dudette, dude.

I'm aware

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Subjunctive posted:

Lain's a dudette, dude.

it was a joke about my getting... everything removed

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Lain Iwakura posted:

tbh it's a good chunk of my job and something that have gotten pretty adept with in the past decade

yeah, and this is my second def con in a long time where I haven’t been knee deep in binary poo poo from 7a-7p so it’s probably just me noticing it more

Midjack
Dec 24, 2007



Cocoa Crispies posted:

yeah, and this is my second def con in a long time where I haven’t been knee deep in binary poo poo from 7a-7p so it’s probably just me noticing it more

it seems a bit more prominent this year.

abigserve
Sep 13, 2009

this is a better avatar than what I had before
Log ingestion, indexing, and long term storage is far from a solved problem so it makes sense.

Harry Lime
Feb 27, 2008


This has been fun to follow this week

https://www.vice.com/en_us/article/8xw9kp/black-hat-talk-about-time-ai-causes-uproar-is-deleted-by-conference

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
🤨✋ talks, especially from vendors
😊👍 making friends in the villages

suffix
Jul 27, 2013

Wheeee!

looks more like mental illness than a scam to me :shrug:
like you see this specific kind of kookery a lot and they always have some new mathematics or unbreakable crypto or what not

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
If it's a random pgp email to an academic, sure

This is a company who paid big money for the slot

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Rufus Ping posted:

If it's a random pgp email to an academic, sure

This is a company who paid big money for the slot

quacks have money, Peter thief believes in jail breaking the universe

Trabisnikof
Dec 24, 2005

If you’re making money off quackery it’s a scam even if you believe it. See: Theranos

Happy Thread
Jul 10, 2005

by Fluffdaddy
Plaster Town Cop
https://www.forbes.com/sites/gordonkelly/2019/08/10/apple-iphone-ipad-security-warning-ios-12-ios13-iphone-xs-max-xr/amp/

Warning Issued For Apple's 1.4 Billion iPad And iPhone Users

Aug 10, 2019,7:40 pm

Every iPhone released since 2011 is potentially vulnerable to having their data and passwords stolen

Apple is having a bad week. Just days after Face ID was hacked and the company’s “user-hostile” iPhone battery practices were exposed, an extraordinary story of Apple neglect has resulted in a warning every iPhone and iPad user needs to know about.

Picked up by AppleInsider, security firm Check Point has revealed it has found a way to hack every iPhone and iPad running iOS 8 right up to betas of iOS 13. This spread covers eight years of devices (iOS 8 supports the 2011 iPhone 4S) and, with Tim Cook stating there are 1.4BN active iOS devices around the world, this is worrying news for the owners of pretty much all of them.

What Check Point discovered is that the Contacts app built into iOS can be exploited using the industry-standard SQLite database so that any search of Contacts can trick the device into running malicious code capable of stealing user data and passwords.

............

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
you need physical access to the unlocked device, lol

here's another security flaw for ya: a hacker can browse through your contacts and copy the information with a pen and paper

Happy Thread
Jul 10, 2005

by Fluffdaddy
Plaster Town Cop
The data being leaked is not contacts, it says it's passwords

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
specifically they can modify the contacts app to execute requests that leak data from elsewhere

or not

infernal machines fucked around with this message at 01:17 on Aug 12, 2019

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
if apple is storing plaintext passwords somewhere for this to leak then yeah that's a fuckup, but i don't see that mentioned in the article?

the entire passwords line seems to be "the hacker could set up malware that steals your password if you type it in later"

and again, need physical access and for the device to already be unlocked.

haveblue
Aug 15, 2005



Toilet Rascal
go up one level:

https://appleinsider.com/articles/19/08/10/apples-ios-contacts-app-claimed-to-be-vulnerable-to-sqlite-hack

the bug appears to be a general exploit for storing and invoking executable code with sqlite. contacts was the app chosen for the example. I’m not sure what exactly they did to contacts to compromise it but it doesn’t seem to be doable remotely, they need physical access to an unlocked device

password only seem to come up because stealing passwords is a traditional thing to do once you have malicious code running somewhere

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
yeah, i read that and "For the purpose of the demonstration, they just had the app crash. The researchers said that they could have crafted the app to steal passwords." is pretty unclear. they don't mention this bypassing sandboxing or anything, so it's basically just "we can execute arbitrary code now"

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD
I doubt they could steal passwords anyway since even if you have your malicious code running you'd need the Secure Enclave to give you a key to unlock the keychain.
Now presumably the malicious code could popup a touchID dialog and if the user authenticates through that as they have been trained to do then your code might be able to read passwords...

haveblue
Aug 15, 2005



Toilet Rascal
that’s actually a serious issue with touchid, users will reflexively press home to escape a misbehaving app but the act of putting your finger on home triggers fingerprint recognition and there’s a good chance it will report authentication before it actually exits the app

there are apps that use this trick to activate subscriptions while confusing the user about whether or not it went through

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i guess that's fixed with face id

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Subjunctive posted:

Lain's a dudette, dude.

dude's been gender-neutral for like ten years IMO

Adbot
ADBOT LOVES YOU

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
okay, so this appears to be the original, four-year-old bug. tl;dr: sqlite has a pair of bugs in its query and database-file parsers

in theory the query parser bug shouldn't be exploitable because nobody would ever be dumb enough to inject user input directly into an sql query string, right?

the file parser bug is only exploitable if you can corrupt the database file that sqlite is working with, but you probably can if there's literally any other bug in the program, because parts of the database file are probably just mmap'ed writably into the address space because that's how databases work. and corruption of the database file will generally persist across reboots, so potentially the exploit can persist, too

i don't know why ios was apparently using an ancient sqlite. probably because the whole clever point of sqlite is that you can just copy it into your project without worrying about adding a dependent project, so people do and then they don't worry about keeping up with security updates

the thing about passwords sounds like bullshit

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply