Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Midjack
Dec 24, 2007



the secfuck-e/n crossover we never asked for

Adbot
ADBOT LOVES YOU

Jewel
May 2, 2009


holy poo poo

Mozi
Apr 4, 2004

Forms change so fast
Time is moving past
Memory is smoke
Gonna get wider when I die
Nap Ghost
Might as well get rid of passwords altogether and just make it illegal to access somebody else's account.

Happy Thread
Jul 10, 2005

by Fluffdaddy
Plaster Town Cop
Richard loving Branson

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
the virgin brightline vs. the chad tri-rail

mystes
May 31, 2006

Someone should try to see if they can get Virgin Media to tell them the email addresses that are using a certain password. "My password is 12345 but I just can't remember what email I used. Can you look it up for me?"

Potato Salad
Oct 23, 2014

nobody cares


hot poo poo, luv 2 advertise to the world that i, a genius, store plaintext passwords

Trabisnikof
Dec 24, 2005

https://twitter.com/virginmedia/status/1162643986013708288

abigserve
Sep 13, 2009

this is a better avatar than what I had before
social media person: hey how do we get users to reset their passwords?
tech: there's a form you fill out, that gets sent to the server as a POST request, and then we mail them the recovery password
social media person: say no more

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Oh hey it's Austrian TMobile 2: Branson Boogaloo

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal
i've started following this thread again for less than a week and this goddamn cavalcade of incompetence is already making me feel like poo poo for somehow being stuck where i am while there's apparently organizations with more than 2 digits users willing to pay people to store passwords in plaintext

like what the gently caress i can make you a db schema with text fields for both users and passwords. i'll even throw in an index or two for free. give me a bonus and i'll throw that poo poo in mongodb or an open s3 bucket if that's what you want

how do you even get the critical mass of incompetence required for this these days

redleader
Aug 18, 2005

Engage according to operational parameters
because there is no incentive to do better. it doesn't matter if you do or don't

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal
ok then how do i get in those "get paid to not give a gently caress" jobs? that might not be infosec per se but i'd expect people here to know their nemesis

taqueso
Mar 8, 2004


:911:
:wookie: :thermidor: :wookie:
:dehumanize:

:pirate::hf::tinfoil:

Do you have any relatives that are around VP level?

Potato Salad
Oct 23, 2014

nobody cares


cram cissp

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

taqueso posted:

Do you have any relatives that are around VP level?

no

guess that's the problem


what in the name of gently caress would make you thing i want anything to do with actual infosec work? you get shat on by managers looking to trim their budgets in the best of times, you get torn apart by execs when something gets breached

i know enough to stay away from that whole dumpster fire. all i'm saying is i know how to google "how to store passwords" which apparently puts me above a whole lot of people yet i'm stuck figuring out how best to shove vertices and bump maps up some gpu's rear end for less than i'd like

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

bcrypt

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Change gotta be management driven. Gotta get that governance and policies in place to push real, meaningful security.

Phone
Jul 30, 2005

親子丼をほしい。
you gotta be the sticky note with this quarters password on it

Happy Thread
Jul 10, 2005

by Fluffdaddy
Plaster Town Cop

Deep Dish Fuckfest posted:

i know enough to stay away from that whole dumpster fire. all i'm saying is i know how to google "how to store passwords" which apparently puts me above a whole lot of people yet i'm stuck figuring out how best to shove vertices and bump maps up some gpu's rear end for less than i'd like

hi graphics buddy, is your place hiring

jerry seinfel
Jun 25, 2007


Deep Dish Fuckfest posted:

i've started following this thread again for less than a week and this goddamn cavalcade of incompetence is already making me feel like poo poo for somehow being stuck where i am while there's apparently organizations with more than 2 digits users willing to pay people to store passwords in plaintext

like what the gently caress i can make you a db schema with text fields for both users and passwords. i'll even throw in an index or two for free. give me a bonus and i'll throw that poo poo in mongodb or an open s3 bucket if that's what you want

how do you even get the critical mass of incompetence required for this these days

i just applied for a job with a large organization and updated my profile on their job website

they helpfully emailed me my password in plaintext in the email confirming the changes i made

Carbon dioxide
Oct 9, 2012

There *are* incentives to be better.

If European companies pulled this poo poo they'd be in for huge fines.

That's why >90% of the 'companies are stupid' stuff in this thread isn't European.

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

Deep Dish Fuckfest posted:

no

guess that's the problem


what in the name of gently caress would make you thing i want anything to do with actual infosec work? you get shat on by managers looking to trim their budgets in the best of times, you get torn apart by execs when something gets breached

i know enough to stay away from that whole dumpster fire. all i'm saying is i know how to google "how to store passwords" which apparently puts me above a whole lot of people yet i'm stuck figuring out how best to shove vertices and bump maps up some gpu's rear end for less than i'd like

see also: why I’m just gonna stick to being a software dev and make all the security holes instead of even attempting to join the club of hackers

Wiggly Wayne DDS
Sep 11, 2010



Deep Dish Fuckfest posted:

what in the name of gently caress would make you thing i want anything to do with actual infosec work?
they mentioned cissp though

Trabisnikof
Dec 24, 2005

Carbon dioxide posted:

There *are* incentives to be better.

If European companies pulled this poo poo they'd be in for huge fines.

That's why >90% of the 'companies are stupid' stuff in this thread isn't European.

the uk is still part of europe for now

redleader
Aug 18, 2005

Engage according to operational parameters

Carbon dioxide posted:

There *are* incentives to be better.

If European companies pulled this poo poo they'd be in for huge fines.

That's why >90% of the 'companies are stupid' stuff in this thread isn't European.

it just means it's harder to see the elementary secfucks the euros are making. plus small orgs are still immune by virtue of no one giving a poo poo

Potato Salad
Oct 23, 2014

nobody cares


Wiggly Wayne DDS posted:

they mentioned cissp though

Soricidus
Oct 21, 2010
freedom-hating statist shill
holy poo poo cissp

Shame Boy
Mar 2, 2010

Deep Dish Fuckfest posted:

no

guess that's the problem


what in the name of gently caress would make you thing i want anything to do with actual infosec work? you get shat on by managers looking to trim their budgets in the best of times, you get torn apart by execs when something gets breached

i know enough to stay away from that whole dumpster fire. all i'm saying is i know how to google "how to store passwords" which apparently puts me above a whole lot of people yet i'm stuck figuring out how best to shove vertices and bump maps up some gpu's rear end for less than i'd like

learn how to make apps with javascript and nodejs and get a job doing that if you want to spend your time being incompetent and contributing nothing of value to anyone like me

KDE Perry
Dec 19, 2012

Grimey Drawer
if you're looking to update your testing phones, the unc0ver jailbreak just updated to work on the current version of iOS (12.4)

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Deep Dish Fuckfest posted:

ok then how do i get in those "get paid to not give a gently caress" jobs? that might not be infosec per se but i'd expect people here to know their nemesis

if you have a degree its super easy. i wandered into mine with no effort.

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
unless you meant like, being actively negligent.

Wiggly Wayne DDS
Sep 11, 2010



surprising no one:
https://twitter.com/faker_/status/1163187161652506624

Shame Boy
Mar 2, 2010


oh hey webmin is still a thing, i remember using that when i was like, 14 and didn't know how to linux at all :allears:

though even back then i was smart enough not to expose it to the external internet

Soricidus
Oct 21, 2010
freedom-hating statist shill
lol nice, open source managing to be owned such that auditing the code won’t find anything

(nobody will ever audit the code either)

ate shit on live tv
Feb 15, 2004

by Azathoth

Special Characters are dumb (ambiguous characters is my main complaint, also the inconsistency is allowed characters), just make a longer minimum length and use numbers+upper/lowercase.

Trabisnikof
Dec 24, 2005

ate poo poo on live tv posted:

Special Characters are dumb (ambiguous characters is my main complaint, also the inconsistency is allowed characters), just make a longer minimum length and use numbers+upper/lowercase.

Excluding basic punctuation from passwords is dumb. But so is their 10 character max.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Trabisnikof posted:

Excluding basic punctuation from passwords is dumb. But so is their 10 character max.

I no longer regret that time someone said we should limit passwords to 250 characters and I didn’t push back

ewiley
Jul 9, 2003

More trash for the trash fire
https://twitter.com/GossiTheDog/status/1163753873351356417?s=20

Hmm what's the over/under this is a secfuck or just an IT outage.

Adbot
ADBOT LOVES YOU

Truga
May 4, 2014
Lipstick Apathy

Shame Boy posted:

oh hey webmin is still a thing, i remember using that when i was like, 14 and didn't know how to linux at all :allears:

though even back then i was smart enough not to expose it to the external internet

i suddenly started getting regularly asked for "access to the cpanel" by a few of our clients in tyool 2019 and i'm like :stonk: every time
1. i don't have that poo poo are you insane
2. i can give you ssh access if you supply me a static ip for the firewall and a public key
https://www.youtube.com/watch?v=NGPHFNR5Gms&t=45s

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply