Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Xarn
Jun 26, 2015

Name and shame glorify? :confused:

This is weird :v:

Adbot
ADBOT LOVES YOU

dreamin of semen
Feb 22, 2013

MULTIPLICATION

Mad Wack posted:

should be mandatory on all logins like black box warnings on cigarettes

clearly we need a solution like australian cigarettes where the login page is just login/pass boxes on top of a bunch of pictures of egregious security breaches, with text detailing the unpatched exploits the server has available

Shaggar
Apr 26, 2006

this is good. all mail servers should do this to all URLs in a message not just clickable links.

Shaggar
Apr 26, 2006
a bunch of advertisers will whine about false positives but I cant imagine caring what they think about anything

haveblue
Aug 15, 2005



Toilet Rascal

Shaggar posted:

this is good. all mail servers should do this to all URLs in a message not just clickable links.

yes, especially unsubscribe links

BlankSystemDaemon
Mar 13, 2009



Isn't this a “People can't sue us when our data "leaks" (to people who pay us), because we warned them” caveat emptor-like piece of corporate bullshit?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

haveblue posted:

yes, especially unsubscribe links

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

second part is probably also true for banks

mystes
May 31, 2006

Telling people "Don't reuse this password" is better advice than telling people to use long/secure passwords anyway.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

mystes posted:

Telling people "Don't reuse this password" is better advice than telling people to use long/secure passwords anyway.

That is what google is trying to do with stored passwords for new accounts, I've been pushing people to use their recommended randomized password more often.

ewiley
Jul 9, 2003

More trash for the trash fire

Shaggar posted:

this is good. all mail servers should do this to all URLs in a message not just clickable links.

Sounds like a great idea
https://twitter.com/RyPeck/status/732405198644228096?s=20

cinci zoo sniper
Mar 15, 2013




https://amonitoring.ru/article/onemore_steam_eop_0day/

new steam vuln by the guy from 2 weeks ago

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Apparently he got banned(?) from reporting vulns by the H1 vulnerability group, so he's openly reporting them now.

Schadenboner
Aug 15, 2011

by Shine
Anyone going to Global Security Exchange in Chicago next week early in September?

Wish I were, convergence with physical security is nifty af.

flakeloaf
Feb 26, 2003

Still better than android clock

I should try to talk my boss into it, sounds fun but doesn't really intersect with my policy wonk duties

pseudorandom
Jun 16, 2010



Yam Slacker

Cocoa Crispies posted:

the virgin brightline vs. the chad tri-rail


I'm a few days late, but I appreciate this joke, Flo-goon.

ewiley posted:

https://twitter.com/GossiTheDog/status/1163753873351356417?s=20

Hmm what's the over/under this is a secfuck or just an IT outage.

Nowadays, when a big company goes down, I think it's best to put your money on Amazon loving up. :nsacloud:


This is why I make sure I only reuse my personal and banking passwords on normal porn sites.

Lol at people looking at animated sec gently caress videos.

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



pseudorandom posted:

This is why I make sure I only reuse my personal and banking passwords on normal porn sites.

Lol at people looking at animated sec gently caress videos.
u rang?
https://www.youtube.com/watch?v=ba2IRyq3dyE

Wiggly Wayne DDS
Sep 11, 2010



timeline of announce to patch:
19-08-20 14:32 UTC: tweet of vuln https://twitter.com/PsiDragon/status/1163816024614944771
19-08-21 23:52 UTC: patch to beta: https://steamcommunity.com/groups/SteamClientBeta#announcements/detail/1599262071399843693
19-08-22 02:46 UTC: h1 policy change allowing EoP: https://hackerone.com/valve/policy_versions?change=3616941

quote:

-* Attacks that require the ability to drop files in arbitrary locations on the user's filesystem.

+* Attacks that involve the user running malware that then places or modifies content on the target machine, which Steam could later run as the local user. However, any case that allows malware or compromised software to perform a privilege escalation through Steam, without providing administrative credentials or confirming a UAC dialog, is in scope. Any unauthorized modification of the privileged Steam Client Service is also in scope.

BlankSystemDaemon
Mar 13, 2009



PagedOut issue #1 is out in PDF form, in case it might take anyone's interest. It's basically like POC||GTFO, in how it gets to the loving point instead of waffling about and wasting peoples time.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
anyone doing defendcon next month?

Miss Mowcher
Jul 24, 2007

Ribbit
Made an account on the Brazilian Mathematical Society store then got the confirmation e-mail:



Welcome etc.
Use this info for access:
*my e-mail
*password I created

:negative:

cinci zoo sniper
Mar 15, 2013




hacking gmail.com as we speak

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/ItsReallyNick/status/1163638087773229056

FungiCap
Jul 23, 2007

Let's all just calm down and put on our thinking caps.
Metadata's a bitch.

Methanar
Sep 26, 2013

by the sex ghost

Stick Insect
Oct 24, 2010

My enemies are many.

My equals are none.

FungiCap posted:

Metadata's a bitch.

I'm reminded of this https://en.wikipedia.org/wiki/Dennis_Rader#Cold_case

quote:

Police found metadata embedded in a deleted Microsoft Word document that was, unknown to Rader, still stored on the floppy disk.[35] The metadata contained the words "Christ Lutheran Church", and the document was marked as last modified by "Dennis."[36] An internet search determined that a "Dennis Rader" was president of the church council.

Garrand
Dec 28, 2012

Rhino, you did this to me!



quote:

In his letters to police, Rader asked if his writings, if put on a floppy disk, could be traced or not. The police answered his question in a newspaper ad posted in the Wichita Eagle saying it would be safe to use the disk.

lol

Methanar
Sep 26, 2013

by the sex ghost

quote:

They obtained a warrant to test the DNA of a pap smear Rader's daughter had taken at the Kansas State University medical clinic when she was a student there. The DNA of the pap smear was processed by the Kansas Bureau of Investigation at their lab in Topeka, and demonstrated a familial match to the sample taken from Wegerle's fingernails.

That's actually kind of hosed up.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Methanar posted:

That's actually kind of hosed up.

where do you think the idea for “23 and speculum” came from?

Shame Boy
Mar 2, 2010


yeah i've read about this before and that's always my favorite part

"hey cops do you pinky swear that you can't get any evidence from this?"

"... uh... sure..."

BattleMaster
Aug 14, 2000

I don't understand why they had to get a family DNA sample all subterfuge-like when like a year prior they did a big 1,300 sample dragnet, could they not have just compelled him for a sample like they did to the many other men

I'm assuming that would be better than violating medical confidentiality

Agile Vector
May 21, 2007

scrum bored



or just dig in his trash in the time honored tradition. how hard would it be to find a bit of hair from a vacuum bag or something

Shame Boy
Mar 2, 2010

BattleMaster posted:

I don't understand why they had to get a family DNA sample all subterfuge-like when like a year prior they did a big 1,300 sample dragnet, could they not have just compelled him for a sample like they did to the many other men

I'm assuming that would be better than violating medical confidentiality

then he would have known they were coming for him and he would have... done... something maybe? idk he seems like he was pretty resigned to just being caught by that point judging by how calmly he went with police and stuff.

Midjack
Dec 24, 2007



Shame Boy posted:

then he would have known they were coming for him and he would have... done... something maybe? idk he seems like he was pretty resigned to just being caught by that point judging by how calmly he went with police and stuff.

unless he was an xxxxxtreme flight risk yeah that’s weird. they probably wanted to set a precedent of shaking down doctors for patient information though.

Schadenboner
Aug 15, 2011

by Shine

Midjack posted:

they probably wanted to set a precedent of shaking down doctors for patient information though.

it's this

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


ymgve posted:

*nervously clicks link, reads article, sees name of site, sighs in relief*

lol.

at work the it sec team did a demo thing in the cafeteria of entering your email on haveibeenpwned and I did it and just as I hit enter thought "gently caress I've had this email address for like 20 years and I was a dumbass teen, I'd this gonna return porn?" but no, it was fortunately just xbox mod forums (lol) and rpg codex or something (double lol)

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
it was interesting searching the old ashley madison leak for clients' domains

it was more interesting notifying the affected parties that their credentials may be breached

crazysim
May 23, 2004
I AM SOOOOO GAY

Powerful Two-Hander posted:

lol.

at work the it sec team did a demo thing in the cafeteria of entering your email on haveibeenpwned and I did it and just as I hit enter thought "gently caress I've had this email address for like 20 years and I was a dumbass teen, I'd this gonna return porn?" but no, it was fortunately just xbox mod forums (lol) and rpg codex or something (double lol)

The porn stuff is behind email verification. They are categorized as sensitive breaches like Ashley Madison.

Pro tip: don’t validate email during demo, but do mention this factoid as an uneasy chuckle laugh for the room.

Shame Boy
Mar 2, 2010

why would they force you all to do that poo poo in public? or are you saying you were just doing it as a demo to other people?

Adbot
ADBOT LOVES YOU

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Shame Boy posted:

why would they force you all to do that poo poo in public? or are you saying you were just doing it as a demo to other people?

it was basically a "you're all probably hosed, use strong passwords ok?" thing, so actually probably a good thing to do given the average failure rate on our lovely phishing tests is like 60%. they got some interns to do it, it was all optional and they were getting ignored so I thought" hey I'll do it, what's the worst that can come up? "

crazysim posted:

The porn stuff is behind email verification. They are categorized as sensitive breaches like Ashley Madison.

Pro tip: don’t validate email during demo, but do mention this factoid as an uneasy chuckle laugh for the room.

drat brb gonna see how embarrassed past me is gonna make me

Powerful Two-Hander fucked around with this message at 03:01 on Aug 25, 2019

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply