Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Nomnom Cookie posted:

you talked about wireguard features and repeated some marketing copy

Ignoring that wireguard has been mentioned:

do you understand the fact that "no runtime allocation" is in fact a technical specification that means something and that it does, in fact, eliminate an entire class of bugs

Adbot
ADBOT LOVES YOU

Nomnom Cookie
Aug 30, 2009



Captain Foo posted:

Ignoring that wireguard has been mentioned:

do you understand the fact that "no runtime allocation" is in fact a technical specification that means something and that it does, in fact, eliminate an entire class of bugs

it's a security feature. it doesn't substitute for experience

Wiggly Wayne DDS
Sep 11, 2010



Nomnom Cookie posted:

it's a security feature. it doesn't substitute for experience
i'd get this framed if it wasn't the last remnant of an endangered species

Tankakern
Jul 25, 2007

Xarn posted:

I wanted to note that I read this effortpost and appreciate it, but Oslo airport ate my notebook, killing my will to respond rn.

tell us where gardermoen touched you

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Nomnom Cookie posted:

it's a security feature. it doesn't substitute for experience

so, no

Midjack
Dec 24, 2007



i think you’ll find that if youre like > ipredator > tor > s3 on all this poo poo then you’re fully protected.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Midjack posted:

i think you’ll find that if youre like > ipredator > tor > s3 on all this poo poo then you’re fully protected.

just don't post it to your personal github afterward

Soricidus
Oct 21, 2010
freedom-hating statist shill

akadajet posted:

ya, you really don't want to use software with the words "open" or "libre" in the name

like ssl, bsd, ssh, jdk, office

i'm sure there are others

openssh is ok isn’t it? it’s probably the least bad of the common sshs at least after the libssh vulns (and just lol at drop”let’s roll our own crypto”bear)

openjdk is also good, it’s the only java anyone should touch now (it is taken as axiomatic for the purposes of this post that java is good)

Raere
Dec 13, 2007

Lain Iwakura posted:

avoid being near arguments by couples in libraries while using ssh if you do implement that

I'm dumb and don't get this, please help.

haveblue
Aug 15, 2005



Toilet Rascal

Raere posted:

I'm dumb and don't get this, please help.

that's how they got ross ulbricht, the silk road guy. they watched him until he unlocked his laptop, then two agents distracted him by pretended to be an arguing couple until someone got close enough to physically stop him relocking it

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Didn't Ross also have a USB dead man's switch that they prevented him from pulling out?

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

CommieGIR posted:

Didn't Ross also have a USB dead man's switch that they prevented him from pulling out?

https://www.wired.com/2015/05/silk-road-2/ doesn't mention one:

quote:

What unfolded next was a piece of improvisational theater. At 3:14 pm, DPR was typing away, writing to Cirrus. Just then, a middle-aged woman and man came toward Ross, ambling along in the kind of semihomeless shuffle you might often see in a San Francisco library. “gently caress you!” the woman yelled when they were directly behind Ross’ chair. As if they were a deranged couple about to fight, the man grabbed the woman by the collar and raised his fist.

Ross turned around for just a second, during which a hand reached across the table and grasped Ross’ Samsung. The petite, unassuming young Asian woman sitting across from Ross this whole time was, to everyone’s surprise, also an FBI agent. Ross lunged for his machine, a hair too late, as she turned like a quarterback for a quick handoff to Kiernan, who appeared out of nowhere—as instructed—to get the laptop. It took less than 10 seconds. From afar, Tarbell was astonished by the elegant choreography of the whole thing. It looked like the police procedural version of a tight jazz quartet.

Schadenboner
Aug 15, 2011

by Shine
I'm hoping they all got their library cards revoked after this.

:decorum:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
nah usbkill was created as a response to his arrest but it's really poorly thought out

https://github.com/hephaest0s/usbkill

based on what i know about its design, it still doesn't thwart usb jigglers if you can find one that mimics a usb mouse the user would use and it wouldn't be hard to find usb drives that match what you're using with some effort

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/TwitterSupport/status/1169334340393689088

how long can y'all hold your breath for?

Schadenboner
Aug 15, 2011

by Shine
Isn't SMS like Caller ID levels of secure?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Schadenboner posted:

Isn't SMS like Caller ID levels of secure?

like i said, how long can you hold your breath?

Fuzzy Mammal
Aug 15, 2001

Lipstick Apathy

my buddy has @courage and has had his verizon account stolen three times even with giant flags on it saying "do not change anything over the phone." it's ridiculous.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Lain Iwakura posted:

nah usbkill was created as a response to his arrest but it's really poorly thought out

https://github.com/hephaest0s/usbkill

based on what i know about its design, it still doesn't thwart usb jigglers if you can find one that mimics a usb mouse the user would use and it wouldn't be hard to find usb drives that match what you're using with some effort

Ah. that must've been where I remembered it from.

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

i would pay good money to see a live show where it's just sarah jeong on stage talking about being a reporter who covered the DPR trial. that story had so many insane angles to it

James Baud
May 24, 2015

by LITERALLY AN ADMIN
Lol @ Exim, true successor of Sendmail.

(CVE-2019-15846: local or remote attacker can execute programs with root privileges)


Good thing I've been using postfix forever - is exim still the default in Debian and variants?

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Lutha Mahtin posted:

i would pay good money to see a live show where it's just sarah jeong on stage talking about being a reporter who covered the DPR trial. that story had so many insane angles to it

CARL MARK FORCE IV

Soricidus
Oct 21, 2010
freedom-hating statist shill

Lutha Mahtin posted:

i would pay good money to see a live show where it's just sarah jeong on stage talking about being a reporter who covered the DPR trial. that story had so many insane angles to it

i imagine that some day i may have a story written about my life, and it would be good to have a detailed account of it

Nomnom Cookie
Aug 30, 2009




in theory, something being impossible prevents it from happening. in practice...

it doesn't matter at all what features it has. are you confused by the way I'm using the word feature? should I have said selling point instead? I won't be surprised if wireguard turns out to be good, and some aspects of its design contribute to that expectation, but whether or not it's good won't be based on how often it calls malloc (or would that be kmalloc lol lets do important things in the kernel).

yes marketing to techies is a thing, duh, you got marketed to. the implementation details of a product have no bearing on its quality

The Fool
Oct 16, 2003


Implementation details are absolutely a contributing factor to a products overall quality

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Nomnom Cookie posted:

the implementation details of a product have no bearing on its quality

:psyduck:

Soricidus
Oct 21, 2010
freedom-hating statist shill
there sure are some takes itt lately

stay tuned, next on the secfuck thread: a poster tries to defend rolling their own crypto

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Nomnom Cookie posted:

the implementation details of a product have no bearing on its quality

what do you really mean here? I’m sure it’s not the obvious meaning of the words

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

i don't even understand the math behind some types of encryption

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Soricidus posted:

there sure are some takes itt lately

stay tuned, next on the secfuck thread: a poster tries to defend rolling their own crypto

i think many threads back we had this happen

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Subjunctive posted:

what do you really mean here? I’m sure it’s not the obvious meaning of the words

yhbt. yhl. hand.

Pie Colony
Dec 8, 2006
I AM SUCH A FUCKUP THAT I CAN'T EVEN POST IN AN E/N THREAD I STARTED

Soricidus posted:

there sure are some takes itt lately

stay tuned, next on the secfuck thread: a poster tries to defend rolling their own crypto

if you roll your own crypto then the NSA can’t backdoor it. nice try narc

Pie Colony
Dec 8, 2006
I AM SUCH A FUCKUP THAT I CAN'T EVEN POST IN AN E/N THREAD I STARTED
and before you ask, yes it's a machine learning crypto algorithm

Nomnom Cookie
Aug 30, 2009



Subjunctive posted:

what do you really mean here? I’m sure it’s not the obvious meaning of the words

you're right, i pushed that post halfway out then broke it off to run to dinner

what i care about are performance, stability, security, functionality, probably other poo poo im not gonna bother to think of. that what makes up product quality. as a user, how those are achieved doesn't make a poo poo. none at all. implementation details absolutely do matter a fuckload for the people building the thing but i'm not doing that. i'm deciding what helm chart to install. avoiding malloc or proving race-freedom or whatever are powerful techniques that are interesting to read about and will never, ever be considered by me when i have to evaluate competing options, unless doing in-house patches is on the table. usually it's not

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
if you were in the business of buying bridges (maintenance of them isn't your job), and had the choice of one made of dog poo poo, or one where the architects proudly avoided using any dog poo poo at all, which would you pick

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
Look, you might say that making bridges out of dog poo poo is an absolutely terrible idea, there's a ton of recent cases of bridges falling down due to being made out of dog poo poo, and these folks making a point of the fact that they don't make their bridges out of dog poo poo is a direct response to it being inexplicably common in the bridge-making industry.

But I will keep looking around for a dog poo poo bridge manufacturer that doesn't have any bridges currently in the process of falling down, because this new-fangled "don't build bridges out of dog poo poo" idea is just totally unproven, you know?

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

that is probably the worst analogy for this situation

repugnant
Jun 29, 2005

You can only think of me.

Hi everyone; I recently came across a device that has a web interface, defaulting to plaintext port 80. It has an option to enable TLS but it makes you upload your own certificate before it enables TLS. I made a certificate with a 1 day expiration and turned on TLS exclusively (no port 80). I tested it, it works. I waited one day, and after the certificate expired it disabled TLS and only allowed port 80. This is a device that controls small scale (200 amp) remote power plants (think LTE and 5G equipment). I feel like I should talk to the manufacturer about this before it gets deployed.

first post in yospos, sorry

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Nomnom Cookie posted:

you're right, i pushed that post halfway out then broke it off to run to dinner

what i care about are performance, stability, security, functionality, probably other poo poo im not gonna bother to think of.

lol if u expect to get all of those in one product. pick 2.

you'll only get 1 at best.

Adbot
ADBOT LOVES YOU

Nomnom Cookie
Aug 30, 2009



Jabor posted:

Look, you might say that making bridges out of dog poo poo is an absolutely terrible idea, there's a ton of recent cases of bridges falling down due to being made out of dog poo poo, and these folks making a point of the fact that they don't make their bridges out of dog poo poo is a direct response to it being inexplicably common in the bridge-making industry.

But I will keep looking around for a dog poo poo bridge manufacturer that doesn't have any bridges currently in the process of falling down, because this new-fangled "don't build bridges out of dog poo poo" idea is just totally unproven, you know?

lol a wireguard stan. I honestly hadn’t thought that could happen

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply