Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
The Fool
Oct 16, 2003


Lain Iwakura posted:

ah no i didn't mention it to her it seems but

https://twitter.com/KateLibc/status/1171174732101644288

i am tempted to just dump the details about how you retrieve the data just to dial up the heat

you have me blocked on twitter and I have no idea why that would be

Adbot
ADBOT LOVES YOU

Trabisnikof
Dec 24, 2005

yeah pagers being insecure and spamming medical details is certainly a long term thing and it seems like at the end of the day no one cares

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

The Fool posted:

you have me blocked on twitter and I have no idea why that would be

what is your twitter handle?

Boiled Water posted:

be careful when ducking with people with deep pockets

this is the provincial government

Shaggar
Apr 26, 2006
in the US its legal to send unencrypted phi thru pagers. idk how it works in Canada. it appears that pipeda allows unencrypted faxes to contain personal info so I would bet paging is ok too.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Lain Iwakura posted:

this is the provincial government

Be careful when ducking with people who can just have you arrested on trumped up "hacking" charges. Sure, they're wrong, but at the end of the day you're in jail and the public is picking up the tab for fighting you tooth and nail.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Volmarias posted:

Be careful when ducking with people who can just have you arrested on trumped up "hacking" charges. Sure, they're wrong, but at the end of the day you're in jail and the public is picking up the tab for fighting you tooth and nail.

can i not be patronised here? i know a thing or seventeen about my line of work

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Be careful when ducking with a pig in mud

sorry

Shaggar
Apr 26, 2006
also technically in the US I think it would actually be illegal to intentionally intercept/receive PHI that was sent via page or fax to someone else.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
not to diminish your work, but i think i remember reading about this in 2600 or something back in the early 2000s, before the prevalence of SDR. the hardware was more specialized and expensive, but obviously the result were the same.

Shaggar
Apr 26, 2006
pager interception is pretty much as old as pagers. still, its definitely good to show people that its a real threat and that it should be avoided even if the law says its ok.

I know of atleast one major health provider that has mostly outlawed faxing for security reasons even though im sure it pissed off a load of doctors and their assistants.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
The fact that Fax machines are still valid in this day and age baffles me.

Trabisnikof
Dec 24, 2005

yeah i think that since we made snooping pagers illegal in the usa that just means they'll keep using insecure pagers until the technology dies

Shaggar
Apr 26, 2006
there are a billion doctors offices with litterrall loving fax machines. not fax services, but fax machines. you can tell them about the many different secure and reliable transports you have for them to use instead, but they don't want to change the workflow of taking the fax off the machine and sticking it in a cabinet.

altho partly CMS is to blame cause they totally hosed up wrt Direct both in the actual design and in how they failed to check validity of EMR implementations.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Shaggar posted:

there are a billion doctors offices with litterrall loving fax machines. not fax services, but fax machines. you can tell them about the many different secure and reliable transports you have for them to use instead, but they don't want to change the workflow of taking the fax off the machine and sticking it in a cabinet.

altho partly CMS is to blame cause they totally hosed up wrt Direct both in the actual design and in how they failed to check validity of EMR implementations.

Yeah, I know, and banks still love them too.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Lain Iwakura posted:

what is your twitter handle?


yea i noticed i was blocked too and i use the same handle on twitter

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

infernal machines posted:

not to diminish your work, but i think i remember reading about this in 2600 or something back in the early 2000s, before the prevalence of SDR. the hardware was more specialized and expensive, but obviously the result were the same.

yes. this wasn't new. i am not sure what you're trying to get at here. my complaint was this remark which was unnecessary:

Volmarias posted:

Be careful when ducking with people who can just have you arrested on trumped up "hacking" charges. Sure, they're wrong, but at the end of the day you're in jail and the public is picking up the tab for fighting you tooth and nail.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

fishmech posted:

yea i noticed i was blocked too and i use the same handle on twitter

you're fixed

i use an autoblock to keep my twitter from giving me grief and if someone ends up on it by accident i generally lift it

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Lain Iwakura posted:

yes. this wasn't new. i am not sure what you're trying to get at here.

er, not particularly trying to get at anything. i guess my intent was just to point out to the person saying "be careful", for whatever reason, that this has been known and discussed and even publicized to some degree in the context of medical PII for 20+ years and no one has cared, so it's unlikely they'll start caring now.

Midjack
Dec 24, 2007



Volmarias posted:

Be careful when ducking with a pig in mud

sorry

:honked::razorback:

influx.
Dec 16, 2007

Nice pants!
Just spent the morning trying to work out how bad one of our users was owned when responding IP to an internal phishing campaign came from a different continent.
Turns out she forwarded it to *old job* helpdesk instead of ours and they detonated it. jesus gently caress.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

influx. posted:

Just spent the morning trying to work out how bad one of our users was owned when responding IP to an internal phishing campaign came from a different continent.
Turns out she forwarded it to *old job* helpdesk instead of ours and they detonated it. jesus gently caress.

lmao

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

influx. posted:

Just spent the morning trying to work out how bad one of our users was owned when responding IP to an internal phishing campaign came from a different continent.
Turns out she forwarded it to *old job* helpdesk instead of ours and they detonated it. jesus gently caress.

so you inadvertently started a corporate espionage campaign?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

influx. posted:

Just spent the morning trying to work out how bad one of our users was owned when responding IP to an internal phishing campaign came from a different continent.
Turns out she forwarded it to *old job* helpdesk instead of ours and they detonated it. jesus gently caress.

this is worth at least one act in your IT support musical if you can get a good harmony under it

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

also call your legal department

influx.
Dec 16, 2007

Nice pants!
luckily the 'payload' is some 'how to spot a phishing email' training doco.

should bill them for the training

El Mero Mero
Oct 13, 2001

quote:

quote:


Much like a doctor can diagnose an illness by analyzing the symptoms your body is exhibiting, zIPS™ can detect both known and unknown threats by analyzing the behavior of your mobile device. By analyzing slight deviations to the mobile device’s operating system’s statistics, memory, CPU and other system parameters, z9™ detection engine can accurately identify not only the specific type of malicious attack, but also the forensics associated with the who, what, where, when, and how of an attack occurrence.

Zimperium developed the innovative and award-winning z9™ engine by training it over many years on proprietary machine-learning algorithms that distinguish normal from malicious behavior on Android and iOS devices. Unlike cloud-based mobile security solutions that employ app sandboxing or tunnel traffic through the cloud, the z9™ engine sits directly on the mobile devices within the zIPS™ app, in order to provide complete protection around the clock.

:allears:

lmao this was rolled out to the government agency I work for this summer. The only thing it did was reduce an iphone battery to 0 in record time, spam the phone with warnings about how it wasn't connected to a VPN, and provide a second notification about patch status. Uh...it also has this feature called "danger zone" that just seems to bring up a map that shows me where I am?

El Mero Mero fucked around with this message at 04:02 on Sep 10, 2019

Agile Vector
May 21, 2007

scrum bored



El Mero Mero posted:

lmao this was rolled out to the government agency I work for this summer. The only thing it did was reduce an iphone battery to 0 in record time, spam the phone with warnings about how it wasn't connected to a VPN, and provide a second notification about patch status. Uh...it also has this feature called "danger zone" that just seems to bring up a map that shows me where I am?

does it show the highway to your location too?

Nomnom Cookie
Aug 30, 2009




lmao this was rolled out to the government agency I work for this summer. The only thing it did was reduce an iphone battery to 0 in record time, spam the phone with warnings about how it wasn't connected to a VPN, and provide a second notification about patch status. Uh...it also has this feature called "danger zone" that just seems to bring up a map that shows me where I am?
[/quote]

i think the best part is the copy admits it does nothing and presents that as a selling point

spankmeister
Jun 15, 2008






lol zimperium is trash

ewiley
Jul 9, 2003

More trash for the trash fire

flakeloaf posted:

https://election.ctvnews.ca/potential-health-data-breach-exposing-names-medical-conditions-discovered-by-privacy-researcher-1.4581914


lol at the people crying about 90 day disclosure, this one waited almost a fuckin year

doctors rely on old tech cause the new os is a pos
but the old os is insecure

This is literally the first interesting thing I did with my little SDR dongle when I was messing around with gnu radio. It was all of 10 minutes of work and there are well documented tutorials on how to do it. Pager signals are crazy strong so I could still reliably decode them sitting in my basement with a 3' whip antenna.

Also wait till they find out about clear police/EMS radio and services like broadcastify where you can just listen to people having bad days all day.

Shaggar posted:

there are a billion doctors offices with litterrall loving fax machines. not fax services, but fax machines. you can tell them about the many different secure and reliable transports you have for them to use instead, but they don't want to change the workflow of taking the fax off the machine and sticking it in a cabinet.

altho partly CMS is to blame cause they totally hosed up wrt Direct both in the actual design and in how they failed to check validity of EMR implementations.

Fax is actually called out in HITECH as insecure so in the US they shouldn't be using it to send PHI.

flakeloaf
Feb 26, 2003

Still better than android clock

ewiley posted:

Fax is actually called out in HITECH as insecure so in the US they shouldn't be using it to send PHI.

and yet they do because, and this i believe is a direct quote, "i waaaant iiiiiiiiitttttttttttttttt"

Feisty-Cadaver
Jun 1, 2000
The worms crawl in,
The worms crawl out.

ewiley posted:

sitting in my basement with a 3' whip antenna.

text me

Shame Boy
Mar 2, 2010

Lain Iwakura posted:

you're fixed

i use an autoblock to keep my twitter from giving me grief and if someone ends up on it by accident i generally lift it

now i'm wondering who fishmech was following that got them on the auto-block list :ninja:

also is that a new hat in your twitter av, it's a nice hat

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


holy lmao our homebrew system for managing "secure" access to database creds logs them in plaintext in an area accessible from all user sessions

I'm either gonna get thanked or fired for flagging this lmao

Soricidus
Oct 21, 2010
freedom-hating statist shill

Powerful Two-Hander posted:

holy lmao our homebrew system for managing "secure" access to database creds logs them in plaintext in an area accessible from all user sessions

I'm either gonna get thanked or fired for flagging this lmao

:nsallears:

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Powerful Two-Hander posted:

I'm either gonna get thanked or fired for flagging this lmao

why not both?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/HackerMovieBot/status/1171903629877342208

The Fool
Oct 16, 2003


:perfect:

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
Some of these are solid gold

https://twitter.com/HackerMovieBot/status/1170128420950274048

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

https://dontduo.com/

homer_drinking_bird.gif

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply