Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
ThePeavstenator
Dec 18, 2012

:burger::burger::burger::burger::burger:

Establish the Buns

:burger::burger::burger::burger::burger:

Subjunctive posted:

https://dontduo.com/

homer_drinking_bird.gif

ahahahahahahahahahahahaha

Adbot
ADBOT LOVES YOU

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
that's a joke, right?

like, if you try to sign up it just sends you an email calling you an idiot... right?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I've just tripled my productivity

influx.
Dec 16, 2007

Nice pants!

infernal machines posted:

that's a joke, right?

like, if you try to sign up it just sends you an email calling you an idiot... right?

sign up to find out. then theyll have your cc deets and mfa.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Subjunctive posted:

https://dontduo.com/

homer_drinking_bird.gif

don't duo what Donny duo does

Nomnom Cookie
Aug 30, 2009



Powerful Two-Hander posted:

holy lmao our homebrew system for managing "secure" access to database creds logs them in plaintext in an area accessible from all user sessions

I'm either gonna get thanked or fired for flagging this lmao

our setup is similar but you have to be a dev to get access to read logs, so the logs are never read, so the system is secure

Metapod
Mar 18, 2012
Hey yall quick question I'm studying to take the CompTIA security+ test is there anything in particular that the test asks a lot about? I've been doing a bunch of practice tests and just trying to narrow the scope of the wide range these practice tests are asking.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

What kinds of questions are even on a comptia level security cert

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Subjunctive posted:

https://dontduo.com/

homer_drinking_bird.gif

this is cute

The Fool
Oct 16, 2003


Metapod posted:

Hey yall quick question I'm studying to take the CompTIA security+ test is there anything in particular that the test asks a lot about? I've been doing a bunch of practice tests and just trying to narrow the scope of the wide range these practice tests are asking.

If you've been a computer toucher for more than a year most of the stuff it covers should be common sense. Make sure you know all the dumb acronyms, and have a basic grasp of business risk and you'll be fine.

Captain Foo posted:

What kinds of questions are even on a comptia level security cert

Basic encryption, networking, business risk, physical security and outdated malware models.

fresh_cheese
Jul 2, 2014

MY KPI IS HOW MANY VP NUTS I SUCK IN A FISCAL YEAR AND MY LAST THREE OFFICE CHAIRS COMMITTED SUICIDE
anybody have an informed opinion on https://threema.ch ?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
the have a whitepaper for their crypto https://threema.ch/press-files/2_documentation/cryptography_whitepaper.pdf

ewiley
Jul 9, 2003

More trash for the trash fire

Subjunctive posted:

https://dontduo.com/

homer_drinking_bird.gif

This is some awesome performance art in support of U2F

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
this is why i harp on people that SMS challenges dont count as 2-factor auth.

hell, even NIST says to quit it with that poo poo

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
to save money just get one dontduo.com account for all your coworkers and then have them all use the same #

even better!

Metapod
Mar 18, 2012

The Fool posted:

If you've been a computer toucher for more than a year most of the stuff it covers should be common sense. Make sure you know all the dumb acronyms, and have a basic grasp of business risk and you'll be fine.


Basic encryption, networking, business risk, physical security and outdated malware models.

Oh cool ty

mystes
May 31, 2006

It's great that in 2019 things like discord have real 2FA but banks all use SMS or are maybe in the process of jury rigging 2FA in their lovely mobile apps.

There's probably a special circle of hell for companies like Bank of America that are members of the FIDO Alliance but still only support SMS in 2019.

ewiley
Jul 9, 2003

More trash for the trash fire

mystes posted:

It's great that in 2019 things like discord have real 2FA but banks all use SMS or are maybe in the process of jury rigging 2FA in their lovely mobile apps.

There's probably a special circle of hell for companies like Bank of America that are members of the FIDO Alliance but still only support SMS in 2019.

USAA uses Symantec VIP, which isn't perfect but it's pretty good

mystes
May 31, 2006

ewiley posted:

USAA uses Symantec VIP, which isn't perfect but it's pretty good
If it's like paypal until 6 months ago and it lets you enter your own serial number for the Symantec VIP token, you might actually be able to use any TOTP app with it: https://it.knightnet.org.uk/blog/use-an-authenticator-app-to-login-to-paypal/

It's really annoying how few people support U2F though.

Schadenboner
Aug 15, 2011

by Shine

mystes posted:

There's probably a special circle of hell for companies like Bank of America that are members of the FIDO Alliance but still only support SMS in 2019.

I somehow doubt this will be the deciding factor for BoA's circle assignment?

:shrug:

Pile Of Garbage
May 28, 2007



ewiley posted:

USAA uses Symantec VIP, which isn't perfect but it's pretty good

i recently had to install symantec VIP on my phone to use one of our vendor's dumbass IaaS cloud platforms which brings the count to 7 MFA apps on my phone lol

Shame Boy
Mar 2, 2010

mystes posted:

It's great that in 2019 things like discord have real 2FA but banks all use SMS or are maybe in the process of jury rigging 2FA in their lovely mobile apps.

There's probably a special circle of hell for companies like Bank of America that are members of the FIDO Alliance but still only support SMS in 2019.

my credit union's online banking system required 8 character number-only passwords until a few years ago. like not alphanumeric, literally just numbers.

to their credit they have since overhauled basically everything and their login system is actually somewhat acceptable now.

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
my credit union had a 8-12 character password requirement, but you had to answer your security questions every time, and they were case sensitive.

i got locked out for a year and didn't go through the recovery process to be let back in until they fixed that poo poo.

Kazinsal
Dec 13, 2011



Shame Boy posted:

my credit union's online banking system required 8 character number-only passwords until a few years ago. like not alphanumeric, literally just numbers.

to their credit they have since overhauled basically everything and their login system is actually somewhat acceptable now.

mine did the same but until the recent overhaul it was seven digits. I'm sure 90% of people's online banking passwords there were just their phone numbers

Shame Boy
Mar 2, 2010

CRIP EATIN BREAD posted:

my credit union had a 8-12 character password requirement, but you had to answer your security questions every time, and they were case sensitive.

i got locked out for a year and didn't go through the recovery process to be let back in until they fixed that poo poo.

my other old credit union would lock you out after 5 password attempts or whatever and require you to come into a branch in person and show ID to unlock your account lmao

i was locked out of that one for a whiiiile

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

ewiley posted:

USAA uses Symantec VIP, which isn't perfect but it's pretty good

its expensive dogshit and you should use something else

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Shame Boy posted:

my other old credit union would lock you out after 5 password attempts or whatever and require you to come into a branch in person and show ID to unlock your account lmao

i was locked out of that one for a whiiiile

yeah i had to call during business hours and talk to the person to reset my stuff.

loved explaining to the nice bank lady how to spell "crip eatin bread"

Jewel
May 2, 2009

https://twitter.com/rd_pentest/status/1172175324827848704

fun

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


this is intentional behavior introduced with Win7 and MS refuses to fix it in a meaningful away. This is why you take the UAC slider up to Always Notify or run with a non-admin account and context switch when you need it

ewiley
Jul 9, 2003

More trash for the trash fire

BangersInMyKnickers posted:

its expensive dogshit and you should use something else

I like USAA :ohdear:

It's not like I have any choice on what mfa solution they use.

fritz
Jul 26, 2003

mystes posted:

It's great that in 2019 things like discord have real 2FA but banks all use SMS or are maybe in the process of jury rigging 2FA in their lovely mobile apps.

There's probably a special circle of hell for companies like Bank of America that are members of the FIDO Alliance but still only support SMS in 2019.

bank of america's already got plenty of spots in hell waiting

Soricidus
Oct 21, 2010
freedom-hating statist shill

mystes posted:

It's great that in 2019 things like discord have real 2FA but banks all use SMS or are maybe in the process of jury rigging 2FA in their lovely mobile apps.

come to Europe. uk banks all hand out chip devices where you stick in your debit card and enter your pin to get a one-time code, or some of them just have authenticated tokens that are the same principle but the thing-you-have is the token rather than the card

not perfect probably but a hell of a lot better than loving sms

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

i think some american banks experimented with that, but then they realized it would lower profits 0.00001%

spankmeister
Jun 15, 2008






Soricidus posted:

come to Europe. uk banks all hand out chip devices where you stick in your debit card and enter your pin to get a one-time code, or some of them just have authenticated tokens that are the same principle but the thing-you-have is the token rather than the card

not perfect probably but a hell of a lot better than loving sms

Some Dutch banks had this, and the devices were rather expensive. As it turned out, they spent millions on those things, and the fraud prevented was less than that, so they lost money.

Instead they have an app now to provide the second factor. Which works well enough, they gave it some thought and it's decently secure.

Soricidus
Oct 21, 2010
freedom-hating statist shill
i know plenty of older people who don’t have a smart phone but do some banking on laptops or w/e. they won’t use apps if they can help it. handing out a cheap device that just uses the chip they already have in their bank card is a great way to get them off sms. idk if the implementation is actually secure but it can’t be worse than sms.

mystes
May 31, 2006

How do they secure the process of authorizing a new phone for the smartphone apps? Do you have to use the old phone to authorize it? If not it seems useless. I think for example capitalone just uses SMS for this so it's no better than normal SMS 2FA.

I think the reason banks in the US gave up on 2FA is that they don't want to deal with people who lose their tokens.

I just wish they would let people use u2f or totp if they know what they're doing.

mystes fucked around with this message at 20:55 on Sep 12, 2019

Shaggar
Apr 26, 2006
I like azure mfa w/ the Microsoft authenticator. its cool because they have plugins for basically everything so you can stick MFA everywhere with little effort.

klafbang
Nov 18, 2009
Clapping Larry

spankmeister posted:

Some Dutch banks had this, and the devices were rather expensive. As it turned out, they spent millions on those things, and the fraud prevented was less than that, so they lost money.

Instead they have an app now to provide the second factor. Which works well enough, they gave it some thought and it's decently secure.

Rabobank still has. But it is cumbersome and if you don’t have your reader with you, you can’t internet bank from public toilets while out and about, so they also allow you to set a 5 digit code to bypass the 2FA (still need the reader to sign transfers to non pre-approved accounts, so it’s slightly less insane than it sounds).

mystes
May 31, 2006

Yeah the problem is allowing fallback to SMS.

Adbot
ADBOT LOVES YOU

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

mystes posted:


I think the reason banks in the US gave up on 2FA is that they don't want to deal with people who lose their tokens.


android isn't doing this poo poo any favors. Those poor suckers have to jump to a new phone install with new tokens every time they change devices, meanwhile I am using the same software token that I setup on my 3gs and have been migrating through 3 phones now

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply