Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
influx.
Dec 16, 2007

Nice pants!
back to bank postin



one of these banks still truncates your password at 6 chars

i discovered this by typoing my password and still getting logged in
as long as the first 6 are correct, anything else after that just gets stripped

Adbot
ADBOT LOVES YOU

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD
And none of them have 2FA, even as an option.

(NAB SMS spams me to setup new payments, I assume the others do too)

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Lutha Mahtin posted:

the loads of ancient GNU software that's still kickin around has been a pretty good source of billable hours for security folks

heh

Progressive JPEG
Feb 19, 2003

~Coxy posted:

And none of them have 2FA, even as an option.

(NAB SMS spams me to setup new payments, I assume the others do too)

ANZ has SMSes in NZ, no idea if that also applies to oz

ewiley
Jul 9, 2003

More trash for the trash fire
The bank of China makes you install some .exe for "security" on windows. Supposedly this is to install some kind of key management app that lets you sign banking transactions but lol if I'm gonna install some random chinese software that is only really supported on winxp.

flakeloaf
Feb 26, 2003

Still better than android clock

what are the odds that it's not a certificate to allow great firewall mitm

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
https://www.forbes.com/sites/daveywinder/2019/09/16/google-warns-lastpass-users-were-exposed-to-last-password-credential-leak/#2514024c4600

lmao at lastpass users

ewiley
Jul 9, 2003

More trash for the trash fire

This seems kinda constrained because you have to find a URL that will load an untrusted iframe in the domain you're authenticating to (unless i'm misreading tavis' description of the issue). This is probably trivial with office 365, google apps, since just about everything lives on *.google.com or *.microsoftonline.net but others maybe not. I hardly expect Forbes to figure out nuance though.

https://bugs.chromium.org/p/project-zero/issues/detail?id=1930

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
yeah but anyone using lastpass deserves whatever they get

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

CRIP EATIN BREAD posted:

yeah but anyone using lastpass deserves whatever they get

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!
I deserve whatever I get

jre
Sep 2, 2011

To the cloud ?




https://twitter.com/taviso/status/1167311357957435392

Wiggly Wayne DDS
Sep 11, 2010



CRIP EATIN BREAD posted:

yeah but anyone using lastpass deserves whatever they get
i mean agreed, but bizarrely taviso finds them competent and considers 1password to be terrible
https://twitter.com/taviso/status/1167400178912882688

The Fool
Oct 16, 2003


While I've seen Tavis endorse LastPass a couple times, I don't remember him ever having an opinion on 1pass

flakeloaf
Feb 26, 2003

Still better than android clock

they're all terrible

use a piece of paper

The Fool posted:

While I've seen Tavis endorse LastPass a couple times, I don't remember him ever having an opinion on 1pass

also thsi

ewiley
Jul 9, 2003

More trash for the trash fire
I'm the pattern passcode of "M"

https://twitter.com/iblametom/status/1173580854871896064?s=20

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

The Fool posted:

While I've seen Tavis endorse LastPass a couple times, I don't remember him ever having an opinion on 1pass

Later in that same thread

https://twitter.com/taviso/status/1167404993260818434?s=19

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/gabro27/status/1173547934132178944

The Fool
Oct 16, 2003



Fair enough. I suppose I should go try to find the incident and decide how much I care. not at all

JawnV6
Jul 4, 2004

So hot ...

whew, without the GIF i'd be super worried about cutting humans out of the loop and bots just mashing code around without supervision

but they had a celebratory gif? so its probably nothing to worry about

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


if thats what it takes to get people to keep their dependencies up to date...

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/gsuberland/status/1173780622562791425

spankmeister
Jun 15, 2008






hot

crystal Ghost
Sep 5, 2019
O _ O

redleader
Aug 18, 2005

Engage according to operational parameters
imagine asking a normal person to use keepass lol

Workaday Wizard
Oct 23, 2009

by Pragmatica

redleader posted:

imagine asking a normal person to use keepass lol

same but cloud thingies. heck imagine asking them to pay rent for password fillers.

geonetix
Mar 6, 2011


duz posted:

if thats what it takes to get people to keep their dependencies up to date...

I ran a snyk test on our companies repo once. panicked, closed the terminal, and went to find another job.

worked out great thusfar

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

anyone here doing work around ML privacy (and to a lesser degree security)? I'm collecting a bibliography to summarize for some folks and plan out our own research agenda, and would love to swap notes. we're chiefly right now focused on reidentification risk (including attribute disclosure) given a restricted set of inference parameters, but we will likely broaden our scope around more specific and ideally measurable privacy characteristics of models given certain properties of the training data and methods

(if not working on this stuff, and you're interested in learning about the current state of things, https://arxiv.org/pdf/1811.01134.pdf is a good overview)

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

does bitwarden have any traps to watch out for if I deploy it myself? it has a bunch of moving parts and I'm not sure how to lock down the inter-container traffic exactly, but I'm not sure if there are other best practices that I would like to find out before I violate them

The Fool
Oct 16, 2003


testing azure sentinel and got our first incident today: a board member logging in to company resources through a public vpn

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

want to socially engineer that catte

https://twitter.com/gabbytropea/status/1097347872901738497?s=21

Squinky v2.0
Nov 16, 2006

Behind you! A three headed monkey!

College Slice

Shinku ABOOKEN posted:

same but cloud thingies. heck imagine asking them to pay rent for password fillers.

you know what doesn’t cost me anything and works flawlessly

hunter2

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

A catte that did not just contemptuously stare at the person trying to get back in

A shameful catte

spankmeister
Jun 15, 2008







clever girl

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


i mean yeah no poo poo if you didn't lock the door it isn't locked

JawnV6
Jul 4, 2004

So hot ...

Powerful Two-Hander posted:

i mean yeah no poo poo if you didn't lock the door it isn't locked
uh, it's a cheap apartment sliding glass door? the little bit of stamped metal clinging to the frame does a lot less than the broomstick

you can see the way she yanks hard on the first pull, it's very likely 'locked' and that's overpowering it

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

mandatory catte for wework offices
https://twitter.com/neerajka/status/1173997679363407872

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

mystes posted:

It's great that in 2019 things like discord have real 2FA but banks all use SMS or are maybe in the process of jury rigging 2FA in their lovely mobile apps.

There's probably a special circle of hell for companies like Bank of America that are members of the FIDO Alliance but still only support SMS in 2019.

wells fargo still won't accept a password longer than 14 characters


edit: and they disable paste functionality on the password change form so you cannot easily create a random password and copy/paste it in

Farmer Crack-Ass fucked around with this message at 00:11 on Sep 18, 2019

abigserve
Sep 13, 2009

this is a better avatar than what I had before
Banks are driven by uptime. If you lose your account because they can't push a change through to provide 2FA, well, that sucks for you. But if their system goes down for 2 minutes of unscheduled outage while doing said change it makes the news, and even though the result is easily worth the tiny amount of pain they don't see it that way.

This is the same in most large enterprise environments - when your IT systems are basically the ground on which your business can operate, anything that could theoretically break it is treated as bad, no matter how good the reason is.

Adbot
ADBOT LOVES YOU

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

geonetix posted:

I ran a snyk test on our companies repo once. panicked, closed the terminal, and went to find another job.

worked out great thusfar

HAHAHA HAHAHAHAHAHA HAHAHA *begins to have nam like flashback about container security*

Its all red. All red.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply