Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

mystes posted:

The biggest problem is just that nobody wants to train users to understand this stuff and deal with customer support when people lose their certificate/token.

yup, it's only like the last five years when people have had any kind of two-factor setup without corporate IT to call about it, and you can only teach the general public one new thing per decade

Adbot
ADBOT LOVES YOU

ewiley
Jul 9, 2003

More trash for the trash fire

mystes posted:

Honestly, just implementing u2f in software using a private key stored in the tpm / trusted enclave / whatever would solve most problems. Ideally add a password or require a fingerprint in case the phone is stolen.

Using client side certificates stored in the TPM could have achieved the same effect on desktops 15 years ago.

The biggest problem is just that nobody wants to train users to understand this stuff and deal with customer support when people lose their certificate/token.

This is great until you have to replace your device. Unless you can backup a u2f key on to a cloud and restore it to a new device seamlessly and consistently [e: and without it getting stolen from your cloud account], you're out of luck if your phone/computer/whatever blows up. U2f USB keys are non-starters for people with only mobile devices to access accounts on and the NFC/bluetooth ones are insanely clunky.

SMS is the lowest-common denominator when it comes to a second factor that will survive you dropping your phone in the toilet and needing to get access back to your facebook account.

ewiley fucked around with this message at 19:49 on Sep 24, 2019

FAT32 SHAMER
Aug 16, 2012



did anyone else see the vbulletin 0day that dropped earlier today

geonetix
Mar 6, 2011


it’s a beauty

apparently it was worth $10000 if they posted it to 0dayium instead of anonymously to the fd list

FAT32 SHAMER
Aug 16, 2012



here’s to hoping SA’s vbulletin is so mangled and old that it SHES this matter lol

geonetix
Mar 6, 2011


doubt the SA vbulletin is new enough to hit the minimum version

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



geonetix posted:

doubt the SA vbulletin is new enough to hit the minimum version

security through obsolescence

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

FAT32 SHAMER posted:

did anyone else see the vbulletin 0day that dropped earlier today

I didn't, op

Doccykins
Feb 21, 2006

geonetix posted:

doubt the SA vbulletin is new enough to hit the minimum version

its not by 3 major releases lol

quote:

The zero-day exploit code is verified to work against supported versions of vBulletin from 5.0.0 to the latest 5.5.4 build.

quote:

Powered by: vBulletin Version 2.2.9 (SAVB-v2.1.24)

Workaday Wizard
Oct 23, 2009

by Pragmatica
we shouldn’t’ve driven the discourse guy away lol

imagine sa with notifications, likes, and badges

Sereri
Sep 30, 2008

awwwrigami

Shinku ABOOKEN posted:

imagine sa with notifications, likes, and badges, stamping on a smiley face - forever

Loky11
Dec 12, 2006

Pull on the new flesh like borrowed gloves and burn your fingers once again

Shinku ABOOKEN posted:

we shouldn’t’ve driven the discourse guy away lol

imagine sa with notifications, likes, and badges

oh hell no please

Shame Boy
Mar 2, 2010

Loky11 posted:

oh hell no please

popup ding sound, "GokuLiker69 has quoted your post and replied: im gay" appears in the corner of your screen on top of the powerpoint you're presenting to the executives

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



chef fatwood of snack overflow

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Achievement: banned for shitposting 10 times!

Achievement: Over 100 goons have placed you on Ignore!

Achievement: Literally just gave money for this one.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Trump thinks Crowdstrike has the Clinton email server, and tried to get the President of Ukraine to investigate:

https://twitter.com/RayRedacted/status/1176867460215128066?s=20

Which is laughable

CommieGIR fucked around with this message at 15:53 on Sep 25, 2019

Vomik
Jul 29, 2003

This post is dedicated to the brave Mujahideen fighters of Afghanistan

Volmarias posted:

Achievement: banned for shitposting 10 times!

Achievement: Over 100 goons have placed you on Ignore!

Achievement: Literally just gave money for this one.

Frog Dog
Kickstart a rural hotdog shop.

Vomik
Jul 29, 2003

This post is dedicated to the brave Mujahideen fighters of Afghanistan
Christmas Is Cancelled
Spend your children’s present money on a rural hot dog shop. (This achievement is only available during the Doobies Christmas Event.)

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

CommieGIR posted:

Trump thinks Crowdstrike has the Clinton email server, and tried to get the President of Ukraine to investigate:

https://twitter.com/RayRedacted/status/1176867460215128066?s=20

Which is laughable

He also tries the full idiot press with other world leaders, which is just disappointing because it means it's not just an act for his supporters.

Loky11
Dec 12, 2006

Pull on the new flesh like borrowed gloves and burn your fingers once again
somethingawful gold for you!

Hed
Mar 31, 2004

Fun Shoe

Shame Boy posted:

popup ding sound, "GokuLiker69 has quoted your post and replied: im gay" appears in the corner of your screen on top of the powerpoint you're presenting to the executives

:bisonyes:

Hed
Mar 31, 2004

Fun Shoe

CommieGIR posted:

Trump thinks Crowdstrike has the Clinton email server, and tried to get the President of Ukraine to investigate:

https://twitter.com/RayRedacted/status/1176867460215128066?s=20

Which is laughable

sounds like the guy/gal who tried to FOIA NSA to get their emails back when they lost them?

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


https://twitter.com/AndrewDesiderio/status/1176890146567983104

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
I was always suspicious about the RGB stuff on gaming system:

https://twitter.com/gsuberland/status/1175570500292108289?s=20

Soricidus
Oct 21, 2010
freedom-hating statist shill
misread that as KGB

Midjack
Dec 24, 2007



Soricidus posted:

misread that as KGB

сука блять!

Pile Of Garbage
May 28, 2007



CommieGIR posted:

I was always suspicious about the RGB stuff on gaming system:

https://twitter.com/gsuberland/status/1175570500292108289?s=20

holy lol:

https://twitter.com/gsuberland/status/1175571371415560193

Janitor Prime
Jan 22, 2004

PC LOAD LETTER

What da fuck does that mean

Fun Shoe
wtf does any of that mean

Salt Fish
Sep 11, 2003

Cybernetic Crumb

Janitor Prime posted:

wtf does any of that mean

Maybe any userspace program can use it to elevate privileges or flash your bios depending on a bunch of specifics to be determined.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
your 2fast2furious gamer systems with rgb led motherboards, videocards, etc. have giant gaping holes to low-level systems that can access everything, so that an app running as an unprivileged user can change the colour of lights

e:
https://twitter.com/gsuberland/status/1175578399039004673

lol

infernal machines fucked around with this message at 04:35 on Sep 26, 2019

Oneiros
Jan 12, 2007



infernal machines posted:

your 2fast2furious gamer systems with rgb led motherboards, videocards, etc. have giant gaping holes to low-level systems that can access everything, so that an app running as an unprivileged user can change the colour of lights

e:
https://twitter.com/gsuberland/status/1175578399039004673

lol

what if i shoved all those rgb components into a windowless, black case. will that protect me? :ohdear:

taqueso
Mar 8, 2004


:911:
:wookie: :thermidor: :wookie:
:dehumanize:

:pirate::hf::tinfoil:

Yeah, good to go

Phone
Jul 30, 2005

親子丼をほしい。
mice now have arm chips in them for blast processing or some poo poo

i wonder if you can get doom to run on your mouse...

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD

Hackers can turn your computer into a RAVE!

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

D. Ebdrup posted:

Also, one thing I forgot to note after having watched the presentation is that they use their position on software updates to argue that companies should "let opensource do the work of updating and vetting the software deployed via repositories" which I think is hugely disingenuous, as it shouldn't be the responsibility of someone doing work in their spare time which a company then benefits from.

most open source code, by a very large margin, is produced by people who are paid to do so. you don’t have to tip IBM or Facebook or Google or the VC-funded devops darling of the minute for using the thing that they released.

BlankSystemDaemon
Mar 13, 2009



Subjunctive posted:

most open source code, by a very large margin, is produced by people who are paid to do so. you don’t have to tip IBM or Facebook or Google or the VC-funded devops darling of the minute for using the thing that they released.
That's quite simply not true. While it's true that Linux has been overtaken by companies to the point that an individual will find it exceeding difficult to get their code commited (and as a result, maybe a lot of the code written under opensource licenses is handled by companies), that doesn't account for a majority of the opensource projects.
There is a staggeringly huge number of software projects in third-party repositories (as well as the code for keeping that software in repositories, such as the FreeBSD ports framework, Debians compressed tar files with shell scripts to build each individual software, and so on) that is handled by anything from students at universities, over people who're doing it in their spare time, to unemployed people who just want to feel useful. Beyond that, consider all the code that never makes it to any repository and just sits in some github, or all the code that's still sitting in sourceforge.

`Nemesis
Dec 30, 2000

railroad graffiti

Janitor Prime posted:

wtf does any of that mean


https://twitter.com/gsuberland/status/1176180763999580160?s=20

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Midjack posted:

сука блять!

more like CMYK BLYAT!

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme


mods name change pls

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

D. Ebdrup posted:

That's quite simply not true. While it's true that Linux has been overtaken by companies to the point that an individual will find it exceeding difficult to get their code commited (and as a result, maybe a lot of the code written under opensource licenses is handled by companies), that doesn't account for a majority of the opensource projects.

(I said “code”, so it’s not much of an italicized stretch to extend my post to indicate that.)

counting the number of projects, as though the GTK IRC clients and billion abandoned React components are as significant as the Linux kernel or postgres, seems uncommonly naive

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply