Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Lain Iwakura posted:

hey everyone. what is the best vpn? 🙃

libreswan obv.

in unrelated news, turns out the feature we added to execute arbitrary code (with full access to our user management libraries) can be used for privilege escalation attacks. who'd have guessed!?

this feature basically exists so that we can tick an extra box for procurement departments. im pretty sure nobody has used it for its stated purpose ever.

Adbot
ADBOT LOVES YOU

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang




what kind of insane handle opens upwards like that

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
i was going to leave this here without comment and jump on a plane, but i hosed up actually posting before i lost signal, so now i just have to give it this lovely prologue

anyway it might be interesting to people

NFX
Jun 2, 2008

Fun Shoe

Krankenstyle posted:

what kind of insane handle opens upwards like that

it feels like a full two-thirds of ollam's cool bypasses only work on shoddy american doors

geonetix
Mar 6, 2011


Share Bear posted:

gonna guess this is still correct? https://gist.github.com/grugq/353b6fc9b094d5700c70

someone put that in the first post

what makes freedome an acceptable vpn?

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

Shaggar posted:

I use nordvpn with code lowtaxspine and it works fine for downloading Linux isos.

i use it for anything because my government session logs everything and insists on handing out traffic logs to any lawyer who asks no questions asked

Soricidus
Oct 21, 2010
freedom-hating statist shill

Lain Iwakura posted:

hey everyone. what is the best vpn? 🙃

pptp

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

rjmccall posted:

i was going to leave this here without comment and jump on a plane, but i hosed up actually posting before i lost signal, so now i just have to give it this lovely prologue

anyway it might be interesting to people

this is great, thank you. I didn’t really understand the discriminator stuff before, but I think I do now

Shaggar
Apr 26, 2006

Krankenstyle posted:

what kind of insane handle opens upwards like that

ADA compliant ones.

power botton
Nov 2, 2011

i accidentally opened up lDAP to the internet and the past month my azure vm uploaded like 17 tb. it was only like 6 or 700 bucks which seems pretty reasonable

power botton
Nov 2, 2011

sure thats bad to add to DOS attacks, but it also felt kinda good to finally be part of something bigger than myself

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

CMYK BLYAT! posted:

libreswan obv.

in unrelated news, turns out the feature we added to execute arbitrary code (with full access to our user management libraries) can be used for privilege escalation attacks. who'd have guessed!?

this feature basically exists so that we can tick an extra box for procurement departments. im pretty sure nobody has used it for its stated purpose ever.

Disable it by default and require admin configuration to enable it?

The Electronaut
May 10, 2009

Deviant Ollam's talks are great.

Winkle-Daddy
Mar 10, 2007

Volmarias posted:

Disable it by default and require admin configuration to enable it?

I think you'll find that might generate calls to support.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
But if no one uses it...

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

Subjunctive posted:

this is great, thank you. I didn’t really understand the discriminator stuff before, but I think I do now

yeah, discriminators are totally central to the protection because it’s unfortunately proven not that hard to find whole functions that work as gadgets

it’s like some sort of hosed-up cake recipe where, okay, you need three cups of flour, a cup of oil, and two cups of sugar, but unlike normal that list isn’t exclusive and it’s okay to throw in ingredients with random other garbage as long as they get you towards your total. like, here’s a dead rat, its carcass contains oil

that analogy was not as illuminating as i was hoping but it sure got vivid

anyway i’m giving a talk about this in about two hours, as soon as the recording is up i’ll let y’all know

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Krankenstyle posted:

what kind of insane handle opens upwards like that

in addition to ADA compliance that Shaggar pointed out there's no reason for the manufacturer to restrict the mechanism because you can just buy the same handle and mount it on either side of a door as needed

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Krankenstyle posted:

what kind of insane handle opens upwards like that

the only thing novel about that is being able to use film and not a piece of scrap metal like do usually does, like 15m29s in:

https://www.youtube.com/watch?v=raBMFqZRB0s&t=929s

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
today at NYT: infoesec is for someone else

https://twitter.com/runasand/status/1186775481615605760

sadus
Apr 5, 2004

May the Krebs be with you

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


holy poo poo who would ever get rid of Runa

Phone
Jul 30, 2005

親子丼をほしい。

Subjunctive posted:

holy poo poo who would ever get rid of Runa

why have runa when you can have bret stephens and bari weiss

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Subjunctive posted:

holy poo poo who would ever get rid of Runa

the "failing" ny times, apparently

this seems like some oldschool "it is a cost center" stuff, but who knows

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Phone posted:

why have runa when you can have bret stephens and bari weiss

well there is that

Nomnom Cookie
Aug 30, 2009



if security is so important how come we dont get pwned more, huh, can you answer that smart guy

Happy Thread
Jul 10, 2005

by Fluffdaddy
Plaster Town Cop

Bulgakov
Mar 8, 2009


рукописи не горят

yah beat me to it

Shame Boy
Mar 2, 2010

p sure you didn't have to like, hack anything to know trump's password was "yourefired"

like it had to be that, or maybe that but misspelled in other ways by his fat stubby sausage fingers

Original GANster
Sep 14, 2005

I'm slightly late to password manager chat, but:

keepassXC doesn't have the same synchronize feature that keepass does, although it has its own, different version.

KeepassXC's sync/share feature is called KeeShare and by all metrics it sucks rear end.

The basic idea is that you'd create a new password group and during the setup (naming, icon selection) a KeeShare 'type' can be selected, either import, export, or sync. You set a path and a password, then you can send 'shared.kdbx.share' to anybody you want and they can import it into their KeepassXC, then you share the passphrase separately for them to unlock and import it.

Imagine trying to use this process to get a password from your computer to your phone.

As a few others said, Bitwarden feels like a more polished, non-rent-collecting alternative to pretty much all the solutions. Flawless multi-device sync and a pretty generous selection of multi-factors. Yubikey, Duo, TOTP, u2f, all supported out-of-the-box if you host it yourself. I think that selection is limited if you use the non-paid hosted version.

on another note, when i attempt to install keepass on my computer it wants to install mono (!!)

code:
2 community/keepass 2.42.1-5 (1.3 MiB 3.1 MiB) 
    A easy-to-use password manager for Windows, Linux, Mac OS X and mobile devices.
1 community/gnome-passwordsafe 3.32.0-1 (297.3 KiB 782.0 KiB) 
    Password manager for GNOME which makes use of the KeePass v.4 format
==> Packages to install (eg: 1 2 3, 1-3 or ^4)
==> 2
[sudo] password for og: 
resolving dependencies...
looking for conflicting packages...

Packages (3) libgdiplus-5.6.1-2  mono-6.0.0.334-1  keepass-2.42.1-5

Total Download Size:    55.22 MiB
Total Installed Size:  244.11 MiB

:: Proceed with installation? [Y/n] 

Progressive JPEG
Feb 19, 2003

Original GANster posted:

As a few others said, Bitwarden feels like a more polished, non-rent-collecting alternative to pretty much all the solutions. Flawless multi-device sync and a pretty generous selection of multi-factors. Yubikey, Duo, TOTP, u2f, all supported out-of-the-box if you host it yourself. I think that selection is limited if you use the non-paid hosted version.

oh that makes sense, was sorta wondering how they would have an open source thing with those omitted - i imagine someone would just fork it and implement support if they werent there

anyway been using it a few days now and its been pretty much a drop-in replacement after having used 1pass for the last ~year. and having actual standalone apps everywhere has been nice

the desktop apps are electron iirc, but still better than 1pass only providing a browser plugin with functionality removed. for example I had to use the work mac to export my stuff since the 1pass browser plugin doesnt do that

Soricidus
Oct 21, 2010
freedom-hating statist shill

Progressive JPEG posted:

the desktop apps are electron iirc

love 2 use a password manager that might randomly leave a convenient debugging port open in case you leave your laptop at home and need to do a quick rce to get your passwords

cinci zoo sniper
Mar 15, 2013




about vpns, mullvad is an alternative to protonvpn if you look for one. they are third party audited, support wireguard, and as low commitment as you can get for a paid service in terms of data - but far from cheapest. third vpn rec i could make is airvpn, but ive moved on from them and have not followed the service since 2016

Original GANster
Sep 14, 2005

Progressive JPEG posted:

oh that makes sense, was sorta wondering how they would have an open source thing with those omitted - i imagine someone would just fork it and implement support if they werent there

i've been running an unofficial clone called bitwarden_rs (https://github.com/dani-garcia/bitwarden_rs) for a few weeks that allows mysql/sqlite to be used instead of mssql which is what the official one wants for some reason

Progressive JPEG posted:

the desktop apps are electron iirc

very easy access through the browser instead which i prefer, and second factors are always required for a browser login, but not with the client when i initially tried it (once i'd logged into the client, I didn't have to 2fa anymore to "unlock" the vault next time i started it)

Truga
May 4, 2014
Lipstick Apathy

Original GANster posted:

on another note, when i attempt to install keepass on my computer it wants to install mono (!!)

well, yeah. the original keepass is made with c#. with mono it can run on any platform, and it has the most plugin support so i use that, and it works ok.

akadajet
Sep 14, 2003

yeah, and if you wanted to run a java program it'd need the jre lol

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

akadajet posted:

yeah, and if you wanted to run a java program it'd need the jre lol

Oracle Keepass

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Progressive JPEG posted:

for example I had to use the work mac to export my stuff since the 1pass browser plugin doesnt do that
why would it? the plugin is for filling in login information to the browser and that's it.

Vanadium
Jan 8, 2005

Chris Knight posted:

why would it? the plugin is for filling in login information to the browser and that's it.

b/c 1password doesn't have a standalone app for All Platforms and bills the browser extension as the substitute

klafbang
Nov 18, 2009
Clapping Larry

Captain Foo posted:

Oracle Keepass for Enterprise 69g

Adbot
ADBOT LOVES YOU

Vomik
Jul 29, 2003

This post is dedicated to the brave Mujahideen fighters of Afghanistan
I just recently heard of this password app called myki - has a kind of interesting security model where everything lives on the phone and it can be used in browsers with you authing with touch/Face ID. anyone know anything about if it’s a massive pos?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply