Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
CmdrRiker
Apr 8, 2016

You dismally untalented little creep!

Buff Hardback posted:


it's signal but with a safety number mechanic that isn't awful and has all sorts of UX problems that a malicious attacker could use, forward secrecy, repudiability on messages if you want

it's honestly really good, and i hope zoom doesn't gently caress it up

Care to elaborate or cite a source on that?

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

Buff Hardback posted:

ok so keybase key management history

2012: keybase launches solely as PGP discovery that isn't hot garbage, you sign statements and tweet them or gist them or whatever. to make things, you could upload your private key (completely optional) so you could perform signing statements on the web

2015: keybase switches to the nacl per-device key model and starts to pivot away from just being PGP key discovery. i think keybase chat showed up right around then, and at that point you could use keybase without ever uploading a pgp public key even

it's a lot less required to use a pgp key in keybase than it used to be


it's signal but with a safety number mechanic that isn't awful and has all sorts of UX problems that a malicious attacker could use, forward secrecy, repudiability on messages if you want

it's honestly really good, and i hope zoom doesn't gently caress it up

my favorite part of installing keybase was when it asked me to install fuse drivers

like i know what they're for and that fuse is probably pretty safe in general and why they're needed for the file sharing bit but a chat app wanting to install drivers (and then supposedly not "requiring" them for just the chat part but then not working at all when I refused) was pretty lol

Raymond T. Racing
Jun 11, 2019

CmdrRiker posted:

Care to elaborate or cite a source on that?

the problem with signal safety numbers is that they only have two states, working okay or new number, and so the UX around safety numbers changing isn't as scary as it should be

quote:

With those apps, you throw away the crypto and just start trusting the server: (1) whenever you switch to a new phone; (2) whenever any partner switches to a new phone; (3) when you factory-reset a phone; (4) when any partner factory-resets a phone, (5) whenever you uninstall and reinstall the app, or (6) when any partner uninstalls and reinstalls. If you have just dozens of contacts, resets will affect you every few days.

SSH screams at you if the pubkey has changed of the server, signal can't be as aggressive about "oh poo poo new safety number" because of amount of times that they'd occur. the signal argument is "you should just check", well people are dumb


keybase on the other hand only ever shows an "oh poo poo danger danger" when someone has completely reset their account. as long as they have one trusted device, that account will never show a safety warning. It moves the scary skull and crossbones into the case where you really should see the skull and crossbones, without making the average user sleep through a little bit of warning that happens every time your number changes in signal

https://keybase.io/blog/chat-apps-softer-than-tofu

Raymond T. Racing
Jun 11, 2019

Shame Boy posted:

my favorite part of installing keybase was when it asked me to install fuse drivers

like i know what they're for and that fuse is probably pretty safe in general and why they're needed for the file sharing bit but a chat app wanting to install drivers (and then supposedly not "requiring" them for just the chat part but then not working at all when I refused) was pretty lol

i forget exactly how they implemented the fuse stuff on non-Windows platforms, but iirc keybase chat is basically backed by kbfs, so it has to use the filesystem for chat to work

RustyKnight
Jul 11, 2016

every day is a new horror



Shame Boy posted:

speaking of zoom, i did a ~tele-health~ appointment with my doctor instead of going in for my usual prescription refill checkup since i'd rather not go to a doctor's office if i'm not sick when there's a global pandemic, and the way he did it was via a normal-rear end zoom meeting, which i'm pretty sure isn't hipaa-compliant but hey

at least he set a goddamn password on the meeting so we didn't get interrupted by naked germans or whatever

mine asked to send her my id number, full name and the exact medication via sms...

BlankSystemDaemon
Mar 13, 2009



Take this with a grain of salt before it's been confirmed, but ProtonMail may have had a SecFuck.

Achmed Jones
Oct 16, 2004



so this the first i'd heard of raidforums, and i was poking around. they have a subforum for buy/sell/tradeing hackthebox flags lmao

BlankSystemDaemon
Mar 13, 2009



Achmed Jones posted:

so this the first i'd heard of raidforums, and i was poking around. they have a subforum for buy/sell/tradeing hackthebox flags lmao
yea, it's a wild ride
their admin has cleverly called himself moot because it's totally moot, the goon who started an offsite, but just in disguise and totally not working at Google instead of posting on a silly web1.0 forum to recapture his lost glory-days

BlankSystemDaemon
Mar 13, 2009



when is the secfuck happening with this?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

it already did, and the person who did it posted in this thread, I thought

Shame Boy
Mar 2, 2010

Subjunctive posted:

it already did, and the person who did it posted in this thread, I thought

was it me? cuz that was the bluetooth protocol for a specific device and the horribly insecure corresponding app made by the original seller of the device, not the buttplug protocol / library which is its own separate open source thing

Midjack
Dec 24, 2007



Shame Boy posted:

was it me? cuz that was the bluetooth protocol for a specific device and the horribly insecure corresponding app made by the original seller of the device, not the buttplug protocol / library which is its own separate open source thing

it was a defcon talk last year. i don't remember the presenter being a goon but i could be wrong.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Shame Boy posted:

was it me? cuz that was the bluetooth protocol for a specific device and the horribly insecure corresponding app made by the original seller of the device, not the buttplug protocol / library which is its own separate open source thing

oh yeah, sorry, wrong erogenous remoting protocol

psiox
Oct 15, 2001

Babylon 5 Street Team

Subjunctive posted:

oh yeah, sorry, wrong erogenous remoting protocol

the only good ERP

Carbon dioxide
Oct 9, 2012

does anyone have the docs for implementing the buttplug interface?

edit: asking for a friend

Carbon dioxide fucked around with this message at 06:54 on May 8, 2020

Midjack
Dec 24, 2007



Carbon dioxide posted:

does anyone have the docs for implementing the buttplug interface?

edit: asking for a friend

layer 1 is pretty straightforward.

Shame Boy
Mar 2, 2010

Carbon dioxide posted:

does anyone have the docs for implementing the buttplug interface?

edit: asking for a friend

it's right there on the site:

https://buttplug-spec.docs.buttplug.io/

https://buttplug-developer-guide.docs.buttplug.io/

i got pretty far into a java implementation of an early version of the protocol back in the day but shelved it and now the project has kinda eclipsed anything i had running back then

Hed
Mar 31, 2004

Fun Shoe

Midjack posted:

layer 1 is pretty straightforward.

very well defined PHY

evil_bunnY
Apr 2, 2003

Buff Hardback posted:

1. esports tournys from home

2. if you're known as a gamedev who is garbage at stopping cheating, the turbonerds who have more influence than they should will tell all their friends that your company is garbage at stopping cheats and will convince their friends to not play
More simply, many games involve a bunch of player sharing the experience, and so cheaters hold an outsize influence on perceived enjoyment (and for many, that's the point).

Truga posted:

enemy territory like normal people :v:
that had the best and most satisfying rifle grenade to this day.

evil_bunnY fucked around with this message at 22:03 on May 8, 2020

Mustache Ride
Sep 11, 2001



DEFCON is cancelled

Proteus Jones
Feb 28, 2013




lol, the "Cancelled" T Shirts default to size 5XL when you go to eBay page.

Midjack
Dec 24, 2007



Proteus Jones posted:

lol, the "Cancelled" T Shirts default to size 5XL when you go to eBay page.

that was a nice touch.

spankmeister
Jun 15, 2008






Proteus Jones posted:

lol, the "Cancelled" T Shirts default to size 5XL when you go to eBay page.

Mine defaults to XL. Maybe it just knows your size.

Proteus Jones
Feb 28, 2013



spankmeister posted:

Mine defaults to XL. Maybe it just knows your size.

Except for a phone battery maybe 15 years ago, I've never purchased a single thing off of eBay. I just went to see what the design was (it was low effort), and that's what it was. It did keep asking me to log into my google account and link it to eBay, so I didn't linger.

taqueso
Mar 8, 2004


:911:
:wookie: :thermidor: :wookie:
:dehumanize:

:pirate::hf::tinfoil:
Maybe they just know the average defcon attendee's size and default to that if you have no data

or average american / wherever you live

maybe your browser fingerprint belongs to someone that is 500 lbs :tinfoil:

Proteus Jones
Feb 28, 2013



taqueso posted:


maybe your browser fingerprint belongs to someone that is 500 lbs :tinfoil:

Too many browser cookies I guess




:razz:

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
that’s two more bits towards doxing you

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

rjmccall posted:

that’s two more bits towards doxing you

Based on those sizes, more like two very big bites

Shame Boy
Mar 2, 2010

evil_bunnY posted:

More simply, many games involve a bunch of player sharing the experience, and so cheaters hold an outsize influence on perceived enjoyment (and for many, that's the point).

otoh that glitch where you could spawn like a bajillion jeeps in battlefield 2 and have them rain down on everyone until the server crashed was really fuckin' funny, so its impossible to say which is better

cinci zoo sniper
Mar 15, 2013




reminds me of early day dayz. it was built on arma engine but with almost all actual military game locked away, and some hackers found away to spawn stuff like abrams tanks or tunguska aa into the game; which led to slightly lopsided outcomes :v:

spankmeister
Jun 15, 2008






Proteus Jones posted:

Except for a phone battery maybe 15 years ago, I've never purchased a single thing off of eBay. I just went to see what the design was (it was low effort), and that's what it was. It did keep asking me to log into my google account and link it to eBay, so I didn't linger.

It was a joke about your physique. But in good natured jest because fat jokes aren't cool.

Schadenboner
Aug 15, 2011

by Shine

Proteus Jones posted:

Except for a phone battery maybe 15 years ago, I've never purchased a single thing off of eBay. I just went to see what the design was (it was low effort), and that's what it was. It did keep asking me to log into my google account and link it to eBay, so I didn't linger.

Nice meltdown.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Proteus Jones posted:

Except for a phone battery maybe 15 years ago, I've never purchased a single thing off of eBay.

Weirdo

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!
Purchased a little baggie of Uranium on eBay back in '08 after jokingly searching and it actually returned results.

I'm probably on a list now.

Schadenboner
Aug 15, 2011

by Shine

klosterdev posted:

Purchased a little baggie of Uranium on eBay back in '08 after jokingly searching and it actually returned results.

I'm probably on a list now.

I mean, :regd06: so you probably already were?

:shrug:

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
uranium is mostly harmless

this guy did it the right way:

https://en.wikipedia.org/wiki/David_Hahn

Pile Of Garbage
May 28, 2007



CRIP EATIN BREAD posted:

uranium is mostly harmless

this guy did it the right way:

https://en.wikipedia.org/wiki/David_Hahn

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

CRIP EATIN BREAD posted:

uranium is mostly harmless

this guy did it the right way:

https://en.wikipedia.org/wiki/David_Hahn

"Hot" singles in your area

asur
Dec 28, 2012

Shame Boy posted:

speaking of zoom, i did a ~tele-health~ appointment with my doctor instead of going in for my usual prescription refill checkup since i'd rather not go to a doctor's office if i'm not sick when there's a global pandemic, and the way he did it was via a normal-rear end zoom meeting, which i'm pretty sure isn't hipaa-compliant but hey

at least he set a goddamn password on the meeting so we didn't get interrupted by naked germans or whatever

HIPAA requirements on telemedicine have basically been temporarily suspended due to the pandemic.

Adbot
ADBOT LOVES YOU

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Huawei invents their own kernel security patch set, fucks it up spectacularly

https://grsecurity.net/huawei_hksp_introduces_trivially_exploitable_vulnerability

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply