Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
go play outside Skyler
Nov 7, 2005


animist posted:

idk if anybody's posted this yet but lol webass is full of holes

not the VMs. the code itself can still be exploited, using basically old school stack smashing. they took out canaries etc because "it's in a VM so it's secure" :allears:

if you load a webassembly library in your code, you risk opening a xss vulnerability on your site ... how is this different from loading a bad version of a dll in your app? i understand that in such a scenario the os would mitigate the exploit with various stack and heap protection techniques , but seeing as webass is fully vm'ed, the stakes are not the same as the whole os getting compromised, no?

show me a real exploit where one site is able to change the contents of another site! then i'll panic! i mean, anyone loading jquery could potentially add an xss vuln to their own site since any piece of js can do document.write or whatever. it seems to me like his conclusion should be that the attack surface is even smaller than traditional js

go play outside Skyler fucked around with this message at 06:50 on Aug 19, 2020

Adbot
ADBOT LOVES YOU

Cybernetic Vermin
Apr 18, 2005

go play outside Skyler posted:

if you load a webassembly library in your code, you risk opening a xss vulnerability on your site ... how is this different from loading a bad version of a dll in your app? i understand that in such a scenario the os would mitigate the exploit with various stack and heap protection techniques , but seeing as webass is fully vm'ed, the stakes are not the same as the whole os getting compromised, no?

show me a real exploit where one site is able to change the contents of another site! then i'll panic! i mean, anyone loading jquery could potentially add an xss vuln to their own site since any piece of js can do document.write or whatever. it seems to me like his conclusion should be that the attack surface is even smaller than traditional js

i think you should view this as the attack *target* being unfettered access to the webpage, which is then the same as in traditional js. the issue is that the attack *surface* is typically way worse since webasm deployments tend to lack all kinds of security measures and mitigations which js does have.

there being sandboxing to keep the exploits from breaking out into the broader system is small comfort if all the important stuff, e.g. your online banking, happens inside the sandbox.

a bit of a classic pattern really, building a secure enclave, then having everything important (i.e. actual user data) move into the secure enclave, making breaking it largely irrelevant. think e.g. of exploits making it onto your user account but not to root, they'll still steal any relevant data (passwords, cookies, important documents) and encrypt it all for ransom. they don't care that they can't access system files, those have no value anyway.

Computer Serf
May 14, 2005
Buglord
how do i secure my cave

Computer Serf fucked around with this message at 10:43 on Aug 19, 2020

Pile Of Garbage
May 28, 2007



turn your monitor on

Garrand
Dec 28, 2012

Rhino, you did this to me!

Computer Serf posted:

how do i secure my cave

Put out your smoke signal.

go play outside Skyler
Nov 7, 2005


Computer Serf posted:

how do i secure my cave

just take out your mom's garbage every once in a while

Soricidus
Oct 21, 2010
freedom-hating statist shill

Computer Serf posted:

how do i secure my cave

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD
Today's whinge: a colleague added my Atlassian account to their Jira but I had to click a link in the phishing email to actually access their tenancy!

mystes
May 31, 2006

This was truly excellent bin laden fan fiction.

ewiley
Jul 9, 2003

More trash for the trash fire
https://twitter.com/kateconger/status/1296517771216293889?s=21

This seems really bad.

Sassafras
Dec 24, 2004

by Athanatos
We had at least three ex-Facebook security team posters in this thread including a couple (I think) who went to Uber... Is he the one who didn't flee across the border to Canada?

Shame Boy
Mar 2, 2010

Sassafras posted:

We had at least three ex-Facebook security team posters in this thread including a couple (I think) who went to Uber... Is he the one who didn't flee across the border to Canada?

that dude is not Subjunctive if that's who you mean

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

nor is it pr0zac

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

mystes posted:

This was truly excellent bin laden fan fiction.

When we went to war with Cobra and this was Cobra Commander's secret mountain fortress playset

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Subjunctive posted:

nor is it pr0zac

who's the third one :pitchforks:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I’m wondering the same thing, but I’m pretty sure Joe isn’t a goon (in the SA sense)

Hed
Mar 31, 2004

Fun Shoe
I just went for one of my free annual credit reports and one of verification questions was:


Based on your birth date, which sign of the zodiac are you?
[ ] Pisces
[ ] Libra
[ ] Sagittarius
[ ] NONE OF THE ABOVE / DOES NOT APPLY

Clark Nova
Jul 18, 2004

somebody do that "so true!" meme with FICO scores

(I suppose the second layer of the joke is that everyone knows its bullshit but it still rules your life)

The_Franz
Aug 8, 2003

Hed posted:

I just went for one of my free annual credit reports and one of verification questions was:


Based on your birth date, which sign of the zodiac are you?
[ ] Pisces
[ ] Libra
[ ] Sagittarius
[ ] NONE OF THE ABOVE / DOES NOT APPLY

where's the "idk i'm under 70 and don't give a poo poo about this horoscope voodoo stuff" answer

haveblue
Aug 15, 2005



Toilet Rascal

The_Franz posted:

where's the "idk i'm under 70 and don't give a poo poo about this horoscope voodoo stuff" answer

clearly that's "does not apply"

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

The_Franz posted:

where's the "idk i'm under 70 and don't give a poo poo about this horoscope voodoo stuff" answer

Got bad news for you re. under 25s

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Hed posted:

I just went for one of my free annual credit reports and one of verification questions was:


Based on your birth date, which sign of the zodiac are you?
[ ] Pisces
[ ] Libra
[ ] Sagittarius
[ ] NONE OF THE ABOVE / DOES NOT APPLY

That's easy to guess though, since you're posts show that you're Cancer

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



[x] all of the above, I AM ETERNAL

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
:stare:

"We were not hacked, a clever criminal convinced us to give him our data – Experian SA CEO"

https://twitter.com/iamkoshiek/status/1296824738233360385

xtal
Jan 9, 2011

by Fluffdaddy
I find that people in regulated industries like banking and insurance don't care about security because "well, it would be against the regulations to hack us"

xtal
Jan 9, 2011

by Fluffdaddy
Security Through Bureaucracy

mystes
May 31, 2006

It's also probably cheaper not to bother with security as long as they don't lose their own money.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



xtal posted:

I find that people in regulated industries like banking and insurance don't care about security because "well, it would be against the regulations to hack us"

same, but all of the industries because "there are no consequences"

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

xtal posted:

I find that people in regulated industries like banking and insurance don't care about security because "well, it would be against the regulations to hack us"

Only registered members can see post attachments!

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



Chris Knight posted:

:stare:

"We were not hacked, a clever criminal convinced us to give him our data – Experian SA CEO"

SecFuck M/T v18.5 - Experian CEO: "We were not hacked, a clever criminal convinced us to give him our data"

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
the old “we were not hacked, we are just incompetent at our core business” defence

Pile Of Garbage
May 28, 2007



boggle, but for passwords: https://www.wired.com/story/dicekeys-cryptography/



idea is you do the boggle, scan the dice faces like a QR code with the website which then derives a long-rear end password that you can then use as the master password for your password manager (their suggestion). the boggle set then gets locked in place to serve as an offline backup for your password.

seems a bit dumb imo. if the app website dealio explodes then good luck scanning your boggle set. also i'm pretty sure that anyone competent enough to use a password manager also knows how to generate sufficiently complex passwords.

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
then some family members come over, find an old game of Boggle in the closet to play, and suddenly your backup is gone

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


*extremely hank hill voice* boggle? I just wanted to log on to propane dot com

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


mellow greetings user weedlord bonerhitler, what is your boggle?

Pile Of Garbage
May 28, 2007



Powerful Two-Hander posted:

mellow greetings user weedlord bonerhitler, what is your boggle?

my boggle?

https://www.youtube.com/watch?v=NbSXrH_CPKg

e: the other thing that irked me about the boggle password is that the app website thing is one of those monstrosities with almost 5MB of JS: https://dicekeys.app/. i understand the guy who created it wants it so that it's all client side and nothing gets sent to any server which is fine but it appears to be an insane amalgamation of node.js and webasm. surely there's a better way...

Pile Of Garbage fucked around with this message at 11:49 on Aug 22, 2020

mystes
May 31, 2006

Pile Of Garbage posted:

boggle, but for passwords: https://www.wired.com/story/dicekeys-cryptography/



idea is you do the boggle, scan the dice faces like a QR code with the website which then derives a long-rear end password that you can then use as the master password for your password manager (their suggestion). the boggle set then gets locked in place to serve as an offline backup for your password.

seems a bit dumb imo. if the app website dealio explodes then good luck scanning your boggle set. also i'm pretty sure that anyone competent enough to use a password manager also knows how to generate sufficiently complex passwords.
This just seems totally pointless compared to generating a password or key normally and printing it out as a qr code or something as a hardcopy backup.

animist
Aug 28, 2018

Cybernetic Vermin posted:

i think you should view this as the attack *target* being unfettered access to the webpage, which is then the same as in traditional js. the issue is that the attack *surface* is typically way worse since webasm deployments tend to lack all kinds of security measures and mitigations which js does have.

there being sandboxing to keep the exploits from breaking out into the broader system is small comfort if all the important stuff, e.g. your online banking, happens inside the sandbox.

a bit of a classic pattern really, building a secure enclave, then having everything important (i.e. actual user data) move into the secure enclave, making breaking it largely irrelevant. think e.g. of exploits making it onto your user account but not to root, they'll still steal any relevant data (passwords, cookies, important documents) and encrypt it all for ransom. they don't care that they can't access system files, those have no value anyway.

i have a strong suspicion we're gonna start seeing more server side webass as well (as people go "ugh docker images are so clunky, if only there was another way to package executables in a portable format"), so that's a big juicy target

Achmed Jones
Oct 16, 2004




read that as dickeyes.app

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Achmed Jones posted:

read that as dickeyes.app

like chernoff faces, but all dongs and eyeballs

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply