Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

flakeloaf posted:

☐ My keyboard has an "Alt Facts" key

i didn't know you work for the CPC

Adbot
ADBOT LOVES YOU

Beve Stuscemi
Jun 6, 2001




this was before the industry standardized on the term Fake News

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
neat: google 2fa key, likely others, clonable with considerable effort

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

how about we just don't have side channels? do we really need them anyway?

Cybernetic Vermin
Apr 18, 2005


real interesting, but just to clarify up front: this is an attack on a physical (cryptographic usb) key *chipset*.

i for a moment read it as a general 2fa cryptographic key attack.

mystes
May 31, 2006

I hope this doesn't slow adoption (if it can even be slowed any further) because even if it might be possible for someone who temporarily has possession of your key to copy it, u2f tokens are still much better than pretty much all the alternatives.

Potato Salad
Oct 23, 2014

nobody cares



I've got one upstairs in a safe and the other in deposit at my bank, I'm good

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
Judging by the pictures in the article this isn't just some power rail attack or anything, it's straight up delidding the chip and probing the internals.

That seems like it requires some very specific chip design to defend against.

Beve Stuscemi
Jun 6, 2001




also it requires some very specific tool and skills to accomplish. probably not a huge worry for your average user

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
their poc turnaround was something like 12 hours, so yeah, this isn't a serious concern for your average user

Subjunctive posted:

how about we just don't have side channels? do we really need them anyway?

just put the one channel in the front and be done with it, i say

Wiggly Wayne DDS
Sep 11, 2010



those 2fa keys aren't for your average user...

flakeloaf
Feb 26, 2003

Still better than android clock

okay grandma, first download kleopatra...

Shame Boy
Mar 2, 2010

Jabor posted:

Judging by the pictures in the article this isn't just some power rail attack or anything, it's straight up delidding the chip and probing the internals.

wait doesn't everyone else have a hydrofluoric acid bath at home :confused:

xtal
Jan 9, 2011

by Fluffdaddy
I used my last one on Victor :(

BlankSystemDaemon
Mar 13, 2009



flakeloaf posted:

☐ My keyboard has an "Alt Farts" key

ate shit on live tv
Feb 15, 2004

by Azathoth
Seems like its not really a big security concern since 2fa devices can be very easily de-associated to any account that uses them. So as long as the user reports their 2fa key lost it can be dealt with in a reasonable amount of time. Now if they find a way to extract a 2fa soft-key via malicious link, then we will see some interesting attacks.

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

some HN commenter posted:

I'm surprised congressional office's laptops do not embed remotely detonated explosives/destruction devices triggered with sat or cellular comms.
:hmmyes:

jetz0r
May 10, 2003

Tomorrow, our nation will sit on the throne of the world. This is not a figment of the imagination, but a fact. Tomorrow we will lead the world, Allah willing.



Shame Boy posted:

wait doesn't everyone else have a hydrofluoric acid bath at home :confused:

ever since I installed my hot HF tub, my windows are all foggy and my bones keep breaking while walking.

cinci zoo sniper
Mar 15, 2013




Jabor
Jul 16, 2010

#1 Loser at SpaceChem

ate poo poo on live tv posted:

Seems like its not really a big security concern since 2fa devices can be very easily de-associated to any account that uses them. So as long as the user reports their 2fa key lost it can be dealt with in a reasonable amount of time. Now if they find a way to extract a 2fa soft-key via malicious link, then we will see some interesting attacks.

If you have a stolen 2fa key that you can keep stolen, you don't need to clone anything - you just use it.

The threat model is you steal their key on Friday, clone it, then return it before Monday so they don't notice it was ever missing.

SoundMonkey
Apr 22, 2006

I just push buttons.


Jabor posted:

The threat model is you steal their key on Friday, clone it, then return it before Monday so they don't notice it was ever missing.

after re-potting the IC and perfectly re-creating the case you cut/melted off to get to it

this really does seem more like a mossad tier attack than something normal people have to care about

Beve Stuscemi
Jun 6, 2001




you keep the one you ruined and give them the clone that’s in good condition, since you already have the info you want.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Jim Silly-Balls posted:

you keep the one you ruined and give them the clone that’s in good condition, since you already have the info you want.

You cannot replicate the greasy cheeto stains though, those are like a thumbprint I can use to identify mine for this specific possibility

ate shit on live tv
Feb 15, 2004

by Azathoth

Jabor posted:

If you have a stolen 2fa key that you can keep stolen, you don't need to clone anything - you just use it.

The threat model is you steal their key on Friday, clone it, then return it before Monday so they don't notice it was ever missing.

Jim Silly-Balls posted:

you keep the one you ruined and give them the clone that’s in good condition, since you already have the info you want.


Yea that's true.

Beve Stuscemi
Jun 6, 2001




Volmarias posted:

You cannot replicate the greasy cheeto stains though, those are like a thumbprint I can use to identify mine for this specific possibility

that’s why they say this vulnerability is so hard to replicate. there are maybe what, two or three master Cheetomen in the world? their services don’t come cheap

crepeface
Nov 5, 2004

r*p*f*c*
https://twitter.com/thezedwards/status/1347756804210479104?s=20

https://twitter.com/alexblagg/status/1347771677011103745?s=20

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

You have no idea how much I needed both of these

Kazinsal
Dec 13, 2011



so who wants to set up a robodialer on a sip trunk with some fresh DIDs from throughout the US and pretend to be Q

crepeface
Nov 5, 2004

r*p*f*c*

Volmarias posted:

You have no idea how much I needed both of these

related:

https://twitter.com/thegrugq/status/1347593973368410112?s=20

jre
Sep 2, 2011

To the cloud ?




:sickos:

Granite Octopus
Jun 24, 2008

can’t wait till they claim antifa tricked them into posting the evidence

pseudorandom name
May 6, 2007

that’s probably true though

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
they'll blab about everything the instant they're alone in the room with a cop that claims to be sympathetic

99% of the time nothing will happen because it's not an interrogation, the cop just actually is sympathetic to white nationalist ideology

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
:sickos:

flakeloaf
Feb 26, 2003

Still better than android clock

Jabor posted:

they'll blab about everything the instant they're alone in the room with a cop that claims to be sympathetic

99% of the time nothing will happen because it's not an interrogation, the cop just actually is sympathetic to white nationalist ideology

reid's nine goose steps

FCKGW
May 21, 2006

https://twitter.com/alexblagg/status/1347782726858928129?s=21

Soricidus
Oct 21, 2010
freedom-hating statist shill
wow the fbi is getting good at deep cover ops

crepeface
Nov 5, 2004

r*p*f*c*

i literally just posted that above???

FCKGW
May 21, 2006

crepeface posted:

i literally just posted that above???

sorry, was just posting a tweet with the screen shot included :)

Adbot
ADBOT LOVES YOU

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

are we sure that's parler with malware from a third party, and not just the official parler

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply