Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
BlankSystemDaemon
Mar 13, 2009



or surfshark got FISA'd and the authorities are hiding this by pretending that he was stupid, which any of us will readily assume

champagne posting posted:

should've used tor
tor by itself is great, but you need a way to make it so that no connection can be made without going through tor

Adbot
ADBOT LOVES YOU

haveblue
Aug 15, 2005



Toilet Rascal

ewiley posted:

if I’m reading this right it’s a buffer overflow in the certificate verification of Mozilla’s NSS that’s existed since like 2014 and Mozilla and Google and other third parties all missed it despite heavily auditing the same code?

I think the solution here is to no longer let Taviso take showers. or perhaps make him take more

yes. most of the article is exploring why it was not caught by automated testing or by automated fuzzing tools

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

BlankSystemDaemon posted:

or surfshark got FISA'd and the authorities are hiding this by pretending that he was stupid, which any of us will readily assume

tor by itself is great, but you need a way to make it so that no connection can be made without going through tor

surfshark is based in the netherlands and operates through the British Virgin Islands, so in theory the process for getting the information would have been slightly more complicated (not impossible, especially if the company cooperates or has representatives in the US).

this person thought that using a commercial VPN service at the device level, through their home residence ISP, was good enough opsec for something this big, so I can definitely believe that they hosed up something as basic as preventing their connection from using anything other than the TAP adapter

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

BlankSystemDaemon posted:

tor by itself is great, but you need a way to make it so that no connection can be made without going through tor
YOU HAVE COME TO A WORLD CALLED TOR *WHIPCRACK*

Shaggar
Apr 26, 2006

Ur Getting Fatter posted:

surfshark is based in the netherlands and operates through the British Virgin Islands, so in theory the process for getting the information would have been slightly more complicated (not impossible, especially if the company cooperates or has representatives in the US).

this person thought that using a commercial VPN service at the device level, through their home residence ISP, was good enough opsec for something this big, so I can definitely believe that they hosed up something as basic as preventing their connection from using anything other than the TAP adapter

yeah the network outage would have killed the vpn and his HACKER TOOLS (web browser logged into aws) reconnected automatically when it came back up without going thru the tunnel.

idk about surf shark but nordvpn has settings to prevent that so even a novice could have done it right with minimum effort

Achmed Jones
Oct 16, 2004



i want to write a bunch "why didn't he x", "why didnt he y" stuff, but i'm terrified that my endpoint will get popped one day and my creds used to do something bad and then somebody will be all "look look achmed was talking about this online before THE CRIME" and ill be like "wait no i wasnt planning anything i was just saying any non-idiot could hide their tracks better, please do not put me in jail i didnt do anything"

and then id end up fired or in jail or something and i dont want that

maybe my brain broke because a ton of what i do is working on stuff to make services resilient against insider threats

evil_bunnY
Apr 2, 2003

BlankSystemDaemon posted:

or surfshark got FISA'd and the authorities are hiding this by pretending that he was stupid, which any of us will readily assume

tor by itself is great, but you need a way to make it so that no connection can be made without going through tor
I mean given the rest of the details, it's not exactly a stretch.

Trabisnikof
Dec 24, 2005

Ur Getting Fatter posted:

surfshark is based in the netherlands and operates through the British Virgin Islands, so in theory the process for getting the information would have been slightly more complicated (not impossible, especially if the company cooperates or has representatives in the US).

this person thought that using a commercial VPN service at the device level, through their home residence ISP, was good enough opsec for something this big, so I can definitely believe that they hosed up something as basic as preventing their connection from using anything other than the TAP adapter

doesn’t the Investigatory Powers Act allow GCHQ to seize data from VPN providers without a warrant?

Shaggar
Apr 26, 2006
vpn providers (supposedly) dont keep logs so there wouldnt be anything to collect. plus in a criminal case like this you i wouldnt think you'd have trouble getting a warrant

Trabisnikof
Dec 24, 2005

the Investigatory Powers Act also requires retaining "connection records" for a year for British based communication service providers, which i assume would apply to surfshark if they have infra in BVI

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Trabisnikof posted:

doesn’t the Investigatory Powers Act allow GCHQ to seize data from VPN providers without a warrant?

BVI doesn't operate under UK law though

Shaggar
Apr 26, 2006

Trabisnikof posted:

the Investigatory Powers Act also requires retaining "connection records" for a year for British based communication service providers, which i assume would apply to surfshark if they have infra in BVI

what a hosed up little island

Trabisnikof
Dec 24, 2005

Rufus Ping posted:

BVI doesn't operate under UK law though

well that'd do it

BattleMaster
Aug 14, 2000

Net crime island

Methanar
Sep 26, 2013

by the sex ghost

BattleMaster posted:

Net crime island

Shaggar
Apr 26, 2006

BattleMaster posted:

Net crime island

Agile Vector
May 21, 2007

scrum bored



BattleMaster posted:

Net crime island

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

BattleMaster posted:

Net crime island

RFC2324
Jun 7, 2012

http 418

BattleMaster posted:

Net crime island

B33rChiller
Aug 18, 2011




Achmed Jones posted:

i want to write a bunch "why didn't he x", "why didnt he y" stuff, but i'm terrified that my endpoint will get popped one day and my creds used to do something bad and then somebody will be all "look look achmed was talking about this online before THE CRIME" and ill be like "wait no i wasnt planning anything i was just saying any non-idiot could hide their tracks better, please do not put me in jail i didnt do anything"

and then id end up fired or in jail or something and i dont want that

maybe my brain broke because a ton of what i do is working on stuff to make services resilient against insider threats
Good points. I don't work in sec or computers, so I'll speculate for you.
This story seems to have the hallmarks of "What if someone tries to pull an Office Space in real life?" With an added dose of unwarranted urgency. Like, it doesn't seem as though this was thought through very well. Ransom from home? Did he think to short the stock before "whistleblowing"? Why do this all at once? Need lots of cash real fast? Get too excited by the thrill of his first heist? Mega dunning Kruger?

BlankSystemDaemon
Mar 13, 2009



Shaggar posted:

vpn providers (supposedly) dont keep logs so there wouldnt be anything to collect. plus in a criminal case like this you i wouldnt think you'd have trouble getting a warrant
if the VPN providers don't keep logs, in a lot of nations they make themselves liable for whatever crimes are committed by their users

so unless the servers are in a place where there's good internet connectivity and no laws making them liable (and there's not a whole lot of places like that left, after it stopped being a thing in the Seychelles), it seems likely to assume that just because they say they don't keep logs, doesn't mean they aren't keeping logs
with openbsm and a dtrace provider, it's trivial to do whole-system monitoring in a way that leaves no trace of it available to someone without privileged access - so i imagine it can be done the same way on other OS'

also, remember that cross-country compliance with information sharing requests is a thing, even if there are no secret courts involved

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed
there's been enough examples of vpn providers claiming they don't keep logs and then turning out to that you'd be dumb to believe them

Midjack
Dec 24, 2007



Plorkyeran posted:

there's been enough examples of vpn providers claiming they don't keep logs and then turning out to that you'd be dumb to believe them

Wild EEPROM
Jul 29, 2011


oh, my, god. Becky, look at her bitrate.
surf shart

kitten smoothie
Dec 29, 2001

Ur Getting Fatter posted:

this person thought that using a commercial VPN service at the device level, through their home residence ISP, was good enough opsec for something this big, so I can definitely believe that they hosed up something as basic as preventing their connection from using anything other than the TAP adapter

he also thought he could lie to the feds rather than do the smart thing and just keep your mouth shut. instead he earned himself a criminal count for making false statements to the feds on top of everything else. he claimed some family member must have used his paypal password to buy that vpn service and literally anyone can tell that's baloney

my wife used to be a criminal defense attorney, and she lamented that her job would be infinitely easier if her customers had just kept their mouths shut when cops asked them questions

in conclusion if cops ask you questions you shut the gently caress up

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


well, nowadays you have to explicitly say you are invoking your right to remain silent, otherwise maybe you just want a dog that is also a lawyer, how could a simple cop know

Trabisnikof
Dec 24, 2005

yeah silence without invoking your rights is not protected

quote:

You Can't Be Silent If You Want to Be Silent

In a closely contested 2013 decision, the U.S. Supreme Court held that prosecutors can, under appropriate circumstances, point to an out-of-custody suspect's silence in response to police questioning as evidence of guilt. (Salinas v. Texas, 133 S. Ct. 2174 (2013).)

but meanwhile in florida

https://twitter.com/mjs_DC/status/1466442103513305093?s=20

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

Trabisnikof posted:

yeah silence without invoking your rights is not protected

but meanwhile in florida

https://twitter.com/mjs_DC/status/1466442103513305093?s=20

So what do you do yell as loudly as you can "I PLEASE THE FIFTH!"???

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

champagne posting posted:

So what do you do yell as loudly as you can "I PLEASE THE FIFTH!"???

you’d probably have more luck if you offer to please all of them

Mr. Nice!
Oct 13, 2005

c-spam cannot afford



in florida you have something called a sentencing scoresheet which takes into consideration prior offenses and the current charge plus aggravating circumstances in order to give judges an idea of what sentence to give. the dude in this case scored 10 years. the max punishment for the offense is 15 years. the state attorneys asked for 10 years.

during his allocution, the convicted man again professed his innocence for constructive possession of a firearm, said that his counsel was ineffective, and that the police forced the kid in the car to say that the gun belonged to him in order to charge him.

the judge said he didn't think the dude was showing any remorse and sentenced him to the max sentence of 15 years.

scofl said that since the max punishment is 15 years, that the punishment itself is inherently lawful as that's the will of the legislature. they further said since the trial judge wasn't looking at aggravating factors that it wasn't wrong for him to do what he did.

this result is not shocking at all if you've ever dealt with judges during sentencing.

Mr. Nice!
Oct 13, 2005

c-spam cannot afford



lol quote is not edit.

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

BlankSystemDaemon posted:

or surfshark got FISA'd and the authorities are hiding this by pretending that he was stupid, which any of us will readily assume

tor by itself is great, but you need a way to make it so that no connection can be made without going through tor

is running tails that hard

Truga
May 4, 2014
Lipstick Apathy
maybe i missed it but i didn't see this one posted
https://www.synack.com/blog/this-microsoft-windows-rce-vulnerability-gives-an-attacker-complete-control/

rce in a rdp dll apparently allowed escaping hyper-v if someone connects to it via console

Shame Boy
Mar 2, 2010

rce, my rdp dll?

Truga
May 4, 2014
Lipstick Apathy
yeah but usually the rce is on the server, this time it was on the client which is funnier to me

Shame Boy
Mar 2, 2010

i was trying to make an "idk, my bff jill?" joke but it didn't really work and also that reference is like 20 loving years old by now so whatever

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


BattleMaster posted:

Net crime island

oi, chav nicked me ip logs

SixFigureSandwich
Oct 30, 2004
Exciting Lemon

champagne posting posted:

So what do you do yell as loudly as you can "I PLEASE THE FIFTH!"???

have you tried being extremely rich

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Shame Boy posted:

rce, my rdp dll?
lmao

Adbot
ADBOT LOVES YOU

Kitfox88
Aug 21, 2007

Anybody lose their glasses?

Shame Boy posted:

i was trying to make an "idk, my bff jill?" joke but it didn't really work and also that reference is like 20 loving years old by now so whatever

i had a giggle at it :)

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply