Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
MrQueasy
Nov 15, 2005

Probiot-ICK

mystes posted:

They're sharing it by passing the qr code around?!!!!!!!

well, not any more once we disclosed it to their leadership and the blue team.

Adbot
ADBOT LOVES YOU

sb hermit
Dec 13, 2016





tired: using a bash script and awk to comb through git repositories for ssh keys and api tokens
wired: using an AI to comb through twitch live and archive streams of people programming and automatically guessing passwords based on typing heuristics and totp qr code screenshots

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


our support team copied the passwords out of the vault and put them on confluence lol

I dropped them right in the poo poo on that one, no point having "segregation of duties" if they're segregated away to idiots

Shame Boy
Mar 2, 2010

just got an email from my identity protection service giving me a report on how my identity is doing

as far as i know i don't have an identity protection service :ohdear:

Shame Boy
Mar 2, 2010

oh it's apparently a FREE BONUS FEATURE that comes with my loving health insurance from work for some reason okay

also it really wants me to use their online password manager, sure let me just give my health insurance company all my passwords, why not

flakeloaf
Feb 26, 2003

Still better than android clock

sb hermit posted:

tired: using a bash script and awk to comb through git repositories for ssh keys and api tokens
wired: using an AI to comb through twitch live and archive streams of people programming and automatically guessing passwords based on typing heuristics and totp qr code screenshots

rsa key on webcam vibes here

Crime on a Dime
Nov 28, 2006
some rad badasses itt. tellin it no questions asked cause they know wtf is up y'all

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

Shame Boy posted:

oh it's apparently a FREE BONUS FEATURE that comes with my loving health insurance from work for some reason okay

also it really wants me to use their online password manager, sure let me just give my health insurance company all my passwords, why not

just think of it as free insurance

for your drivers license





please submit your drivers license to continue, for free, NOW






submit goddamnit

sb hermit
Dec 13, 2016





dang man, all my health insurance gives me is a free $10K in life insurance

or was that my credit union?

Shame Boy
Mar 2, 2010

sb hermit posted:

dang man, all my health insurance gives me is a free $10K in life insurance

or was that my credit union?

i feel like health insurance should give you a much higher amount of free life insurance as a sort of money-back guarantee

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

sb hermit posted:

dang man, all my health insurance gives me is a free $10K in life insurance

or was that my credit union?

don't ask me man i just got this sweet binance card

with this one weird trick you can buy cryptos on margin then sell it before the bill comes!

it's


free


money

RFC2324
Jun 7, 2012

http 418

Shame Boy posted:

i feel like health insurance should give you a much higher amount of free life insurance as a sort of money-back guarantee

I wonder how well that would work to fix coverage issues. "If medical care would have fixed it, insurance pays out 10 million to the survivors"

Wiggly Wayne DDS
Sep 11, 2010



ymgve posted:

question, though: if you put a fake login on the whiteboard when interviewing someone for a red team role, would seeing that login being attempted count as positive or negative?
extreme negative: outside of terms of engagement, may be a mixture of naïve or arrogant, and didn't bring up the obvious red herring in the interview - if you're not willing to highlight poor practices in the interview between peers how can i trust you to do that against clients who don't know as much? then again that depends on the seniority of the role and if using this trick in an interview it'd be mentioned at the end of just to see if they noticed it but felt like it wasn't a good time to mention it (don't use tricks in interviews)

if it wasn't cleared up after the interview then i'd be interested in what services they tried stuffing and how overt they were but neither would be relevant to their role in practice

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face
just really awkwardly drop the u/p in the middle of your conversation, bonus points if it's alphanumeric plus extra for punctuation and whitespace

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

Beeftweeter posted:

don't ask me man i just got this sweet binance card


Arent those the crypto nazis or am I misremembering

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

ZeusCannon posted:

Arent those the crypto nazis or am I misremembering

as in nazi gold digital krugerrands maybe

yes, just yes

Achmed Jones
Oct 16, 2004



+1 to the good dentist

Midjack
Dec 24, 2007



ZeusCannon posted:

Arent those the crypto nazis or am I misremembering

yes they were the ones with the official swastika symbol a few weeks ago.

BlankSystemDaemon
Mar 13, 2009



It's nice to know that CloudFlare, who present themselves as the only company who can solve security issues, isn't excempt from being a secfuck.

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

BlankSystemDaemon posted:

It's nice to know that CloudFlare, who present themselves as the only company who can solve security issues, isn't excempt from being a secfuck.

lol also their stock crashed like 40% over the past two days

Wiggly Wayne DDS
Sep 11, 2010



BlankSystemDaemon posted:

It's nice to know that CloudFlare, who present themselves as the only company who can solve security issues, isn't excempt from being a secfuck.
nice collection of bugs and lol at them fully remaking it from azure devops to kubernetes only to forget to lockdown the network

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
Lol that Chase asks me to log into the app and authenticate myself if I change IP addresses, but only requires you to reply YES to an SMS to authorize unusual, multi-thousand USD, wire transfers.

Great threat model there.

sb hermit
Dec 13, 2016





I find that older businesses that should have tighter security are usually the ones that have the most conservative and outdated security models and controls.

  • Logging into the us treasury website uses a virtual keyboard (if javascript is detected) even though it precludes the ability to use a password manager
  • My credit union still uses password expiration, even though it's known to make things more insecure
  • My bank requires 2fa to be done only through SMS, even though there are constant examples of how that is among the least secure 2fa mechanisms (due to sim swapping, sim duplication, or just sms forwarding)
  • All of this "death of password" stuff is nice, but it won't make a difference if these places don't implement fido2 or a near equivalent.
  • And I still encounter the occasional website that doesn't allow you to paste your password.

At least, in the wider sense, password expiration is going away. I hope password complexity goes with it. I think account security should just require a six character password minimum that isn't your username, and a second factor.

Wild EEPROM
Jul 29, 2011


oh, my, god. Becky, look at her bitrate.
can’t wait to see what a loving nightmare this turns out to be for literally anyone who isn’t a twenty something guy with english as their first language

Zamujasa
Oct 27, 2010



Bread Liar
the gas utility here redid their website last year and the new version is a dog poo poo react app and the password field has right clicking and pasting disabled

it rules having to dev tools the event handlers away so i can use my password manager

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Beeftweeter posted:

lol also their stock crashed like 40% over the past two days

still higher than when i sold off my options in april 2020 lol

look, i was correct on tech stocks and the economy in general taking a dive, just like 2 years early


sb hermit posted:

I find that older businesses that should have tighter security are usually the ones that have the most conservative and outdated security models and controls

At least, in the wider sense, password expiration is going away. I hope password complexity goes with it. I think account security should just require a six character password minimum that isn't your username, and a second factor.

i wish i were a fly on the wall privy to these security discussions but i don't know why im expecting vigorous debate or w/e. most of my brain tells me "no, it's exactly like what you saw recently": there's a mid-50s management person who is driven to show that THEY ARE EXPERIENCED AND KNOW THINGS, so they take personal control over dictating what the contractors implement, so they recommend the state of the art in password security circa 1992 without consulting anyone with actual domain knowledge, and don't bother changing this when subordinates inform them it's outdated af because THERE ARE MORE IMPORTANT THINGS TO DO, LIKE ADDING MORE OUTDATED poo poo TO THE DESIGN. the idiot idealist parts of my brain continue to shout that this can't be the case.

anyway, i am thankful my small CU is inexplicably way ahead of the curve on this; ask me why the passwords to our very needfully highly secure support ticket portal requires 4 classes of characters in passwords that expire monthly

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face
i am moving into a position where i do infosec analysis for literally 10s of millions of people, things are going to be interesting

i will be issuing many yospos-esque reports

A Man With A Plan
Mar 29, 2010
Fallen Rib
Can anyone explain why, with full benefit of doubt, a website would disallow pasting passwords? What conceivable security benefits are there?

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


ur clipboard might be hacked

mystes
May 31, 2006

A Man With A Plan posted:

Can anyone explain why, with full benefit of doubt, a website would disallow pasting passwords? What conceivable security benefits are there?
If you make your users sufficiently angry, they might go to your office building with a loaded gun and coincidentally end up shooting an intruder who happens to be attempting to compromise your computer systems at the same time.

pseudorandom name
May 6, 2007

A Man With A Plan posted:

Can anyone explain why, with full benefit of doubt, a website would disallow pasting passwords? What conceivable security benefits are there?

password reuse is bad

mystes
May 31, 2006

pseudorandom name posted:

password reuse is bad
Allowing copying and pasting, a thing that totally causes password reuse.

As opposed to making people enter passwords from memory, which causes them to enter totally unique 10 digit passwords with uppercase letters, numbers, and symbols, and never reuse them

Shame Boy
Mar 2, 2010

if you copy and paste, you're assumed to be copying and pasting from a passwords.txt notepad file sitting on your desktop

haveblue
Aug 15, 2005



Toilet Rascal
I just take a photo of my post-it collection and OCR it

redleader
Aug 18, 2005

Engage according to operational parameters

Shame Boy posted:

if you copy and paste, you're assumed to be copying and pasting from a passwords.txt notepad file sitting on your desktop

which, assuming complex and unique passwords, is still substantially better than what most regular people do

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

redleader posted:

which, assuming complex and unique passwords, is still substantially better than what most regular people do

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
same as the re-enter email field. how else will you ensure that users typed it properly from memory! if they forget or typo you will have to send a costly automated password reset email!!!

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

CMYK BLYAT! posted:

same as the re-enter email field. how else will you ensure that users typed it properly from memory! if they forget or typo you will have to send a costly automated password reset email!!!

if they misenter the email address, where exactly do you send the reset email?

A Man With A Plan
Mar 29, 2010
Fallen Rib
Where I work a lot of business processes depend on a basically defunct software suite that has 90s era password requirements like no punctuation except exclamation points, no more than 3 of the same character class in a row, etc. So if you don't want random things to fail, your domain password also has to follow these requirements

Adbot
ADBOT LOVES YOU

mystes
May 31, 2006

A Man With A Plan posted:

Where I work a lot of business processes depend on a basically defunct software suite that has 90s era password requirements like no punctuation except exclamation points, no more than 3 of the same character class in a row, etc. So if you don't want random things to fail, your domain password also has to follow these requirements
Weird requirements are great for making it hard to use randomly generated passwords

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply