Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Zamujasa
Oct 27, 2010



Bread Liar
https://twitter.com/sachee/status/1592308273071681536

Adbot
ADBOT LOVES YOU

BaldDwarfOnPCP
Jun 26, 2019

by Pragmatica

i used to play bass for a band called tunnels in miami

it was supposed to be ironic

Midjack
Dec 24, 2007




rip but i'm sure she'll be okay at the next gig.

Kitfox88
Aug 21, 2007

Anybody lose their glasses?

Volmarias posted:

Boo this man



Shame Boy posted:

oh i just got it


... boooo

:hehe:

Also in retrospect paying 44 billion to destroy one of the premier communication networks in the world today is actually pretty cheap, huh.

EndlessRagdoll
May 20, 2016


oh that's nice.

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


and the tunnels were his second idea, after he couldn't figure out how to make on ramps for a highway with many, many levels

RFC2324
Jun 7, 2012

http 418

duz posted:

and the tunnels were his second idea, after he couldn't figure out how to make on ramps for a highway with many, many levels

He shoulda played some satisfactory

post hole digger
Mar 21, 2011

every time i think i understand dmarc, i guess i dont :psyduck:

haveblue
Aug 15, 2005



Toilet Rascal

duz posted:

and the tunnels were his second idea, after he couldn't figure out how to make on ramps for a highway with many, many levels

idea: an ultra-futuristic vacuum transport pod that travels at Mach 1

reality: a tunnel that cars drive through one at a time poorly

Babies Getting Rabies
Apr 21, 2007

Sugartime Jones
https://www.bankinfosecurity.com/twitter-second-factor-authentication-has-vulnerability-a-20475

quote:

A researcher contacted Information Security Media Group on condition of anonymity to reveal that texting "STOP" to the Twitter verification service results in the service turning off SMS two-factor authentication.

"Your phone has been removed and SMS 2FA has been disabled from all accounts," is the automated response.

lol, lmao even

Shifty Pony
Dec 28, 2004

Up ta somethin'


hear me out... maybe sms-based 2FA is not good?

Shaggar
Apr 26, 2006
SMS in general is bad and should be discontinued

Shaggar
Apr 26, 2006

honestly this is a pretty good way to handle this. Carriers are gonna ban you from sending SMS if you dont respect stop/opt out requests from a recipient even if they signed up to receive the messages. its surprising they've actually accounted for it and disable SMS MFA rather than leaving it enabled and having the SMS messages go nowhere, effectively locking you out of the account.

of course it would be better to not use SMS but this isnt the worst thing since they actually considered the use case.

mystes
May 31, 2006

Shaggar posted:

honestly this is a pretty good way to handle this. Carriers are gonna ban you from sending SMS if you dont respect stop/opt out requests from a recipient even if they signed up to receive the messages. its surprising they've actually accounted for it and disable SMS MFA rather than leaving it enabled and having the SMS messages go nowhere, effectively locking you out of the account.

of course it would be better to not use SMS but this isnt the worst thing since they actually considered the use case.
The problem is it's much, much easier to spoof caller id for a number you don't own than to receive messages on that number. This means that pretty anyone can trivially disable 2FA for anyone else.

This is basically like letting people disable 2fa simply by sending an email claiming to be from that person's address

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
Is that really a thing? Surely there's verification they actually sent the message on their end, so you'd have to request it by knowing their password and so then it's not functionally different than logging in with a 2fa code and removing 2fa from settings normally

and the "SMS is not 2fa" battle was lost years ago when every single bank and CC company switched over to use it

Bhodi fucked around with this message at 00:08 on Nov 17, 2022

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
quote is not edit

Shaggar
Apr 26, 2006

mystes posted:

The problem is it's much, much easier to spoof caller id for a number you don't own than to receive messages on that number. This means that pretty anyone can trivially disable 2FA for anyone else.

This is basically like letting people disable 2fa simply by sending an email claiming to be from that person's address

afaik its not as easy to send fake caller id for SMS as it is for normal phones. "Spoofing" your outbound ANI on a traditional phone circuit is a feature, not a defect, but its very easy to abuse. I dont know how you'd even go about spoofing an SMS sender. Every system i've ever seen for sending SMS is very locked down on sender number.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

there are lots of apps and services like https://www.spoofmytextmessage.com/ out there purporting to let you spoof SMS, but I haven’t tested any

sb hermit
Dec 13, 2016





anyways, for an account that has had mfa using sms, I would just disable the account if sms is disabled and there was no available second factor. If no one can get in the account, the account is secure!

mystes
May 31, 2006

sb hermit posted:

anyways, for an account that has had mfa using sms, I would just disable the account if sms is disabled and there was no available second factor. If no one can get in the account, the account is secure!
You will be pleased to know that twitter apparently recently locked out everyone using 2FA

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

mystes posted:

You will be pleased to know that twitter apparently recently locked out everyone using 2FA

only SMS, TOTP still worked I believe

sb hermit
Dec 13, 2016





mystes posted:

You will be pleased to know that twitter apparently recently locked out everyone using 2FA

:unsmith:

spankmeister
Jun 15, 2008







this is only a vulnerability if you can disable 2fa from a spoofed number. otherwise you still need to sim swap the victim and at that point you can just use 2fa normally anyway. the article is light on details so it's unclear whether or not this is the case.

e: just occurred to me that perhaps someone could be phished into sending it themselves. Send a lot of annoying emails and put "TEXT STOP TO <number> TO UNSUBSCRIBE" or something

spankmeister fucked around with this message at 09:04 on Nov 17, 2022

sb hermit
Dec 13, 2016





make a meme on tiktok or something to have everyone flood the sms endpoint with STOP to voice your disapproval of SMS MFA

Crime on a Dime
Nov 28, 2006

sb hermit posted:

make a meme on tiktok or something to have everyone flood the sms endpoint with STOP to voice your disapproval of SMS MFA

if anyone does this we are gonna assume it was you

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
see, now this is the type of Elon-related content for the thread, the rest of him just running Twitter into the ground is better off left in the other one.

sec fucks for this thread, gently caress SECs for the other thread

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
i think she's onto something...
https://twitter.com/wbm312/status/1593439295519412226

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I hope so, because the "download your stuff" service seems to be broken

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

Subjunctive posted:

I hope so, because the "download your stuff" service seems to be broken

lol

Shame Boy
Mar 2, 2010


the musk thread already discussed this (not her tweet, people have been saying this for a little while now) and it seems real likely yeah

Wiggly Wayne DDS
Sep 11, 2010



Subjunctive posted:

I hope so, because the "download your stuff" service seems to be broken
it worked for me a couple of days ago, might be regional as well

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Wiggly Wayne DDS posted:

it worked for me a couple of days ago, might be regional as well

Might also just be one of those totally irrelevant and unimportant plates finally stopped spinning when anyone who knew about it left.

haveblue
Aug 15, 2005



Toilet Rascal
downloading your history was a microservice

Truga
May 4, 2014
Lipstick Apathy
https://twitter.com/CalumBoal/status/1593225022772244481
lmao

spankmeister
Jun 15, 2008






https://twitter.com/cpartisans/status/1593634667147988993

post hole digger
Mar 21, 2011


:cawg:

Zamujasa
Oct 27, 2010



Bread Liar
i ran into "inserting null truncates the rest of the field in mysql" long ago, really "fun" one

Shifty Pony
Dec 28, 2004

Up ta somethin'


Shame Boy posted:

the musk thread already discussed this (not her tweet, people have been saying this for a little while now) and it seems real likely yeah

after seeing the "think you're a hardcore enough coder to save Twitter? click here or be fired." email I've come to the conclusion that the only thing preventing the company from getting absolutely wrecked is that nobody knows who is still working there to send the spear phishing email to.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
oops!
https://twitter.com/matrosov/status/1593333424126730240

Adbot
ADBOT LOVES YOU

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

"We maintain it internally"



Edit: to be clear i dunno what their response / reason is i just hear that poo poo all the time from vendors

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply