Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
haveblue
Aug 15, 2005



Toilet Rascal
more like failchimp

Adbot
ADBOT LOVES YOU

post hole digger
Mar 21, 2011

Powerful Two-Hander posted:

EVERY MORNING I WAKE UP AND OPEN PALM SLAM A PASSWORD INTO THE VAULT. ITS IOS SAFARI PASSWORD MANAGER AND RIGHT THEN AND THERE I START COPYING MY PASSWORDS TO MY MAIN MOBILE BROWSER, FIREFOX. I TYPE EVERY PASSWORD AND I DO TYPE IT HARD. MAKIN WHOOSHING SOUNDS WHEN I EXCEED 10 CHARACTERS OR EVEN WHEN I MISTYPE A LETTER. NOT MANY CAN SAY THEY CREATED THE GALAXY’S MOST CONVOLUTED PASSWORD MANAGEMENT SOLUTION. I CAN. I SAY IT AND I SAY IT OUTLOUD EVERYDAY TO PEOPLE IN THE SECFUCK THREAD AND ALL THEY DO IS PROVE PEOPLE IN YOSPOS CAN STILL BE IMMATURE JERKS. AND IVE LEARNED ALL THE PASSWORDS AND IVE LEARNED HOW TO MAKE MY LIFE MORE DIFFICULT BY TYPING EM ALL. 2 HOURS INCLUDING WIND DOWN EVERY MORNING. THEN I LOG IN

Shame Boy
Mar 2, 2010

haveblue posted:

more like failchimp

dammit this is way better

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Shame Boy posted:

more like mailchump

haveblue posted:

more like failchimp
lol x 2

mystes
May 31, 2006

Powerful Two-Hander posted:

EVERY MORNING I WAKE UP AND OPEN PALM SLAM A PASSWORD INTO THE VAULT. ITS IOS SAFARI PASSWORD MANAGER AND RIGHT THEN AND THERE I START COPYING MY PASSWORDS TO MY MAIN MOBILE BROWSER, FIREFOX. I TYPE EVERY PASSWORD AND I DO TYPE IT HARD. MAKIN WHOOSHING SOUNDS WHEN I EXCEED 10 CHARACTERS OR EVEN WHEN I MISTYPE A LETTER. NOT MANY CAN SAY THEY CREATED THE GALAXY’S MOST CONVOLUTED PASSWORD MANAGEMENT SOLUTION. I CAN. I SAY IT AND I SAY IT OUTLOUD EVERYDAY TO PEOPLE IN THE SECFUCK THREAD AND ALL THEY DO IS PROVE PEOPLE IN YOSPOS CAN STILL BE IMMATURE JERKS. AND IVE LEARNED ALL THE PASSWORDS AND IVE LEARNED HOW TO MAKE MY LIFE MORE DIFFICULT BY TYPING EM ALL. 2 HOURS INCLUDING WIND DOWN EVERY MORNING. THEN I LOG IN
lmao

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

Powerful Two-Hander posted:

EVERY MORNING I WAKE UP AND OPEN PALM SLAM A PASSWORD INTO THE VAULT. ITS IOS SAFARI PASSWORD MANAGER AND RIGHT THEN AND THERE I START COPYING MY PASSWORDS TO MY MAIN MOBILE BROWSER, FIREFOX. I TYPE EVERY PASSWORD AND I DO TYPE IT HARD. MAKIN WHOOSHING SOUNDS WHEN I EXCEED 10 CHARACTERS OR EVEN WHEN I MISTYPE A LETTER. NOT MANY CAN SAY THEY CREATED THE GALAXY’S MOST CONVOLUTED PASSWORD MANAGEMENT SOLUTION. I CAN. I SAY IT AND I SAY IT OUTLOUD EVERYDAY TO PEOPLE IN THE SECFUCK THREAD AND ALL THEY DO IS PROVE PEOPLE IN YOSPOS CAN STILL BE IMMATURE JERKS. AND IVE LEARNED ALL THE PASSWORDS AND IVE LEARNED HOW TO MAKE MY LIFE MORE DIFFICULT BY TYPING EM ALL. 2 HOURS INCLUDING WIND DOWN EVERY MORNING. THEN I LOG IN

Achmed Jones
Oct 16, 2004



Powerful Two-Hander posted:

I think I only outright remember two passwords: ms account for logon and keepass vault.

and I guess the windows PIN it insisted I set up after I stupidly upgraded to win 11

EVERY MORNING I WAKE UP AND OPEN PALM SLAM A PASSWORD INTO THE VAULT. ITS IOS SAFARI PASSWORD MANAGER AND RIGHT THEN AND THERE I START COPYING MY PASSWORDS TO MY MAIN MOBILE BROWSER, FIREFOX. I TYPE EVERY PASSWORD AND I DO TYPE IT HARD. MAKIN WHOOSHING SOUNDS WHEN I EXCEED 10 CHARACTERS OR EVEN WHEN I MISTYPE A LETTER. NOT MANY CAN SAY THEY CREATED THE GALAXY’S MOST CONVOLUTED PASSWORD MANAGEMENT SOLUTION. I CAN. I SAY IT AND I SAY IT OUTLOUD EVERYDAY TO PEOPLE IN THE SECFUCK THREAD AND ALL THEY DO IS PROVE PEOPLE IN YOSPOS CAN STILL BE IMMATURE JERKS. AND IVE LEARNED ALL THE PASSWORDS AND IVE LEARNED HOW TO MAKE MY LIFE MORE DIFFICULT BY TYPING EM ALL. 2 HOURS INCLUDING WIND DOWN EVERY MORNING. THEN I LOG IN

cinci zoo sniper
Mar 15, 2013




Powerful Two-Hander posted:

EVERY MORNING I WAKE UP AND OPEN PALM SLAM A PASSWORD INTO THE VAULT. ITS IOS SAFARI PASSWORD MANAGER AND RIGHT THEN AND THERE I START COPYING MY PASSWORDS TO MY MAIN MOBILE BROWSER, FIREFOX. I TYPE EVERY PASSWORD AND I DO TYPE IT HARD. MAKIN WHOOSHING SOUNDS WHEN I EXCEED 10 CHARACTERS OR EVEN WHEN I MISTYPE A LETTER. NOT MANY CAN SAY THEY CREATED THE GALAXY’S MOST CONVOLUTED PASSWORD MANAGEMENT SOLUTION. I CAN. I SAY IT AND I SAY IT OUTLOUD EVERYDAY TO PEOPLE IN THE SECFUCK THREAD AND ALL THEY DO IS PROVE PEOPLE IN YOSPOS CAN STILL BE IMMATURE JERKS. AND IVE LEARNED ALL THE PASSWORDS AND IVE LEARNED HOW TO MAKE MY LIFE MORE DIFFICULT BY TYPING EM ALL. 2 HOURS INCLUDING WIND DOWN EVERY MORNING. THEN I LOG IN

Dr_0ctag0n
Apr 25, 2015


The whole human race
sentenced
to
burn
"Hey, did you see we just completely overhauled our LastPass browser extension today? It's got a new Security dashboard pane!



Guys? :v:...anyone?"

mystes
May 31, 2006

Dr_0ctag0n posted:

"Hey, did you see we just completely overhauled our LastPass browser extension today? It's got a new Security dashboard pane!



Guys? :v:...anyone?"
Lastpass, the only password manager where you need a security dashboard that shows you minute-by-minute updates on how much your passwords have been compromised as a result of the site being hacked

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

Powerful Two-Hander posted:

EVERY MORNING I WAKE UP AND OPEN PALM SLAM A PASSWORD INTO THE VAULT. ITS IOS SAFARI PASSWORD MANAGER AND RIGHT THEN AND THERE I START COPYING MY PASSWORDS TO MY MAIN MOBILE BROWSER, FIREFOX. I TYPE EVERY PASSWORD AND I DO TYPE IT HARD. MAKIN WHOOSHING SOUNDS WHEN I EXCEED 10 CHARACTERS OR EVEN WHEN I MISTYPE A LETTER. NOT MANY CAN SAY THEY CREATED THE GALAXY’S MOST CONVOLUTED PASSWORD MANAGEMENT SOLUTION. I CAN. I SAY IT AND I SAY IT OUTLOUD EVERYDAY TO PEOPLE IN THE SECFUCK THREAD AND ALL THEY DO IS PROVE PEOPLE IN YOSPOS CAN STILL BE IMMATURE JERKS. AND IVE LEARNED ALL THE PASSWORDS AND IVE LEARNED HOW TO MAKE MY LIFE MORE DIFFICULT BY TYPING EM ALL. 2 HOURS INCLUDING WIND DOWN EVERY MORNING. THEN I LOG IN

polyester concept
Mar 29, 2017

https://www.youtube.com/watch?v=EemoOviEC74

Tankakern
Jul 25, 2007

cinci zoo sniper
Mar 15, 2013




https://www.bleepingcomputer.com/news/security/paypal-accounts-breached-in-large-scale-credential-stuffing-attack/

so, is this lastpass

cinci zoo sniper
Mar 15, 2013




https://www.bloomberg.com/news/articles/2023-01-19/t-mobile-tmus-says-hacker-stole-data-for-37-million-customers

T-Mobile US Inc. said a hacker obtained data for 37 million customer accounts, though it didn’t include payment information, passwords or other sensitive personal data.

The wireless provider said in a federal filing it discovered the hack on Jan. 5 and was able to trace the source and stop it within a day.

The investigation is still ongoing, the company said, but the culprit appeared to obtain the information through a single entry point serving customer data, and doesn’t appear to have breached the company’s systems or network.

sb hermit
Dec 13, 2016





haveblue posted:

more like failchimp

new thread title please

Kesper North
Nov 3, 2011

EMERGENCY POWER TO PARTY
https://www.dailydot.com/debug/no-fly-list-us-tsa-unprotected-server-commuteair/

quote:

Analysis of the server resulted in the discovery of a text file named “NoFly.csv,” a reference to the subset of individuals in the Terrorist Screening Database who have been barred from air travel due to having suspected or known ties to terrorist organizations.

The list, according to crimew, appeared to have more than 1.5 million entries in total. The data included names as well as birth dates. It also included multiple aliases, placing the number of unique individuals at far less than 1.5 million.

On the list were several notable figures, including the recently freed Russian arms dealer Viktor Bout, alongside over 16 potential aliases for him.

Babies Getting Rabies
Apr 21, 2007

Sugartime Jones
happy xmas (war is over) by john lennon starts playing

cinci zoo sniper posted:

so, is this lastpass

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

what are people doing with managed devices and passkeys or whatever non-Apple people call the WebAuthn stuff? can they be escrowed like with a password manager or (I think) WHfB?

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

Subjunctive posted:

what are people doing with managed devices and passkeys or whatever non-Apple people call the WebAuthn stuff? can they be escrowed like with a password manager or (I think) WHfB?

my hope is they can but so far i haven't heard anything. it's frustrating because i use windows, linux, and macos plus ios so i really want a universal way to handle all of them with a third party pwm (in my case, bitwarden)

e: looks like 1password is working on it: https://blog.1password.com/1password-is-joining-the-fido-alliance/ so hopefully bitwarden will follow suit

e2: looks like probably yes for bitwarden, in 2023 (buried in a table in this article): https://bitwarden.com/blog/bitwarden-extends-passwordless-leadership-with-acquisition/

Cold on a Cob fucked around with this message at 19:27 on Jan 20, 2023

Potato Salad
Oct 23, 2014

nobody cares


There are 128 Andrews on the nofly list

cinci zoo sniper
Mar 15, 2013




219 James

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



hats shoes off to jameses

Pendragon
Jun 18, 2003

HE'S WATCHING YOU
is there a list somewhere that tells me which JVM CVEs/versions I actually need to worry about if I’m running server side Java? Nessus goes nuts over almost every JVM we have, but like 99% of the exploits are only possible in applets or running untrusted code.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

BlankSystemDaemon posted:

A cloud provider isn't more or less likely to lose data than you are, if you have proper backups in place (meaning a 3-2-1 procedure with RPO-/RTO-targets and automated testing)

To be clear, have you ever met an end user?

Potato Salad posted:

There are 128 Andrews on the nofly list

And yet I assume all of them can sweat.

Shame Boy
Mar 2, 2010

https://twitter.com/mspfa/status/1616454903982919681?s=20

cinci zoo sniper
Mar 15, 2013




thank you for psychic damage

sb hermit
Dec 13, 2016





I guess people with a cybersecurity major are incredibly poo poo at cybersecurity.

The #1 rule in cybersecurity is to create disaster plans, funny enough.

The #2 rule is to actually test the disaster plans.

And why would someone run malware inside what is probably their primary computer instead of just a VM?

Chalks
Sep 30, 2009

examining the contents of an exe by double clicking on it must be part of the advanced classes

Slashrat
Jun 6, 2011

YOSPOS
Imagining the wild alternate reality in which self-taught Infectious Disease Researchers also think it's fine to examine samples of Ebola in their living room

Andohz
Aug 15, 2004

World's Strongest Smelly Hobo
You Wouldn't Download An Anthrax Sample

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
hi i'm not a security researcher but if i was "examining" something like this my first thought is to do it on an airgapped pc with a clean install of windows and whatever tools i need to study it. i wouldn't have discord installed on it. lol. lmao.

FungiCap
Jul 23, 2007

Let's all just calm down and put on our thinking caps.
colleague got DA immediately in an assessment many years ago because he sent a phish to a few employees and they correctly reported the phish.

a security engineer (of like, 20+ years experience!) then interacted with the malware on his domain machine to "research" the malware despite having no idea what that entails (like seriously, you don't have any reverse engineering experience at all, what do you think you're going to find out?). i dont know what the pivot step from there to DA was, but i'm gonna take a wild guess and say cleartext admin creds on a file on the desktop.

mystes
May 31, 2006

Lol

FungiCap posted:

colleague got DA immediately in an assessment many years ago because he sent a phish to a few employees and they correctly reported the phish.

a security engineer (of like, 20+ years experience!) then interacted with the malware on his domain machine to "research" the malware despite having no idea what that entails (like seriously, you don't have any reverse engineering experience at all, what do you think you're going to find out?). i dont know what the pivot step from there to DA was, but i'm gonna take a wild guess and say cleartext admin creds on a file on the desktop.
ok this might be even better

Shame Boy
Mar 2, 2010

sb hermit posted:

I guess people with a cybersecurity major are incredibly poo poo at cybersecurity.

The #1 rule in cybersecurity is to create disaster plans, funny enough.

The #2 rule is to actually test the disaster plans.

And why would someone run malware inside what is probably their primary computer instead of just a VM?

serious question: how does one make a disaster plan for a discord? now that everyone's moving everything off the internet and into closed little discord boxes i get the feeling that a hell of a lot of important poo poo is just one click away from being obliterated forever

distortion park
Apr 25, 2011


idk but it definitely involves speaking to their enterprise support team and then handing over a lot of money

Potato Salad
Oct 23, 2014

nobody cares



The core security issue is that we do things with computers, and poo poo would dramatically improve once we stop doing things with computers.

cinci zoo sniper
Mar 15, 2013




Shame Boy posted:

serious question: how does one make a disaster plan for a discord? now that everyone's moving everything off the internet and into closed little discord boxes i get the feeling that a hell of a lot of important poo poo is just one click away from being obliterated forever

you don’t; which is why i hate to seeing purportedly knowledge sharing-oriented discord servers

Shaggar
Apr 26, 2006

Shame Boy posted:

serious question: how does one make a disaster plan for a discord? now that everyone's moving everything off the internet and into closed little discord boxes i get the feeling that a hell of a lot of important poo poo is just one click away from being obliterated forever

i would have expected backups to be a feature of discord since its all hosted by them, but looks like its not. seems like a gently caress up, imo.

Adbot
ADBOT LOVES YOU

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
youtubers that have lost control of their channels have had everything restored. i wonder if that's possible with discord. there are differences though, like youtubers bring in money to google, not sure free discord users do?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply