Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Subjunctive
Sep 12, 2006

✨sparkle and shine✨

ErIog posted:

Loose lips sink ships, but those same lips also help a lot of people make enough money giving blowjobs so it's impossible to say if it's good or bad

what part of that would be bad?

Adbot
ADBOT LOVES YOU

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
something something dead seamen

4lokos basilisk
Jul 17, 2008


Jabor posted:

something something dead seamen

dead seamen on your loose lips? more likely than you think!

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


hooooly poo poo did I just find a fuckup

we have a cloud platform that uses sso across the company domain(s), so when you go to it and enter powerfultwohander@company.com, it forces sso against our idp (you can probably see where this is going), but only if the domain is yours.

so if you go to it and enter the email address as powerfultwohander@yospos.com it just reverts to username and password and you can then upload whatever you like!

loving lmao. not only did it security not think of this (neither did until just now but it's not my job), but the vendor didn't think to mention it and their solution to it is absolute trash (just ip restrict to that domain your morons).

bonus: we don't monitor outbound data on the main domain account anyway lol

this is gonna ruin at *least* two people's days

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Powerful Two-Hander posted:

this is gonna ruin at *least* two people's days

since it's a friday, you have a moral obligation to wait until 4:55pm to report it.

sb hermit
Dec 13, 2016





Powerful Two-Hander posted:

the vendor didn't think to mention it and their solution to it is absolute trash

vendor keeping up the status quo though, good for them

SlowBloke
Aug 14, 2017

Powerful Two-Hander posted:

hooooly poo poo did I just find a fuckup

we have a cloud platform that uses sso across the company domain(s), so when you go to it and enter powerfultwohander@company.com, it forces sso against our idp (you can probably see where this is going), but only if the domain is yours.

so if you go to it and enter the email address as powerfultwohander@yospos.com it just reverts to username and password and you can then upload whatever you like!

loving lmao. not only did it security not think of this (neither did until just now but it's not my job), but the vendor didn't think to mention it and their solution to it is absolute trash (just ip restrict to that domain your morons).

bonus: we don't monitor outbound data on the main domain account anyway lol

this is gonna ruin at *least* two people's days

Isn't that standard keycloak behaviour? I don't think you can do much to mitigate it.

outhole surfer
Mar 18, 2003

SlowBloke posted:

Isn't that standard keycloak behaviour? I don't think you can do much to mitigate it.

it's standard behavior at every saas that's supported sso since the beginning of time too

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


infernal machines posted:

since it's a friday, you have a moral obligation to wait until 4:55pm to report it.

I told my boss 45 mins before he got on a plane lol

SlowBloke posted:

Isn't that standard keycloak behaviour? I don't think you can do much to mitigate it.

turns out you sort of can. you can add your organisation identity id as an outbound http header to all traffic to the domain so that requests containing that header get forced to logon using domain emails

it would be much, much, easier if they had org specific subdomains and you could just block the others in your firewall

e; this isn't that bad in the scheme of things because it's basically "turns out you can send data over the internet!" but there was a big "someone sent sensitive info to an external account" poo poo that went down recently so, lol

evil_bunnY
Apr 2, 2003

Crimew did the Well There's Your Problem podcast lmao
https://www.youtube.com/watch?v=FgbQb7G6e7w

Submarine Sandpaper
May 27, 2007


Powerful Two-Hander posted:

I told my boss 45 mins before he got on a plane lol

turns out you sort of can. you can add your organisation identity id as an outbound http header to all traffic to the domain so that requests containing that header get forced to logon using domain emails

it would be much, much, easier if they had org specific subdomains and you could just block the others in your firewall

e; this isn't that bad in the scheme of things because it's basically "turns out you can send data over the internet!" but there was a big "someone sent sensitive info to an external account" poo poo that went down recently so, lol

When I ask for SSO from our vendors I usually hope they can act as you describe is a huge issue. Usually accounts not in our iDP collaborate on the platform so there are both local and federated accounts. Doing a domain bounce to the iDP rather than account by account is cool and good.

I'd like PW to be a non exposed field until a full username is put in but a lot of SaaS won't support that.

Volguus
Mar 3, 2009

Submarine Sandpaper posted:

I'd like PW to be a non exposed field until a full username is put in but a lot of SaaS won't support that.

It also messes up password managers, sometimes. Why would anyone want to do that?

Submarine Sandpaper
May 27, 2007


So users will question any time they actually put in a PW.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


I actually unironically got a "please say 'my voice is my password ' to biometrically authenticate" the other day. I barely remember setting that up and when I did, doing it mainly to see what would actually happen.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
my bank has prompted me to do that every time I've called in to activate a credit card or authorize a limit increase, for like five years now

i've always declined to turn it on

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


for maximum security I put on an accent and ended with a question mark to add a special character

*australianishly* my voice is my password?

cinci zoo sniper
Mar 15, 2013




i remember the leak well, since a guy i know was one of the victims of it, but i did never have an idea about how the hacker got caught lmao https://krebsonsecurity.com/2023/02/finlands-most-wanted-hacker-nabbed-in-france/

quote:

In late October 2022, Kivimäki was charged (and “arrested in absentia,” according to the Finns) with attempting to extort money from the Vastaamo Psychotherapy Center. In that breach, which occurred in October 2020, a hacker using the handle “Ransom Man” threatened to publish patient psychotherapy notes if Vastaamo did not pay a six-figure ransom demand.

Vastaamo refused, so Ransom Man shifted to extorting individual patients — sending them targeted emails threatening to publish their therapy notes unless paid a 500-euro ransom.

When Ransom Man found little success extorting patients directly, they uploaded to the dark web a large compressed file containing all of the stolen Vastaamo patient records.

But as documented by KrebsOnSecurity in November 2022, security experts soon discovered Ransom Man had mistakenly included an entire copy of their home folder, where investigators found many clues pointing to Kivimäki’s involvement.From that story:

“Among those who grabbed a copy of the database was Antti Kurittu, a team lead at Nixu Corporation and a former criminal investigator. In 2013, Kurittu worked on an investigation involving Kivimäki’s use of the Zbot botnet, among other activities Kivimäki engaged in as a member of the hacker group Hack the Planet (HTP).”

“It was a huge opsec [operational security] fail, because they had a lot of stuff in there — including the user’s private SSH folder, and a lot of known hosts that we could take a very good look at,” Kurittu told KrebsOnSecurity, declining to discuss specifics of the evidence investigators seized. “There were also other projects and databases.”

According to the French news site actu.fr, Kivimäki was arrested around 7 a.m. on Feb. 3, after authorities in Courbevoie responded to a domestic violence report. Kivimäki had been out earlier with a woman at a local nightclub, and later the two returned to her home but reportedly got into a heated argument.

Police responding to the scene were admitted by another woman — possibly a roommate — and found the man inside still sleeping off a long night. When they roused him and asked for identification, the 6′ 3″ blonde, green-eyed man presented an ID that stated he was of Romanian nationality.

The French police were doubtful. After consulting records on most-wanted criminals, they quickly identified the man as Kivimäki and took him into custody.

omg

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

loving looool

Kitfox88
Aug 21, 2007

Anybody lose their glasses?
my_criminal_empire.zip

Quackles
Aug 11, 2018

Pixels of Light.


Volguus posted:

It also messes up password managers, sometimes. Why would anyone want to do that?

Doesn't mess up Firefox.

Tankakern
Jul 25, 2007

i did wonder what happened to that shitstain that resorted to extorting patients

haveblue
Aug 15, 2005



Toilet Rascal

Kitfox88 posted:

my_criminal_empire.zip

tar -xvf ~ /crimes

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
Everyone knows that Ransom Man is weak to the Opsec Torpedo.

Zamujasa
Oct 27, 2010



Bread Liar
hoist by your /home/ petard

Kitfox88
Aug 21, 2007

Anybody lose their glasses?

haveblue posted:

tar -xvf ~ /crimes

Zamujasa posted:

hoist by your /home/ petard

:nsavince:

flakeloaf
Feb 26, 2003

Still better than android clock

thumbprints.db

fisting by many
Dec 25, 2009



Zamujasa posted:

hoist by your /home/ petard

Raymond T. Racing
Jun 11, 2019

Volguus posted:

It also messes up password managers, sometimes. Why would anyone want to do that?

if implemented properly it should never gently caress up password managers

see google sign in, ebay, etc

distortion park
Apr 25, 2011


cinci zoo sniper posted:

i remember the leak well, since a guy i know was one of the victims of it, but i did never have an idea about how the hacker got caught lmao https://krebsonsecurity.com/2023/02/finlands-most-wanted-hacker-nabbed-in-france/

omg

lmao

quote:

When they roused him and asked for identification, the 6′ 3″ blonde, green-eyed man presented an ID that stated he was of Romanian nationality.

The French police were doubtful.

racial profiling finally bringing home the goods for the french cops

bicycle
Oct 23, 2013
HTP and zf0 zines back in the day were one of the reasons i began to enjoy security fuckups so i am glad they are still bringing the goods even if its unintentional this time

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


distortion park posted:

lmao

racial profiling finally bringing home the goods for the french cops

lol drat I missed that

post hole digger
Mar 21, 2011

Zamujasa posted:

hoist by your /home/ petard

Nerdlord Actual
Apr 14, 2007

Awaken to your true self with Wisconsin Potatoes
Grimey Drawer
I surface from the depths to share this

https://kotaku.com/ai-seinfeld-twitch-ban-transphobia-chatgpt-dalle-jerry-1850077836

That AI generated Seinfeld stream on Twitch got banned because it dropped some sick bigotry "jokes".... and why?

quote:

Hartle shared a technical explanation for what happened while discussing the results of an internal investigation into Larry’s transphobic mishap, saying something went wrong with an in-use OpenAI GPT-3 model.

“We’ve been investigating the root cause of the issue,” Hartle said. “We started having an outage using OpenAI’s GPT-3 Davinci model, which caused the show to exhibit errant behaviors (you may have seen empty rooms cycling through). OpenAI has a less sophisticated model, Curie, that was the predecessor to Davinci. When Davinci started failing, we switched over to Curie to try to keep the show running without any downtime. The switch to Curie was what resulted in the inappropriate text being generated. We leverage OpenAI’s content moderation tools, which have worked thus far for the Davinci model, but were not successful with Curie. We’ve been able to identify the root cause of our issue with the Davinci model, and will not be using Curie as a fallback in the future. We hope this sheds a little light on how this happened.”

"We were having tech issues so we made a change on live, rather than production" strikes again. Hope they enjoy their two week time out and sort their poo poo.

haveblue
Aug 15, 2005



Toilet Rascal
a few days ago they were talking about how infinite AI seinfeld is not a weird gimmick joke but actually the future of popular entertainment

endlessmonotony
Nov 4, 2009

by Fritz the Horse
I wouldn't even say the resulting joke was transphobic, it absolutely would have read as mocking hack comedians had it come from a human. Especially with the very fitting punchline.

The chatbots are edgy now, what a world.

Last Chance
Dec 31, 2004

that seinfeld ai thing was boring and extremely unfunny anyway

cinci zoo sniper
Mar 15, 2013




haveblue posted:

a few days ago they were talking about how infinite AI seinfeld is not a weird gimmick joke but actually the future of popular entertainment

tbh it's pretty entertaining to read about it today, but i hope it gets more story arcs than testing code in prod

endlessmonotony
Nov 4, 2009

by Fritz the Horse
That joke reads as pitch-perfect mockery of Jerry Seinfeld, and if the AI really produced it unscripted, I will defend this entire project as a masterpiece of art.

It's a brilliant recontextualization entirely by accident.

evil_bunnY
Apr 2, 2003

Zamujasa posted:

hoist by your /home/ petard
:perfect:

Adbot
ADBOT LOVES YOU

Tankakern
Jul 25, 2007

Last Chance posted:

that seinfeld ai thing was boring and extremely unfunny anyway

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply