Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
shame on an IGA
Apr 8, 2005

dpkg chopra posted:

changelog:

added prep.h to codebase to mitigate effects from fartbleed

Adbot
ADBOT LOVES YOU

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

dpkg chopra posted:

changelog:

added prep.h to codebase to mitigate effects from fartbleed

- switch underpinnings
- attempt to close hole to mitigate fartbleed

haveblue
Aug 15, 2005



Toilet Rascal
fartbleed, the sequel to back orifice

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

dpkg chopra posted:

changelog:

added prep.h to codebase to mitigate effects from fartbleed

changelog: ok NOW it's mitigated

Agile Vector
May 21, 2007

scrum bored



dpkg chopra posted:

changelog:

added prep.h to codebase to mitigate effects from fartbleed

Shame Boy
Mar 2, 2010

dpkg chopra posted:

changelog:

added prep.h to codebase to mitigate effects from fartbleed

lmao if i ever wind up doing anything with the domain i will work this in somehow

PIZZA.BAT
Nov 12, 2016


:cheers:


lotta people are gonna have a fun one today

https://github.blog/2023-03-23-we-updated-our-rsa-ssh-host-key/

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.




quote:

This week, we discovered that GitHub.com’s RSA SSH private key was briefly exposed in a public GitHub repository.

lol

quote:

Please note that this issue was not the result of a compromise of any GitHub systems or customer information. Instead, the exposure was the result of what we believe to be an inadvertent publishing of private information. We have no reason to believe that the exposed key was abused and took this action out of an abundance of caution.

lmao even

cinci zoo sniper
Mar 15, 2013





the vuln was not an act of malice. it was a deliberate action of malicious consequence

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD
I'm probably a smooth brain who thinks that more=better but I've recently thought it was dumb that git uses RSA keys

Wild EEPROM
Jul 29, 2011


oh, my, god. Becky, look at her bitrate.
gib hut

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


private RSA keys? no, public repo!

Achmed Jones
Oct 16, 2004



the declarative version of the joke doesn't work because "no public repo" doesn't really scan on its own

C+ good attempt, see me after class

Soricidus
Oct 21, 2010
freedom-hating statist shill

~Coxy posted:

I'm probably a smooth brain who thinks that more=better but I've recently thought it was dumb that git uses RSA keys

there’s nothing particularly wrong with them in this context, is there? it’s not like key exchange where the old rsa algorithms have significant security deficiencies.

mystes
May 31, 2006

Soricidus posted:

there’s nothing particularly wrong with them in this context, is there? it’s not like key exchange where the old rsa algorithms have significant security deficiencies.
I guess ssh has forward secrecy anyway? So the only risk is quantum computers?

mystes fucked around with this message at 15:26 on Mar 24, 2023

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
https://twitter.com/thezdi/status/1639013632779628545

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

https://twitter.com/Synacktiv/status/1638996681260781574

lmao sounds bad

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


what a car crash

Albinator
Mar 31, 2010

dpkg chopra posted:

changelog:

added prep.h to codebase to mitigate effects from fartbleed

Zamujasa
Oct 27, 2010



Bread Liar

Achmed Jones posted:

the declarative version of the joke doesn't work because "no public repo" doesn't really scan on its own

C+ good attempt, see me after class

private RSA keys?

no, public exposure!

unknown
Nov 16, 2002
Ain't got no stinking title yet!


Tesla will probably claim all crashes are due to hackers from now on and not their software.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

~Coxy posted:

I'm probably a smooth brain who thinks that more=better but I've recently thought it was dumb that git uses RSA keys

its for the centos 6 servers still in production

Pile Of Garbage
May 28, 2007



apparently scams are going around tricking people into giving their steam login creds to dodgy sites to get access to the CS2 limited launch lmao: https://mastodon.social/@cs2unofficial/110093825035120363

cinci zoo sniper
Mar 15, 2013




Pile Of Garbage posted:

apparently scams are going around tricking people into giving their steam login creds to dodgy sites to get access to the CS2 limited launch lmao: https://mastodon.social/@cs2unofficial/110093825035120363

this after all the trillions of totally real dollars in stolen skins? goddamn, at some point cs players have to basically deserve getting owned

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


cinci zoo sniper posted:

this after all the trillions of totally real dollars in stolen skins? goddamn, at some point cs players have to basically deserve getting owned

*nods sagely* terrorists win

Pile Of Garbage
May 28, 2007



if anything Valve should have learned from the literature that reactive counter-terror is not a deterrent and instead proactive anti-terror is much more effective. also most of the "terrorists" are good guys anyway

Jenny Agutter
Mar 18, 2009

Powerful Two-Hander posted:

*nods sagely* terrorists win

cinci zoo sniper
Mar 15, 2013




https://twitter.com/naglinagli/status/1639343866313601024

Pile Of Garbage
May 28, 2007



lmfao that has nothing to do with chatgpt. its just that openai hosed up configuring the caching on their CDN and it's open to abuse:

https://twitter.com/naglinagli/status/1639353297982087180

you'd be forgiven for thinking otherwise ofc, given how the OP framed it

Apex Rogers
Jun 12, 2006

disturbingly functional

.css stands for cross site scripting, right? :magemage:

Pile Of Garbage
May 28, 2007



Caching Sure Sucks

Zamujasa
Oct 27, 2010



Bread Liar
Credentials Stored Securely

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Can’t Senter Simply

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

Pile Of Garbage posted:

lmfao that has nothing to do with chatgpt. its just that openai hosed up configuring the caching on their CDN and it's open to abuse:

https://twitter.com/naglinagli/status/1639353297982087180

you'd be forgiven for thinking otherwise ofc, given how the OP framed it

i don’t see the problem with the framing. they didn’t say it was a vulnerability in chatgpt, they said it was a vulnerability in the website and could give the attacker access to your chat history among other things. mentioning chatgpt is appropriate given that this could have affected most chatgpt users

Pile Of Garbage
May 28, 2007



from the OP tweet:

"The team at @OpenAI just fixed a critical account takeover vulnerability I reported few hours ago affecting #ChatGPT. It was possible to takeover someone's account, view their chat history, and access their billing information without them ever realizing it."

literally said affecting ChatGPT. irresponsible disclosure.

edit: link if it was lost https://twitter.com/naglinagli/status/1639343866313601024

Pile Of Garbage
May 28, 2007



idk admittedly maybe im letting my dislike of the subject take over but if anything it should be clear that the OP deliberately phrased and then posted about the exploit in a way that it would sound like chatgpt was the cause. that you have to dig four tweets in to find that it's actually just CDN fuckery is ugh.

good for them thou, stack paper from the rube mode

Pile Of Garbage
May 28, 2007



oh also it's just a config issue with their setup so we never ever have to care about it ever lmao

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
aren’t most chatgpt users using it through that website?

Pile Of Garbage
May 28, 2007



nah. nahhh

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




apparently twitter had gone open sores too https://www.theverge.com/2023/3/27/23657928/twitter-source-code-leak-github

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply