Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
did he really just wait 48 hours after notification

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Cyrezar posted:

i work there, they don't tell us to print anything unless we have to. definitely not emails
you're supposed to print out important memos and poo poo when you're an important person, like the head of the organization. but the government hasn't done proper e-mail archival since forever, sooooo

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

minivanmegafun posted:

yeah, uh, what problem does cryptocat solve that pidgin/Adium + OTR don't
installing software is such a hassle! *b/w video of grandma mashing floppy diskettes into a crt*

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Wiggly Wayne DDS posted:

time to get a judge to handover microsoft's domains to fix this malware issue
nice!

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:

code:
>>> import requests
>>> r = requests.get('http://reddit.com')
>>> r.headers
{'content-length': '19692', 
'x-xss-protection': '1; mode=block', 
'x-content-type-options': 'nosniff', 
'content-encoding': 'gzip', 
'vary': 'accept-encoding', 
'server': "'; DROP TABLE servertypes; --", 
'connection': 'keep-alive', 
'date': 'Thu, 03 Jul 2014 14:47:30 GMT', 
'x-frame-options': 'SAMEORIGIN', 
'content-type': 'text/html; charset=UTF-8'}
please

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Mido posted:

you could say there has been a privilege elevation vulnerability

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Aleksei Vasiliev posted:

i later got prescribed vyvanse

LARD LORD posted:

congrats on ur ADHD

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
hey i just found out cryptome has a kickstarter https://www.kickstarter.com/projects/1874173687/cryptome-global-archives

i think they would be closer to their goal if they put up more pledge levels though, pretty unfortunate for them

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
LOL ) some one go to jail ahaha its me

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
president obama was caught eavesdropping, impeach now

https://www.flickr.com/photos/whitehouse/14565226493/

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:



thanks canada post. it also specifies that the maximum is 12

on a related note, i am moving and found out through my gf that the forwarded uhaul e-mail i gave her had a link that signed her right into my account
if they are successfully privatized maybe stricter controls will be implemented

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Nintendo Kid posted:

it really isn't, privatization of the usps essentially halted long ago
lol if u believe this

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lol he is representative of the state of california

anthonypants fucked around with this message at 01:46 on Jul 12, 2014

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Snapchat A Titty posted:

in that case i do not want darrel issa talking points

american politics has become so skewed that i dont want any part of it at all. i vote red/green alliance and i am proud.
that's okay. if the women don't find you handsome they should at least find you handy

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Bloody posted:

yeah but thats not free software
caveat emptor

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Heresiarch posted:

False Intelligence Spreading Heuristic MECHanism

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

infernal machines posted:

windows admins are shitlords of the highest caliber given the chance. they're like any other kind of greybeard, but smug about not actually knowing anything
at my last job all the windows admins had been novell admins but kept their positions when they moved to ad. those people didn't get let go because it was local government, so instead they made it a joint nds/ad thing in order to claim some level of competency i guess

actually that place was full of really really good security fuckups, like this one




also on my last day i pulled a list of users who had not logged in for a year but still had active accounts (it was like 100 people) and sent that list to the auditors, and then later found out that the sysadmin boss got replaced. lmao

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

infernal machines posted:

novell was amazing for allowing security fuckups of the highest order.

at my highschool we had netware auth with a four month password change policy, you were forced to change your password once it expired. when it expired you could log in to the account with any or no password whatsoever, then set a password as prompted.

since no one removed or audited old accounts there were several board-wide admin accounts that had been idle for more than a year

student accounts(e.g. unprivileged user accts.) were able to access the netware user admin tool, they couldn't make changes, but could see a list of accounts domain wide.

guess what happened.
i think you could do things like this where i worked, but then it tried to log you into windows with that password, and it would tell you your password was wrong. password desync for no reason was easily half of the support calls at that place.

anthonypants fucked around with this message at 05:59 on Jul 17, 2014

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Luigi Thirty posted:

remember when i said that a site emailed me my pw in plaintext when my subscription was up

guess who got hacked and had all their cc numbers leaked last week

guess who got a phone call from their bank about fraudulent activity this morning :suicide:
i give up who

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Powercrazy posted:

Is it a security gently caress-up to have your internal CA issue certs that don't expire for almost 100 years?
kind of but your internal ca should be able to issue a revocation for them pretty easily

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
is it possible to prevent your workplace from ssl cert injection

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BeOSPOS posted:

to paraphrase Ledar this evening, "I enjoy reading about bit coiners losing their passwords or accidentally destroying their hard drives."

someone buy him an account
who

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ultramiraculous posted:

the ~forensics tool~ needed here is a demo copy of iexplorer.
iexplore.exe

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
since they didn't say it wasn't encrypted, what significance does "without requiring a backup password" have

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:

it's only criminal if the dropbox gets breached and this information comes out

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

flakeloaf posted:

encryption legorithm

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Bloody posted:

anybody else uncomfortable with assisting recaptcha in their quest to ocr photographs of peoples addresses
lol if you aren't putting "boners" or something in for those words

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

scroogle nmaps posted:

as if the govt uses anything that modern

some bureaucrat in their 70s writes each returned page's html by hand and feeds the punchcard into the mainframe

at least that's the only explanation i have for websites that close after 5pm in the evening.
i worked at the local VA hospital a while back and their intranet was classic asp and sharepoint. lol coldfusion

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
yeah i refuse to believe that wasn't intentional

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Optimus_Rhyme posted:

The only reason you keep a mainframe is because it's job security for greybeards.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Broken Machine posted:



That looks fairly real to me.

The following is a hypothetical. Suppose you're :nsa:. You contact HP / Intel, anyone who makes prebuilt computers. You request that they provide you with any and all bios source before they're released for public consumption. They then insert whatever code they want, compile the image and send it back to the company to be released. Do you suppose that happens?
yes but that's not what badbios was

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Wiggly Wayne DDS posted:

that wasn't what was said at all but okay fishmech
no that's actually how dragos described badbios. iirc he even provided a recording of the ultrasonic sounds coming from his pc speaker which was one of the few pieces of evidence he was willing to share

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Wiggly Wayne DDS posted:

i recall him theorising on machine-to-machine communication, it reinfecting in an unknown way and those seperate ideas being muddled together through chinese whispers
https://twitter.com/dragosr/status/396815689484218368
https://twitter.com/dragosr/status/397018715151024129

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Wiggly Wayne DDS posted:

yeah to be clear it's this part:

that i'm complaining about
that's literally what dragos claimed. he thinks it jumped from his macbook to his pc, he theorized that one of the transmission vectors was ultrasonic audio and then with those tweets he says, "guess I can stop calling it a hypothesis now"

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

uncurable mlady posted:

it's kinda hard to keep track of what badbios is or isn't because he basically stopped posting about it and i don't really recall a thorough writeup
maybe he'll pick it up again in another three years

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Broken Machine posted:

I don't really mess with anything that low-level either, but yes if you actually took the time to read through the machine code or assembly, it's possible you could find a compromised bios. It'd be like looking through all of OpenSSL for security holes. I don't know if UEFI allows just a straight executable.
it would have been really simple for him to make available the firmwares from his bios or his efi partition, but he didn't because

uncurable mlady posted:

i think my favorite part has to be "if you've ever actually used a computer then it's impossible to trust your forensic results because they might have already gotten to you"
and a bios is like, 4k? 8k at the most? don't compare scrutinizing that to the openssl project

anthonypants fucked around with this message at 20:39 on Jul 31, 2014

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

papa_november posted:

i was under the impression that the ultrasound bit was pure science fiction due to the fact that the lovely speakers and microphones built into most laptops/desktops (to say nothing of the lovely piezo beepers built into motherboards) had no hope in hell of reaching the frequencies needed

like all good science fiction though, badbios had some interesting if not plausible ideas for future technology
it is, just like the rf transmission vector he proposed before the ultrasound one

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Kuvo posted:

you all are fishmeching pretty hard here

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
courtesy brian krebs, a target smartcard reader on ebay

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Luigi Thirty posted:

lol that tweet didn't last long

briankrebs (@briankrebs) August 4, 2014 posted:

Nice! A relic from Target's early (and, sadly, ill-fated) experiment with Chip-and-PIN tech, for sale on eBay http://t.co/BUkVrqgRSk

  • Locked thread