Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
CLAM DOWN
Feb 13, 2007




some kinda jackal posted:

Anyone else hear about Entrust getting popped? I can’t find any news sources to back it up so maybe I’m full of poo poo.

Omg please say this happened, obviously it would be disastrous but also lol and lmao

Adbot
ADBOT LOVES YOU

Diva Cupcake
Aug 15, 2005

Literal bastards
https://twitter.com/BleepinComputer/status/1545174259487621122

vanity slug
Jul 20, 2010

CLAM DOWN posted:

Omg please say this happened, obviously it would be disastrous but also lol and lmao

Untrust

ShoeFly
Dec 28, 2006

Waiter, there's a fly in my shoe!


Jesus Christ, pathetic

Potato Salad
Oct 23, 2014

nobody cares


every motherfucker who complained about getting blindsided by this has an X painted on their back

Thanks Ants
May 21, 2004

#essereFerrari


If you're such a broken organisation that you rely on macros then take the several months notice of the change and write a single group policy. I hate Microsoft for this obsession with not upsetting the laziest administrators in the industry.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Potato Salad posted:

every motherfucker who complained about getting blindsided by this has an X painted on their back

Honestly I'm paying big attention to where I hear these coming from.

cr0y
Mar 24, 2005



Uh eh?

SlowBloke
Aug 14, 2017

Thanks Ants posted:

If you're such a broken organisation that you rely on macros then take the several months notice of the change and write a single group policy. I hate Microsoft for this obsession with not upsetting the laziest administrators in the industry.

We hoped to start yelling from the rooftops about no more macros but nope, macros forever. loving invertebrates.

navyjack
Jul 15, 2006



Every Cybersecurity bigwig in my town is at an event at my bar and I can’t network without pissing off my boss who is running it! Imma try and be discreet lmao

Internet Explorer
Jun 1, 2005





navyjack posted:

Every Cybersecurity bigwig in my town is at an event at my bar and I can’t network without pissing off my boss who is running it! Imma try and be discreet lmao

I've seen this movie!

Achmed Jones
Oct 16, 2004



the move here is to challenge them to a video game contest. if that doesn't work show them the pool on the roof

droll
Jan 9, 2020

by Azathoth
The real move is don't attend, let them die from covid then take their job.

BaldDwarfOnPCP
Jun 26, 2019

by Pragmatica

Internet Explorer posted:

I've seen this movie!

Come and knock on our door...

hmm hmm hmm hmm hmm hmm

Evis
Feb 28, 2007
Flying Spaghetti Monster

droll posted:

The real move is don't attend, let them die from covid then take their job.

That’s how you get a job with more responsibilities and the same pay.

Potato Salad
Oct 23, 2014

nobody cares


you first need to wait for the bar to be lowered by the neuropathy of multiple covid infections

navyjack
Jul 15, 2006



Potato Salad posted:

you first need to wait for the bar to be lowered by the neuropathy of multiple covid infections

Sadly, I work IN the bar so I can plan on getting multiple Covid infections every year for the rest of my short, miserable, cheese-lunged life.

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

some kinda jackal posted:

Anyone else hear about Entrust getting popped? I can’t find any news sources to back it up so maybe I’m full of poo poo.

Seems true, and you had this like 2 weeks ago

https://twitter.com/GossiTheDog/status/1550127981145649163?s=20&t=ptr5GbRgKkMVhHRoMgrsAg

some kinda jackal
Feb 25, 2003

 
 
Gonna be funny when it turns out the credentials for running the blog or whatever are the same as those for git repos for their HSM firmware or something

RFC2324
Jun 7, 2012

http 418

some kinda jackal posted:

Gonna be funny when it turns out the credentials for running the blog or whatever are the same as those for git repos for their HSM firmware or something

code:
3ntrust!

Maneki Neko
Oct 27, 2000

RFC2324 posted:

code:
3ntrust!

Still more complex than Solarwinds!

Internet Explorer
Jun 1, 2005





Speaking of hardcoded passwords.

Hardcoded password in Confluence app has been leaked on Twitter
Advisory had already warned hardcoded password was "trivial to obtain."

some kinda jackal
Feb 25, 2003

 
 
disabledsystemuser

Narrator: "It wasn't"

CLAM DOWN
Feb 13, 2007





Lol. Lmao.

RFC2324
Jun 7, 2012

http 418


oh gently caress you atlassian. you aren't even pretending to make something thats secure anymore

Arivia
Mar 17, 2011

RFC2324 posted:

oh gently caress you atlassian. you aren't even pretending to make something thats secure anymore

yeah how the gently caress does an enterprise services company do this poo poo these days

Absurd Alhazred
Mar 27, 2010

by Athanatos
Enterprise is just poo poo software with more expensive and draconian licenses.

CLAM DOWN
Feb 13, 2007




https://twitter.com/jerryaldrichiii/status/1551774522214191104

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Different companies, I think?

The Fool
Oct 16, 2003


It clearly says T-Mobile in both screenshots

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

The Fool posted:

It clearly says T-Mobile in both screenshots

The brand name for a company can be licensed out, which AIUI is the case here

Pablo Bluth
Sep 7, 2007

I've made a huge mistake.
Ars Technica article about EUFI rootkits
https://arstechnica.com/information-technology/2022/07/researchers-unpack-unkillable-uefi-rootkit-that-survives-os-reinstalls/

The Fool
Oct 16, 2003


Volmarias posted:

The brand name for a company can be licensed out, which AIUI is the case here

I was being facetious

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

The Fool posted:

I was being facetious

I've just been so continuously trampled on by Poe's law that I just assume now.

AlternateAccount
Apr 25, 2005
FYGM

How is infection accomplished? Tricking people into updating a compromised UEFI image?

Achmed Jones
Oct 16, 2004



probably physical access: evil maid, sending in a spook at midnight, paying off IT support person, etc

could also be a supply chain thing but i doubt it

e: lol embarrassing typo

Achmed Jones fucked around with this message at 02:15 on Jul 27, 2022

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Yeah this feels like a TAO sort of thing, but it's probably just some fucker at one of the factories slipping a different image to flash the machines with or something.

navyjack
Jul 15, 2006



Anybody have any experience/advice about being a Cybersecurity Sales Engineer? I have a friend trying to get me into it and it sounds a little too good to be true? If anyone has done it or dealt with it and knows what the day-to-day is like? It’s a lot of money.

spankmeister
Jun 15, 2008






It's selling companies magic boxes they don't need so that they can tick a box on an audit and pretend they're secure. If you're okay with that I'm sure it's a sweet gig.

Adbot
ADBOT LOVES YOU

Evis
Feb 28, 2007
Flying Spaghetti Monster

It could also be selling consulting services for audits that may or may not produce useful results or help manage business risks.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply