Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Absurd Alhazred
Mar 27, 2010

by Athanatos
https://twitter.com/MalwareTechBlog/status/1118275308543549440

More like Kim Dot DUMB

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


I had a daydream moment today of a service like like Spotify introducing a feature where you can chat with people listening to a certain song and all the guys in ISIS sticking Scatman John on a loop and hanging out in the chat.

Schadenboner
Aug 15, 2011

by Shine

:aaaaa:

The Fool
Oct 16, 2003


I need to be more careful posting tweets linked from here into work chat, twitter embeds the referrer in the url.

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010

It's ok bro, it was a ZERO DAY

https://twitter.com/briankrebs/status/1118202707318382593

RFC2324
Jun 7, 2012

http 418

Thanks Ants posted:

I had a daydream moment today of a service like like Spotify introducing a feature where you can chat with people listening to a certain song and all the guys in ISIS sticking Scatman John on a loop and hanging out in the chat.

I'd end up getting radicalized in 2 days

Internet Explorer
Jun 1, 2005





The Fool posted:

I need to be more careful posting tweets linked from here into work chat, twitter embeds the referrer in the url.

I always open the tweet and then copy it from Twitter. Doesn't embed the referrer.

astral
Apr 26, 2004

I let Firefox's content blocking prevent the tweet load entirely.

Proteus Jones
Feb 28, 2013



Millions using 123456 as password, security study finds

quote:

For its first cyber-survey, the NCSC analysed public databases of breached accounts to see which words, phrases and strings people used.

Top of the list was 123456, appearing in more than 23 million passwords. The second-most popular string, 123456789, was not much harder to crack, while others in the top five included "qwerty", "password" and 1111111.

I blame Mel Brooks.

https://www.bbc.com/news/technology-47974583

PBS
Sep 21, 2015
I wonder how many of those are for accounts people don't really care about vs regularly used or important accounts.

Probably still a significant percentage, but hopefully not quite as bad.

That being said the finding isn't that surprising, pretty sure I've seen this same article dozens of times over the last 15 or so years.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Proteus Jones posted:

Millions using 123456 as password, security study finds


I blame Mel Brooks.

https://www.bbc.com/news/technology-47974583

Hell, millions still use planeplain dictionary words. We had a load balancer get hit like that.

CommieGIR fucked around with this message at 21:51 on Apr 22, 2019

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

CommieGIR posted:

Hell, millions still use plane dictionary words. We had a load balancer get hit like that.

Like NATO alphabet spelling of their name?

astral
Apr 26, 2004

CommieGIR posted:

Hell, millions still use plane dictionary words. We had a load balancer get hit like that.

:911:

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Subjunctive posted:

Like NATO alphabet spelling of their name?

:mmmhmm:

Sarern
Nov 4, 2008

:toot:
Won't you take me to
Bomertown?
Won't you take me to
BONERTOWN?

:toot:

CommieGIR posted:

Hell, millions still use plane dictionary words. We had a load balancer get hit like that.

Plane dictionary words should be a pretty flat load though. No balancing required.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

CommieGIR posted:

Hell, millions still use plane dictionary words. We had a load balancer get hit like that.

Holy poo poo

Weaponized Autism
Mar 26, 2006

All aboard the Gravy train!
Hair Elf
What types of systems are these passwords still being used on? The article doesn't say, but I'm guessing these are passwords they use for internal applications at work?

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

CommieGIR posted:

Hell, millions still use plane dictionary words. We had a load balancer get hit like that.

The new LB password is: elevon canard Immelmann pitot

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
I love spellcheck, and you guys are all great.

Volguus
Mar 3, 2009
E2E Soccer is recognized as a leader in IT solutions for soccer organizations with solutions in club and league management, referee assignment, and scheduling.

Their forgot password form sends the previously registered password in plain text. :negative:

astral
Apr 26, 2004


Bonus points if the e-mails were sent unencrypted!

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

When you're the only one in the field, you're the defacto leader.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Volmarias posted:

When you're the only one in the field, you're the defacto leader.

Whoa whoa, they’re a leader.

Internet Explorer
Jun 1, 2005





Hurray, sanity prevails!

Password1, Password2, Password3 no more: Microsoft drops password expiration rec
For years, Microsoft's baseline security policy has expired passwords after 60 days.

Thanks Ants
May 21, 2004

#essereFerrari


The cynic in me thinks it's because password expiry works so poorly with Azure AD Connect, though it's still a positive change.

Diva Cupcake
Aug 15, 2005

AES128 is stupidly strong and effectively unbreakable unless we're talking about theoretical quantum computers in the hands nation states.

It should have always been the recommendation for just about every reasonable BitLocker use case.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Diva Cupcake posted:

AES128 is stupidly strong and effectively unbreakable unless we're talking about theoretical quantum computers in the hands nation states.

It should have always been the recommendation for just about every reasonable BitLocker use case.

Its one of those things where we won't know the relative strength until it's pretty much broken. AES256 isn't AES128 with twice the key size, its a different algorithm using the same fundamentals with a key chaining method to increase the key size. Similar to DES and 3DES. The thing we don't know is does this key chaining reduce the effective strength of AES256 and if it does, does this reduce its functional security to less than AES128? Overhead is pretty much identical these days for systems supporting AES-NI, so its a bit of a pick your poison situation, but you have to be supporting some seriously sketchy hardware where you need to opt for AES128 for performance reasons.

wyoak
Feb 14, 2005

a glass case of emotion

Fallen Rib
now to wait a decade for PCI to update their standards

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

Diva Cupcake posted:

AES128 is stupidly strong and effectively unbreakable unless we're talking about theoretical quantum computers in the hands nation states.

I was under the impression that quantum computing was only a problem for asymmetric algorithms. Symmetric stuff like AES would be (mostly) unaffected.

cergos
Apr 23, 2019

The hush of the night sky is the silence of a graveyard.

Powered Descent posted:

I was under the impression that quantum computing was only a problem for asymmetric algorithms. Symmetric stuff like AES would be (mostly) unaffected.

Grover's algorithm?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Nah that just produces an unusable mess

:grovertoot:

Thanks Ants
May 21, 2004

#essereFerrari


Load-bearing ciphers

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

cergos posted:

Grover's algorithm?

Hence the "mostly".

But I went back and checked, and you're right, it has more impact there than I had remembered, but still not fatally.

Grover's reduces the effective keyspace to the square root of what it would be when brute-forcing classically. In other words, cut the exponent in half: a 128-bit key becomes effectively 64-bit security. That's in the range of nation-state capabilities, so I was wrong to think that AES-128 would remain secure if we should end up in a quantum-computing future.

But the way to secure it again is very simple -- just bump up the key size. AES-256 would give you 128 bits of security against a quantum computer, which should still be fine for a long time to come. Making asymmetric algorithms resistant to quantum computers will be... more complex.

https://www.schneier.com/blog/archives/2018/09/quantum_computi_2.html

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I haven't been following it closely but I thought TLS 1.3 was mandating ECDHE with curves that were at least quantum resistant

BangersInMyKnickers fucked around with this message at 14:50 on Apr 26, 2019

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Had to open an.l incident because a user shared his private key rather than his public.

Proteus Jones
Feb 28, 2013



CommieGIR posted:

Had to open an.l incident because a user shared his private key rather than his public.

:cripes:

Internet Explorer
Jun 1, 2005





wyoak posted:

now to wait a decade for PCI to update their standards

If both NIST and Microsoft are not recommending password expiries, that's at least some ammo to push back against auditors. Maybe no PCI, but enough that we should be pushing.

Boris Galerkin
Dec 17, 2011

I don't understand why I can't harass people online. Seriously, somebody please explain why I shouldn't be allowed to stalk others on social media!
Docker Hub hacked. 190k accounts exposed via usernames, hashed passwords, and github/bitbucket auth tokens.

https://news.ycombinator.com/item?id=19763413

FYI docker hub doesn’t support 2fa, makes you register an account just to download things (can be circumvented by googling for direct links but come on), and requires full github account access for those exposed tokens to take advantage of many features.

Absurd Alhazred
Mar 27, 2010

by Athanatos
Anybody have context on why Kevin Mitnick is harassing @notdan?

https://twitter.com/notdan/status/1122130594475991040

Adbot
ADBOT LOVES YOU

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Cos he's an one trick pony / attention seeking charlatan like Krebs

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply