Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Would just like to throw out that the red text for him is fantastic.

Adbot
ADBOT LOVES YOU

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

These are excellent rules.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

OSI bean dip posted:

Please come out to this sometime:
http://vansec.org

Need one of these in Edmonton, yarr.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

This is excellent.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Thanks Ants posted:

Ah, the "have cake and eat it" approach to discussions

The ever classic.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Ah Kazaa and Limewire. Willfully infecting your computer with the worst aids in order to listen to some mp3's.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Absurd Alhazred posted:

From the A/T cons and scams thread:


People are the weakest link in your security framework.

There is no facepalm big enough :allbuttons:

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Was it so people didn't have to brave the snow?

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Kazinsal posted:

The Free Software Foundation's developers being anti-women turbospergs who are actually really bad at what they do is entirely unsurprising

Pretty much.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Looks like some cute fireworks blowing up around the BetterDiscord community. Haven't read into anything that's going on, my twitter feed is just getting a few people throwing red flags around.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Not super deep digging, but there may just be no issue. BetterDiscord seems fine; people appear to be the problem (shocker). They're throwing a hissy fit about a 3rd party plugin that was stealing auth tokens and BetterDiscord is taking all the blame. I am the dumb for not spending a minute of my time to read into that before posting "oh hey this could be fun".

This was the image that started the whole bush fire:

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Doug posted:

Good post. You should really work it up into a blog post, I think there are probably a lot of people that would get value out of it.

Agree with that. Also excellent story.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Hahahhahahahahahahahaha

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Wiggly Wayne DDS posted:

that they've gone to the media to coerce payment and didn't make an example of, say, a thousand random devices being wiped says it all

Pretty much this.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
So this came across my feed:

https://twitter.com/Snowden/status/850766326943690752

Haven't had a chance to look through it yet.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

What in the actual gently caress is this...

Unreal lol

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

hobbesmaster posted:

yeah I can't believe flipboard is still going either

:perfect:

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Mopp posted:

OK, I managed to crack the first part and got two flags. It looks like the traffic gets encrypted after this exchange.

code:
S[80]: "4plugin:{
	'seed_key_arg1':1095923727,'
	arch':'x86',
	seed_key:'U\x89\xe5\x83\xec\x bla bla bla',
	'crypt':'U\x89\xe5\x81\x00\x89\x02\x83\xc2\x04\xb8\x00g bla bla bla'}"
C[81]: "plugin{'seed_key_arg2':3459613537, 'seed_key_arg3':2312051101}"
S[82]: 'got it'

drat this actually looks fun.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Moatman posted:

For some reason I only post in this thread when it's about Marcus Hutchins (@MalwareTechBlog) but it sure looks like he just got blackbagged by the FBI
https://twitter.com/josephfcox/status/893145496788795392

.....

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I'm glad they've managed to at least figure out where he is. Doesn't make this any less insane though.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Lockpick village would be hard to replicate online. That place is so fun.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
EveryMicrosoftExamEver.jpg

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Wicaeed posted:

Is it common practice for a third party we use to host an external support website (these guys are pretty large too) to ask for the following?


Doesn't sending the private keys to someone that didn't generate them defeat one of the basic points of a loving private key? :confused:

What are you trying to do here? Renew a cert? I would say you are extremely correct to be suspect of this request. I can't imagine a world in which they would need your private key for any reason other than to pretend to be your company.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

BangersInMyKnickers posted:

Phasing out 3DES is going to be a huge PITA since its the last symm cipher XP/2003 and older systems have left and the world is going to scream murder over it.

It will be painful, but it will also be glorious.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
So literally any info, even fake garbage, was likely at risk? Dang I guess we should all sign up for the credit monitoring.

Borrowed this from another thread:

quote:

You give up your right to sue Equifax. If you get the credit monitoring service, you must agree to submit any complaints against Equifax to arbitration. You can’t sue on your own behalf, and you can’t join a class-action case or benefit from any class-action settlement that Equifax agrees to.

Well alright then.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Subjunctive posted:

NY AG says that clause is illegal and unenforceable, has told Equifax to remove it.

I admit to being an ignorant Canadian, but I thought I heard arbitration clauses were legal. Super glad to hear that I was wrong.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
That's impressive. I don't even know how to feel about that.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

lol

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Unreal. I love this.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Potato Salad posted:

I think at least some small part of it is how short our memories are, and how powerfully conditioned we seem to be to give every possible benefit of the doubt to the invisible hand of money -- capitalism as something that cultivates self-policing, ethical behavior. My much more personal opinion is that we frequently conflate capitalism, patriotism, and Christianity -- so many Americans fuse those three separate things into a single lens through which they interpret the world. I'm only really comfortable living where I do because my husband is a canadian citizen with a current passport with our marriage certificate stapled inside

:canada:

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

:perfect:

Actual content: There's a TOR tunnel to Ireland going through a firewall at one of my clients. Happy Wednesday.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

CLAM DOWN posted:

Bank websites (lol)

This is less funny because it's true.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

CLAM DOWN posted:

https://googleprojectzero.blogspot.ca/2017/10/over-air-vol-2-pt-3-exploiting-wi-fi.html

Another part is up, this is a super technical but absolutely fascinating read.


This owns.



:allears:

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

anthonypants posted:

Does android still do that thing where if you install a root certificate, like you might for a VPN, it leaves a notification forever that your phone's network activity is being monitored? There were at least two threads about it on the Google issue tracker, but that was a while ago and they've been disappeared.

I also haven't had this stuck on my Andriod for a while now.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
e: wrong as gently caress thread

Content >> I have no idea how much bandwidth I push over my VPN monthly, but my home connection (Twitch, Youtube, imgur, stuff) can push 1TB with those services alone.

ChubbyThePhat fucked around with this message at 00:16 on Oct 19, 2017

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Volmarias posted:

Sometimes when we want to move the big crate of data it doesn't have straps or handles, so we sort of have to shove it and push it to get it over there instead of being able to pull it.

Kicking and screaming where necessary.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Volmarias posted:

I'm curious: who's requesting the service from you? The person whose credit is being pulled, or an agent acting on their behalf (finance person at a store, etc)? Is this some sort of credit escrow service where you can "prove" to an interested party that you'll be a good risk without having to give them more intimate details?

I'm basically curious how the password even helps here, since you'd be using the service so infrequently that you're almost guaranteeing any repeat visits involve a password recovery flow and what are you using for THAT?

Good post/av combo.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
"This seems like a bad idea. I could just call up and be like 'hey my SSN is <insert SSN of marketing guy>' and get a credit check pulled as some random dude I don't know."

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

D. Ebdrup posted:

That sounds like the kind of Fun you get in Dwarf Fortress.

Everything always ends in fire.

...So we're not far off really.

Adbot
ADBOT LOVES YOU

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
That's pretty much accurate. It can be a pain to stand up a CA inside an already existing environment because lots of authentication will break until you sort out the individual certs.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply