Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
astr0man
Feb 21, 2007

hollyeo deuroga
You could say that about any CA though. At least letsencrypt is open and uses really short lifetimes for their certificates.

Adbot
ADBOT LOVES YOU

astr0man
Feb 21, 2007

hollyeo deuroga

SeismicTriangle posted:

anyone here come from military background? im currently about to enlist for this. People are saying it will be pretty easy to transition to a civilian career afterwards, just wondering if thats true from your perspectives and anything else you'd like to share. I dont really know anything about infosec/networks atm and school is only 6mo long so i have my doubts about those claims

am i goina be the bad guy

I wasn't military but I used to work with CTNs and the other branch equivalents on the DoD civilian side. You'll gain a lot of exposure to things like pentesting that will make you employable in infosec as a civilian, but like hobbesmaster said the biggest thing is that you will end up with a TS/SCI clearance. This means that the civilian companies that will want to employ you the most will be defense contractors. Infosec is really broad so you will have other options, but having the clearance is basically a golden ticket to a large paycheck if you stick with government contractors. And no you won't be stuck just doing help desk/IT stuff in the civilian world.


Whether or not you will be the bad guy really depends on how you feel about the US military industrial complex. The NSA would be a potential duty station for a CTN, so again it depends on your personal opinions.

astr0man
Feb 21, 2007

hollyeo deuroga

myron cope posted:

I just did the algo deploy to DigitalOcean (actually I'd done it before, destroyed that droplet for Streisand today, then went back to algo). Am i really supposed to just create a new server instead of updating it? The FAQ seems to suggest that.

It's fairly easy to do, but it's a pain setting up the VPN connections everywhere. Can I just apt-get update && apt-get upgrade every once in a while?

If you set it up with the security enhancements role it will use the unattended-upgrades package so you get the automatic ubuntu security patches and so on (essentially what you get from doing apt-get upgrade without needing to ssh in and do it yourself). But as far as upgrading algo itself, yes you are supposed to just squash your server and re-deploy the newer version of algo.

astr0man
Feb 21, 2007

hollyeo deuroga
So the NSA is finally declassifying their internal reverse engineering tool: https://www.rsaconference.com/events/us19/agenda/sessions/16608-come-get-your-free-nsa-reverse-engineering-tool

It's great that there might finally be a real viable alternative to IDA Pro. It's been ~6 or 7 years since I last used ghidra, but even a gimped/redacted public build should still be better than pretty much anything currently available right now other than IDA (although I've never tried binary ninja), and IDA's pricing is what it is. I'm real interested in seeing what ghidra modules they'll actually be releasing.

astr0man
Feb 21, 2007

hollyeo deuroga
Free IDA is at least decent now, and being usable at all is a huge upgrade from the prior free version. But being x64 only, no debugger, and no scripting/plugin support are all still pretty big drawbacks.

astr0man
Feb 21, 2007

hollyeo deuroga
Ghidra is out now: https://ghidra-sre.org/

https://twitter.com/RGB_Lights/status/1103019876203978752

Adbot
ADBOT LOVES YOU

astr0man
Feb 21, 2007

hollyeo deuroga

Absurd Alhazred posted:

Has anyone here tried out NSA's Ghidra?

It's good. IMO, the lack of a debugger is the only thing holding it back from being a complete IDA replacement right now (and supposedly there is a debugger coming at some point down the road). I'm sure there are cases where hexrays does a better job decompiling something better than Ghidra (and vice-versa) but I haven't run into anything that Ghidra has handled significantly worse than IDA.

also for whatever reason, Ghidra performs better than IDA on my machine but ymmv.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply