Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Absurd Alhazred
Mar 27, 2010

by Athanatos

Diva Cupcake posted:

lol. lmao. I think most orgs are using SaaS but still.
https://twitter.com/HackingLZ/status/1532480905335345152

And here I thought the problem is that it's an inferior Wiki with annoying JIRA integration.

Adbot
ADBOT LOVES YOU

Absurd Alhazred
Mar 27, 2010

by Athanatos
Enterprise is just poo poo software with more expensive and draconian licenses.

Absurd Alhazred
Mar 27, 2010

by Athanatos
https://twitter.com/ImbecillicusRex/status/1558903108574625792

#wholesome

Absurd Alhazred
Mar 27, 2010

by Athanatos
So, this is a basic GDPR violation, right? With astronomical fines since they've been keeping this under wraps for years?

Absurd Alhazred
Mar 27, 2010

by Athanatos
https://twitter.com/chrisrohlf/status/1562152113190354946

:jerkbag:

Absurd Alhazred
Mar 27, 2010

by Athanatos
So, ignoring everything else wrong with this smart lock, isn't the fact that "[t]here are a total of seven ways to control the door lock: your key, the smartphone / Apple Watch app, NFC tags using your phone, a key code using a keypad, a fingerprint reader, an NFC keycard, and smart home / voice control" absolutely dreadful? That's 7 different attack surfaces if we assume nothing else is wrong with it.

Absurd Alhazred
Mar 27, 2010

by Athanatos
https://twitter.com/wbm312/status/1567981004555698176


Why would a payment platform need a security team, anyway?

Absurd Alhazred
Mar 27, 2010

by Athanatos

Diva Cupcake posted:

Outsourced it is.



When I think of aspects of an organization that should be outsourced to the lowest bidder, security is definitely number one.

Absurd Alhazred
Mar 27, 2010

by Athanatos
Yeah, that's how entry level looks in tech. I'd have a different list of technologies for my industry, but still a lot.

Looks good on your resume a few years in when you're looking for senior roles, though!

Absurd Alhazred
Mar 27, 2010

by Athanatos
Just don't be afraid to ask a bunch of stupid questions and be forthcoming about mistakes and I think you should be fine. You always start up feeling stupid. And then you just end up finding more complicated things to feel stupid about, so you forget how many things you're just gliding through now.

Absurd Alhazred
Mar 27, 2010

by Athanatos
What am I missing here? How does "a severe security vulnerability in the desktop app for Microsoft Teams that gives threat actors access to authentication tokens and accounts with multi-factor authentication (MFA) turned on" not "meet the criteria for patching"?

Absurd Alhazred
Mar 27, 2010

by Athanatos
CS teaches you a lot of theoretically-useful cruft that you need to dig out of to actually do your job, but is good to have as your background.

Asymptotic reasoning about algorithm complexity is great - but you are often NOT at large enough n.

Absurd Alhazred
Mar 27, 2010

by Athanatos

more falafel please posted:

See every 23 year old gamedev thinking that everything should be a red-black tree instead of the humble and cache-coherent flat-rear end array

Yup! Simplicity and readability trumps cleverness most of the time. You can always add clever later.

Absurd Alhazred
Mar 27, 2010

by Athanatos
Someone with all those qualifications, who doesn't have anything better to do than go anywhere near that very public trash fire, and will be coming on board to actually improve their security instead of just owning them again and bailing.

Absurd Alhazred
Mar 27, 2010

by Athanatos

My "I am definitely not asking you to do something illegal" T-shirt is raising many questions already answered by the shirt

Absurd Alhazred
Mar 27, 2010

by Athanatos

AlternateAccount posted:

Duo now supports the thing where the site presents a code you have to enter into the app. Gonna be standard fare all around, I expect.

Is that better or worse than push verifications?

Absurd Alhazred
Mar 27, 2010

by Athanatos

astral posted:

Weekend Web reimagined as Mastodon Monday

YES

Absurd Alhazred
Mar 27, 2010

by Athanatos

Takes No Damage posted:

When the internet first started going everyone was so innocent and naive they didn't see anything wrong with using all real info. Everyone's email was just firstname.lastname@whatever, phone numbers were all over the place. Like if you ever go read a comic book from the 90s in the letters section they were still publishing full names and addresses of the people who wrote in, including children:
"Hi I'm Sally Jay I'm 12 years old and I love your comic!"
--full name and address with apartment number :stare:

Then everyone figured out that was a bad idea and stopped doing it. But now the Social Media Generation has grown up with a huge chunk of their identities being online their whole lives and we're back to having to teach people not to plaster their name and birthday all over Facebook :doh:

You also used to get doxed on a yearly basis by a physical book everyone got for free (financed through ads).

Absurd Alhazred
Mar 27, 2010

by Athanatos
Discord is newer and is where all the kids are at and is therefore better than boring old forums.

Absurd Alhazred
Mar 27, 2010

by Athanatos
I'm surprised there hasn't been an exploit based on Riot's kernel-level DRM. Or maybe I just haven't heard of one.

Absurd Alhazred
Mar 27, 2010

by Athanatos
Ring ring ring goes the ransom/
Ding ding ding you've been hacked/
Bling bling bling went your money/
From the moment your system was cracked

Absurd Alhazred
Mar 27, 2010

by Athanatos

Thankfully mine is a Snapdragon. This seems to be the list of Exynos phones, that's the affected platform.

Absurd Alhazred
Mar 27, 2010

by Athanatos

acetcx posted:

As I understand it the chip contains some secret data (think like private keys for encryption) which is supposed to be impossible to copy or extract. When you insert or tap your card the secret is used internally on the chip to digitally sign the transaction so the bank knows it's real. The secret never leaves the chip, only the signature.

A magstripe just stores a small amount of unencrypted data - like the card number, expiry date, and cardholder name. It's all the stuff written on the card (minus the CVV code) but in a format a computer can easily read. It's just so that you don't have to enter that stuff into the machine by hand.

A long time ago I worked in retail and we had to staff an outside stand that didn't have an electronic credit card reader, so we used the old-old fashioned system: a press that copies the raised text from the card onto carbon paper.

A few customers had cards where the text wasn't raised, and this was only found out when they had left because it was busy and we weren't paying attention. There our only choice to do it right was to copy the details down manually.

Absurd Alhazred
Mar 27, 2010

by Athanatos
You folks really are never going to be unemployed.

https://twitter.com/mholt6/status/1657133439546695680

Absurd Alhazred
Mar 27, 2010

by Athanatos
That sudo that you do so well

Absurd Alhazred
Mar 27, 2010

by Athanatos
What is MOVEit even for? Saving an sftp line in some admin script?

Absurd Alhazred
Mar 27, 2010

by Athanatos
So like SharePoint, or Dropbox links?

Absurd Alhazred
Mar 27, 2010

by Athanatos
Woops, sorry, tripped over a network cable. Should be back soon.

Absurd Alhazred
Mar 27, 2010

by Athanatos
Kevin Mitnick died of pancreatic cancer.

Adbot
ADBOT LOVES YOU

Absurd Alhazred
Mar 27, 2010

by Athanatos
At least they're willing to let you work for 7 days total!

Also is it legal to require someone to be a US Citizen to work in a job like this?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply