Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Actually, on the same topic, I'm thinking of migrating from last pass to 1password, but using their cloud sync stuff + browser integration, since that's my big use case. Has anyone done an analysis of what they do, and how it compares to last pass?

Adbot
ADBOT LOVES YOU

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Right, and that's why I'm asking about it. I don't have an interest in doing the syncing myself, I want them to do it and have everything magically work without effort or thought, even though I'm a team of one.

Given that this is pretty close to LastPass, I thought I'd ask if anyone has reviewed this yet.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

flosofl posted:

I haven't used the "Family/Teams" version, so I can't talk to using their own cloud service for synching.

Unfortunately, this is basically what I want to know about. They're offering a service that's remarkably similar to LastPass, including a web based management of your password store. I just want to know if anyone has anything to say about it, since the thread (read: OSIBeanDip) is pretty set against Lastpass's implementation.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Sorry that I'm late to the party with this one, but

Internet Explorer posted:

Sorry, I only store my hashed password database on an encrypted flash drive stuffed in my rectum that requires a specific sequence of hot peppers at random Scoville values to dislodge.

Fart Knocking

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
It helped me tremendously to learn that everything is garbage everywhere, it's just generally a matter of degrees. No matter where you go. Just because things are moving slowly doesn't mean that the problem is you.

manchego posted:

I don't want to be in a PM position and not know what the gently caress I'm talking about.

PMs are supposed to lean on their SMEs to tell them what the gently caress is going on, don't think for a moment that this should hold you back if being a PM is your jam.

Volmarias fucked around with this message at 02:53 on Feb 17, 2017

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Cup Runneth Over posted:

"Change every password you have, starting with the most important ones, until you get bored"

0 passwords later

"OK I guess I'm good to go! :downs:"

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Martytoof posted:

How do you guys deal with "black box" products going into your environments that are really just Linux based appliances? Enforcing hardening standards seems unfeasible since you typically have no visibility into the inner workings of the solution but just trusting a vendor to harden the device seems like a foolish thing to do. I'm fairly sure if I go to a vendor and say "we need this hardened to CIS level 2" they'll just reply "nope" so all of a sudden I have to create exceptions for my own policies and hope to put enough compensating controls around the black box. I'm getting a headache trying to figure out what kinds of questions to even ask short of just asking vendors to describe the security of their appliance to me which will likely result in a boilerplate PDF with buzzwords.

This isn't even considering antimalware agents or HIDS.

Just assume that it's a ticking time bomb that will never ever receive security updates.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Nice

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
On the plus side, we've started to see some sites/apps have a checkbox for "show my password"

Mostly, it's because doing that checkbox requires additional development time, while just doing <input type="password"> gives them the bullets for characters for free and they can get on with writing new features.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
There's interesting stuff, but nothing damaging or revealing as the NSA leaks, from what I understand.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Email addresses aren't generally considered secret, so I'm not sure what you're protecting against, save for password reuse on other sites.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Context for those of us not Australian? Or is it just the funny goatse?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Based on what I've seen before, I'd safely bet that the image attachment is solely to get around spam text scanning in low end anti spam endpoints. It's been around so long that I can't imagine it still working though.

Just ignore them.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Seriously, the answer here is to figure out the underlying issue and figure out if it's fixable.

I guess it's also a question of how sensitive this info is vs how hard it is to actually fix the problem vs how important the one user here is.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

PBS posted:

Trashed 1password, it butchered the import completely. Tested out the form fill and it doesn't even work on some popular sites I tried. (With new, non-butchered items)

New subscription based model they're using is 3$ a month, 3x the cost of lastpass premium which isn't even necessary anymore.

Yeah, security is important so lastpass needs to go, but I don't see 1password as a viable replacement for it.

Pretty much this. It was garbage usability-wise last year when I tried it out. I'd be ecstatic if there was a competent password manager that wasn't itself insecure which was also as reasonable to use as lastpass is.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Furism posted:

It's something "I have" and is an extra layer of security from something "I know." My password doesn't have such a huge entropy (120 bits or so) because I need to type it regularly so it needs to be somewhat memorable. If I'm losing a device with the keepass database on it, and somehow it's found unlocked (I could get mugged, the laptop could be stolen while I'm working on it, who knows ; I do travel a lot for work so the chances of this happening are higher than the average), I don't want anyone to be able to brute force it. I feel that 2FA helps with this.

If someone mugged you and stole your laptop, why wouldn't they take whatever hardware your 2nd factor is too? Will you be carrying it clenched tight between your paranoid cheeks?

Who exactly is your adversary that's going to brute force your db password instead of immediately wiping and or flipping the laptop? In particular, who is doing so faster than you getting a backup copy and changing all of your passwords?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Doug posted:

This is a pretty good resource too if you want to learn crypto by breaking it: https://cryptopals.com/

Seconded, this was fun.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

You can roll your robots, just don't loving expose them to the internet.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Thermopyle posted:

I always wish I could talk to the people who implemented these stupid things and find out what the hell they were thinking.

"We need to get this thing out yesterday and they're not paying us to do anything after it's feature complete" mostly

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Some amazing luck right there

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Cup Runneth Over posted:

Yeah, but it's a good incentive.

The computer still running XP for the X-Ray machine software is not getting updated to Windows 10 because now it's $0 instead of $100. It is not getting upgraded for any reason, unless the reason is "the manufacturer is giving us a free version of their newest software and sending a tech out gratis to handle the migration and also they're buying a new computer and also they're compensating us heavily for the cost of our machine being out of commission while they do it"

Except the manufacturer went bust 10 years ago so that's never even a theoretical

Volmarias fucked around with this message at 12:57 on May 13, 2017

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Could have stopped at "Tata"

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Furism posted:

yeah I think Druva's side isn't super fast) and now IT tells me to store the files somewhere like C:\firmwares. I'm fairly sure that's against some recommended best practice from Microsoft and that the only place we should put files on a Windows systems is under C:\Users\<myUser>\.

Is this just me imagining things or is it ok to store (non-confidential) files outside of my user's home?

If you are asking from the "will this break anything" side, it's totally fine to place your files under some random root directory. If you're used to Linux et all, Windows basically mounts the hard disk whole, excepting some boot data that is totally transparent to the end user. While programs SHOULD look in the user's home directory, there's no need for them to do so. If this is a laptop that only you will use, there aren't permissions concerns to worry about here.

From a "is this a nice thing to do" perspective it's a little gross but still very much the norm in many places.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
It definitely would be nice if the source code was provided under a non commercial license of some kind solely for archivists.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Boris Galerkin posted:

What do I need to do to take care of my poo poo in light of this new breach?

Freeze your credit if you haven't already, and pray that TransUnion and Experian handle their pins better.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

:piss:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Thanks Ants posted:

Always.

Never forget the Adobe position on non-local storage in TYOOL 2017:

While I want to give them poo poo, i know that this position is probably born of people using some sort of goofy and slow network storage over a lovely remote connection causing the file to be half written when the user closes the lid on their laptop, causing a VERY MYSTERIOUS case of data loss that must be Adobe's fault.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Subjunctive posted:

2 Fuckup Authentication

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Subjunctive posted:

2 Fuckup Authentication

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
... That was not intentional, but drat if it didn't make it funnier.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

fyallm posted:

Hahaha Deloitte ... What.. The... gently caress..

https://twitter.com/GossiTheDog/status/912712517541089282

:discourse:

Looking forward to the total lack of effective repercussions

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Absurd Alhazred posted:

If Deloitte isn't penny-stock by next week, I'm going to be very disappointed in the Invisible Hand of the Market.

Better prepare your pity party, the market has shown that it doesn't care about massive security breaches.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Furism posted:

To log into my bank I need to use my customer number and a 6 digits PIN. So, okay, they log you out after 5 attempts, but to reset the PIN they send you a snail mail. If anybody determined knows where I live it'd be trivial to steal it.

I get it, they need to keep it simple for old folks but they should also offer better means (FIDO, 2FA, ...) as options.

Mailing you the new PIN sounds perfectly reasonable, since the alternative is "what's your mother's maiden name" or "what color was your first car". You're right that it's vulnerable to Steve Down The Street taking the letter, but that's orders of magnitude less likely than the typical attack scenario of Uri From The Ukraine.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Furism posted:

Analog APT.

Advanced Postal Threat

Guy Axlerod posted:

Sign up for informed delivery: https://informeddelivery.usps.com/box/pages/intro/start.action

They send you pictures of the envelopes that are supposed to be delivered that day. I've had a few that never show up. Nothing important yet, and it's probably the fuckwit delivery person putting the envelopes in the wrong box. There's a nice link in there to report stuff that you didn't get that is supposed to go to the postal inspectors.

Sweet, full color scans of the local circulars that get shoved into my mailbox. Let me know when I can pay money to have the garbage not delivered TO my home.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Guy Axlerod posted:

Yeah, just the FINAL NOTICE letters from "Car Warranty" companies. The W2, replacement bank cards, and DMV stuff is good though.

This. Everything important is on autopilot and the bills come by email. I'd be delighted if there was a way to be notified if an actually important piece of mail came, but there typically never is, outside of W2s and replacement CCs. I can basically just bring in the trash mail, sort the circulars directly into the bin, and anything that needs shredding comes inside.

I'd really, genuinely be far more excited and willing to pay money for a system that allowed the junk mail to never reach me in the first place.

Volmarias fucked around with this message at 21:23 on Oct 1, 2017

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
And then marketing and product make angry screeches about how many steps it takes to sign up and why are you making this so difficult??? So you just give in and resign yourself to a "verified" flow happening after account creation.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
It's still pretty awful. Even if you have "identity theft target DO NOT CHANGE ACCOUNT OVER PHONE" and you tell them to require you to say a password, they'll still assign your number to another sim if someone sweet talks them enough. This happened to a co-worker a year ago or so, and the most he got out of them was "oh, oops.". It's perfectly understandable on their end because there's no actual ramifications for them if you can't realistically change networks because only one has adequate coverage of your area.

That said, it's better than nothing, especially for users that don't use password managers, but only barely.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Furism posted:

Why do you guys say "push 1TB" when you mean "pull"?

Sometimes when we want to move the big crate of data it doesn't have straps or handles, so we sort of have to shove it and push it to get it over there instead of being able to pull it.

That's just how bandwidth works :shrug:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
The fact that they're using IDA at all puts them light years ahead of the rest of the industry as far as representing computer things goes, where this is common:

https://www.youtube.com/watch?v=u8qgehH3kEQ

Adbot
ADBOT LOVES YOU

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
I'm curious: who's requesting the service from you? The person whose credit is being pulled, or an agent acting on their behalf (finance person at a store, etc)? Is this some sort of credit escrow service where you can "prove" to an interested party that you'll be a good risk without having to give them more intimate details?

I'm basically curious how the password even helps here, since you'd be using the service so infrequently that you're almost guaranteeing any repeat visits involve a password recovery flow and what are you using for THAT?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply