Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
F4rt5
May 20, 2006

Thermopyle posted:

Eagerly awaiting patches from Asus for my 5 year old self-built system.


Hahaha, I will be waiting forever.


Nalin posted:

Nice, my motherboard's last BIOS update was in 2013. Everybody is totally going to be safe from Meltdown.

My H81M-P Plus had an update released Jan 3, marked beta, with the note "update microcode 0x23". Won't install it yet, even though it's just a microcode update it's a beta. From Asus. I don't trust them after a bad experience fifteen years ago lol.

Adbot
ADBOT LOVES YOU

F4rt5
May 20, 2006

CLAM DOWN posted:

What are the odds Oracle releases anti-Spectre microcode updates for SPARC processors lmao gently caress my life

It would be *so* awesome if the greybeard inventors of SPARC came out of hiding after a couple of weeks of hacking and published just this. Like, they just took the time from retirement to do that. But hey are SPARC processors vulnerable anyway?

F4rt5
May 20, 2006

À propos HTTPS and 301 stuff, I've been away from the web scene for a while and imagine my surprise when I discovered that you can just use a thing called certbot to install valid, public certificates for your hosts without the hassle of buying them or adding your own CA for development. it's awesome and why didn't anyone thing of doing that sooner?

F4rt5
May 20, 2006

I just use "pass" for linux, I like the structure and GPG nature of it. But I also carry my private GPG and SSH keys on a USB stick on my keychain if I need to SSH into a server from a random computer so I guess I don't care about security at all?

I guess that if anyone found me dead they wouldn't know what to do with those files and if I had a high-security job I'd do things differently. All I know is that I've virtualized my BankID two-factor with an app on my phone protected with my fingerprint and not the dongle so I'm safe enough.

F4rt5
May 20, 2006

CLAM DOWN posted:

Just curious, do you protect these with a passphrase or something?

Yes.

F4rt5
May 20, 2006

Use Mullvad if you need VPN. They take cash. I also hear OK things about ExpressVPN.

F4rt5
May 20, 2006

I hadn't until now, thanks. I don't use a VPN anyway, I have only tried a couple.

F4rt5
May 20, 2006

Darchangel posted:

You're not supposed to like bugs, you're supposed to eradicate them.
Also, it's called a bug because the first one was a literal bug in a relay.
A common misconception. The incident you are thinking of was the first LITERAL bug found in a computer. The expression was in use before that.

Thomas Edison, 1878 posted:

It has been just so in all of my inventions. The first step is an intuition, and comes with a burst, then difficulties arise—this thing gives out and [it is] then that "Bugs"—as such little faults and difficulties are called—show themselves and months of intense watching, study and labor are requisite before commercial success or failure is certainly reached.
e: I guess because bugs are annoying, like the ants during a picnic trope? Seems logical.

F4rt5 fucked around with this message at 14:15 on Mar 19, 2020

F4rt5
May 20, 2006

Volmarias posted:

If you're not a computer toucher or computer toucher adjacent you're not doing that though.
Some things can't be made to work around people's stupidity or ignorance, but people will not realize that :(

F4rt5
May 20, 2006

DrDork posted:

.

But yeah, those IT teams are gonna be putting in a ton of overtime to re-image
Re-image? Nonononono. All computers, phones, networking gear, etc etc in the building must be regarded as potentially compromised and thus be discarded. You cannot rule out bad actors, and they had physical access, my dude.

F4rt5
May 20, 2006

I long for the day sites and services require 2FA at account creation, but only via Authy or Bitwarden or similar, because lord SMS 2FA is stupid because of how easy it is to socially engineer or directly hack.

At least in my neck of the woods replacing a SIM requires valid ID but it's exploitable by smooth talking in some cases, or corruption in general...

Like how there was a scandal with our equivalent of the DMV where one department had a rascal that gave out drivers licenses to whomever willing to pay for it, forging test results etc.

F4rt5
May 20, 2006

I've used all of them extensively and now it's Bitwarden for life. Like to pay for your pw manager? 5$/yr if you want to - but you don't have to. Afraid of their cloud security? Host your own server. Afraid of the app's security? It's open source, compile it yourself. If you are a masochist. Otherwise rely on others' eyes to confirm it's cool and good and not stealing / pwning your gibson. User friendly like 1password? Yup. Available on all platforms? Yup.

Hand's down the best.

F4rt5 fucked around with this message at 19:25 on Feb 17, 2021

F4rt5
May 20, 2006

Some intern /must/ have fudged something, I can't imagine Facebook not being their own registrar

Imagine Facebook forgetting to pay their domain fee to themselves

F4rt5
May 20, 2006

First the Epik Fail, now Twitch; if these 120+ GB leaks keep coming, I need more hard drive space.

F4rt5
May 20, 2006

Isn't it LastPass that has been owned on multiple occasions?

F4rt5
May 20, 2006

Arivia posted:

Yeah, I'm not a fan of rolling my own because I don't trust myself to keep the infrastructure secure (hence paying 1Password all this time), but maybe it's time.
BitWarden has cloud vault, and it's either free or a :10bux: one-time fee?

F4rt5
May 20, 2006

more falafel please posted:

Can I still buy a jaz drive, I was always jealous of those. A whole gigabyte of storage, in your pocket.

On an actual loving hard drive platter in a caddy, it was amazing and made me think of the old fridge-sized HDs with cartridges on top

F4rt5
May 20, 2006

One of our biggest security firms has a system that is set up so that to update the code, you log on through labyrinthian multi-hop terminal server connections to India and code directly, with a second delay for keypresses etc.

Because it had to be SO secure.

The database of all their alarm installations and all other crap that this system uses? It runs MySQL 5.1 on 32-bit Windows Server, and is exposed to the internet (MySQL login: root) via PHPMyAdmin 3.2, powered by Apache 2.2.11

And the password is… hideous

Looks like it was all updated in 2011 at the latest. I just… can’t even.

Yes they’ve been told about SSH pubkey access etc but no they won’t do anything.

F4rt5
May 20, 2006

BlankSystemDaemon posted:

If you've got postfix and dovecot, shouldn't you also be running rspamd for its blacklists, solr for full-text search, and sieve for filtering and statistical training of rspamd based on what's moved to the junk folder?

That’s why I run Mailcow Dockerized

F4rt5
May 20, 2006

RFC2324 posted:

Yeah, goon consensus has been abandon LastPass for years at this point.

And somehow every time there is a hack someone asks if its recommended

So many IT and infosec «professionals» on Twitter just now discovering what we’ve known for years I smh and wonder about switching carreers

F4rt5
May 20, 2006

Haptical Sales Slut posted:

This is sort of what I've been assuming....I just use it to look at naughty material and when aimlessly browsing on PC and don't wanna leave a ton of easily identifiable cookies for advertisers, but idk if a VPN would even help in that situation lol.

This is what I was considering going to. I know a guy that like mailed money to someone in an envelope to a different country and got a login via the snail mail like 3 weeks later. I assume outfits like that might be less likely to share data with law enforcement or governemnts, but who the F knows?

Mullvad is Swedish and takes cash by mail for more complete anonymity.

Adbot
ADBOT LOVES YOU

F4rt5
May 20, 2006

flakeloaf posted:

The song they used to teach us how to count had a drum score that was impossible to count

https://www.youtube.com/watch?v=TMtGImlEmu0

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply