Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

snype

Adbot
ADBOT LOVES YOU

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

that is a pro snipe

jre
Sep 2, 2011

To the cloud ?



http://www.bbc.co.uk/news/technology-38415067

quote:

Security firms have launched routers at CES that can stop smart household gadgets being hijacked by hackers.
Symantec, BitDefender and Intel unveiled devices that scrutinise data as it flows across home networks.
The companies say routers with built-in defences will be essential as homes are filled with net-connected gadgets.
The routers also come with parental control features that help manage how much time children spend online and what they see.
Home invasion
"You will have to buy a security solution for your internet-of-things," said Alex Balan, chief security researcher at BitDefender.

quote:

"You will have to buy a security solution for your internet-of-things," said Alex Balan, chief security researcher at BitDefender.

quote:

"You will have to buy a security solution for your internet-of-things,"

quote:

"You will have to buy a security solution for your internet-of-things,"

quote:

"You will have to buy a security solution for your internet-of-things,"

Thanks Ants
May 21, 2004

#essereFerrari


an internet connected consumer electronics device to protect your internet connected consumer electronics

Rectus
Apr 27, 2008

https://us.norton.com/core posted:

For purchases made at Norton.com, after you receive your first year complimentary subscription to Norton Core Security Plus, you will automatically be renewed each year for an annual term where you’ll be billed 9.99 USD (plus applicable taxes) per month. The price is subject to change and we’ll notify you in advance.

...

The subscription is an integral part of the security of the router.

looking forward to 2018, the year of iot security appliance botnets

spankmeister
Jun 15, 2008






I preferred the previous thread title tbh

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

spankmeister posted:

I preferred the previous thread title tbh

jre
Sep 2, 2011

To the cloud ?



https://www.theguardian.com/world/2017/jan/06/russian-hacker-putin-election-alisa-shevchenko

quote:

Young Russian denies she aided election hackers: ‘I never work with douchebags’
White House claims Alisa Shevchenko was involved in hacking the US election but in an interview she says authorities misinterpreted facts or were fooled

She said she dropped out of three different universities, as she was passionate about learning but did not enjoy the structure of a university course. Around 2004, she joined Kaspersky Lab, a high-profile Russian cybersecurity firm.

She left to set up her own company, initially called Esage Lab (“I was thinking of something ‘sage’, as in a wizard or a magician,” she said). Later, she changed its name to ZOR.

im_zor.gif

Trabisnikof
Dec 24, 2005


quote:

Shevchenko specialises in finding so-called “zero-days”, previously undisclosed software bugs that could leave companies vulnerable. “We have not only searched for bugs but exploited them, but only with the customer’s sanction,” she said. She said she never hired anyone she knew to have a criminal background for her companies.

Lol yes you only exploited 0-days when your clients said it was ok, but youre pretty sure none were bad guys

Shame Boy
Mar 2, 2010

Trabisnikof posted:

Lol yes you only exploited 0-days when your clients said it was ok, but youre pretty sure none were bad guys

i like "she never hired anyone she knew to have a criminal background"

we don't run background checks or anything, i just don't hire any people i personally know to be criminals

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

are background checks reliable in Russia anyway?

negromancer
Aug 20, 2014

by FactsAreUseless

Subjunctive posted:

are background checks reliable in Russia anyway?

In Mother Russia, you run in the background towards a check

Celexi
Nov 25, 2006

Slava Ukraini!

negromancer posted:

In Mother Russia, you run in the background towards a check

Segmentation Fault
Jun 7, 2012

Farcry 5 looking good

crazysim
May 23, 2004
I AM SOOOOO GAY

Segmentation Fault posted:

Farcry 5 looking good

it would be crazy if they did do something to tie watch dogs to far cry with some knock off mcaffe

spankmeister
Jun 15, 2008






A drug crazed cybersecurity executive with a personal army of cyber hackers.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

negromancer posted:

In Mother Russia, you run in the background towards a check

:pwn: lol

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

negromancer posted:

In Mother Russia, you run in the background towards a Czech

negromancer
Aug 20, 2014

by FactsAreUseless

reminder that when I met him he told me that I reminded him a lot of himself and wasn't sure how to take that.

Daman
Oct 28, 2011

Trabisnikof posted:

Lol yes you only exploited 0-days when your clients said it was ok, but youre pretty sure none were bad guys

I mean she's Russian so "found bugs and exploited them" probably means found bugs and wrote exploits that clients could use

so she is making more of an effort to filter out bad guys than zerodium

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

negromancer posted:

reminder that when I met him he told me that I reminded him a lot of himself and wasn't sure how to take that.

Did he smell like smokes too because that is what I remember of him

I got to meet him at DEFCON in 2015

Tayter Swift
Nov 18, 2002

Pillbug

Security
Hardware for the
Internet of
Things

There Will Be Penalty
May 18, 2002

Makes a great pet!

Tayter Swift posted:

Security
Hardware for the
Internet of
Things

:eyepop:

El Mero Mero
Oct 13, 2001

negromancer posted:

In Mother Russia, you run in the background towards a check

El Mero Mero fucked around with this message at 05:37 on Jan 8, 2017

negromancer
Aug 20, 2014

by FactsAreUseless

Tayter Swift posted:

Security
Hardware for the
Internet of
Things

:perfect:

KOTEX GOD OF BLOOD
Jul 7, 2012

Tayter Swift posted:

Security
Hardware for the
Internet of
Things
:wow:

AggressivelyStupid
Jan 9, 2012

Tayter Swift posted:

Security
Hardware for the
Internet of
Things

Haquer
Nov 15, 2009

That windswept look...

Tayter Swift posted:

Security
Hardware for the
Internet of
Things

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Tayter Swift posted:

Security
Hardware for the
Internet of
Things

mods

Sereri
Sep 30, 2008

awwwrigami

Carbon dioxide posted:

http://www.bbc.com/news/technology-38521973

Folks scanned for non-password protected mongoDB databases exposed to the open internet and if there was any useful data in them, encrypted them with ransomware. Nice.

I get the desire for :10bux: but instead they should've told them to announce to their users how lovely their security is in exchange for the decryption keys.

Midjack
Dec 24, 2007



Carbon dioxide posted:

http://www.bbc.com/news/technology-38521973

Folks scanned for non-password protected mongoDB databases exposed to the open internet and if there was any useful data in them, encrypted them with ransomware. Nice.

the best one i've seen so far is a bootleg website for playing the cyberpunk card game Netrunner got their poo poo wrecked :ironicat:

karoshi
Nov 4, 2008

"Can somebody mspaint eyes on the steaming packages? TIA" yeah well fuck you too buddy, this is the best you're gonna get. Is this even "work-safe"? Let's find out!

Tayter Swift posted:

Security
Hardware for the
Internet
Of
Things

Segmentation Fault
Jun 7, 2012

Tayter Swift posted:

Security
Hardware for the
Internet of
Things

my eyes glazed over this the first few emptyquotes

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

Tayter Swift posted:

Security
Hardware for the
Internet of
Things

:drat:

slam flanders
Jan 13, 2015


hey baby

Progressive JPEG
Feb 19, 2003

Sharktopus posted:

if you're scrolled above a full address form and half of it is off screen do you think autofill should fill the whole form or just the fields you can see???

I think there's no realistic way the autofiller could ensure that all fields are visible+obvious to the user, so may as well just have the autofill bring up a prompt saying 'about to fill these fields: <bulleted list>, look good?'

Then at least a user has an opportunity to think 'why does it want to fill in my address wtf'

I mean that does zero protection against someone clicking through and maybe the real solution is to have the user just type that poo poo in but there you go

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Progressive JPEG posted:

I think there's no realistic way the autofiller could ensure that all fields are visible+obvious to the user, so may as well just have the autofill bring up a prompt saying 'about to fill these fields: <bulleted list>, look good?'

Then at least a user has an opportunity to think 'why does it want to fill in my address wtf'

I mean that does zero protection against someone clicking through and maybe the real solution is to have the user just type that poo poo in but there you go

you could just make the user interact with each field individually but the list is still better UX

ohgodwhat
Aug 6, 2005

Relatively tame but this guy's not off to a good start:
http://security.stackexchange.com/questions/147216/hacker-used-picture-upload-to-get-php-code-into-my-site

Roughly, "I don't know how this hacker is getting PHP files past my client side validation!"

burning swine
May 26, 2004



Munkeymon posted:

you could just make the user interact with each field individually but the list is still better UX

as has been said many times before, security often comes at the expense of convenience. solution: patch autofill out of all of these browsers

Adbot
ADBOT LOVES YOU

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Progressive JPEG posted:

I think there's no realistic way the autofiller could ensure that all fields are visible+obvious to the user, so may as well just have the autofill bring up a prompt saying 'about to fill these fields: <bulleted list>, look good?'

Then at least a user has an opportunity to think 'why does it want to fill in my address wtf'

I mean that does zero protection against someone clicking through and maybe the real solution is to have the user just type that poo poo in but there you go

You're just training the user to hit the enter key after doing an autofill without reading what it says.

  • Locked thread