Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Wiggly Wayne DDS
Sep 11, 2010



akadajet posted:

How would blocking the US help with GDPR?
it'd help a ton with any discussion related to it if prior threads have been any indication

Adbot
ADBOT LOVES YOU

Pierre Chaton
Sep 1, 2006

is 1password still the best choice for a low hassle, cross platform password manager?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Father Jack posted:

is 1password still the best choice for a low hassle, cross platform password manager?
yes. if you're on windows get the v4 version

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

anthonypants posted:

yes. if you're on windows get the v4 version

v7 beta has standalone vaults now

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Wiggly Wayne DDS posted:

it'd help a ton with any discussion related to it if prior threads have been any indication

lol

Pierre Chaton
Sep 1, 2006

Rufus Ping posted:

v7 beta has standalone vaults now

oh? so you can sync with dropbox instead of buying a subscription?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Rufus Ping posted:

v7 beta has standalone vaults now
last i heard it was still in alpha and they got rid of the bonjour lan sync

Pierre Chaton
Sep 1, 2006

anthonypants posted:

yes. if you're on windows get the v4 version

why v4 rather than the current version?

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Rufus Ping posted:

v7 beta has standalone vaults now

they also have a CLI version for all platforms: https://support.1password.com/command-line-getting-started/

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
i have weird sync issues between my mac and windows box lol

Proteus Jones
Feb 28, 2013



Father Jack posted:

why v4 rather than the current version?

The current non-alpha/beta Windows version requires a 1Password cloud subscription. v4 is currently the supported stand-alone (it still gets security updates), but there’s not Edge extension for it if that’s a deal breaker.

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

https://www.nytimes.com/interactive/2018/05/03/magazine/money-issue-iowa-lottery-fraud-mystery.html

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Powerful Two-Hander posted:

I had to do some it sec training today and it had an absolutely superb "interview with a hacker" segment that had:

*hacker sitting in the dark wearing a hoodie
*multiple screens of green text scrolling by
***extremely hacker voice***
*a progress bar of COMPROMISING SYSTEM....HACKED
*something like "all I have to do is send them some clickbait and wait for them to play right into my hands... By the time they realise they've been hacked, I'm already selling their data on the dark Web"


it was very funny. We probably paid 50,000 for it.

cmon you have to leak that now, that sounds brilliant

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


this was good, thanks

Salt Fish
Sep 11, 2003

Cybernetic Crumb
The presentation was corny and cringy as a tool to ensure you paid attention and remembered it. You took to the training so well that you're here telling us to be careful about what we click on, and to pay attention to when someone is trying too hard to get our browser traffic. I'd say the training was well worth the cost.

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Subjunctive posted:

this was good, thanks

i think it's pretty cool the article explained programming stuff, like pseudocode and the actual sneaky bit of code. i also think it's pretty bad that the lottery association doesn't keep backups and was foiled by if (date == memorial Day) {rigThe Game();}

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/KateLibc/status/992810127383183364

the thread i quoted is good too but yeah. telephony sucks and it will never get better so i talked about how i abused it once

Shaggar
Apr 26, 2006
with the current way the networks are setup the best way to handle robocalls is to put liability for them onto the carriers with penalties paid by the carriers to consumers reporting the calls rather than the FTC.

brand engager
Mar 23, 2011

I think someone started doing that poo poo for my area too. I get a bunch of spam calls from numbers with the same area code and first 3 digits as my cell phone. gently caress to phones

Achmed Jones
Oct 16, 2004



yeah same. i get it at my cell number and google voice number. at&t has a blocker/“likely spam” app now, so we’ll see how well it works

Shame Boy
Mar 2, 2010

Achmed Jones posted:

yeah same. i get it at my cell number and google voice number. at&t has a blocker/“likely spam” app now, so we’ll see how well it works

i've been using that app for a while, it works... alright. a few still get through since the spammers are literally just randomly changing numbers so it's kinda hard to do any sort of correlation

an interesting side effect though is it shows you each individual time it blocks something, which shows interesting behavior - they'll call over and over again rapidly, like 8 to 10 times in a few seconds, then give up for a while and call again two days later, stuff like that

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

wait, which one is RCE? it can't be the exif bug since that is an overread, and none of the other bugs backported to 5.6 look like an RCE either.

i mean i get that they've decoupled all these php bugs from cve numbering to prevent integer exhaustion but come on

(i'm using RHEL so I need a CVE to see if redhat has/will patch it)

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
https://www.bleepingcomputer.com/news/security/microsoft-working-on-a-fix-for-windows-10-meltdown-patch-bypass/

quote:

Welp, it turns out the Meltdown patches for Windows 10 had a fatal flaw: calling NtCallEnclave returned back to user space with the full kernel page table directory, completely undermining the mitigation. This is now patched on RS4

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

amazing

Raere
Dec 13, 2007

just in time for the next spectre patches to be released and also hosed up

Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.
The New York Times Magazine has an article about how the man who was responsible for much of the IT for the lotteries in a number of states (including RNG implementation) put in a back door so he could cheat. There's some very stupid things in there, like how he managed to buy a jackpot ticket (despite knowing every possible number that could win so easily could have played a non-winning number to ensure he missed the jackpot), how he bought his own lottery tickets (despite being legally forbidden from playing the lottery as a lottery employee), how the lottery RNG was a Mersenne Twister (not a cryptographically secure RNG) seeded with Geiger counter readings, and how they apparently only relied on third-party black-box testing to audit the RNG's functionality with no internal testing or even code review (which would have caught the described backdoor very easily). To top it all off: his stated reason for doing it in the first place? A coworker joked about him having the power to do it and he wanted to see if he actually could :downs:

Mr.Radar fucked around with this message at 03:37 on May 6, 2018

Garrand
Dec 28, 2012

Rhino, you did this to me!

Mr.Radar posted:

The New York Times Magazine has an article about how the man who was responsible for much of the IT for the lotteries in a number of states (including RNG implementation) put in a back door so he could cheat. There's some very stupid things in there, like how he managed to buy a jackpot ticket (despite knowing every possible number that could win so easily could have played a non-winning number to ensure he missed the jackpot), how he bought his own lottery tickets (despite being legally forbidden from playing the lottery as a lottery employee), how the lottery RNG was a Mersenne Twister (not a cryptographically secure RNG) seeded with Geiger counter readings, and how they apparently only relied on third-party black-box testing to audit the RNG's functionality with no internal testing or even code review (which would have caught the described backdoor very easily). To top it all off: his stated reason for doing it in the first place? A coworker joked about him having the power to do it and he wanted to see if he actually could :downs:

Yes, that would be this article


My favorite part is that this guy had been getting his friends and family rigged lottery tickets for years but was trying to pass himself off as an ambitious nerd who just wanted to see if it could be done and not the actual thief he was.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

brand engager posted:

I think someone started doing that poo poo for my area too. I get a bunch of spam calls from numbers with the same area code and first 3 digits as my cell phone. gently caress to phones

I made an app that I'm unreasonably proud of to just block all same area code + prefix calls without even ringing.

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
i finally started a twitter account for my professional/hobbyist computer touching

other than tavis, who's a good follow for infosec stuff

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

brand engager posted:

I think someone started doing that poo poo for my area too. I get a bunch of spam calls from numbers with the same area code and first 3 digits as my cell phone. gently caress to phones

this has been happening to me at least twice daily for almost a year, and it's infuriating

Salt Fish
Sep 11, 2003

Cybernetic Crumb

Volmarias posted:

I made an app that I'm unreasonably proud of to just block all same area code + prefix calls without even ringing.

That's incredible and you are right to be proud and also give me it because my ringer is just off 24/7 because I get like 10 calls a day.

Shame Boy
Mar 2, 2010

RISCy Business posted:

i finally started a twitter account for my professional/hobbyist computer touching

other than tavis, who's a good follow for infosec stuff

i follow tavis, @thegrugq (if you don't mind weird thai politics and crazy stuff sometimes) and lain's @KateLibc account

infosec taylor swift has fallen out of favor with the thread it seems so follow at your own peril

Shame Boy
Mar 2, 2010

there's also that one account with the pony avatar that's apparently good but which i refuse to follow on principle

...unlike my ironic pony avatar that is cool and good and totally excusable

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

RISCy Business posted:

i finally started a twitter account for my professional/hobbyist computer touching

other than tavis, who's a good follow for infosec stuff

Krebs is pretty good.

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

this was a good read

redleader
Aug 18, 2005

Engage according to operational parameters

Subjunctive posted:

I built a custom string type that couldn't easily be passed to logging functions for things like message text and passwords. if there was an implicit conversion, they would convert to things like "[[message text: 251 chars]]" or "[[password]]" and log a warning about misuse. it took about two days including converting a relatively large codebase. I don't know why people don't use the type system more for stuff like this

oooh this is a cool idea

redleader
Aug 18, 2005

Engage according to operational parameters

Garrand posted:

Yes, that would be this article


My favorite part is that this guy had been getting his friends and family rigged lottery tickets for years but was trying to pass himself off as an ambitious nerd who just wanted to see if it could be done and not the actual thief he was.

on the other hand, lotteries exist purely to siphon money from the poor. stealing from a lottery is good.

Pile Of Garbage
May 28, 2007



Powerful Two-Hander posted:

I had to do some it sec training today and it had an absolutely superb "interview with a hacker" segment that had:

*hacker sitting in the dark wearing a hoodie
*multiple screens of green text scrolling by
***extremely hacker voice***
*a progress bar of COMPROMISING SYSTEM....HACKED
*something like "all I have to do is send them some clickbait and wait for them to play right into my hands... By the time they realise they've been hacked, I'm already selling their data on the dark Web"


it was very funny. We probably paid 50,000 for it.

did the hacker say "i'm in" in a hacker voice?

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


cheese-cube posted:

did the hacker say "i'm in" in a hacker voice?

yep I think they did because I said it out loud at the same time and got a weird look from the guy next to me

Adbot
ADBOT LOVES YOU

Carbon dioxide
Oct 9, 2012
Probation
Can't post for 32 minutes!

RISCy Business posted:

i finally started a twitter account for my professional/hobbyist computer touching

other than tavis, who's a good follow for infosec stuff

Troy Hunt.

  • Locked thread