Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Shame Boy
Mar 2, 2010

ratbert90 posted:

what if kink shaming is his kink?????

then he'll ask you to do it and have a nice conversation discussing boundaries first, or it's not consensual :colbert:

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

Wheany posted:

someone make brodyquest but with tavis.

well don't make it, but think about it.

pretty good, eh?

tavis or-mandy tavis or-man-dy

it works pretty well

Shame Boy
Mar 2, 2010

Subjunctive posted:

I built a custom string type that couldn't easily be passed to logging functions for things like message text and passwords. if there was an implicit conversion, they would convert to things like "[[message text: 251 chars]]" or "[[password]]" and log a warning about misuse. it took about two days including converting a relatively large codebase. I don't know why people don't use the type system more for stuff like this

aw man i thought i came up with this idea :argh:

Shame Boy
Mar 2, 2010

anthonypants posted:

apparently twitter thought they didn't need to tell anyone about the password disclosure https://twitter.com/paraga/status/992135139994943488

later he walked that back https://twitter.com/paraga/status/992146630232043520

im the CTO of twitter that doesn't even have a blue check

Shame Boy
Mar 2, 2010

Subjunctive posted:

we both did!

yeah but you used it in actual production code and i used it in a dumb hobby project from 10 years ago so i think you win :v:

Shame Boy
Mar 2, 2010

Jewel posted:

arbituary code execution

arbitrary code execution that's so bad it kills you

Shame Boy
Mar 2, 2010

Achmed Jones posted:

yeah same. i get it at my cell number and google voice number. at&t has a blocker/“likely spam” app now, so we’ll see how well it works

i've been using that app for a while, it works... alright. a few still get through since the spammers are literally just randomly changing numbers so it's kinda hard to do any sort of correlation

an interesting side effect though is it shows you each individual time it blocks something, which shows interesting behavior - they'll call over and over again rapidly, like 8 to 10 times in a few seconds, then give up for a while and call again two days later, stuff like that

Shame Boy
Mar 2, 2010

RISCy Business posted:

i finally started a twitter account for my professional/hobbyist computer touching

other than tavis, who's a good follow for infosec stuff

i follow tavis, @thegrugq (if you don't mind weird thai politics and crazy stuff sometimes) and lain's @KateLibc account

infosec taylor swift has fallen out of favor with the thread it seems so follow at your own peril

Shame Boy
Mar 2, 2010

there's also that one account with the pony avatar that's apparently good but which i refuse to follow on principle

...unlike my ironic pony avatar that is cool and good and totally excusable

Shame Boy
Mar 2, 2010

even if it never was that big a real threat rowhammer will always be one of my favorite exploits just from a technological standpoint, it's just such a neat idea

Shame Boy
Mar 2, 2010

i've gotten multiple calls from "000-000-0000" which seems like it would be trivially easy and completely legal to filter out at the network level but i guess not

Shame Boy
Mar 2, 2010

flakeloaf posted:

threatening to autodial 1000 other people while spoofing your number would be a more effective threat, i'd think

they do that even without threatening - i've gotten occasional calls from confused people who angrily yell "i don't know what you're selling but take me off your drat list!!!" into my voicemail

Shame Boy
Mar 2, 2010

hmm, i wonder if you could use it as an alibi while doing crimes

"oh this guy can't be the murderer, he was clearly busy making 1000 calls per minute all afternoon"

Shame Boy
Mar 2, 2010

Raere posted:

no microprocessors? it's a prison not a hardened nuclear command bunker

the reason the article states is so they can hire rando handymen to fix it instead of having to pay someone who knows what they're doing

Shame Boy
Mar 2, 2010

Farmer Crack-rear end posted:

it annoys me how i have to opt-out of Steam remembering my credit card every time i make a purchase


no goddamnit i do not trust you with my goddamn credit card number!

they accept paypal now so i just use that instead because yeah lol even if they're using some third party processor i don't trust valve not to gently caress up somehow

Shame Boy
Mar 2, 2010

quote:

Important new features in npm and the npm Registry will help you discover, share, and reuse code with confidence.

npm audit
Starting in npm@5.10.0, a new npm command can perform a security review of your projects.

Simply type `npm audit` to analyze your code and its dependencies against the Node Security Platform database of JavaScript vulnerabilities. The command generates a report of vulnerabilities, simple-to-run npm commands and recommendations to resolve them, and links to web pages with more details.

...

Vulnerability alerts
When you install a package from the npm Registry, npm now analyzes the code you request. If we detect insecure code, npm will display a postinstall warning message.

Users of npm@5.10.0 and greater will receive detailed information about each vulnerability, instructions for updating the affected packages, and a link to a webpage with more details. Users of earlier npm versions will receive a truncated warning with a link to more details.

For maximum protection against unsafe code, as well as significant performance and stability improvements, every user should install and use npm@6. Simply type `npm install npm -g`.

cue 8 million "insecure" warnings on each npm install because a bunch of things 8 dependencies deep haven't been updated in half a decade

oh well, good job trying npm

Shame Boy
Mar 2, 2010

do copiers fall into the dumb grandfathered in exclusions to HIPAA rules like fax machines do? i mean a lot of copiers are also fax machines...

Shame Boy
Mar 2, 2010

pseudorandom name posted:

because printing things takes time

why do they need to store everything ever printed forever though

like an 8G flash drive could probably store all the print jobs you could reasonably queue up at once i'm not sure why it needs a 120G+ hard drive in it

Shame Boy
Mar 2, 2010

Jonny 290 posted:

office tech lags the bleeding edge quite a bit. i'm fairly confident that ssd for them is probably a 2017 and newer thing if anything. theyve had platters for 20 years

yeah i get that, but i'm not really wondering why they use a hard drive instead of flash, i'm more curious as to why it's apparently 120GB or more

pseudorandom name posted:

it may just be a dumb file system that keeps deleted files around

it did sound like they needed "forensic tools" to recover the files so maybe :shrug:

Shame Boy
Mar 2, 2010

Jabor posted:

It's cheaper to make a bulk order for the smallest hard drive that's currently being manufactured and standardising on that, rather than trying to wrangle up a bunch of unsold surplus tinier drives.

for some reason i thought they were still making 20G hard drives since those were huge and cutting edge at one point so obviously they'll continue to be relevant forever, but of course they're not i'm just getting old :smith:

Shame Boy
Mar 2, 2010

ymgve posted:

were they actually used by anyone at all

really seems like the kind of thing exclusively used by SEO urchins and the kind of marketing team that lists the number of facebook likes their corporate site got as proof that they're the most popular brand of toilet paper

Shame Boy
Mar 2, 2010

akadajet posted:

I figured they'd just use volatile memory for that poo poo.

eh the copiers in question were probably designed sometime between 1995 and 2005 and gigabytes of ram wasn't exactly cheap back then

Shame Boy
Mar 2, 2010

i like that the simpsons is way down on the list, and not expert status

Shame Boy
Mar 2, 2010

actually it's gnu/pg

Shame Boy
Mar 2, 2010

Shaggar posted:

authentication is optional in email in general, but if your client supports authentication and it gets an invalid signature theres no scenario where it shouldn't just put up a big fat error message and refuse to display the message.

i'm pretty sure most pgp implementations do that, i know the one i use started doing that the minute someone's key expired :shrug:

Shame Boy
Mar 2, 2010

Shaggar posted:

if the signature is valid but the signer's key is expired, then it would be untrusted rather than invalid so you could be prompted to ignore the trust issue. In the case of an invalid signature (meaning one that doesn't match the signed content) it should outright refuse to display.

yeah it was that you're right, but it did prevent the email from showing even text until i had dismissed the warning which is what i was trying to get across, i'd assume it does the same for invalid sigs but lol

Shame Boy
Mar 2, 2010

CRIP EATIN BREAD posted:

i bet there's a grey forum poster still recommending truecrypt

did we ever find out why truecrypt vanished like it did

Shame Boy
Mar 2, 2010

Shaggar posted:

+ emails are fuckin dumb because any spammer worth a drat is gonna strip it immediately.

i don't know, i don't think enough people even know it exists let alone use it to make spammers care

though i just have my personal domains forward all mail that doesn't match a known mailbox to me so i can use email addresses with the company name in it, like, "popeyes-chicken-lovers-club@butt-chuggin-babes.mobi" or w/e

Shame Boy
Mar 2, 2010

Shaggar posted:

just keep telling the user to fix it until the USPS address search returns an exact zip+4 match. if an input address doesn't resolve, its not valid and the usps probably wouldn't deliver it anyway.

USPS is actually very good at intuiting what you meant if you gently caress up an address

Shame Boy
Mar 2, 2010

EssOEss posted:

What does the +4 stand for?

it's 4 more zip code digits added to the end that allow the code to be specific enough to narrow it down to something like a city block, apartment complex, small neighborhood etc

Shame Boy
Mar 2, 2010

Jewel posted:

shady as hell warnings with bribes in attempt to get around GDPR??

https://twitter.com/jjbbllkk/status/997491067086819328

opt in/out of.. what

synergy is doing something slightly different but equally cheeky:



ooo you want to hear that exciting news don't you, eh buddy? ehh?

Shame Boy
Mar 2, 2010

Cocoa Crispies posted:

are they gonna announce which synergy they are?

it's the one that lets you use your mouse and keyboard across multiple computers, i'm only on their mailing list now because i donated like :10bux: to them back when it was open source so when the guy gave up and started charging for it he sent an email to everyone that donated with like, 10 free license keys and a sentimental email which was nice :unsmith:

Shame Boy
Mar 2, 2010


lmao they're so desperate they're resorting to the lowest tier of spammer tricks, this is great

Shame Boy
Mar 2, 2010

Volmarias posted:

Woah, hold up, next you'll be suggesting that we don't autoplay audio and video in the ads that follow the user as they scroll as well.

Look MALE SHOEGAZE you're a good engineer but you just don't understand what customers want.

8 out of 10 teens and moms and teen moms prefer when their advertising is targeted, animated, loud and 2/3s of the screen according to our very scientific study done by the very scientific sounding Ad Science Studies center, and i think they know what they're doing, after all they're big data scientists :colbert:

Shame Boy fucked around with this message at 04:21 on May 20, 2018

Shame Boy
Mar 2, 2010


quote:

The president uses at least two iPhones, according to one of the officials. The phones — one capable only of making calls, the other equipped only with the Twitter app and preloaded with a handful of news sites — are issued by White House Information Technology and the White House Communications Agency, an office staffed by military personnel that oversees White House telecommunications.

lmao they gave him a phone just for twitter and fox news presumably because he kept trying to install twitter on his other secret white house phone

e: lmao

quote:

The White House declined to comment for this story, but a senior West Wing official said the call-capable phones “are seamlessly swapped out on a regular basis through routine support operations. Because of the security controls of the Twitter phone and the Twitter account, it does not necessitate regular change-out.”

Trump’s call-capable cellphone has a camera and microphone, unlike the White House-issued cellphones used by Obama. Keeping those components creates a risk that hackers could use them to access the phone and monitor the president’s movements. The GPS location tracker, however — which can be used to track the president’s whereabouts — is disabled on Trump’s devices.

The West Wing official refuted the idea that the presence of a camera and microphone on the president’s phone posed any risk, telling POLITICO, “Due to inherent capabilities and advancement in technologies, these devices are more secure than any Obama-era devices.”

we got the most securest twitters and cameras unlike obama

Shame Boy
Mar 2, 2010

Subjunctive posted:

they gave Obama a phone without a mic? he’d just listen and send back DTMF?

literally yes, they did - if you read the full article his phone couldn't even make calls and he described it as "a toy phone you'd give a 3 year old"

Shame Boy
Mar 2, 2010

here's one I haven't seen before

WHOIS is disappearing – confirm your ownership now! posted:

On May 25, 2018, the General Data Protection Regulation will take effect. This means the WHOIS will “disappear”. In the new public record system, personal data will no longer be visible either to individuals or Sedo. So far we were able to verify from the WHOIS records that you are the legitimate owner of the domains you listed for sale. This means it will be much harder for us to match your account data with the WHOIS information in order to clear your domains for sale on our site.

The Solution: Our Owner Self-Verification. With the Owner Self-Verification, you can quickly prove your ownership of any domain you list for sale. Even on weekends and holidays!

No Owner Self-Verification = longer wait times

If you do not perform the Owner Self-Verification, it will take at least 3 business days for your domains to be listed for sale. During the review period, we will randomly check individual domains and may contact you to request proof of ownership (e.g., in the form of an up-to-date screenshot of the domain entry).

Self-Verification is not available for domain parking

If you already use Sedo's domain parking and forward your domains through our domain name servers (DNS), owner self-verification is currently unavailable. DNS forwarding enables your domains to be automatically listed for sale without waiting time. As of now, nothing changes for you.

We want to provide buyers and sellers with a safe and user-friendly platform at all times and look forward to your support. Do you have questions about owner verification? Our Customer Support Team is happy to answer them.

i've never listed a domain for sale ever, let alone with sedo, but i'll get right on it :thumbsup:

Shame Boy
Mar 2, 2010

Cocoa Crispies posted:

jamming a cell network isn’t a crime that doesn’t leave evidence, it’s interfering with a massive government contractor's use of a public resource to generate revenue in a way that’s extremely obvious to someone with access to a local network of fancy radios

i wonder if you could do something fancy with highly directional antennas or like, phased arrays or some other RF magic to force a single phone to connect to your fake tower or jam it or whatever without interfering with anything else

Shame Boy
Mar 2, 2010


https://www.youtube.com/watch?v=PBwAxmrE194

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

Jonny 290 posted:

the long tail danger is FirstNet because all cop and fed radios are going 5G and so is your phone and you'll be using the same network, so guess what, when a protest happens, bandwidth and signal will be given to the cop radios first. funny how that's gonna shut down all the protest footage and is why i'm building portable mesh networks

i've been sketching out designs for simple to build basic little radio systems you could in theory make using cheap parts taken out of other things or bought for a few bucks and use to establish links in phone-jammed environments for this same reason. i'm not actually any good at it though so they probably won't work once i get around to building one ¯\_(ツ)_/¯

  • Locked thread