Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
flakeloaf
Feb 26, 2003

Still better than android clock

https://twitter.com/pcgamer/status/1305823956503613442

can't understand why having to log into my mouse is a bad idea

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

flakeloaf posted:

https://twitter.com/pcgamer/status/1305823956503613442

can't understand why having to log into my mouse is a bad idea

oh no someone's gonna hack all the ouyas :ohdear:

Wild EEPROM
Jul 29, 2011


oh, my, god. Becky, look at her bitrate.
ouyaboros

xtal
Jan 9, 2011

by Fluffdaddy
Lmao I literally bought a Razer mouse yesterday and when it asked me to make an account I closed the window immediately. Glad my instinct was correct

flakeloaf
Feb 26, 2003

Still better than android clock

meanwhile in nvidia land you need an account to log in to an app that runs locally on your pc to manage video settings and check for driver updates

The Fool
Oct 16, 2003


in logitech land I need to log in to an app to make a configuration change to my remote control

Wiggly Wayne DDS
Sep 11, 2010



Shame Boy posted:

oh no someone's gonna hack all the ouyas :ohdear:

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

flakeloaf posted:

meanwhile in nvidia land you need an account to log in to an app that runs locally on your pc to manage video settings and check for driver updates

or you could not and just manage the driver settings through the driver settings panel. the "geforce experience" requires an account, but the geforce experience isn't required to do anything with the driver settings, it's an optional install

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

infernal machines posted:

or you could not and just manage the driver settings through the driver settings panel. the "geforce experience" requires an account, but the geforce experience isn't required to do anything with the driver settings, it's an optional install

last I tried it was really annoying to do anything with DSR that way

Wiggly Wayne DDS
Sep 11, 2010



Subjunctive posted:

last I tried it was really annoying to do anything with DSR that way
huh last i remember you set DSR factors in the ye olde control panel, experience just covers auto-settings for games, driver installs or their remote play solution

where do you even change dsr in experience

flakeloaf
Feb 26, 2003

Still better than android clock

infernal machines posted:

or you could not and just manage the driver settings through the driver settings panel. the "geforce experience" requires an account, but the geforce experience isn't required to do anything with the driver settings, it's an optional install

"update automatically" is not in that panel

if you do not have geforce experience you aren't notified about new driver versions and have to install them manually every time by downloading them from a bad website

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
heaven forfend

e: i'm of the opinion that not automatically updating drivers is a feature, so YMMV

Subjunctive posted:

last I tried it was really annoying to do anything with DSR that way




IDK how annoying it is, but it's there

A Man With A Plan
Mar 29, 2010
Fallen Rib

I feel like I must be misunderstanding what's going on here because it feels like they're using AES as some sort of janky hashing method? Like it mentions throwing away the IV, but afaik IVs aren't secret and are usually just sent prepended to the ciphertext. What the hell is going on here?

haveblue
Aug 15, 2005



Toilet Rascal

A Man With A Plan posted:

I feel like I must be misunderstanding what's going on here because it feels like they're using AES as some sort of janky hashing method? Like it mentions throwing away the IV, but afaik IVs aren't secret and are usually just sent prepended to the ciphertext. What the hell is going on here?

as I understand it:

-ms didn't bother to randomize their IV, it's just all zeroes every time on both ends of the connection

-when you generate a random AES key and use it to encrypt a plaintext that's all zeros, there is a chance (1/256) that the first byte of the ciphertext is still zero

-if you do the cyclic encryption process with a block size of 1 starting with all zeroes (most of the all-zero IV plus the single zero byte from the intermediate ciphertext) the final payload ciphertext is, again, still all zeroes

-the server generates the AES key at random each time you initiate authentication and for some reason does not have retry limits

so, if you repeatedly hit the server with a string of zeroes, eventually you get lucky and all zeroes happens to be what it was expecting, and the server will be receptive to your RPC request despite never having known the shared secret

the rest of the paper is about how to move from one "authenticated" connection to some more straightforward security holes

haveblue fucked around with this message at 21:14 on Sep 15, 2020

A Man With A Plan
Mar 29, 2010
Fallen Rib
Yeah thanks haveblue. I think I understand the exploit's process well enough, I just wish they provided more detail on what nonsense MS is using as an authentication scheme. Idk if the author left it out to help avoid replication, or for clarity or space reasons

Wiggly Wayne DDS
Sep 11, 2010



there's already pocs and it works on samba soooo

NoneMoreNegative
Jul 20, 2000
GOTH FASCISTIC
PAIN
MASTER




shit wizard dad


I love Neil Breen.

Also

https://research.digitalinterruption.com/2020/09/10/giggle-laughable-security/

Starts off with common-or-garden secfuck, continues on into shithead-devfuck.

spankmeister
Jun 15, 2008






Wiggly Wayne DDS posted:

there's already pocs and it works on samba soooo

Yeah I tried it today and the one from the fox it guy worked flawlessly.

I didn't know it also applied to samba, that's cool.

ninepints
Sep 7, 2017
four and a half quarts

A Man With A Plan posted:

I feel like I must be misunderstanding what's going on here because it feels like they're using AES as some sort of janky hashing method? Like it mentions throwing away the IV, but afaik IVs aren't secret and are usually just sent prepended to the ciphertext. What the hell is going on here?

I think they're "throwing away" the IV in the sense that they're not transmitting it because it's all zeros (and everyone involved knows it). You're correct that if they used a real IV they would need to send that along for anyone to make use of the encrypted value.

e: like, consider a one-byte message, where the ciphertext is a single byte equal to plaintext ^ AES(key, IV)[0]. without knowledge of both the key and IV you have no idea what the right-hand side of that xor is and can't recover the plaintext

ninepints fucked around with this message at 10:45 on Sep 16, 2020

Schadenboner
Aug 15, 2011

by Shine

flakeloaf posted:

https://twitter.com/pcgamer/status/1305823956503613442

can't understand why having to log into my mouse is a bad idea

What does this have to do with the Isle of Man though?

:confused:

Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.
the kids are alright :unsmith:

https://twitter.com/jessicashortall/status/1306024580780380162

mystes
May 31, 2006

Obviously teach her to fill out if with fake information.

Phone
Jul 30, 2005

親子丼をほしい。

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe
https://twitter.com/mangopdf/status/1306020053280841730

basic security poo poo from that old defcon talk

flakeloaf
Feb 26, 2003

Still better than android clock

Schadenboner posted:

What does this have to do with the Isle of Man though?

:confused:

i prefer software that doesn't tail me

Midjack
Dec 24, 2007




it’s an entertaining read.

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD
Worth it for the ending.

Pretty sure logging into Qantas is still technically a crime though.

Achmed Jones
Oct 16, 2004



a decent story poorly-told imo. worth reading but be prepared to skim over the twee affectations

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Computer people have a pretty bad track record of trying to be funny. Probably shouldn't try

The Fool
Oct 16, 2003


yeah, i mean, look at this site

cinci zoo sniper
Mar 15, 2013




it was actually funny, y’all old

Schadenboner
Aug 15, 2011

by Shine

cinci zoo sniper posted:

it was actually funny, y’all old

Oh hey, the baltic mosquitoes didn't devour you!

:peanut:

xtal
Jan 9, 2011

by Fluffdaddy

cinci zoo sniper posted:

it was actually funny, y’all old

30 isn't old. It's the children who are wrong.

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl
i thought it was a fun read, sounds like sec nerds are just brokenly jaded from dealing with security poo poo

cinci zoo sniper
Mar 15, 2013




Schadenboner posted:

Oh hey, the baltic mosquitoes didn't devour you!

:peanut:

yeah, alive and well. bored out of my mind and on 10th month of unemployment, but well nevertheless

Crime on a Dime
Nov 28, 2006
iexplore.exe is a lolbin

Y[ ]
N[ ]

Schadenboner
Aug 15, 2011

by Shine

cinci zoo sniper posted:

yeah, alive and well. bored out of my mind and on 10th month of unemployment, but well nevertheless

I'm sorry to hear that, friendo. You're a big data guy (or something quanty IIRC)? I'd bet that's pretty cyclical, unfortunately (COVID -> no more jobs -> not a lot of people buying poo poo -> no sexy big datasets to mung for recommendations -> no more jobs)?

:(

BlankSystemDaemon
Mar 13, 2009



Crime on a Dime posted:

iexplore.exe is a lolbin

Y[ ]
N[ ]

Pile Of Garbage
May 28, 2007



hey rufus if you wanna update the OP: the v1.0 secfuck thread was moved to the mod forum because i posted a directory traversal exploit i'd discovered on the itSMF website and a bunch of us piled-in on it. iirc the exploit was with a PHP script they used to render image thumbnails on the fly for some reason. it took a path parameter but didn't have any checks in place so you could feed it any path like /../../../../etc/passwd and it would happily spit the file back at you

so yeah, not exactly epic, just textbook irresponsible disclosure by my dumb self. i and some others copped bans, the website in question has since moved to WP. good times

e: tl;dr as alereon so eloquently put it in my ban: "You made a series of very bad decisions."

Adbot
ADBOT LOVES YOU

Crime on a Dime
Nov 28, 2006

Pile Of Garbage posted:

hey rufus if you wanna update the OP: the v1.0 secfuck thread was moved to the mod forum because i posted a directory traversal exploit i'd discovered on the itSMF website and a bunch of us piled-in on it. iirc the exploit was with a PHP script they used to render image thumbnails on the fly for some reason. it took a path parameter but didn't have any checks in place so you could feed it any path like /../../../../etc/passwd and it would happily spit the file back at you

so yeah, not exactly epic, just textbook irresponsible disclosure by my dumb self. i and some others copped bans, the website in question has since moved to WP. good times

e: tl;dr as alereon so eloquently put it in my ban: "You made a series of very bad decisions."

mods gnu

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply