Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast
all i know is that the cloud will help me stay secure cuz it's always up to date

Adbot
ADBOT LOVES YOU

Armitag3
Mar 15, 2020

Forget it Jake, it's cybertown.


Sniep posted:

all i know is that the cloud will help me stay secure cuz it's always up to date

The cloud is secure because I'm all the way up heeeeeeeere

cinci zoo sniper
Mar 15, 2013




bleeding kansas posted:

you wouldnt think anyone would need a reminder at this point

and yet

you wouldn’t download a passport

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

Armitag3 posted:

The cloud is secure because I'm all the way up heeeeeeeere

DELETE CASCADE
Oct 25, 2017

i haven't washed my penis since i jerked it to a phtotograph of george w. bush in 2003
all the pii your car will ever need, rock auto dot commmmm

bleeding kansas
Nov 15, 2019
7 hits this weekend

and this trash from cocacolawow.co.il i had to throw out



so close i could taste it

bleeding kansas
Nov 15, 2019
covid ruined my breach

starting to think its bad

Progressive JPEG
Feb 19, 2003

ligatures in code are super gross lemme tell you

bleeding kansas
Nov 15, 2019
kate is so fancy

i think it handles large files better than vscode tho

maybe just delusions

psiox
Oct 15, 2001

Babylon 5 Street Team

Progressive JPEG posted:

ligatures in code are super gross lemme tell you

ligature nuts

git apologist
Jun 4, 2003

Progressive JPEG posted:

ligatures in code are super gross lemme tell you

:yeah:

Zamujasa
Oct 27, 2010



Bread Liar

Progressive JPEG posted:

super gross lemme tell you

:hmmyes:

ate shit on live tv
Feb 15, 2004

by Azathoth

Progressive JPEG posted:

ligatures in code are super gross lemme tell you

wtf. Why would you want that functionality?

Shame Boy
Mar 2, 2010

ate poo poo on live tv posted:

wtf. Why would you want that functionality?

i could sort of understand if it made common mistakes more plainly obvious, like have big visibly different symbols for == and === since this is javascript, but that tiny rear end not equals to symbol is actually way harder to read at a glance than != so if anything it's having the opposite effect.

my eyes were drawn to it though, because i thought it was an assignment in the wrong place, so mission accomplished i guess

cinci zoo sniper
Mar 15, 2013




i use ligatures both in code editor _and_ terminal

Agile Vector
May 21, 2007

scrum bored



i turn them off on the line i'm focused on because i like the unified notation for !== and === but it seems silly to delete 'invisibly' as it shifts between ligatures

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
I don't know whether my distaste for ligatures is because I'm old and Change Is Bad, because it's actually harder to notice them unless you look closer, or a combination of both.

I'm looking forward to some delightful exploits arising as a result of them though!

cinci zoo sniper
Mar 15, 2013




Volmarias posted:

I don't know whether my distaste for ligatures is because I'm old and Change Is Bad, because it's actually harder to notice them unless you look closer, or a combination of both.

I'm looking forward to some delightful exploits arising as a result of them though!

we’ll then just switch to ligation, like in iosevka

Quackles
Aug 11, 2018

Pixels of Light.


cinci zoo sniper posted:

we’ll then just switch to ligation

I'm pretty sure the West is already too deep on litigation to switch.

bleeding kansas
Nov 15, 2019

Shame Boy posted:

i could sort of understand if it made common mistakes more plainly obvious, like have big visibly different symbols for == and === since this is javascript, but that tiny rear end not equals to symbol is actually way harder to read at a glance than != so if anything it's having the opposite effect.

my eyes were drawn to it though, because i thought it was an assignment in the wrong place, so mission accomplished i guess

yeah i like how well it highlights the difference between == and ===

not equals eh, its whatever

i dont write code in kate i just review it tho

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


Volmarias posted:

I don't know whether my distaste for ligatures is because I'm old and Change Is Bad, because it's actually harder to notice them unless you look closer, or a combination of both.

I'm looking forward to some delightful exploits arising as a result of them though!

i thought the whole point of ligatures was to make it easier to tell the symbols apart

ultrafilter
Aug 23, 2007

It's okay if you have any questions.


https://twitter.com/CubicleApril/status/1465438594588459018

Better late than never, I guess.

Kazinsal
Dec 13, 2011



is that even something zoom has a problem set for? I was under the impression zooms were all on *.zoom.us or localized equivalent and so “block untrusted certs” really means “shut down our entire business when someone forgets to renew a cert”

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
cjs: a bank prospect complained about our admin interface using an indefinitely-lived unary credential (yes, really, it's unary--you can dictionary attack the password without so much as trying to use a lazy "admin" username along with because the password alone really is all you need)

an enterprising sales engineer worked around this by using the hack job we used to support session cookie access instead of said unary credential, further hacked so that a CLI client can mimic the auth flow of our GUI client despite doing things the GUI auth flow was never intended to support. "yes, i was surprised also" is always something good to hear in an authentication context

it is, at least, merely profoundly stupid (effectively it ends up being a pointless wrapper around an OIDC access token) in this case rather than obviously harmful, but still

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

Kazinsal posted:

is that even something zoom has a problem set for? I was under the impression zooms were all on *.zoom.us or localized equivalent and so “block untrusted certs” really means “shut down our entire business when someone forgets to renew a cert”

depends what it means by "untrusted"

if it previously accepted self-signed certs, or certs chaining up to an unknown CA, then the encryption was providing essentially zero protection against an active mitm attack

cinci zoo sniper
Mar 15, 2013




https://www.bloomberg.com/news/articles/2021-11-30/finland-battles-exceptional-malware-attack-spread-by-phones wtf is going on in finland

shame on an IGA
Apr 8, 2005


[

4lokos basilisk
Jul 17, 2008


tsek eemail

Zamujasa
Oct 27, 2010



Bread Liar

Kazinsal posted:

is that even something zoom has a problem set for? I was under the impression zooms were all on *.zoom.us or localized equivalent and so “block untrusted certs” really means “shut down our entire business when someone forgets to renew a cert”

i'm wondering if they did anything to ensure it's only zoom's certificates or if it just trusts any "trusted" certificate, but at that point you're starting to get into "they could just pwn the machine directly" territory (e.g. organizations or malware that have their own root cas that they sign poo poo with)


CMYK BLYAT! posted:

cjs: a bank prospect complained about our admin interface using an indefinitely-lived unary credential (yes, really, it's unary--you can dictionary attack the password without so much as trying to use a lazy "admin" username along with because the password alone really is all you need)

an enterprising sales engineer worked around this by using the hack job we used to support session cookie access instead of said unary credential, further hacked so that a CLI client can mimic the auth flow of our GUI client despite doing things the GUI auth flow was never intended to support. "yes, i was surprised also" is always something good to hear in an authentication context

it is, at least, merely profoundly stupid (effectively it ends up being a pointless wrapper around an OIDC access token) in this case rather than obviously harmful, but still

time to move off of vnc

endlessmonotony
Nov 4, 2009

by Fritz the Horse

Penisface posted:

tsek eemail

Minä juon nyt kahvia.

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

Is this more Mike Lindell bullshit about the 2020 election still

unbutthurtable
Dec 2, 2016

Total. Tox. Rereg.


College Slice
Cyber defenders, assemble

4lokos basilisk
Jul 17, 2008


endlessmonotony posted:

Minä juon nyt kahvia.

onko sinulla normipäivä?

endlessmonotony
Nov 4, 2009

by Fritz the Horse

Penisface posted:

onko sinulla normipäivä?

No tänään vituttaa. Eli siis ihan normi päivä.

evil_bunnY
Apr 2, 2003

pissed off some russians again eh?

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER


one baby box too many

repiv
Aug 13, 2009

https://googleprojectzero.blogspot.com/2021/12/this-shouldnt-have-happened.html

oops

cinci zoo sniper
Mar 15, 2013




https://www.bleepingcomputer.com/news/security/former-ubiquiti-dev-charged-for-trying-to-extort-his-employer/ lmao

quote:

Throughout this process, the defendant tried hiding his home IP address using Surfshark's VPN services. However, his actual location was exposed after a temporary Internet outage.

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER


should've used tor

Adbot
ADBOT LOVES YOU

ewiley
Jul 9, 2003

More trash for the trash fire

if I’m reading this right it’s a buffer overflow in the certificate verification of Mozilla’s NSS that’s existed since like 2014 and Mozilla and Google and other third parties all missed it despite heavily auditing the same code?

I think the solution here is to no longer let Taviso take showers. or perhaps make him take more

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply