Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Sagebrush posted:

the little credit union where i first got a bank account when i was a child started doing online banking about 5 years ago

the login is your account number

the password is your ATM PIN, which must be four numbers

it was something like this for the credit union i got my last car loan through. i didn't care though because it was my only account with them, so the only risk would have been if some hacker came along and wanted to pay off a used ford taurus

Adbot
ADBOT LOVES YOU

The Electronaut
May 10, 2009

pseudorandom name posted:

looks like there's also OS updates to go along with it and OS devs aren't happy that Lenovo leaked the CVE reveal dates.

Any links?

pseudorandom name
May 6, 2007


The Lenovo leak, such that it is, is at https://download.lenovo.com/pccbbs/mobiles/n1cet75w.txt

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!


code:
VERSION INFORMATION

  The following versions of UEFI BIOS has been released to date.

  UEFI BIOS (BIOS ID)  Issue Date
  -------------------  ----------
  1.43 (N1CET75W)      2019/04/26
  1.42 (N1CET74W)      2019/02/15
  1.41 (N1CET73W)      2018/12/17
  1.40 (N1CET72W)      2018/11/15
  1.39 (N1CET71W)      2018/09/28
  1.39 (N1CET71W)      2018/09/18
  1.37 (N1CET69W)      2018/07/20
  1.36 (N1CET68W)      2018/06/29
  1.35 (N1CET67W)      2018/06/12
  1.34 (N1CET66W)      2018/03/29
  1.33 (N1CET65W)      2018/02/19
  1.31 (N1CET63W)      2017/12/26
  1.30 (N1CET62W)      2017/11/28
  1.28 (N1CET60W)      2017/10/04
  1.27 (N1CET59W)      2017/09/08
  1.26 (N1CET58W)      2017/07/07
  1.25 (N1CET57W)      2017/06/02
  1.24 (N1CET56W)      2017/04/28
  1.23 (N1CET55W)      Factory Use Only
  1.22 (N1CET54W)      2017/02/14
  1.20 (N1CET52W)      2016/12/07
  1.16 (N1CET48W)      2016/09/29
  1.15 (N1CET47W)      2016/08/18
  1.14 (N1CET46W)      2016/07/21
  1.13 (N1CET45W)      2016/06/10
  1.11 (N1CET43W)      2016/04/21
  1.08 (N1CET40W)      2016/03/15
  1.06 (N1CET38W)      2016/02/16
  1.05 (N1CET37W)      2016/01/29
  1.04 (N1CET36W)      2016/01/15
N1CE

The Electronaut
May 10, 2009

Thanks.

Hmm, all three of the cves were reserved back in June. CVE-2018-12126, CVE-2018-12127, CVE-2018-12130

Curiosity got me. I wondered if anyone had extracted the update from the firmware to do diffs or the like, which led me to this tool: https://github.com/platomav/MCExtractor. The maintainer also maintains a repository: https://github.com/platomav/CPUMicrocodes.

I pulled down the firmware and extracted the .bin from the archive, sending it through the MCE python script. The update to the microcode was released on 1 April 2019. Looking at that repo and the change log to the database there was a change adding this one (cpuid 406E3 rev CC) and others on the 4th of May. The awareness of the update (though no connection to the CVEs) appears to come in a Windows Insider/Fast Track update in mid April based on comments in a forum posting on Win-Raid.com.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
javascript card skimming via merchant services analytics in the wild

Wiggly Wayne DDS
Sep 11, 2010



yeah that's been active for a few years and has been very quietly effective

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i like that the exfiltration is just appending all the details to an image load request

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

somewhere, Mark Miller is sighing with a combination of disappointment and smugness

(everywhere)

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Subjunctive posted:

I’m going to abuse my relationship with Lain to post a job description here. I don’t read YOSPOS anymore so PM me or sbjnctv@gmail.com if you’re a loser without plat.

I’m going to need a software developer focused on security soon. Hit me if that’s you.

- I’d be your boss’ boss, and you’ll never have as supportive a management chain as this one. I’m not kidding even a little.
- you need to make good decisions about tooling vs process vs just writing the diffs and tests yourself
- someone else handles all the certification/audit poo poo, you just deal with real problems and getting ahead of them
- our office is attached to a downtown subway station (line 1, west line best line)
- other software developers want to do a good job and will thank you for helping them not gently caress up
- when you tell a PM they shouldn’t ship because of a security issue, they listen
- strong privacy and tech ethics values, and we spend to honour them
- training? conferences? working from Tbilisi for two weeks because you’ve never been there (actual example)? tell your boss how it makes sense and sure. you’re an adult
- more than a year of runway
- actual paying customers
- you should be able to tell me about how you fixed a security fuckup and made sure it stayed fixed
- we have fired recruiting agencies for bringing us only white dudes for leadership and tech positions
- you don’t need to know about AI, but you’ll sure learn about it, including privacy and bias pieces
- talking to people (internal mostly) is part of the job. you can get coached to gently caress and back, but you can’t dodge it
- you’re moving to Toronto or convincing me that you can kick all the rear end if you’re here 1 out of 3 weeks
- your options are meaningfully in the black on day one because Canadian tax accounting is amazing

e: Lain isn’t even OP, well whatever

there's a decent vegan place near your work too

Michael Transactions
Nov 11, 2013

Looks like some one hosed up. Lmao

EssOEss
Oct 23, 2006
128-bit approved
for the last 6 hours, one of the Estonian (+neighbors) national ID card web services is down. the id card is a smart card, enabling 2fa and mandatory for every citizen so naturally, over the past 20 years most important services like banks have migrated to using the ID card as the primary authentication mechanism because everyone has it. the secondary mechanism being a SIM card variant of the exact same thing, also down now because it works out to the same mechanism in a different package.

the affected service appears to be one used to sign and validate documents.

when russia tried to do its supposed cyberwar on Estonia back in 2008, perhaps they should have targeted this service instead of ddosing random government websites

Shame Boy
Mar 2, 2010

Subjunctive posted:

I’m going to abuse my relationship with Lain to post a job description here. I don’t read YOSPOS anymore so PM me or sbjnctv@gmail.com if you’re a loser without plat.

I’m going to need a software developer focused on security soon. Hit me if that’s you.

- I’d be your boss’ boss, and you’ll never have as supportive a management chain as this one. I’m not kidding even a little.
- you need to make good decisions about tooling vs process vs just writing the diffs and tests yourself
- someone else handles all the certification/audit poo poo, you just deal with real problems and getting ahead of them
- our office is attached to a downtown subway station (line 1, west line best line)
- other software developers want to do a good job and will thank you for helping them not gently caress up
- when you tell a PM they shouldn’t ship because of a security issue, they listen
- strong privacy and tech ethics values, and we spend to honour them
- training? conferences? working from Tbilisi for two weeks because you’ve never been there (actual example)? tell your boss how it makes sense and sure. you’re an adult
- more than a year of runway
- actual paying customers
- you should be able to tell me about how you fixed a security fuckup and made sure it stayed fixed
- we have fired recruiting agencies for bringing us only white dudes for leadership and tech positions
- you don’t need to know about AI, but you’ll sure learn about it, including privacy and bias pieces
- talking to people (internal mostly) is part of the job. you can get coached to gently caress and back, but you can’t dodge it
- you’re moving to Toronto or convincing me that you can kick all the rear end if you’re here 1 out of 3 weeks
- your options are meaningfully in the black on day one because Canadian tax accounting is amazing

e: Lain isn’t even OP, well whatever

what kind of software is this developing, or at least what languages? it's not php is it :ohdear:

also I have stories of fixing security fuckups but i feel they're not as good as other posters' stories because the place i was working was appallingly bad so it was stuff like "make it so you actually need a password to access this private server" or "replace unsalted MD5 with something less stupid" or my favorite, "discover that one of the main servers had been running an ancient version of tomcat that was vulnerable to literally everything and hadn't been updated in a decade and I was the first person to ever notice because everyone thought the dozens of different malwares that had been installed on it was just part of our software"

BattleMaster
Aug 14, 2000


those all sound like randomly-generated scam sites

lighteningcornhole[.]com

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug

so is this a staged rollout for different models? nothing new available for x1 carbons 3rd and 6th gen afaict

e: or are those not affected?

Cybernetic Vermin
Apr 18, 2005

Lysidas posted:

so is this a staged rollout for different models? nothing new available for x1 carbons 3rd and 6th gen afaict

e: or are those not affected?

from what i understand nothing is supposed to be available yet and we only know something exists because that one leaked (that may have changed though, or, as likely, I've misunderstood)

4lokos basilisk
Jul 17, 2008


EssOEss posted:

for the last 6 hours, one of the Estonian (+neighbors) national ID card web services is down. the id card is a smart card, enabling 2fa and mandatory for every citizen so naturally, over the past 20 years most important services like banks have migrated to using the ID card as the primary authentication mechanism because everyone has it. the secondary mechanism being a SIM card variant of the exact same thing, also down now because it works out to the same mechanism in a different package.

the affected service appears to be one used to sign and validate documents.

when russia tried to do its supposed cyberwar on Estonia back in 2008, perhaps they should have targeted this service instead of ddosing random government websites

afaik the ID card itself contains the certificates necessary for signing documents so this service is not essential for that part. it is just the public website where you can sign using a smart card reader - there is also an app for signing and encrypting documents locally. you can also validate the signatures locally but I am not sure if this actually requires connection to a government server (probably does)

also what most people tend to use is the mobile id part of the whole solution. I do not use it personally because I am living abroad but essentially it is a 2fa tied to your phone SIM card and you get to do most necessary procedures without having to stick the card in the reader.

that said it’s still lovely that servers are down

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Shame Boy posted:

what kind of software is this developing, or at least what languages? it's not php is it :ohdear:

we build AI business applications. languages are mostly Scala/python right now but I expect Rust to take some turf soon

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

a russian cryptolocker author is really mad that somebody released a decrypter for his malware. "shoes you booze" indeed

https://twitter.com/campuscodi/status/1126602241463308288

flakeloaf
Feb 26, 2003

Still better than android clock

Иiсэ меlтбоши ьгф

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
Security Fuckup Megathread v18 - more than once I stroked Squirrel by the tail

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Shame Boy posted:

what kind of software is this developing, or at least what languages? it's not php is it :ohdear:

also I have stories of fixing security fuckups but i feel they're not as good as other posters' stories because the place i was working was appallingly bad so it was stuff like "make it so you actually need a password to access this private server" or "replace unsalted MD5 with something less stupid" or my favorite, "discover that one of the main servers had been running an ancient version of tomcat that was vulnerable to literally everything and hadn't been updated in a decade and I was the first person to ever notice because everyone thought the dozens of different malwares that had been installed on it was just part of our software"

I should say that I don't care what languages you know already, because learning languages while working in a code base with co-workers to ask is not a tall order. I care how you think about security problems in the context of software, policy, tooling, product features, etc.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Lutha Mahtin posted:

a russian cryptolocker author is really mad that somebody released a decrypter for his malware. "shoes you booze" indeed

https://twitter.com/campuscodi/status/1126602241463308288

Security fuckup megathread: you booze, you lose (your aes keys)

flakeloaf
Feb 26, 2003

Still better than android clock

sucks to your aeskeys

Shame Boy
Mar 2, 2010

Subjunctive posted:

I should say that I don't care what languages you know already, because learning languages while working in a code base with co-workers to ask is not a tall order. I care how you think about security problems in the context of software, policy, tooling, product features, etc.

yeah i think "be able to learn new languages" is something any developer should be able to do just as part of their job, i was more asking just out of curiosity cuz there are certainly some languages i enjoy working with more than others :shrug:

Potato Salad
Oct 23, 2014

nobody cares


florida lan posted:

Security Fuckup Megathread v18 - more than once I stroked Squirrel by the tail

one hell of a post/av

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

flakeloaf posted:

sucks to your aeskeys

Sereri
Sep 30, 2008

awwwrigami

Blow it out your aes

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Sereri posted:

Blow it out your aes

lmao

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Sereri posted:

Blow it out your aes

lol

graph
Nov 22, 2006

aaag peanuts

Sereri posted:

Blow it out your aes

poo poo this is way better

ewiley
Jul 9, 2003

More trash for the trash fire

Sereri posted:

Blow it out your aes

Wait do people pronounce AES as 'ace'?

flakeloaf
Feb 26, 2003

Still better than android clock

ewiley posted:

Wait do people pronounce

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

ewiley posted:

Wait do people pronounce AES as 'ace'?

we do now

ewiley
Jul 9, 2003

More trash for the trash fire

Well ok then

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.




:hmmyes:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Sereri posted:

Blow it out your aes

Yeah that one is better

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
this new title is great

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
https://twitter.com/BillyCorben/status/1126655402127577088

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

and by "hack" we almost definitely mean "find an unattended login, or type the password, which is the name of the school and the number of its civic address"

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply