Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
fins
May 31, 2011

Floss Finder
An interesting paper on Find My stuff

https://arxiv.org/pdf/2205.06114.pdf

quote:

When an iPhone is turned off, most wireless chips stay on. For instance, upon user-initiated shutdown, the iPhone remains locatable via the Find My network. If the battery runs low, the iPhone shuts down automatically and enters a power reserve mode. Yet, users can still access credit cards, student passes, and other items in their Wallet. We analyze how Apple implements these standalone wireless features, working while iOS is not running, and determine their security boundaries. On recent iPhones, Bluetooth, Near Field Communication (NFC), and Ultra-wideband (UWB) keep running after power off, and all three wireless chips have direct access to the secure element. As a practical example what this means to security, we demonstrate the possibility to load malware onto a Bluetooth chip that is executed while the iPhone is off.

Adbot
ADBOT LOVES YOU

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

> As a practical example what this means to security, we demonstrate the possibility to load malware onto a Bluetooth chip that is executed while the iPhone is off.



:shepface:

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face
that's pretty cool but not unexpected really

if you use a BTLE scanner around here there's a bazillion beacons, i really wish there were some way to just nuke them all

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


hmm yes software vendor I am going to be difficult and you will "have to talk to engineering" about it because your $OtherVendor integration should not require a full administrative account with a static password when there are perfectly good APIs available that provide four different documented authentication methods, none of which require what you're asking for.

also "we don't know we'll have to check but can you set this up please it's holding us up?" is the wrong answer when someone asks you why you need admin access to something jfc

post hole digger
Mar 21, 2011

:blastu: lazy vendors

FlapYoJacks
Feb 12, 2009

Powerful Two-Hander posted:

hmm yes software vendor I am going to be difficult and you will "have to talk to engineering" about it because your $OtherVendor integration should not require a full administrative account with a static password when there are perfectly good APIs available that provide four different documented authentication methods, none of which require what you're asking for.

also "we don't know we'll have to check but can you set this up please it's holding us up?" is the wrong answer when someone asks you why you need admin access to something jfc

This reminds me of a past project I jumped on, and when asked "why does this run as root?" the answer was "We need to be able to write to the config file!"

I changed the permissions on the config file and root was no longer needed.

:suicide:

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

fins posted:

An interesting paper on Find My stuff

https://arxiv.org/pdf/2205.06114.pdf
their POC requires a jailbroken iphone so lol

git apologist
Jun 4, 2003

CRIP EATIN BREAD posted:

the term “nonce” for one time use predates the dumb brits version of it.

they can go kick rocks

yeah why should we change, they’re the one who sucks

git apologist
Jun 4, 2003

haveblue posted:

my new cryptocurrency uses poof-of-stake

mystes
May 31, 2006

please use poof-of-steak where you feed me wagyu

Jenny Agutter
Mar 18, 2009

lmao https://arstechnica.com/information-technology/2022/05/digital-drivers-license-used-by-4m-australians-is-a-snap-to-forge/

NSW offers a digital driver's license app. the identity file data can be backed up to a pc via itunes. the file is encrypted with a 4-digit numeric pin. the data on the phone is never checked against a central server. the qr code only contains the name and whether the person is over 18.

Hed
Mar 31, 2004

Fun Shoe
Nice MVP, they’ll fix it in the next release!!

Raere
Dec 13, 2007

Client side validation of drivers' licenses

fins
May 31, 2011

Floss Finder

Chris Knight posted:

their POC requires a jailbroken iphone so lol

i never knew of the existence of dck 3.0. can't seem to find much, but lol this:

fins fucked around with this message at 04:01 on May 25, 2022

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

Jenny Agutter posted:

lmao https://arstechnica.com/information-technology/2022/05/digital-drivers-license-used-by-4m-australians-is-a-snap-to-forge/

NSW offers a digital driver's license app. the identity file data can be backed up to a pc via itunes. the file is encrypted with a 4-digit numeric pin. the data on the phone is never checked against a central server. the qr code only contains the name and whether the person is over 18.

do you know how fast you were going Mr. Drop Table?

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

fins posted:

i never knew of the existence of dck 3.0. can't seem to find much, but lol this:


alternately, we could use a physical token that’s permanently paired to the car and is 100% non-interceptable

Jenny Agutter
Mar 18, 2009

Captain Foo posted:

alternately, we could use a physical token that’s permanently paired to the car and is 100% non-interceptable

*posts photo of key online* id like to see anyone intercept this!

mystes
May 31, 2006

Jenny Agutter posted:

*posts photo of key online* id like to see anyone intercept this!
That won't work with car keys that have chips in them which was common for a long time before keyless ignition.

Maybe cars should just have usb slots for fido2 tokens.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


FlapYoJacks posted:

This reminds me of a past project I jumped on, and when asked "why does this run as root?" the answer was "We need to be able to write to the config file!"

I changed the permissions on the config file and root was no longer needed.

:suicide:

so their answer is "we need it to set up an oath token and the admin access is needed to provision users" but their documentation says that the user provisioning function is deprecated (and you don't need full admin for this anyway).

at least they are using one of the actual APIs though, I was expecting them to be doing a headless login and screen scraping or something

outhole surfer
Mar 18, 2003

FlapYoJacks posted:

"We need to be able to write to the config file!"

this alone loving destroys me. i rage tirelessly against server applications that insist on being able to rewrite their own config files. i get that it isn't all that different from just storing configuration data in the application's data store, but i really like having a line between startup configuration with credentials for connecting to a data store and runtime configuration that can live in said data store

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

fins posted:

i never knew of the existence of dck 3.0. can't seem to find much, but lol this:


Could we, you know, NOT do this?

Potato Salad
Oct 23, 2014

nobody cares


Jenny Agutter posted:

*posts photo of key online* id like to see anyone intercept this!

you're right, but I think they were referring to key fobs

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

CommieGIR posted:

Could we, you know, NOT do this?

yeah, let's crowdsource a blockchain that proves car ownership

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Beeftweeter posted:

yeah, let's crowdsource a blockchain that proves car ownership

:thunk: Hm, yes. This is better.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

car is up on blocks chain

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

CommieGIR posted:

:thunk: Hm, yes. This is better.

it can be powered by the cars! they're computers these days, you know

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
yeah i got an nft, a Nice loving Truck

BrianRx
Jul 21, 2007

dpkg chopra posted:

yeah i got an nft, a Nice loving Truck

Aren't you worried someone could just like "right click" on the driver side window and "download" your truck?

Quackles
Aug 11, 2018

Pixels of Light.


Captain Foo posted:

car is up on blocks chain

security fuckup megathread: car is up on blocks chain

Kitfox88
Aug 21, 2007

Anybody lose their glasses?

Captain Foo posted:

car is up on blocks chain

BlankSystemDaemon
Mar 13, 2009



Beeftweeter posted:

that's pretty cool but not unexpected really

if you use a BTLE scanner around here there's a bazillion beacons, i really wish there were some way to just nuke them all
any good sdr will let you see just how much fuckery there is to had if you have the talent for it

Jenny Agutter
Mar 18, 2009

They have some flipper zeroes in stock rn if people are looking for them
the page says unavailable but seems like you can actually order them

Crime on a Dime
Nov 28, 2006

Jenny Agutter posted:

They have some flipper zeroes in stock rn if people are looking for them
the page says unavailable but seems like you can actually order them

how does one order them? the buy button says sold out for me

spankmeister
Jun 15, 2008






Flippers zero

spankmeister
Jun 15, 2008






i got one in my cart but then it says it can't calculate shipping for my address

Jenny Agutter
Mar 18, 2009

Crime on a Dime posted:

how does one order them? the buy button says sold out for me

I clicked this link but they might be gone

https://twitter.com/gmman_bzflag/status/1529912433392766976?s=21&t=LbeAwE1fTmYGob6nWZz81g

Crime on a Dime
Nov 28, 2006
US only :(

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
drat I really want one of those but I don't have enough of a use for it to justify the 180 bucks.

spankmeister
Jun 15, 2008







yeah found that out too 🤬

Adbot
ADBOT LOVES YOU

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Im coordinating the goon group buy

Joke

Rufus Ping fucked around with this message at 11:40 on May 27, 2022

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply