Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Winkle-Daddy
Mar 10, 2007
was this posted already?

https://twitter.com/LasVegasLocally/status/1704986596439941601

that's not nearly enough money lmfao

Adbot
ADBOT LOVES YOU

Winkle-Daddy
Mar 10, 2007

Zamujasa posted:

i feel like i remember LVL (that twitter) being not on the up and up so i'd push x to doubt on that one until i saw the actual real job posting

especially considering the hack was supposedly social engineering, immediately jumping to hire someone with incredibly lovely conditions reeks of bs

no clue, hopefully that's the case since this seems woefully ill thought out otherwise.

Winkle-Daddy
Mar 10, 2007

thanks, I hate it.

Winkle-Daddy
Mar 10, 2007
anyone ever figure out why Facebook poo poo the bed yesterday?

Winkle-Daddy
Mar 10, 2007

post hole digger posted:

going to stop you right there

"lol"
- former oracle engineer for oke

Winkle-Daddy
Mar 10, 2007
because oracle was a joke

Winkle-Daddy
Mar 10, 2007
yeah, OL with the unbreakable kernel is still a thing afaik.

does this thread like spicy CAB forum chat or is that too in the weeds. either way, this seems...uh... https://bugzilla.mozilla.org/show_bug.cgi?id=1883843

Winkle-Daddy
Mar 10, 2007

Subjunctive posted:

really looking forward to the “but dad, I don’t waaaaannaaaaaa” non-revocation incident too

it's so loving wild and terrifying to me that such a fundamental part of web trust is basically non profits and corporations in loose agreement to follow some BRs. this_is_fine.jpg

e: this seems pretty flagrant. I've not seen any appetite for disciplinary action in years. kind of hope this changes that...

Winkle-Daddy fucked around with this message at 04:49 on Mar 16, 2024

Winkle-Daddy
Mar 10, 2007

shackleford posted:

fuckin' lol that entrust guy on the mozilla bug is the vice chairperson of the CA/Browser forum

https://cabforum.org/about/leadership/#current-cabrowser-forum-chair-and-vice-chair

... I'm just gonna scream into my pillow for a few minutes. brb.

Winkle-Daddy
Mar 10, 2007

Wiggly Wayne DDS posted:

chrome root program jumping into the entrust debacle: https://bugzilla.mozilla.org/show_bug.cgi?id=1883843#c19. rather than quote everything i'll just include their questions:

and their abuse email isn't handling certs within 24h: https://bugzilla.mozilla.org/show_bug.cgi?id=1885754

Ryan has activated beast mode, holy hell lmao

e: I only heard about this because a buddy of mine is on his compliance rotation at work where he has to read all these bugs and see if there's any lessons to be learned. he saw this and started immediately sharing it lol.

Winkle-Daddy fucked around with this message at 17:51 on Mar 18, 2024

Winkle-Daddy
Mar 10, 2007

FlapYoJacks posted:

Ryan fucks.

that's why he was on parental leave

Winkle-Daddy
Mar 10, 2007
anyone know what's going on with ez anti cheat? did they get owned? is it time for another round of mocking smooth brains defending ring-0 anti cheat?

Winkle-Daddy
Mar 10, 2007
some more sharable reading on this issue: https://webpki.substack.com/p/entrust-mis-issues-a-certificate

thanks Amir!

Winkle-Daddy
Mar 10, 2007
I wonder if Google slack has a channel called #all-the-ryans and everyone named Ryan hangs out there sharing Ryan memes and just generally having a really good time :allears:

Winkle-Daddy
Mar 10, 2007
my laughter is starting to give way to just feeling really bad for entrust dude. :(

hope he's taking some form of spring break soon

Winkle-Daddy
Mar 10, 2007
fair counterpoint. get destroyed by the Ryans, Paul.

Winkle-Daddy
Mar 10, 2007
don't scare the idealists away, we need them to make a better future :ohdear:

Winkle-Daddy
Mar 10, 2007
in like 2007 when I was doing tech support for Adobe products, the Adobe trainer told us they make more money licensing postscript than all their creative products combined. the font folio and ps licensing gave them the gently caress you money to buy Macromedia flash. idk if this is true but I believe and perpetuate it.

Winkle-Daddy
Mar 10, 2007

Subjunctive posted:

not for EV (derogatory)

Winkle-Daddy
Mar 10, 2007
just finished the entrust update. that was rough, lmao. I suspect the groveling will be deemed sufficient.

Winkle-Daddy
Mar 10, 2007
Amir owns

Winkle-Daddy fucked around with this message at 15:26 on Apr 10, 2024

Winkle-Daddy
Mar 10, 2007
I should buy amir an account.

Winkle-Daddy
Mar 10, 2007
CAB forum rules now state a CA must monitor the sec fuckup thread for incidents and amusement

Winkle-Daddy
Mar 10, 2007

Wiggly Wayne DDS posted:


yes that post was too into the weeds. for sure. definitely.

I meant too in the weeds to be interesting or funny. if only I'd been able to see what was to come.

Winkle-Daddy
Mar 10, 2007

Wiggly Wayne DDS posted:

don't worry they did offer to do that because it's a weird mess! almost as if one party isn't capable of following the rules and is flooding the board with issues.

anyway i was phoneposting 5m ago so here's the actual quote on their tooling

https://github.com/certainsecurity/phasnoo/blob/main/x509/x509.go#L2238

:classiclol:

Winkle-Daddy
Mar 10, 2007
god I wish "Apparently some participants in the discussion forum did not understand the European approach to the matter" wasn't too long for a thread title.

e: it's for the best, they're coming fast this week

Winkle-Daddy
Mar 10, 2007

Captain Foo posted:

pki is a gently caress
revoke em all 219
i am bugzilla man
26624 mis issued certs

Adbot
ADBOT LOVES YOU

Winkle-Daddy
Mar 10, 2007

Subjunctive posted:

unrelated:

ok wait I’m hearing that the Palo vuln that destroyed the world is a loving ../ traversal bug in HTTP handling?

for real? for real real?

I reviewed access logs in TYOOL 2023 that showed some site was owned via url injection on a loving download.php file lmao -- the fact it wasn't popped in like 2014 was what impressed me most. it turns out that while technology may not be cyclical, vulnerabilities are.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply