Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Kazinsal
Dec 13, 2011



Celexi posted:

Russia has no problem murdering anyone's citizens abroad

ftfy

Adbot
ADBOT LOVES YOU

Kazinsal
Dec 13, 2011



tres gatos enojados posted:

An attacker with root privileges on the device can modify the contents of the FPGA anchor bitstream, which is stored unprotected in flash memory.

wait hold up, you need root access?

so, you need to have already pwned the box?

Kazinsal
Dec 13, 2011



Subjunctive posted:

Serious Hardware / Software Crap > YOSPOS > Security Fuckup Megathread v18.2 - of course it was Lenovo

Kazinsal
Dec 13, 2011



James Mickens' bit on the Mossad/Not Mossad Threat Model is something that deeply applies here

Kazinsal
Dec 13, 2011



flakeloaf posted:


brb handcrafting a gig economy bailiff app

bailyft

Kazinsal
Dec 13, 2011



Lutha Mahtin posted:

ONLY TRUST YOUR PUNCHCARDS

ECC WILL NEVER HELP YOU

Kazinsal
Dec 13, 2011



I honestly don't get how companies don't have any email from taviso immediately go to every important security person plus maybe their phone system to ring a few SIP enabled klaxons

Kazinsal
Dec 13, 2011



malware? on my tv?

it's honestly about as likely as you'd think

Kazinsal
Dec 13, 2011



governments get ltsb, users get automatic updates

and can we just kill off any non-enterprise version of win7 already

Kazinsal
Dec 13, 2011



we got dudes to the moon and back with a 2MHz guidance computer with 4KB of RAM and 72 KB of ROM

goddamn surgical life support needs windows updates though

Kazinsal
Dec 13, 2011



page torn from a notebook and stuffed in your wallet

Kazinsal
Dec 13, 2011



drat and I had already moved on to the eat monopoly -> poo poo connect four stage

Kazinsal
Dec 13, 2011



same with webex these days, though you can't host a screenshare through the WebRTC client

Kazinsal
Dec 13, 2011



I did two years of basically an associate's diploma at a polytechnic institute where the course material was CCNA+CCNP and some microsoft and oracle bullshit and the company I still work for handed me a job and a relocation bonus before I had even finished the program up. but to be honest, if money weren't everything in this hosed up world and having a job wasn't something I needed I'd go back to school, maybe do something in the humanities. leave tech behind and wander off into the library.

if it were 1972 I'd want to go into compsci research but every actual game-changing research paper has been written and everyone's research now is on how to make a computer be more efficient at upscaling video games or cross-referencing and identifying minorities' psychological pressure points from a blurry security camera frame and raw access to facebook's internals

Kazinsal
Dec 13, 2011



mystes posted:

If the FBI was investigating, openbsd probably knew about it, and as long as they had any backups (even if not signed) they could presumably have looked at them to see if anything was changed?

this is probably a fair assessment considering that the openbsd people are (rightfully) possibly the most security-conscious and/or paranoid bunch on the planet

Kazinsal
Dec 13, 2011



that sounds less like a math paper and more like an aggressive arg for the new tool album

Kazinsal
Dec 13, 2011



Shame Boy posted:

my credit union's online banking system required 8 character number-only passwords until a few years ago. like not alphanumeric, literally just numbers.

to their credit they have since overhauled basically everything and their login system is actually somewhat acceptable now.

mine did the same but until the recent overhaul it was seven digits. I'm sure 90% of people's online banking passwords there were just their phone numbers

Kazinsal
Dec 13, 2011



cinci zoo sniper posted:

there's like half a dozen of competently put together torrent clients that are at least semi-actively maintained/developed

yeah qbittorrent and deluge are still alive and kicking. no idea what exists in the realm of CLI poo poo but chances are nobody bothered to buy the torrent equivalent of lynx for adware distribution

Kazinsal
Dec 13, 2011



Kazinsal
Dec 13, 2011



Dumb Lowtax posted:

is doing Meth a common thing among 10x programmers, and also how is any of this website still functioning

it's just a little 10am crank to get search working what could possibly--

Kazinsal
Dec 13, 2011



esports competitions have drug testing now because a couple counterstrike teams were pumped to the gills full of adderall during a major tournament a few years ago

Kazinsal
Dec 13, 2011



it continues to amaze me that so many people use an an anonymity suite developed by the US Navy for so much incredibly illegal poo poo

Kazinsal
Dec 13, 2011



in the same way that I'm looking forward to seeing the results of the impending climate catastrophe I'm looking forward to seeing how nbsd manages to out-nbsd himself when he's off his ban+30 in a week

Kazinsal
Dec 13, 2011



Volmarias posted:

"When spies talk to each other

"what? spies in my computer? healthcare espionage? and they can do this because of encryption? that's scary! encryption is now illegal" - judge dipshit q. lawmaker

Kazinsal
Dec 13, 2011



infernal machines posted:

seriously though, how did no one realize this when they were developing it? if they did realize it, why did they keep developing it?

because faster performance on what the user sees and is interacting with means more cycles in which to snag advertising data

Kazinsal
Dec 13, 2011



ewiley posted:

oh boy, working with a group that is stuck on win10 1703 for a variety of reasons. there IS a patch for win10 1703 for the Surface Hub which you can extract and use to patch crypt32.dll but goddamn what a hack :moonrio:

according to enormous CSV of files in each rollup, KB4534296 has the patched crypt32.dll for 1703.

Kazinsal
Dec 13, 2011



graph posted:

the best part about the netscaler poo poo is that no one from citrix bothered to reach out to any of their customers

on top of that they've released patches for an end of development version and the previous LTS version but not the latest or current LTS versions

citrix: because gently caress you for following recommendations

Kazinsal
Dec 13, 2011



Subjunctive posted:

I used netscalers before the Citrix acquisition and they were awful then too. many pained exchanges with their support and engineering to discover that the documentation was omitting yet another way in which they violated the HTTP spec

I'm looking forward to ripping ours out and replacing them with literally anything else

Kazinsal
Dec 13, 2011



ewiley posted:

i don’t disagree I think azure MFA is great, but I’ve had a dozen or so active phishing campaigns specifically target my users assuming we use Microsoft’s default logins and typo squatted domains similar to ours.

same here on the phishing campaigns, even though we don't have azure mfa implemented. it feels like they just shoot them at any corporation with exchange 365. thinking about giving duo a shot though.

Kazinsal
Dec 13, 2011




:nsavince:

Kazinsal
Dec 13, 2011



so does gnu avatar twitter mans think we should replace every instance of ret with `pop r11; lfence; jmp r11;` or what

Kazinsal
Dec 13, 2011



lowtax's 9k/month patreon going to good use

Kazinsal
Dec 13, 2011



I wonder how bad NFS for windows clients is these days

Kazinsal
Dec 13, 2011



Pile Of Garbage posted:

if you BYOD then sorry but you hosed-up.

agreed - at the very least, consumer CPUs have had hardware virtualization acceleration for over a decade so there's no reason not to VPN into work through a virtual machine with no access to your home network.

Kazinsal
Dec 13, 2011



redleader posted:

the what now

oh poo poo

wow, I'm actually kinda glad we dogfood the cisco products we sell now

if webex does that I haven't found the bit in the admin portal that spills its guts about it

Kazinsal
Dec 13, 2011



it's been a good while since SA got subpoenaed. usually it happens because of d&d though

Kazinsal
Dec 13, 2011



lmao you're scamming an illegal casino

you're going to get whacked you loving idiot

Kazinsal
Dec 13, 2011



most anticheats have a ring0 component. the difference with vanguard is that it loads at boot instead of on-demand so it can't be hooked at load time by cheat software

Kazinsal
Dec 13, 2011



mystes posted:

Anticheat software does really crazy stuff that you aren't supposed to do, which is why it keeps breaking new versions of windows. I'm surprised Microsoft even allows them to continue doing these things but I guess they're worried it would hurt the pc gaming market.

yeah, I've been involved in the development of anticheat software before, and despite only ever doing user mode stuff we still did some frankly wonky stuff to catch people doing dumb things to our game. it worked because very few people were willing to shell out for crazy poo poo like pcie cards that gently caress with the game's memory by busmastering and DMAing poo poo you tell it to.

Adbot
ADBOT LOVES YOU

Kazinsal
Dec 13, 2011



gently caress, terrible snipe on my part

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply