Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
traditional banks can’t make a person-to-person payment system safe and I’m saying that as someone who bought a shmoocon ticket in a dark alley in Berlin

Adbot
ADBOT LOVES YOU

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

endlessmonotony posted:

... what happened to June, July and August?

black hat/def con talk hype wasteland

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

fins posted:

netcat

not e2e, what you want is openssl s_client and openssl s_server (with openssl x509 to generate key material)

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

COACHS SPORT BAR posted:

got sucked into a chat with multiple other people? Lol guess what you can't leave that chat, and you're gonna get notifications for every single thing said by anyone

nah you can leave a group chat, but if you accidentally add someone you can’t remove them

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

COACHS SPORT BAR posted:

not from the desktop client you can't

lol

yeah signal would be great if the UI was finished

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

haveblue posted:

they learned nothing from the xbox (the first xbox, which was called the xbox 1)

which was probably designed at the same time as modern tpm poo poo

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Potato Salad posted:

inertia is a property of matter

lol I can't read that without thinking of "bill maher the n-word guy"

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Jabor posted:

I'm the binaries checked into source control, which may or may not be compiled from the accompanying code.

security skills are distinct from “using git” or “writing complex software”

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Soricidus posted:

it's been 2 years. microsoft released patches for everything, even operating systems that had been EOL for years. how the gently caress are people still vulnerable to those nsa exploits.

the only person who installs the post-eol updates for windows xp pos ready is fishmech

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Subjunctive posted:

loved his screenshot LP of this!

“their” iirc

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
when I read "A Canadian man who sold encrypted BlackBerry smartphones to criminals worldwide that enabled them to sell drugs and even plan murders while avoiding the prying eyes of law enforcement was sentenced Tuesday to nine years in prison." I thought "oh they finally got Jim Balisille"

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

PCjr sidecar posted:

useful for all those times your writing dns packets by hand, i guess?

still unclear why it’s important firefox allow them in urls

or really, curl

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Proteus Jones posted:

He did say it was a memory corruption thing, but won't be anymore specific until the patch is released or 90 days pass.

I mean 90% of arbitrary code execution can be classified as "memory corruption"

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Subjunctive posted:

you install a custom firmware which displays a nonce at boot, and then you know if it got written, maybe

how’s a picture of aatrek going to help with that

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shaggar posted:

it should be harder. its too easy for old people to use and they clog up the self checkout lanes.

yes, that's how it works

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

mystes posted:

The description posted earlier made it sound like other phones would add the location (encrypted by the public key) so if that's correct the devices being located wouldn't need a way to locate themselves.

It does seem like a lot of overhead though.

could probably use less it by doing less if you see more iPhones nearby

and not broadcasting if you’ve been unlocked recently, or are talking to a currently-worn watch

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

BIGFOOT EROTICA posted:

the point is you go and recover it yourself with 3-4 friends and your firearms

or it’s to make apple poo poo not worth stealing so lost device recovery is about just going to where you lost the thing

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
beta tested in the future

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

pluggin for popular php app allows xss? what is it, 2004?

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shame Boy posted:

why is there a bitcoin in that phone

did they steal that graphic from a bitcoin website

u can pay select cellebrite employees in bit coins to unlock a phone if you’re not a cop

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shame Boy posted:

lol sarnsung deleted the tweet about the TV antivirus

"do you have any idea how bad a tweet telling people to anti-virus their tvs makes us sound?"
"ok so will you make the tvs not need anti-virus software?"
"no, we just won't tell people they need it"

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

flakeloaf posted:

to postpone this virus scan for four hours, stand up and yell "MCAFFEE"

only do this if he isn't near you, otherwise you're a snitch

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shame Boy posted:

i heard if you say his name three times in front of a mirror in the dark when you turn the lights back on he appears in the mirror and reads the entire john galt speech and if you don't listen to the whole thing he pulls you into his mirror hell dimension

ugh I can't imagine how awful life in the libertarian party must be

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shame Boy posted:

i heard if you say his name three times in front of a mirror in the dark when you turn the lights back on he appears in the mirror and reads the entire john galt speech and if you don't listen to the whole thing he pulls you into his mirror hell dimension

alternate ending: free trip to Belize!

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Raere posted:

Thank goodness for FIPS

FIPS mode is the greatest

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

I love everything about hosed up RNGs that leads to hardware recalls, like the previous yubikey 4 vuln

https://crocs.fi.muni.cz/public/papers/rsa_ccs17

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

my most charitable reading is that the maker of that usb sells a catered seminar about phishing

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

mystes posted:

Doesn't the instance's IP change when you restart it?

no

https://aws.amazon.com/ec2/pricing/on-demand/#Elastic_IP_Addresses

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
Extinction Level Event for FIPSmode yubikeys

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Farmer Crack-rear end posted:

do you guys think there's gonna reach a point where organizations decide it's more convenient/feasible to simply roll back automation/networking/computerization than to try to deal with computer security, and if so how far away do you think that day is

the costs of automation won't be recognized until we're hiding from autonomous death robots like in "breath of the wild"

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
seems good, keeps every dumb rear end real estate guy from knocking on my door at the ungodly hour of 9am to ask me about how owned they are

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

CRIP EATIN BREAD posted:

when my stepmother had brain cancer and she had to get surgery, i was shocked by the surgeon who talked us and told us "there's nothing to worry about, nobody dies during brain surgery".

that's some fishmech level "well they stopped the surgery so they could die not in brain surgery" nitpicking

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

akadajet posted:

did star citizen come out?

that can be kind of a personal question,

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Potato Salad posted:

Security podcasts. Go.

you’re not my supervisor

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Kuvo posted:

https://www.zdnet.com/article/7-eleven-japanese-customers-lose-500000-due-to-mobile-app-flaw/

However, in a mind-boggling turn of events, the app contained a password reset function that was incredibly poorly designed. It allowed anyone to request a password reset for other people's accounts, but have the password reset link sent to their email address, instead of the legitimate account owner.

I’m shocked a big Japanese company would make a security fuckup of this nature

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shame Boy posted:

you'd do stuff like conveniently not fix security vulnerabilities found by said state security agency, or other plausibly deniable things like that.

yeah this really seems like how it works, see https://en.wikipedia.org/wiki/Zerodium

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Cybernetic Vermin posted:

the gigantic corporations don't run a linus-blessed kernel, and have no intent of doing so.

in practical effect redhat controls the kernel that is used.

also, consider every android, running a 6-year-old kernal that every intern at Qualcomm has hosed with

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Raere posted:

Why even bother having severities when 99.43% are high

it's probably commutative where if you depend on something with a high sev vuln you have one too

and because js has basically no standard library beyond import() if there's a flaw in "is-positive-integer" or "string-length" lmao every package is busted

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Ayin posted:

the current edition of rpgmaker finally moved on from ruby... to javascript

ow oof

Adbot
ADBOT LOVES YOU

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
yeah I like to bcrypt my passwords

B
C
R
Ystore
Plaintext
T

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply