Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
https://www.warbyparker.com/pd/instructions



supposedly the site is a legit optician but lol at this perfect-for-phishing process

Adbot
ADBOT LOVES YOU

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
Someone claims to have broken the SIMON cipher on shorter keylenghts

https://eprint.iacr.org/2019/474

but the whole document is...weird

https://twitter.com/colmmacc/status/1127100892883312640

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Munkeymon posted:

English as a Language Lerned After the Age of Five or ELLAAF

are you having ELLAAF?

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
still lolling at the fact that pressing backspace a few dozen times was a grub exploit

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Cybernetic Vermin posted:

i originally found thompsons 'trusting trust' talk (you know the ones, the impossibility of figuring out a backdoor inserted by a compiler by source inspection), but it comes up pretty often in this kind of conversation: yeah, no poo poo, you can't trust anything. your intel-based laptop comes with three operating systems installed, and you can only have an effect on the one that is least trusted and loads last.

i peered down the rabbit hole a bit today and got pointed at https://savannah.nongnu.org/projects/stage0 - a process for bootstrapping an OS install from a few hundred bytes of hand-inspectable assembly code

still, that doesn't take care of the hardware side of things - I guess the only way to be 100% sure your computer is doing what you intend it to do is to revert back to mechanical computers, like you can't even wire up a CPU from transistors or ttl components because there's a nonzero chance someone placed tiny malware in the transistor packaging

of course, this is purely academic because not even the us military is that paranoid about their hardware

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
in the future, 90% of bluetooth bandwidth will be apple devices endlessly confirming their own location to each other

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
facebook's new blockchain seems to require everyone to verify with a government issued photo id

as if they don't already store way too much data about you

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

ewiley posted:

Oh look another worthy kickstarter, can't wait to see how this turns out :munch:

https://twitter.com/GossiTheDog/status/1144127167216988160?s=20

e: duh i should read upthread

this is just two laptops glued together back to back where one has the wifi chip smashed

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
do android/ios still have permissions as "pretty please do not do this" or are they actually blocking system calls that the app haven't been given permission for

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
but why the gently caress do apps have access to the list of visible APs

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Boiled Water posted:

why not just eight characters but you have to change it every two weeks?

15+ characters means it won't be converted to weak LM hashes anywhere, because LM splits the password into two 7 char blocks and hashes each piece individually

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Rex-Goliath posted:

it's really surprising seeing how much bad information there is out there regarding credit in general

is it really, when a lot of the bad information directly benefits the banks

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

*nervously clicks link, reads article, sees name of site, sighs in relief*

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
I hope they only upload libraries when on a wifi connection, because some of those libraries can be pretty large

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

love all the replies that complain about it being released on a friday and they can't fix poo poo until monday



the patch has been out for months

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
I still laugh when I get mails with "hey, [real name], click here to see your latest Paypal transactions"

I'm like 75% sure it is legit (got my real name and written in my native language) but I've never clicked the links in the mail, that all go to the dodgy looking "epl.paypal-communication.com" which people online are hotly debating whether is legit or a scam, but it DOES have a valid Paypal TLS certificate.

If those are legit, Paypal is basically doing its best to appear dodgy as gently caress.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Ur Getting Fatter posted:

it’s gonna be all of them

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Chalks posted:

Does it matter as long as they're able to repeat the character sequence consistently?

but what if they aren't

like they get a new phone and suddenly it uses another representation of national characters/smiles (yes I know they should be done in canon unicode but you know, software)

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
https://www.youtube.com/watch?v=WVDQEoe6ZWY

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
normal brain: blacklist login attempts after x number of failures


galaxy brain: always fail the first time when password and 2fa is correct, a real user will just try again

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

mystes posted:

When people say that piracy is easier than dealing with the fragmentation of streaming video services now, I'm pretty sure that this flowchart is not what they're envisioning.

people pay pirate sites so the sites can do all the flowchart stuff and the end user just press play in their mobile app

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Djeser posted:

one time spotify somehow caused a collision between someone else's account and my own, which deleted a bunch of my playlists but let me broadcast music to their computer

being a lovely memelord i played smash mouth at full volume, but then i changed my password to be safe and that fixed it somehow

facebook as auth bites another company in the rear end, I guess

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
worse: a snapchat dump which contains every image ever sent on the service

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
Protip: Hackers expect passwords to be complicated, so just use "secret" and "password" because they will never guess it's that simple!

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
why the gently caress does their AES encryption key contain the string "RSA1" and tons of zeroes

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
waiting for the moment where intel just says "gently caress it, side channel attacks on the desktop is a non issue"

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
just flatten and reinstall

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Tankakern posted:

the magic of gentoo is that you'll never feel the need to do a reinstall, so if you did bother to set up a kde system as you'd like, you're set for life

kde has really good support on gentoo too, using it to write this post atm

I've started my factorio games from scratch like a 100 times now because I felt it became a convoluted mess instead of a pretty base


I fear what I would become if I tried to install gentoo

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
There is never a system in gambling.

edit: If you want people to believe you, explain the system. Unless you're literally exploiting a blatant flaw in some RNG or something, there is never a system.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
Teach your wife to do the system. Then she can earn money and keep it in her account, out of your reach.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
the best ending of all of this is if the bitcoin gambling site is so obviously flawed that everyone that plays there discover it


but it is a ruse, the site did it intentionally, to make you deposit more butts, and you will never be able to withdraw beyond a small amount to account for "test withdrawals"

(USER WAS PUT ON PROBATION FOR THIS POST)

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
"please break your security model for us so we can peddle useless antivirus solutions"

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
im just gonna go hog wild and assume that they work in area 51

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
server side analysis is also much more prone to false positives, in contrast with client side countermeasures

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
also people cheat just to troll

i bought dark souls remastered on steam at launch, and within half an hour some cheater had broken my savegame irreversively, because there was no anticheat at all, and all the old hacks still worked

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
the only good thing about the old way of keeping data and executables in the same directory was that uninstaller programmers had to be slightly more careful so they didn't nuke some user's data files


also doesn't installshield and nsis and poo poo register every file that they install so you can just go "wipe this list of files, kthx"?

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock


is it possible that this is an exploit payload and that's how it looks on non-vulnerable phones?

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
remember the services where you could send WHATIS keyword or something as a SMS to a number and you would get a wikipedia snippet back and it cost a few dollars each time

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

suffix posted:

tbh i was confused because "turn off exposure notifications" sure is a wording that sounds like it would disable notifications but not the tracking

product idea: a camera with a bluetooth receiver you put by the door and it tells you when any of your employees/customers mark themselves as having covid

Well, there is no actual tracking in the normal way, the only time something gets sent to the server is when the owner of the phone has/had Covid

Adbot
ADBOT LOVES YOU

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
there are lots of regional apps that don’t use the google/apple api and instead do actual location tracking on their own which gets sent to the cloud and nsa

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply