Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Vomik posted:

Idgi. what specifically are you investigating dashlane for?

1Password, lastpass, and dashlane all have pretty much the exact same functionality and use.

dashlane costs more but it has a vpn and some other items. included. they all have emergency contacts which you don’t have to setup.

dashlane is also originally (?) from france so I suppose it may have stricter data regulations... depending on if they’re used or if it matters since they have servers in the US who knows.

in terms of a copy... I guess but in the same sense lastpass is a copy of 1password.

you could always use keepassXC which has the EFF seal of approval.

this is a garbage response and you don't seem to get the spirit of this thread

i'm saying that lastpass looks like trash and there is little on their website documenting how it even functions

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Wiggly Wayne DDS posted:

and also this dashlane product people speak of

that too. my brain categorized it as the same I guess

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
considering that one of the mars viking missions ended because an engineer mistakenly sent a command to turn down a receiving antenna...

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/iangcarroll/status/1155986280234119170

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
psst this is the security fuckup thread, not the finance and credit one

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
good thread title

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i dropped out third year into my bachelors and hold a decent infosec job

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/whid_injector/status/1157976716196941824?s=21

This is how you get on a list somewhere.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
government backdoors will work and will not be exploited by anyone

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/katelibc/status/1159355614704783360?s=21

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
ground floor

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
use emojis

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

CommieGIR posted:

So, we're SEIM shopping, down to Secureworks, Logrythm, and Splunk.

But now it looks like they are not going to allow us to budget for any of them, and we are not renewing with Symantec for MSS, because its garbage.

I'm trying to develop a fallback plan around ELK if we can't get the C levels to sign off on any of our picks.

whatever happens, don’t do logrhythm

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

CommieGIR posted:

That's the gist of what we've been getting, but Splunk is outrageously pricey. Logrythm is desperate because they are losing customers right and left.

But at this point, Symantec's is so bad that Logrythm might be honestly better, especially if we are using a Managed Services to actually configure and filter. So we can tie deliverable to it and call them out on it via contracts if they cannot.

I'd preffer ELK or Splunk.

go with ELK

you can find consultants who'll work with you and logrhythm is a sinking ship

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

The Fool posted:

Tangentially related to ELK, do you have opinions on Graylog?

e: link, https://www.graylog.org/

zero

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

hasn’t avast done this before?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
and people wonder why my hatred for AV runs deep

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Subjunctive posted:

the alerts are stored in the balls

this post needs to get more love

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

pseudorandom posted:

If they had a sign that said "wouldn't you rather drown in drinks than alerts" and then had a liquor pit, then I'd be interested.

to be honest it would be an even worse toxic waste pit

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Cocoa Crispies posted:

I feel like I’ve heard a million people talking about splunk and elk stack all weekend

either I’m finding a pattern where none exists or I’m lucky to not have to store and search logs

tbh it's a good chunk of my job and something that have gotten pretty adept with in the past decade

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Subjunctive posted:

Lain's a dudette, dude.

it was a joke about my getting... everything removed

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

COACHS SPORT BAR posted:

https://mobile.twitter.com/zer0pwn/status/1158433002239746048

0-day for kde disclosed, apparently without any attempt to report it to the devs. lol

when there are only three users of kde, why not just use twitter?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Janitor Prime posted:

https://mashable.com/article/dmv-vanity-license-plate-def-con-backfire/

Idiot buys vanity NULL license plate, some system somewhere starts sending him a bunch of unpaid tickets. :owned:

Droogie is an old friend of mine. I should ask him about this sometime

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
some kids are probably going to jail

https://twitter.com/Techmeme/status/1161348231911104513

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
I’ve worked somewhere on the receiving end of taviso

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Captain Foo posted:

I would like to know more

but I suspect nda

it has been years and it wasn't so bad minus him giving a talk on the whole matter and work getting uppity about me being at said conference, fearing that the media would somehow figure out that i worked for them

i don't really care anymore but taviso does strike fear into some companies and i know this first-hand

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
your butt plug is a piece of poo poo

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Volmarias posted:

My bank just magnanimously informed me via email that my contactless credit card that I never wanted nor asked for is now on the way since I'm such a good customer.

How currently hosed is this technology and do I have to wrap my card in tinfoil now?

Tap is better than chip because you’re not having liability shifted to you.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
anyone doing defendcon next month?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/ItsReallyNick/status/1163638087773229056

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
there were politicians and Christian Right folks in Ashley Madison

it is how one of the Duggars lost their job

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://seclists.org/fulldisclosure/2019/Aug/24

quote:

Hard-coded credentials on ProGrade/Lierda Grill Temperature Monitor [CVE-2019-15304]
From: tim () tepatti com
Date: Sat, 24 Aug 2019 23:50:36 -0400
[Author:] Tim Tepatti
[Website:] tepatti.com

[Title:] Hard-coded credentials on ProGrade/Lierda Grill Temperature
Monitor [CVE-2019-15304]

[Product:] Grill Temperature Monitor
[Manufacturer:] ProGrade / Lierda
[Affected Version(s):] V1.00_50006
[Tested Version(s):] V1.00_50006
[Vulnerability Type:] Use of hard-coded credentials (CWE ID 798)
[CVE Reference:] CVE-2019-15304


[TL;DR:]

ProGrade/Lierda Grill Temperature Monitor V1.00_50006 has a default
password of admin for the admin account, which allows an attacker to
cause a Denial of Service or Information Disclosure via the
undocumented access-point configuration page located on the device.

[Long Info:]

ProGrade/Lierda Grill Temperature Monitor V1.00_50006 has a default
password of admin for the admin account, which allows an attacker to
cause a Denial of Service or Information Disclosure via the
undocumented access-point configuration page located on the device.

The access point configuration page is never made known to the end
user - the user is never supposed to access it or change any of the
options, and as such, the end user has no idea that an attacker could
access this page. This is different than a normal access point or
internet router where the administration page is required for setup
and configuration, and the end user is made aware of the risk of
default credentials. This makes the vulnerability more severe because
the attack vector is something which the end user wasn't aware even
operated on their device.

Additionally, there were two vendors provided because Lierda is a
wholesaler who actually created the device, and ProGrade simply
re-branded the device for the American market. This way, both
customers will be aware of the security vulnerabilities in the
product.

[Technical Info:]

[Default Web Server IP:] 11.11.11.254
[Default Web Server Port:] 80

[Reference(s):] http://progradegrill.com/wifi-grilling-thermometer/

i am the grill master who cannot visually determine if the meat is ready

tbf i am vegetarian so i wouldn't know somewhat

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
this june oven just made me lose my poo poo

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
fortinet has scummy recruiters

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/campuscodi/status/1167440284269121540

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/TwitterComms/status/1167591003143847936

SMS :allears:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Carbon dioxide posted:

I don't, I just 'know' the tech guy on IRC.

BTW, the passwords in the forums leak were MD5 hashed.

no salt too eh

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/dnsprincess/status/1168274528650301441?s=21

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/BulletinAtomic/status/1168306294702432256

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply