Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Computer Serf
May 14, 2005
Buglord
:siren: /!\ everyone set your clocks back /!\ :siren:

Adbot
ADBOT LOVES YOU

Computer Serf
May 14, 2005
Buglord

Shame Boy posted:

i've got a question about old cryptography that y'all can probably answer: so i know that in world war 2, the allies used that weird robotic voice SIGSALY system for their highest-level communications. what did the axis powers use for that same role? was it just some more complicated variant of a rotor-based system like the enigma machine?


maybe your answer is in this fine book on vocoders
http://howtowreckanicebeach.com/?page_id=14

edit: :thunk: the enigma machine?

Computer Serf fucked around with this message at 01:42 on May 13, 2019

Computer Serf
May 14, 2005
Buglord
All Computers Are Broken!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

Computer Serf
May 14, 2005
Buglord
:tbear:

Computer Serf
May 14, 2005
Buglord
not sure if someone posted this yet, but cisco is bork again
and they named the bug 😾😾😾

THRANGRYCAT DOT COM posted:

😾😾😾 is caused by a series of hardware design flaws within Cisco’s Trust Anchor module. First commercially introduced in 2013, Cisco Trust Anchor module (TAm) is a proprietary hardware security module used in a wide range of Cisco products, including enterprise routers, switches and firewalls. TAm is the root of trust that underpins all other Cisco security and trustworthy computing mechanisms in these devices. 😾😾😾 allows an attacker to make persistent modification to the Trust Anchor module via FPGA bitstream modification, thereby defeating the secure boot process and invalidating Cisco’s chain of trust at its root. While the flaws are based in hardware, 😾😾😾 can be exploited remotely without any need for physical access. Since the flaws reside within the hardware design, it is unlikely that any software security patch will fully resolve the fundamental security vulnerability.

https://thrangrycat.com/

Computer Serf
May 14, 2005
Buglord
thanks cisco :catbert:

Computer Serf
May 14, 2005
Buglord
:tinfoil:

Only registered members can see post attachments!

Computer Serf
May 14, 2005
Buglord
wheres the obscure deep irc fried onion forum where they explain the technical details behind cves

because when a vendor says:

lovely app posted:

An attacker can overwrite or restore files to locations they do not have write privileges to. This can be accomplished via API or via the User Interface.

lovely app posted:

A proxy auto-configuration file, crafted by a lesser privileged user, may be used to execute arbitrary code at a higher privilege as the service user.

that seems to imply some shitlord can just send api requests to everyone running this app and :pwn:

Computer Serf
May 14, 2005
Buglord
without knowing how hosed up this gently caress up is i dont know how much anxiety to allocate :negative:

Computer Serf
May 14, 2005
Buglord

spankmeister posted:

It was probably a good idea in like, the 90's

Computer Serf
May 14, 2005
Buglord
is it normal when an embeded nas suddenly changes its update server to something in china


code:
download.qnap.com.cn.	217	IN	CNAME	download.qnap.com.cn.cloudglb.com.
download.qnap.com.cn.cloudglb.com. 3599	IN CNAME down.fwcdncb.cloudglb.com.
down.fwcdncb.cloudglb.com. 59	IN	A	117.27.232.35
:smithcloud:

Computer Serf
May 14, 2005
Buglord

infernal machines posted:

where do you think qnap as a company comes from?

:gop:

Computer Serf
May 14, 2005
Buglord

Chris Knight posted:

what do you think CNAME stands for?

:ohdear:

Computer Serf
May 14, 2005
Buglord

mystes posted:

Taiwan.

But it is funny how uploading 100% of your private data, location history, etc. to a server in the US is okay but even pinging a Chinese server is automatically Chinese espionage/treason now.

It's also interesting how people are freaking out how AMD licensed it's CPU designs to a company in China because suddenly it's like, "How dare AMD give away American secrets to China?!"

Apparently even Americans who are anti-Trump are 100% on board with the trade war.

idk it was more like, why did the firmware update server suddenly change from
download.qnap.com
to
download.qnap.com.cn

maybe it was just a normal janitoring fuckup :shrug:

tbh anytime a piece of network equipment has an irregular issue like an unexpected reboot i just assume either a teenager or some nation state prob just :owned: my box so i put it in my freezer until i find a proper burial site

:tinfoil:

Computer Serf
May 14, 2005
Buglord

infernal machines posted:

functionally what's the difference between download.qnap.com and download.qnap.com.cn? do they even resolve to different ips?

if qnap wanted to gently caress any of its customers im sure it could just leave an obscure set of vulnerabilites in and have plausible deniability so ultimately its probably just a novelty that the update server changed but it just got me thinking about update servers and end user transparency.

releases might be signed, or if you're lucky the developers will publish checksums but then there's situations like that time some guy handed over one of the largest node.js libraries to another developer and the new guy put malware in it and all the projects using that library pushed to their releases so this is all the more reason why we need an entirely new architecture made up of a network of unhackable laptops and ROM chips

code:
; <<>> DiG 9.8.3-P1 <<>> @8.8.8.8 download.qnap.com
; (1 server found)

;; QUESTION SECTION:
;download.qnap.com.		IN	A

;; ANSWER SECTION:
download.qnap.com.	216	IN	CNAME	dxt6jdtd35g5p.cloudfront.net.
dxt6jdtd35g5p.cloudfront.net. 59 IN	A	13.224.29.16
dxt6jdtd35g5p.cloudfront.net. 59 IN	A	13.224.29.120
dxt6jdtd35g5p.cloudfront.net. 59 IN	A	13.224.29.52
dxt6jdtd35g5p.cloudfront.net. 59 IN	A	13.224.29.95
code:
;; QUESTION SECTION:
;download.qnap.com.cn.		IN	A

;; ANSWER SECTION:
download.qnap.com.cn.	162	IN	CNAME	download.qnap.com.cn.cloudglb.com.
download.qnap.com.cn.cloudglb.com. 3599	IN CNAME down.fwcdncb.cloudglb.com.
down.fwcdncb.cloudglb.com. 59	IN	A	117.27.232.35

CRIP EATIN BREAD posted:

so yeah .cn goes to a chinese only CDN while the .com goes to an aws cloudfront hosted cdn.

everything is in the cloud

Computer Serf
May 14, 2005
Buglord

Lutha Mahtin posted:

lol if u haven't configurated your POS

Computer Serf
May 14, 2005
Buglord

Plorkyeran posted:

i can't imagine any significant number of people actually ever downloaded a forked version of firefox 38

Computer Serf
May 14, 2005
Buglord

Trabisnikof posted:

you need a chill-sec person and a security kraken. follow the chill-sec advice and you won’t attract the worm

:coolspot:

Computer Serf
May 14, 2005
Buglord

Lain Iwakura posted:

so this got posted to the grey thread

saphirecalypso posted:

I have always been a fan of elliptic curve. Is there anything that you suggest which is better?

I am new to these forums.



apparently there is a crypto challenge involved. if you look at his rap sheet it appears that they posted another thread and people took a crack at it

oh weird thats a girl i used to date, we met on linkedin

Computer Serf
May 14, 2005
Buglord

D. Ebdrup posted:

you used to date a porn star?

:confuoot:

technically it was a long distance fling anyway so i'll just accept this allegation at face value

Computer Serf
May 14, 2005
Buglord
whos gonna be debugging that secfuck with the hookers

Computer Serf
May 14, 2005
Buglord

Ur Getting Fatter posted:

after an automatic update windows 10 enabled a hidden "default" user account with no password and admin privileges

apparently this is a known issue since 2016

jfc microsoft

:nsallears:

Computer Serf
May 14, 2005
Buglord

:skeltal:

Computer Serf
May 14, 2005
Buglord

Shame Boy posted:

the kids call it double multi-factor bumping, nasty stuff. one minute you're just trying to secure your amazon account and the next thing you know you're waking up in a cold sweat 3 days later with a bunch of powdered yubikey dust on your nose and all your computers running gentoo

Computer Serf
May 14, 2005
Buglord

Phone posted:

oopsiesec

Computer Serf
May 14, 2005
Buglord

simble posted:

i can only get through about half of an apress book

video gaem speed runners taught me buffer overflows are part of the system and valid if you can finish the level

Computer Serf
May 14, 2005
Buglord
other than ye ole same old economic stratification within gaming world economies, what’s really fucky is how much effort is being put into designing addictive systems to harvest attention

oh wai..

Computer Serf
May 14, 2005
Buglord
remember that presentation from some hell marketing company trying to explain a system that knows how much income each user has, paired with an AI that learns how frustrated you are and adjusts the gameplay and cyber economy to maximize the grift

oh and it secretly maps the layout of everyones home and surroundings through wifi radar magic


https://gamerant.com/microtransactions-ai-artificial-intelligence-document-leak/

Computer Serf
May 14, 2005
Buglord
x86 iddqd godmode bit?

https://m.youtube.com/watch?v=_eSAF_qT_FY

Computer Serf
May 14, 2005
Buglord

Grace Baiting posted:

the useriferous aethernet

Computer Serf
May 14, 2005
Buglord
huh alec uses DoHoT
:allbuttons:
https://github.com/alecmuffett/dohot

seems like a weird threat model but okay

Computer Serf
May 14, 2005
Buglord
they also have a MUD up and running

and someone kindly uploaded the :question:cassette tape:question:

:iiam:

Computer Serf
May 14, 2005
Buglord
op just use an analog camera and process the negatives yourself

Computer Serf
May 14, 2005
Buglord

PIZZA.BAT posted:

starting to lose my patience with nord. i've been having a lot of trouble connecting over the past few weeks and their app gives you no indication of where the problem may be. pretty frustrating!!

nord is pretty wild they spend a shitload of money advertising and apparently somewhere close to $0 on configuring their vpn servers

this is a pretty good list of vpn hosts and caveats
https://thatoneprivacysite.net/

Computer Serf
May 14, 2005
Buglord

Oneiros posted:

i recently spun up a new digital ocean droplet for vpn / dns (pi-hole) purposes 'cause apparently they're offering double the resources for the same price i had been paying and i decided to give wireguard a shot instead of openvpn. super easy to setup, very happy with it so far.

are there any concrete concerns with wireguard, beyond it just being the new hotness and therefore probably actually broken in three dozen facepalm worthy ways?

algo or Streisand will setup encrypted DNS for whatever that’s worth

30 TO 50 FERAL HOG posted:

openvpn is fine but windows 10 does some absolutely mind glowingly dumb poo poo with networking that fucks with any VPN that doesn't specifically use a built in windows tunnel interface and openvpn/basically all ssl vpn just install a virtual 10/100/1000 adapter

just get an openwrt compatible router and install openvpn or wireguard on it and then you can safely remove windows and install gentoo

Computer Serf
May 14, 2005
Buglord
security in my browser?
:nsacloud:
nein danke!

Computer Serf
May 14, 2005
Buglord
how do i secure my cave

Computer Serf fucked around with this message at 10:43 on Aug 19, 2020

Computer Serf
May 14, 2005
Buglord

xtal posted:

Flowers for alg=none

Computer Serf
May 14, 2005
Buglord

Cybernetic Vermin posted:

an experiment already happening on a vast scale. vast enough in fact that it is unfortunately hard to really control for. mental health issues are on the rise among the young, but as they all grew up with both screens and the decay of society it is not obvious which part is the problem.

one of the most disturbing thing I’ve ever seen on the internet is the youtube comments section of spammy animated songs for kids and realizing the gibberish comments are babies smashing keyboards, but in different languages

bad education is the where secfuckups start

Adbot
ADBOT LOVES YOU

Computer Serf
May 14, 2005
Buglord

Methanar posted:

give your laptop your desktop's private key

seems risky, what if someone steals your laptop

xtal posted:

You can just send them to the desktop, remember that you only need to send the public key, which is... public.

ya just add multiple public keys to your servers authorized keys list, there’s an added benefit that you can individually revoke a key

imo it’s best to setup a deadman’s switch on a 15 minute timer so if you’re under duress the servers can safely remove the keys and secure the data with a xor from /dev/urandom

Rufus Ping posted:

Log in with your password via the web serial console and paste the new key into your authorized_keys

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply