426
General Software Discussion / Re: TeamViewer hacked?
« Last post by Stoic Joker on June 06, 2016, 06:59 AM »http://arstechnica.c...n-mass-account-hack/
After reading through the comments there.
Okay, this is getting ugly - where's the popcorn?
With the massive justificational back and forth, the thing that seems to be most consistently appearing is the ability of - the attackers - computer to guess X passwords per second ... which automagically makes most - if not arguably all - passwords less that 20 something characters "easily guessable. And then the "need" for 2FA get's brandished over, and over, and over... *Sigh*
Why does everybody keep glossing right past lockout limits?? I mean WTF - If a system like that is allowing 3+ login attempts per second - like anybody can actually type that fast... - without locking down the account. I don't care how many whoop-de-do factors they have in place, their system is fundamentally flawed...and the fault is theirs.
After reading through the comments there.
Okay, this is getting ugly - where's the popcorn?
With the massive justificational back and forth, the thing that seems to be most consistently appearing is the ability of - the attackers - computer to guess X passwords per second ... which automagically makes most - if not arguably all - passwords less that 20 something characters "easily guessable. And then the "need" for 2FA get's brandished over, and over, and over... *Sigh*
Why does everybody keep glossing right past lockout limits?? I mean WTF - If a system like that is allowing 3+ login attempts per second - like anybody can actually type that fast... - without locking down the account. I don't care how many whoop-de-do factors they have in place, their system is fundamentally flawed...and the fault is theirs.

Recent Posts

)- that can make virtually any application available to pretty much anything. I even got our internal LOB application to run on my cellphone acceptably for quick stuff in a pinch. It leverages (desktopless) RDP for the delivery mechanism so iOS and Android devices can be used to access internal resources as well.
And .exe is not the only 'executable' code, Flash, Java, JavaScript, and friends all have options to reak havoc if applied in that fashion...and once again: There is no security blocking access - by the current user - to the current users files...and those are ransomware's target. That's precisely what makes the damn thing so freaking dangerous.