topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Thursday March 19, 2026, 12:27 pm
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Recent Posts

Pages: prev1 ... 177 178 179 180 181 [182] 183 184 185 186 187 ... 246next
4526
Living Room / Re: Microsoft unveils new UI prototype - Windows 8?
« Last post by Stoic Joker on February 27, 2011, 11:49 AM »
As I understand, Surface is still thousands of dollars. It will be a little while before that technology is affordable for the mass market.

The thousands of dollars part was only for the infrared camera (in the base to watch for fingers), and the commercial (restaurant) quality heavy Plexiglas tabletop for the UI. The software was fairly basic and the computer used for all the back-when demos was a bog standard off-the-shelf machine.

With the touch screens available today, all MS really needs to launch it is an OS designed around it and an updated marketing plan.
4527
General Software Discussion / Re: Windows 7 SP1 released
« Last post by Stoic Joker on February 27, 2011, 11:42 AM »
Okay, running with Win7 x64 SP1 now on the home dev machine. Haven't done much (just logged in after reboot), but it went surprisingly quick (5-10min) and still runs...
4528
Living Room / Re: A point of grammar
« Last post by Stoic Joker on February 25, 2011, 03:35 PM »
My head hurts.
4529
Living Room / Re: print webpages that don't fit the page
« Last post by Stoic Joker on February 25, 2011, 03:32 PM »
In IE8, highlight the center part you want, right click the highlighted text and select Print Preview, from the middle drop down select print "As selected on screen".
4530
Living Room / Re: [Humor]: An update is available for your computer!
« Last post by Stoic Joker on February 25, 2011, 11:32 AM »
We use Kaseya to manage updates (and etc.) for the office and client networks. So I have a central point to approve updates (or not) for everyone at once. That way I can wait a few days to see if there is any screaming before pushing out any given update to 100 machines scattered across the countryside.

At home I just use automatic downloading and let me choose when to install. That way I can time when to do what, because the reboot question is frequently dependent on what is running at the time the patch is installed.

I think I only rebooted about 8 times last year.
4531
I'd find it funnier if I could make out what the console stuff said. I feel like I am missing the punchline.

Imagine what happens when Watson evaluates whether the answer is good or not...
If by good, you mean valid, and he formatted himself in the middle of the show ... Yeah that would be hysterical.
4532
Living Room / Re: Show us your desktop
« Last post by Stoic Joker on February 24, 2011, 06:40 PM »
I can't find my Desktop...

Desktop.jpg
4533
General Software Discussion / Re: Instantly Increasing Password Strength
« Last post by Stoic Joker on February 24, 2011, 12:44 PM »
HBGary/HBGeary I had a feeling I spellt that wrong... :)

Their problem was the front door had a set of keys left in it ... In the form of unvalidated SQL input being allow to execute against the server. Which is how the table got "dumped". This allowed all of the bruteforcing to be done off-line on fast (and distributed) hardware. No more internet connection speed slowing down the number of attempts per second.
4534
I really should have fully checked out the cable possibilities before anything else, but I didnt - live n learn...

I've had days like that, glad you got it straightened out. I'd asked the HP regional troubleshooting specialist about it, But only got run through the stuff already tried.
4535
JGPaiva's GridMove and Ahk Tools / Re: Weird behavior in remote desktop
« Last post by Stoic Joker on February 24, 2011, 11:38 AM »
Hotkeys and remote desktop are notoriously unpredictable, are you running the RDP session windowed or full screen? Full screen sessions generally make for much more predictable hotkey use.

Just a Thought... :)
4536
General Software Discussion / Re: Instantly Increasing Password Strength
« Last post by Stoic Joker on February 24, 2011, 11:32 AM »
Anything else done to reduce the complexity or length in order to make it more suitable for human use will reduce the level of security.

Not necessarily. As I suggested before in another thread, three way login forms can be very powerful.

You can't mass brute force a photo upload for an image captcha unless you have access to the home storage file already but even then you have to know each users' specific thought process and which personal photo they are using to access something.

Okay, from a front door perspective only...I'd agree - I find the user, pass, pic, phrase logons much less annoying and effective than capachas which are easily defeated with OCR. But... That's not what we are (or the thread is) discussing.

The question on the table was regarding the HBGeary fiasco. Where the User Table had already been dumped via SQL injection. So the additional bits of info (pic & phrase) could simply be read from the next column over, and would afford no further resistance.

So the discussion was really focused on how complex does a password really need to be to keep it from being Hash Cracked in a matter of hours (e.g. it's all straight up back door stuff).
4537
It's for CLI users and pure keyboard users. My guess is that just as the KDE file manager combined both file browser and web browser, Chrome will do this + a terminal.

...Isn't that the exact same (high level of integration) behavior that had everybody pissed-off at Microsoft (rampant security hole) about 5 or 6 years ago?
4538
Developer's Corner / Re: To persist with Windows 2000 support?
« Last post by Stoic Joker on February 24, 2011, 06:56 AM »
You can get VS2003 from there, but can you get the VCToolkitSetup.exe for the VC2003 Toolkit package?

Nope, I missed that distinction earlier ... :-[ ... Only the full VS.NET 2003 is available.
4539
General Software Discussion / Re: Most Pirated Software?
« Last post by Stoic Joker on February 24, 2011, 06:33 AM »
Autodesk Autocad - Hardware keyed ...
Isn't that for non-USA versions only? Or is the dongle-protection introduced there also?

Yepper it's here in the US too. I've got a client that has had fits trying to keep their fully legal copy running because of the stupidly unstable Sentinal Hardware Key driver.
4540
Developer's Corner / Re: To persist with Windows 2000 support?
« Last post by Stoic Joker on February 23, 2011, 06:58 PM »
(I don't think there's any way to get 2003toolkit from MS?)

Oh hell yeah, the MSDN goes all the way back to Visual C++ v1.52. Granted you need a subscription (not cheap) but they are still available.
4541
General Software Discussion / Re: Instantly Increasing Password Strength
« Last post by Stoic Joker on February 23, 2011, 06:49 PM »
WeRntf,Y3t!

Easy to Remember (for me), and I'd wager quite difficult to guess, even for the table.
Good question - a quick google does suggest that the easy-to-find publicly available tables don't even reach 10 characters for the larger character sets, and those tables are already huge and take a while to generate. But do keep in mind that criminals have access to very large botnets, and people have started renting Amazon EC2 servers (including GPU acceleration) for nefarious deeds. I definitely wouldn't feel too safe with a passphrase lower than 10 characters with a large character set.

And it does seem it takes a while (for a single box) to process passphrases, even with rainbow tables - but anybody serious enough to have serious tables are going to have more than a single box available.

Quite true, But what are they really after? HBGary was completely torched in less that 24 hours. So there is an obvious time requirement involved. It their case the Low-Hanging-Fruit was also pay dirt ... So there was really no point in continuing. The object is to get as many of the accounts as possible, in the shortest time possible. So it is not really required to out run the bear, just the rest of the hunting party... :)

Besides even if you do manage to memorize a 8,000 character password ... If they really want you specifically, that badly ... Well, the term Rubber-Hose Cryptography comes to mind...
Indeed, and that's one of my favorite XKCDs. You have to balance your security based on who's likely to try to attack you. I protect my digital signature / online-banking stuff with longer passphrases than forum logins, simply because attackers would be more interested in spending energy on something they can have real financial gain from.

That said, access to a forum or account account can be valuable as well - interesting information can sometimes be gathered form such access, either directly or through social engineering. And if the user has used the same passphrase in multiple locations, well...

Guilty as charged ... I stole the line from you.  :D

And password reuse is definitely to be avoided, usually by using fsekrit.
4542
General Software Discussion / Re: Most Pirated Software?
« Last post by Stoic Joker on February 23, 2011, 06:20 PM »
IMO


Autodesk Autocad - Hardware keyed and hard to use for beginners
Virus software (various) - Who ever updates that?
Microsoft Windows (XP-Vista-7) - Comes with machine and update requirements scare off most of the casual folks
Nero Burning - This is a good candidate, but isn't that expensive

Microsoft Office - Oh Yeah
Adobe Photoshop - Oh Yeah

These two are very popular, way expensive, and are still easy to casual copy if a bit of common sense is used.
4543
General Software Discussion / Re: Instantly Increasing Password Strength
« Last post by Stoic Joker on February 23, 2011, 06:05 PM »
Anything else done to reduce the complexity or length in order to make it more suitable for human use will reduce the level of security.

Exactly, any rule or technique you develop only doubles the attackers work/rainbow table, ie they test their search space once with the rule, and once without. So they simply use two computers instead of one.

Okay, but... To everything there is a point called a bit too far. If you do go with a really long mixed case alphanumeric password with garbage characters. you not only encourage, but basically force over half of the users to jot said password on a sticky note. ... And your Uber fortress gets hacked by the cleaning lady.

How random is random enough? If a popular phrase is used for a pass phrase, well that's reasonable to assume it won't last too long. But if the phrase used is some comic line your grandfather quipped at a family event one time that's not so predictable.

Now it has been mentioned that common/popular/most likely work combinations both can and are used in many of the (let's say...) High-end Rainbow Tables. Okay, but what about word fragments used as a mnemonic for the string? Here's an example:

A popular phrase and long standing joke around our house, is a quote of mine that was originally said when I was trying to lighten the mood when an auto repair was going quite badly. The quote was "We Are Not Totally F***ed ...Yet!"

So if I was to use that (which I don't), for a mnemonic it would go something like this:
We Are Not Totally F***ed ...Yet!

-or-

WeRntf,Y3t!

Easy to Remember (for me), and I'd wager quite difficult to guess, even for the table.


Here's the thing, and it's a very critical and key point. Who is cracking what, and why. Lets say it's HacKeRtasTic group X. and they are digging into Evil Bank Y.

Now they got into Evil Bank Y's server and dumped the user tables (yada, yada, yada...) ... And they want to get (lets say) 10,000 user accounts to post online to shame Evil Bank Y, And they also have an order for 10,000 more accounts for the ID theft folks...For a total order of 20,000 accounts needed, out of the (lets say) 100,000 accounts the bank has.

Now regardless of what can be done (even in an evil geek's wet dream) there are still some things that are just flat not cost effective. The tables are going to instantly pop on the first wave of (low-hanging-fruit) idiot simple passwords. Then the harder ones, and the harder ones ... And after a while the CPU time (cost) vs. the Cracked Hash (win) is going to skew...a lot. And that will most likely happen long after the "Order Requirement" of 20,000 accounts have been passed by a country mile.

Besides even if you do manage to memorize a 8,000 character password ... If they really want you specifically, that badly ... Well, the term Rubber-Hose Cryptography comes to mind...
4544
Post New Requests Here / Re: IDEA: Internet Explorer Address Bar Search Utility
« Last post by Stoic Joker on February 23, 2011, 11:37 AM »
(I could be wrong, but...) You really don't need a tool, unless you're going to be doing a large number of them at once. It's really just a matter of doing a search on the given target site to see how they pass in the search string to what. Then set the @ value to that string, give it a new alias, and reapply the new .reg patch file.
4545
Living Room / Re: Black ops: how HBGary wrote backdoors for the government
« Last post by Stoic Joker on February 23, 2011, 11:16 AM »
So, the moral of this story is: Never use a production db server for a honeypot...  :D
4546
Living Room / Re: Power Ranger Punches Kid for Accusing Him of Stealing Gloves
« Last post by Stoic Joker on February 23, 2011, 11:08 AM »
Atheist also, but...
I think it might be a good idea to put that pic in a spoiler, considering dc's

Um, Yeah ... Not everybody is going to find that funny.


On a side note, isn't Tapping Out just a Pro Sports way of crying uncle/ to concede the match and avoid further injury?
4547
Living Room / Re: Black ops: how HBGary wrote backdoors for the government
« Last post by Stoic Joker on February 23, 2011, 08:35 AM »
Security companies that get hacked by SQL injection deserve it.

Damn Straight! ...Love the cartoon, I'll be laughing about that (Little Bobby Tables) for the rest of the day.
4548
General Software Discussion / Re: Windows 7 SP1 released
« Last post by Stoic Joker on February 23, 2011, 08:20 AM »
They had an update mid way through last month that suddenly decided my Win7 computer was suddenly non-genuine.

You got that one too?!? I thought I was special...  :(

It showed up on my Win7 x64 Pro dev machine about the same time, but revalidated after a reboot or two (I'm thinking at some point it reinstalled part of the WGA stuff, but I wasn't really paying attention).
4549
Living Room / Re: Black ops: how HBGary wrote backdoors for the government
« Last post by Stoic Joker on February 23, 2011, 07:01 AM »
http://lcamtuf.blogs...world-of-hbgary.html

Linked in the above post is a link to the details of the attack, how hbgary got compromised: http://arstechnica.c...-the-hbgary-hack.ars

Wow - That's completely mind blowing - I will never feel guilty for harping about the 80/20 rule ever again.
4550
General Software Discussion / Re: Windows 7 SP1 released
« Last post by Stoic Joker on February 22, 2011, 06:57 PM »
I'm just after the with SP1 install images to eliminate a few hours of update downloading on reinstalls. :)

Other than that I don't recall hearing of anything earth shatteringly new in it.
Pages: prev1 ... 177 178 179 180 181 [182] 183 184 185 186 187 ... 246next