Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
Donations
Please Support Us!

Please help keep (=WDG=) alive

Donate with PayPal!
Last 100 Shouts:
January 27, 2024, 05:26:45 PM
Happy new year WDG
December 10, 2023, 05:52:39 PM
Hello Power!
November 24, 2023, 09:51:34 PM
Helloes! I'm here for my annual password change! How is everyone doing?
August 03, 2023, 08:42:51 PM
WDG are going to i71. All welcome. Message for more information or ask on discord
July 27, 2023, 07:35:21 PM
The WDG discord channel is up and running. Send me a message or post for details
December 08, 2022, 04:05:12 PM
Odd. Should do. Send Mode a messsage here. He should be able to pick it up and send you an invite
December 07, 2022, 11:26:55 PM
@berath link doesn?t work Sad
August 08, 2022, 09:32:46 PM
December 23, 2020, 12:34:53 PM
Spammers be gone!
September 28, 2020, 11:18:57 PM
Nice!
September 28, 2020, 09:55:06 PM
I’m in 🙌
September 28, 2020, 02:59:45 PM
Yay!!!!!! Wix is in da house
September 28, 2020, 02:55:44 PM
Hey Berath !! I made it !
September 25, 2020, 05:13:56 PM
Wix - we may have some new friends playing a new game finding their way here soon.....
July 01, 2020, 11:05:23 PM
Hello Terror. People still drop by here now and again
June 29, 2020, 02:02:45 PM
Hi guys. I hope you are all well and keeping sane and safe during these trying times (and all that).

Just FYI that mode was looking for ways to get back in touch via reddit (r/WDG).
February 24, 2020, 09:26:46 AM
Zombie TF2? Do we need to dress up?
February 19, 2020, 01:03:56 AM
I'd play zombie TF2
February 19, 2020, 12:52:19 AM
Any appetite for a TF2 revival?
February 19, 2020, 12:52:01 AM
Awesome
February 19, 2020, 12:48:30 AM
Yes this thing is still on
February 19, 2020, 12:47:16 AM
Hello! Is this thing still on?
December 26, 2019, 12:43:10 AM
Merry Christmas!!!
August 13, 2019, 07:35:11 PM
Sweeping and clearing out the cobwebs, keeping everything spruce https://gph.is/2oImD0j
March 08, 2019, 11:38:14 AM
Cheers Stu / Berath was going to happen one day Sad
March 06, 2019, 11:08:46 PM
It's officially 'not secure' according to Chrome now
March 06, 2019, 11:07:11 PM
Damn. 1&1 have upgraded their something or other but seem to have allowed for ancient forums like this to keep on
March 05, 2019, 03:37:50 PM
NuB site is no more due to a forced PHP v7 upgrade on the web host that breaks SMF/TinyPortal.
January 31, 2019, 09:50:48 AM
Sad
January 22, 2019, 11:22:09 PM
Sad nub  site down Sad bye bye

January 01, 2019, 11:43:02 AM
Happy new year.
Who Dares... Grins!!
December 30, 2018, 08:04:52 PM
no
December 29, 2018, 12:05:55 PM
MEssaage me
for a free steam key for faeria
December 25, 2018, 02:35:39 PM
merry xmas wdg
December 23, 2018, 11:34:33 AM
Hello Milli!
December 21, 2018, 10:55:25 PM
Hello WDG!
December 13, 2018, 10:51:13 PM
I still pop by to give the old place a dusting and clear out
November 09, 2018, 03:36:17 PM
The shoutbox has actually had shouts in it recently? Impossible.
November 08, 2018, 07:45:58 PM
:dohjan: :newkid:
November 06, 2018, 07:11:48 PM
Enjoy!
November 05, 2018, 11:49:05 PM
Just poking about
June 02, 2018, 12:56:39 PM
Goodness me, so it does!
May 22, 2018, 03:38:35 PM
this site needs a shout in 2018 Smiley
November 16, 2017, 08:08:43 PM
Spam removed. Thank you muchly Hulinut
October 15, 2017, 06:02:47 PM
Yay, been fixed!
October 14, 2017, 07:08:12 PM
I'm trying to get the mumble server up again
October 11, 2017, 06:23:26 PM
Orange Box 10 years old wow
June 18, 2017, 09:46:41 PM
Fluffy!
June 14, 2017, 03:14:35 PM
:p
May 30, 2017, 10:14:48 PM
Hmph. Spammers!
April 19, 2017, 08:20:44 PM
Also - hai!
April 19, 2017, 08:20:38 PM
Just in case no-one saw it - I posted about i61 over on the wdg-reddit!
April 17, 2017, 02:18:03 PM
April 16, 2017, 12:28:45 PM
Don't mind me, just helping Berath clean up the dust
April 04, 2017, 09:46:13 PM
Mumble server down: I've submitted a ticket
March 13, 2017, 01:20:32 AM
It is. Sleeping
March 11, 2017, 06:24:54 PM
so quiet
December 06, 2016, 03:10:39 PM
Every day or so I drop by to empty out the logs, dust down the furniture and shake out the curtains
November 04, 2016, 05:15:57 PM
How's tricks WDG?
November 02, 2016, 10:36:32 PM
Yay CruelCow!!
November 01, 2016, 08:17:40 PM
Yeah, I still check here regularly
November 01, 2016, 06:16:46 PM
Forum is back up after I did some tinkering. Did anyone notice it was down?!?
September 03, 2016, 05:48:48 PM
Thanks for offering but platformers = frustration for me. All that jumping about and getting impaled
September 03, 2016, 10:54:37 AM
Does anyone want a 75%off coupon for Feist?
July 09, 2016, 02:56:39 PM
I knew you were behind them!
July 08, 2016, 11:40:05 AM
What the fucking hell is all this shit?

You'll be blaming me for shit Tf2 updates next!
July 06, 2016, 11:35:09 PM
Therefore, Lefty is indeed responsible
July 06, 2016, 10:56:20 PM
Wales voted Leave
June 25, 2016, 05:30:56 PM
Well he *is* called Leftism
June 24, 2016, 07:36:47 PM
I'm going to completely unjustifiably hold Lefty to blame for the Brexit.
That is all.
June 05, 2016, 01:56:52 PM
Woop woop i58 ticket bought!
May 13, 2016, 06:08:28 PM
I want that game
May 07, 2016, 10:20:36 PM
its not optimized well just like the ps4 version
May 07, 2016, 09:01:50 PM
why does everyone's gone rapture run like doggegg on my pc
April 13, 2016, 05:18:58 PM
Just to really bang it home. WDG sub-reddit here: https://www.reddit.com/r/WDG/
April 06, 2016, 10:06:39 AM
Thank you Smiley
April 04, 2016, 04:24:56 PM
Just send you one.
April 04, 2016, 10:48:17 AM
If there are any still going, I'll have one
April 02, 2016, 11:47:32 AM
i have beta passes if anyone wants them as well
March 23, 2016, 12:18:40 PM
If anybody wants a tf2 competetive beta pass, i have a spare.
March 18, 2016, 12:18:46 PM
It's too expensive Sad
March 15, 2016, 03:24:04 PM
Will you all go buy The Division now so I have someone to play with? Smiley
March 11, 2016, 08:32:56 PM
FIREWATCH
March 11, 2016, 07:56:09 PM
March 11, 2016, 07:56:08 PM
March 02, 2016, 06:02:38 PM
some of the stealth sections are a bit of a drag, but they're not as bad as the VIP escort missions in THE VITNESS
March 02, 2016, 12:06:23 PM
Easy with the spoilers, guys! I'm still  on the blunderbuss part.
March 01, 2016, 09:17:32 PM
Can't believe Henry managed to use his NAVY Seal experience to defuse the bomb that was strapped to the bear in the end
March 01, 2016, 03:38:29 PM
I just unlocked the rifle scope in firewatch, makes it much easier to pick off bears before they get into melee range
March 01, 2016, 12:34:14 PM
FIREWATCH
March 01, 2016, 12:13:37 PM
I can't believe GAMERS don't like the witness. It's the MOST GAMER game EVER.
February 29, 2016, 12:08:32 PM
Its overrated. Now FIREWATCH on the other side...
February 29, 2016, 11:21:43 AM
I got the basic ending in the witness and it was B A D
February 22, 2016, 10:58:37 AM
I have no understanding of the environmental puzzles
February 22, 2016, 10:58:25 AM
Every so often someone says something about "environmental puzzles" in the witness and I skip it because of spoilers
February 15, 2016, 01:02:48 AM
press x to exercise 5th freedom
February 14, 2016, 11:53:36 AM
My game came with an EXCLUSIVE PREORDER CODE for the Chaos Theory suit, shoulda preordered DUH
February 14, 2016, 02:02:52 AM
i want the super stealth suit.

I go lethal on grim missions
February 13, 2016, 12:40:44 PM
any of the optional missions are annoying.
Calendar
April 2024
MoTuWeThFrSaSu
1234567
891011121314
15161718192021
22232425262728
2930

Birthdays
Cheez (34), Sk1nn3d (40)

Upcoming Events
Upcoming Birthdays: Cheez (34), Sk1nn3d (40)
Members
Total Members: 304
Latest: vayuh
Stats
Total Posts: 126974
Total Topics: 4004
Online Today: 13
Online Ever: 340
(September 23, 2014, 12:11:24 PM)
Users Online
Users: 0
Guests: 39
Total: 39
Pages: [1] 2
Print
Author Topic: Security  (Read 10156 times)
0 Members and 1 Guest are viewing this topic.
discordance


Karma: 417
Offline Offline

Gender: Male
Posts: 4933


Curious


« on: April 08, 2014, 10:43:08 PM »

For your safety and amusement, boys and girls the big one is here. The mother of all security bugs.

http://arstechnica.com/security/2014/04/critical-crypto-bug-in-openssl-opens-two-thirds-of-the-web-to-eavesdropping/
http://arstechnica.com/security/2014/04/critical-crypto-bug-exposes-yahoo-mail-passwords-russian-roulette-style/

66% of websites and servers are affected, they each put 64kb of active memory out over their "secure" SSL connections (The 64kb is a different area of memory each time a message is sent). Passwords, certificates, encrypted data, everything must go!
Logged

discordance


Karma: 417
Offline Offline

Gender: Male
Posts: 4933


Curious


« Reply #1 on: April 09, 2014, 06:29:45 PM »

You need to change passwords on any service affected, but only after they have applied the patch and revoked their old certificates.
The following relevant sites so far are confirmed compromised.

Amazon hosting
minecraft
Flickr, Archive.org, Yahoo.com (and Yahoo Mail), Imgur, OKCupid, XDA-Developers, Steam (SteamCommunity.com), Eventbrite, 500px, and Slate

Steam haven't issued a statement yet which is extremely worrying considering they have been confirmed and reported as affected.

https://github.com/musalbas/heartbleed-masstest/blob/master/top1000.txt
« Last Edit: April 09, 2014, 06:47:46 PM by discordance » Logged

Berath
Clan leader
*****

Karma: 579
Offline Offline

Gender: Female
Posts: 3780


Who is This Who is Coming?


WWW
« Reply #2 on: April 09, 2014, 06:50:44 PM »

So they need to tell us when they've applied the patch then.
Logged
discordance


Karma: 417
Offline Offline

Gender: Male
Posts: 4933


Curious


« Reply #3 on: April 09, 2014, 07:19:54 PM »

applying the patch is useless without revoking your certificates as well, they have to do both. But yes this is the worrying thing. They've said nothing yet despite being reported as vulnerable on many tech news sites.
Logged

r007
Supporting the Brits since 2008
Clan admin
****

Karma: 489
Offline Offline

Gender: Male
Posts: 1789


Bow before me, for I am root.


WWW
« Reply #4 on: April 10, 2014, 08:53:18 AM »

My guess is they'll just silently switch the keys. At least that's what I'll do once I get around to it.

At any rate, if someone (*cough*NSA*cough*) was actively using this before it became publically known, they're facing a huge needle and haystack problem.
« Last Edit: April 10, 2014, 08:55:48 AM by r007 » Logged


Ceterum censio RFC1855 esse legendam.
discordance


Karma: 417
Offline Offline

Gender: Male
Posts: 4933


Curious


« Reply #5 on: April 10, 2014, 09:42:15 AM »

Reports have come in of attacks dating back to at least last november. Fuck.

Silently changing your certs is extremely inappropiate in this case as all users need to change passwords after. Its a sign of total incompetance and no commitment to security to leave your users high and dry in this (talking bout valve but if you have users you need to tell them too r007 or at least just force a password reset). Perhaps they are being slow still but they are running out of time for handling this.
« Last Edit: April 10, 2014, 09:44:30 AM by discordance » Logged

CruelCow
Unofficial Official Non-WDG WDG member


Karma: 1665
Offline Offline

Gender: Male
Posts: 5922


Move along. Nobody suspicious is here.


« Reply #6 on: April 10, 2014, 11:10:16 AM »

a huge needle and haystack problem.

Not really. People were able to extract private keys within hours after they heard about the bug. A state level attacker (who had potentially 2 years!) should've been able to do that on a wide scale easily.

Reports have come in of attacks dating back to at least last november.

Link? Openssl doesn't log heartbeats, so it shouldn't be detectable retroactively.
« Last Edit: April 10, 2014, 11:12:19 AM by CruelCow » Logged
discordance


Karma: 417
Offline Offline

Gender: Male
Posts: 4933


Curious


« Reply #7 on: April 10, 2014, 01:13:08 PM »

Cant link from here. The suspect packet packet is loggable though on extreme logging settings. Security researchers had a few servers that have such packets in their logs from last november. The packet itself has a 0 length payload but a header declaring a 64kb length. This is what has been identified in some logs.

OpenSSL trusts the declared length of the packet and allocates that much memory then copies in the received payload. If the payload isnt actually the right length you get uninitialised memory. This isnt just a bounds check fail. This is the guy who wrote and then implemented the spec on heartbeat and trusted an external packet to declare a valid length. So dumb.

EDIT in round 2 dumbness they specifically disabled security features of malloc to prevent buffer overflow. Dumb dumb dumb dumb etc.

Only took 3 whole days but its finally the featured story on the guardian this afternoon. Perhaps because according to the bbc facebook and google were also affected and have been fixed and they need password changes now.
« Last Edit: April 10, 2014, 04:35:30 PM by discordance » Logged

discordance


Karma: 417
Offline Offline

Gender: Male
Posts: 4933


Curious


« Reply #8 on: April 10, 2014, 04:36:32 PM »

In case my last post buries it. Google and facebook are reported by the bbc as affected and you now need to reset your passwords
Logged

Banrab
Clan member
***

Karma: 9
Offline Offline

Gender: Male
Posts: 186



« Reply #9 on: April 10, 2014, 04:42:09 PM »

What sucks is I have so many passwords for so many sites and now I'm gonna have to change them all Sad.


Is it really that bad or could I risk not changing them (every site has a slightly diff password)
Logged

how do i use this what's it for
discordance


Karma: 417
Offline Offline

Gender: Male
Posts: 4933


Curious


« Reply #10 on: April 10, 2014, 04:51:36 PM »

Its really that bad. The attack has been known for a minimum of 5 months and has been around for 2 years. All passwords affected by this have to be assumed compromised. Get a password manager like keepass or lastpass it will help you get a grip on this mess and have stronger passwords.

EDIT: and bear in mind that the NSA were/are recording all encrypted communications... They might not be responsible for this but its a given they knew about it and recorded as much as they could. So they have server certs and passwords for basically everyone everywhere...
« Last Edit: April 10, 2014, 06:33:18 PM by discordance » Logged

discordance


Karma: 417
Offline Offline

Gender: Male
Posts: 4933


Curious


« Reply #11 on: April 11, 2014, 12:18:26 AM »

Oh good routers now.
http://arstechnica.com/security/2014/04/cisco-finds-13-products-so-far-vulnerable-to-heartbleed-including-phones/
Logged

Hulinut


Karma: 33
Offline Offline

Gender: Male
Posts: 222


I left my shield belt in my other pants


« Reply #12 on: April 11, 2014, 09:46:12 PM »

In case anyone didn't get disco's explanation of how the bug worked, xkcd has a nice one: http://xkcd.com/1354/
Logged

Brahms
I can't start laughing


Karma: 725
Offline Offline

Posts: 3801


I'm Johannes Brahms and I died in 1897


WWW
« Reply #13 on: April 11, 2014, 10:07:49 PM »

http://blog.cloudflare.com/answering-the-critical-question-can-you-get-private-ssl-keys-using-heartbleed

Logged

Official unofficial WDG Minecraft Server:
discordance


Karma: 417
Offline Offline

Gender: Male
Posts: 4933


Curious


« Reply #14 on: April 11, 2014, 11:29:52 PM »

http://arstechnica.com/security/2014/04/nsa-used-heartbleed-nearly-from-the-start-report-claims/

I was ignoring the cries of conspiracy at first. But hmmmmm. To be fair they probably have the people to do the software verification than OpenSSL couldn't be bothered to do. But still, right from the start? Getting a bit suspicious.
Logged

Pages: [1] 2
Print
My CommunityForumPublicTechnicalTopic: Security
Jump to:  


Who Dares... Grins UK TF2 Clan