Showing posts with label wtf. Show all posts
Showing posts with label wtf. Show all posts

Thursday, August 6, 2026

IT department's cunning new password security scheme

It put yellow sticky notes with username and password on corporate laptops:

The company decided to take some old laptops and give them out to new users. To make life easy for the recipients, they put sticky notes – everyone’s favorite credential-sharing tool – on the laptops with the name of each employee and their initial login credentials on it.

Let’s just stop for a moment to remark on how bad it is to put usernames and passwords on a piece of paper where the wrong person could see them. Even the IT department should not know your password, should someone in IT themselves turn rogue. So, even if the laptop stayed on a shelf in a closet that only the support staff had access to, having that sticky note would be bad.

However, our situation is even worse because the laptops in question were stored in a conference room while the facilities team finished readying the office for the move. During that time, anyone who had access to the conference room could go in and get multiple user account credentials.

And that's exactly what happened ...
Angels and Ministers of Grace defend us.  And remember - this was the IT Department that did this.

Sigh.

This is why we can't have nice (security) things on the Internet.

Friday, May 29, 2026

Boston, amirite?

It seems like this is something being pushed by the Boston.Gov:


I'm afraid I don't even understand what they're talking about.  Does this mean dudes in dresses learning about periods, or the other way around?  Quite frankly, the terminology may be intentionally confusing.  Just shut up and nod your head, right?

Oooooh kaaaay.

I am SO glad I got out of there. Didn't even get cut up too badly going over the wire at the border ...

Thursday, May 14, 2026

Massachusetts demonstrates the futility of gun control

Via Insty, here's proof of the utter futility of gun control:

A man named Tyler Brown opened fire on Memorial Drive in Cambridge, Mass., this week, turning an ordinary Monday afternoon into a rolling ambush near Harvard and MIT.

Middlesex DA Marian Ryan said Brown, a 46-year-old Boston man (notice no doctor was needed to identify Brown as a man), fired roughly 50 to 60 rounds from a rifle at vehicles on the roadway.

A Mass Statie and Our Hero (legally carrying, natch) shot the dirty perp.  So well done!  And I hear you ask, what's the tie in to gun control.  This:

Brown didn't appear from thin air; his criminal record included a 2020 shootout with Boston police, and he had pleaded guilty to charges tied to armed assault with intent to murder. He was reportedly out on probation when the Cambridge shooting unfolded. 

OK, so Massachusetts is run by dumbasses.  Dude was out on parole for armed assault with intent to murder, and he shot up a bunch of stuff, including a Massachusetts State Police cruiser.

But here's the punch line:

[The perpetrator] survived with non-life-threatening injuries and faces serious charges, including armed assault with intent to murder. [Emphasis mine - Borepatch]

This time he'll be sorry! 

Some Masshole judge will release him in 4 or 5 years.  But more gun control is just the thing.  Oooooooh kaaaaaay.

It's quite a mystery why all the retarded Massachusetts liberals think they're so much smarter than we are.  The evidence is against them. 

 

Monday, December 1, 2025

Why can't the US Navy build ships?

First, they canceled the Little Crappy Shops (LCS) program as not fit for purpose.  Now it's the Constellation class Frigate program that gets the axe:

By 2024, the first ship of the class was 36 months behind schedule, with the second already considered two years behind before its keel was even laid. The plan, as I mentioned before, was to retain roughly 85% of the FREMM frigate design to expedite production, but by that point, the Constellation design retained only about 15% of its parent design. This caused a cascade of other issues, like the need to write new code for a reported 95% of the ship’s control system software due to deviations from the FREMM design it came from, and the incorporation of new equipment and systems.

The Constellation-class frigate seemed to suffer from a classic case of scope-creep, a term used to describe a program that keeps seeing new requirements tacked onto it as it develops, resulting in cost overruns and delays. As one lawmaker put it, the Navy kept chasing a 100% solution to the point where they ended up with 0% of the ship being delivered.

There's more here from the Tech Press, so this is getting attention. 

As Yogi Berra once said, if you don't know where you're going you'll end up somewhere else.  SECNAV should see to it that the Program Management Office finds itself somewhere else - preferably not working for the Navy.  Pour encourager les autres ...

Wednesday, November 5, 2025

Skynet has arrived

Um, I've seen this movie:

Nation-state goons and cybercrime rings are experimenting with Gemini to develop a "Thinking Robot" malware module that can rewrite its own code to avoid detection, and build an AI agent that tracks enemies' behavior, according to Google Threat Intelligence Group.

In its most recent AI Threat Tracker, published Wednesday, the Chocolate Factory says it observed a shift in adversarial behavior over the past year. 

Attackers are no longer just using Gemini for productivity gains - things like translating and tailoring phishing lures, looking up information about surveillance targets, using AI for tech support, and writing some software scripts. They are also trialing AI-enabled malware in their operations, we're told. 

It seems that the Bad Guys are using all the old malware tricks (obfuscation, hidden files, etc) plus some new ones (sending commands via LLM prompts, i.e. the malware queries (prompts) other LLMs to get commands.

The security model for AI/LLM is hopelessly broken, and the design is defective.  I mean heck - the designers didn't consider two decade old attack techniques.  I don't know if it's correct to label this broken as designed but it's not far off.  This is software engineering malpractice.

I can't wait to see what happens with this and one of Elon's humanoid robots ... 

Wednesday, October 29, 2025

I would have throught that German IT Security teams would be more competent than this

I was not expecting this:

Germany's infosec office (BSI) is sounding the alarm after finding that 92 percent of the nation's Exchange boxes are still running out-of-support software, a fortnight after Microsoft axed versions 2016 and 2019.

While the end of Windows 10 updates occupied most of the headlines, Microsoft's support for Exchange and a bunch of other 2016 and 2019-branded products ended on October 14, as scheduled a year earlier.

Alternate title: 90% of German firms fail their SOC 2 audit.  Look, this isn't landing a man on the moon, and you had a whole year.  You just couldn't be bothered.

Was ist los? 

 

Tuesday, October 28, 2025

AI Browsers considered unsafe

OK, that post title is more than a bit inflammatory, but who on earth would want to use something like this?

Several new AI browsers, including OpenAI's Atlas, offer the ability to take actions on the user's behalf, such as opening web pages or even shopping. But these added capabilities create new attack vectors, particularly prompt injection.

Prompt injection occurs when something causes text that the user didn't write to become commands for an AI bot. Direct prompt injection happens when unwanted text gets entered at the point of prompt input, while indirect injection happens when content, such as a web page or PDF that the bot has been asked to summarize, contains hidden commands that AI then follows as if the user had entered them.

This is unbelievably bad.  How bad?  This bad: 

Last week, researchers at Brave browser published a report detailing indirect prompt injection vulns they found in the Comet and Fellou browsers. For Comet, the testers added instructions as unreadable text inside an image on a web page, and for Fellou they simply wrote the instructions into the text of a web page.

When the browsers were asked to summarize these pages – something a user might do – they followed the instructions by opening Gmail, grabbing the subject line of the user's most recent email message, and then appending that data as the query string of another URL to a website that the researchers controlled. If the website were run by crims, they'd be able to collect user data with it.

Surely they must be exaggerating, I hear you say.  Nope - the author of the post at El Reg recreated the exploit his very own self, simply by creating a web page with the commands hidden in it.  FYI, that's 1996 technology right there.

Now look, I may be an old crabby security geezer (no comments, Glen Filthie!) but the problem of sanitizing user input is a really old one.  So old that it was old when XKCD did it's classic "Bobby Tables" cartoon:


There have been over 3000 XKCD cartoons; that one was number 327.  Yeah, that long ago. 

My opinion about anything regarding AI is that the hype is so fierce that the people developing the applications don't really focus much on security, because security is hard and it would slow down the release cadence.  And so exploits that wouldn't have surprised anyone back in 2010 keep popping up.

Le sigh.  Once again, security isn't an afterthought, it wasn't thought of at all.  My recommendation is not to touch these turkeys with a 100' pole.

Tuesday, August 19, 2025

Wow

Having grown up during the Cold War, I got used to European leaders who, if not always friendly, were all serious people.  Francois Mitterand was serious.  The Iron Lady Thatcher was serious.  Heck, even pinko Willy Brandt was serious.

Now Donald Trump lines them up like school kids.


It's arguable that the only serious European leader today is Vladimir Putin.  Good Grief.

UPDATE 19 AUGUST 2025 16:46:  HMS Defiant leaves a comment about Hungary's Prime Ministor Viktor Orban as being a serious leader.  I 100% agree. I would also suspect that many of the leaders from Central and Eastern Europe are also serious.  The ones in the photo, not so much.

Tuesday, July 15, 2025

Security: not advancing at the speed of a freight train

Well, the security of the freight train, that is:

When independent security researcher Neil Smith reported a vulnerability in a comms standard used by trains to the US government in 2012, he most likely didn't expect it would take until 2025 to sort the matter out, but here we are.

The US Cybersecurity and Infrastructure Security Agency (CISA) issued CVE-2025-1727 (CVSS v3.1 8.1) last week, specifying the issue as one of weak authentication in the end-of-train to head-of-train linking protocol - allowing an attacker to input their own braking commands and stop the train in its tracks.

Now that's pretty bad, just by itself.  This could also cause derailment.  But this part is maddening:

With a simple exploit sitting out there in the open since 2012 (if Smith discovered it, someone else might too), it seems practically negligent that someone didn't take action, but as a 2016 story from the Boston Review explains, it's not a surprise.

The article tells the story of Smith's by then four-year tussle with the AAR upon first reporting the matter to the US Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) after successfully recording telemetry data from a passing train using an SDR in 2012.

ICS-CERT went to AAR with Smith's concerns, hoping they would be open to further security testing, but that initial contact was as far as it went - and as far as the BR story was able to glimpse into the struggle.

As Smith explained on X, the Boston Review article led to some burnout on the matter until security researcher Eric Reuter gave a talk at DEFCON in 2018, presenting an independent discovery of the same issue. By 2024, ICS-CERT had restructured several times, and Smith decided to reach back out to see if they could reopen the issue.

According to Smith, AAR's infosec director saw it as a minor issue since the FRED protocol was end-of-life and slated for replacement, despite still being in use.

Translation: yeah, we sat on this for 12 years but it's all good, bro. 


All those people going on about "OMG Trump is going to gut Internet Security teams" should ask themselves just what the heck those teams have been up to for the last dozen years.

Wednesday, July 9, 2025

Things I did not know, vol XCIII

A bunch of States have State Dinosaurs

I guess that since it's true that nobody's Life, Liberty, or Property are safe when the Legislature is in session, I have to approve of all the time that went into passing these bills. 

Tuesday, May 6, 2025

Microsoft to end passwords for Windows

Well, Windows for consumers, at least:

The software giant announced the move Thursday, May 1, traditionally known as "World Password Day," with a declaration it had joined forces with the Fast Identity Online (FIDO) Alliance to re-name the pseudo-holiday "World Passkey Day."

Redmond’s not just playing with words as the Windows giant has also decided that all new Microsoft accounts will use passkeys by default. Passkeys, which involve the use of biometric identification like a fingerprint or face scan, PIN, and the like, will be the de facto new way to set up an account, and existing Microsoft users are being encouraged to visit their account settings page to delete their passwords and start using passkeys.

(Think of passkeys as a replacement of passwords.)

I'm of two minds here.  On the upside, passwords are generally an infinitely renewable source of insecurity.  This has been known  for decades:


On the downside, there is one negative that can simply never be fixed: you cannot change your biometrics if this somehow gets compromised.  You cannot revoke a fingerprint and issue a new one.

My take: hold off on this one.  Certainly Microsoft's commercial customers will never go here - password rotation is specifically required by essentially all industry security mandates (ISO 27000, SOC2, etc).

Color me unconvinced.  I'm not sure exactly what motivated Microsoft to do this.

Thursday, January 16, 2025

Security wasn't an afterthought, it wasn't thought of at all

This keeps coming up over and over.  The latest example is GoDaddy:

GoDaddy has failed to protect its web-hosting platform with even basic infosec tools and practices since 2018, according to the FTC, but the internet giant won’t face any immediate consequences for its many alleged acts of omission.

As one of the world's largest web-hosting companies, and a registry and registrar with about 82 million domain names in its care, one would assume GoDaddy would be adept at applying software updates and monitoring security-related events in its hosting environment to protect its millions of customers and the visitors to their websites from online threats.

But according to a Wednesday statement from the FTC, “GoDaddy has failed to implement reasonable and appropriate security measures to protect and monitor its website-hosting environments for security threats, and misled customers about the extent of its data security protections on its website hosting services.”

So what triple-propellorhead security tech did they miss?  Basics like security log analysis tools, multi-factor authentication on login, missing security patches, and not maintaining an inventory of their systems.  This is all Security 101.  Actually, it may be Security Pre-K.

If you use GoDaddy's hosting you might want to consider an alternative.

 

Wednesday, October 9, 2024

Florida Man lives in my neighborhood?

Sumd00d posted to the neighborhood Facebook group, recommending that people prepare their lanai screen for the high winds by cutting them.

[blink] [blink]

That's some righteous hurricane prep, right there [rolls eyes so hard you can hear it over the hurricane]

My thought is why not open all your windows to keep the wind from blowing them out, amirite?  Sheesh.

Friday, October 4, 2024

Meta fined for storing user passwords with no encryption

Holy cow, I've been in this industry for decades and can't remember a time when everyone knew that you encrypted the damn passwords*:

Officials in Ireland have fined Meta $101 million for storing hundreds of millions of user passwords in plaintext and making them broadly available to company employees.

Meta disclosed the lapse in early 2019. The company said that apps for connecting to various Meta-owned social networks had logged user passwords in plaintext and stored them in a database that had been searched by roughly 2,000 company engineers, who collectively queried the stash more than 9 million times.

This is such a rookie mistake that it makes you wonder what those 9 million queries were looking for.  Meta has such a horrible reputation for abusing its users privacy that the suspicion is that this was just one more wring on that rag.  That's only a suspicion, but Meta has certainly earned that suspicion over the years.

* Yeah, yeah I know - one-way hash.  I try not to use too much tech jargon.

Thursday, September 5, 2024

Well, that's one way to improve the Internet coverage on a Navy ship

Navy finds hidden Starlink dish on ship:

Still, the ambassador had nothing on senior enlisted crew members of the littoral combat ship USS Manchester, who didn't like the Navy's restriction of onboard Internet access. In 2023, they decided that the best way to deal with the problem was to secretly bolt a Starlink terminal to the "O-5 level weatherdeck" of a US warship.

They called the resulting Wi-Fi network "STINKY"—and when officers on the ship heard rumors and began asking questions, the leader of the scheme brazenly lied about it. Then, when exposed, she went so far as to make up fake Starlink usage reports suggesting that the system had only been accessed while in port, where cybersecurity and espionage concerns were lower.

Well, it is a pain in the rear end to get hooked up to SIPRnet ... 

Of course, there's been a general helping of Courts Martials to everyone involved.

And the funniest bit?  Elon Musk had Starlink change the default WiFi SSID to "Stinky" to encourage customers to change the damn defaults.

Wednesday, September 4, 2024

What is this, 1990?

SolarWinds issues security patch to eliminate hard coded password:

SolarWinds left hardcoded credentials in its Web Help Desk product that can be used by remote, unauthenticated attackers to log into vulnerable instances, access internal functionality, and modify sensitive data

The software maker has now issued an update to address that critical oversight; its users are encouraged to install the fix, which presumably removes the baked-in creds.

[blink] [blink]

What makes this even more double-plus ungood is that SolarWinds is a security company.  They know that hard coded passwords are not just A Very Bad Thing Indeed, but considered harmful*.

I guess the only other possibility is that they don't know this, but I just don't believe that.  Heads should roll over this.

* Old computing graybeards will remember the ACM paper "GoTo Considered Harmful" which created such a furor that "considered harmful" is now considered harmful when used descriptively.

Except here, where it is 100% justified.

Tuesday, August 27, 2024

Well, that doesn't sound like much of a "Cybersecurity Lab"

Cybersecurity Lab didn't use antivirus:

Dr. Emmanouil "Manos" Antonakakis runs a Georgia Tech cybersecurity lab and has attracted millions of dollars in the last few years from the US government for Department of Defense research projects like "Rhamnousia: Attributing Cyber Actors Through Tensor Decomposition and Novel Data Acquisition."

The government yesterday sued Georgia Tech in federal court, singling out Antonakakis and claiming that neither he nor Georgia Tech followed basic (and required) security protocols for years, knew they were not in compliance with such protocols, and then submitted invoices for their DoD projects anyway.

It seems that Dr. Antonakakis wasn't much impressed with antivirus products.  Fair enough - it's a perpetual game of locking the barn door after the horse got out.

But the contract said that the lab would follow particular standards (in this case, NIST 800-171) which mandates antivirus, and the lab issued compliance statements with the invoices they submitted.  This case seems pretty cut and dried.

And not at all impressive for Georgia Tech Cybersecurity Lab.

 

Wednesday, August 21, 2024

Disney+ Terms of Service does not give blanket immunity

Sanity breaks out at Disney:

Disney said it is abandoning its motion to compel arbitration in a case filed by a man who alleges his wife died from anaphylaxis after a restaurant at a Disney complex failed to honor requests for allergen-free food.

Disney's motion to compel arbitration controversially cited the Disney+ streaming service's subscriber agreement, which includes a binding arbitration clause. The plaintiff's lawyer called the argument "absurd."

Disney confirmed this week that it will withdraw the motion, which it filed on May 31.

Good.  It was a stupid argument anyway.  Man, they generated a lot of ill will with that bone-headed move, though.

 

 

Thursday, August 15, 2024

The buzz from Black Hat this year

Every year in the heat of the Las Vegas desert is the Black Hat Briefings, the premier computer security conference.  There's always interesting news from the briefings (and from the much less buttoned down conference, DEFCON, which runs immediately afterwards).

So what's the buzz from Black Hat this year?  It seems that Palo Alto Networks had Booth Bunnies at their display booth:

[blink] [blink]

Now I did my share of manning the booths (yes, I was a Booth Bunny, thank you for asking) back in the '90s and the '00s.  But even in the '90s we were considerably more buttoned down than this, and for good marketing reasons.  Sure, some of the attendees might like the scenery, but some will not - and some of them will very much not like the scenery.  This has been known to be bad conference marketing juju for literally decades.

Of course, the Palo Alto Networks' Chief Marketing Officer had to go full frontal groveling* in his apology:

PAN's chief marketing officer Unnikrishnan KP, or Unni as he's often called, issued his apology earlier this week calling it "tone deaf."

"Last week at Black Hat in Las Vegas, an unfortunate decision was made at a Palo Alto Networks event to have hostesses wear branded lampshades on their heads," he said. "It was tone-deaf, in poor taste, and not aligned with our company values or brand campaign. 

"I take full responsibility for this misjudgment and have addressed it with my team and am taking steps to prevent such misguided actions in the future.

"Please accept my heartfelt apologies for this regrettable incident."

Nikesh Arora, PAN's chairman and CEO, doubled down on the apologies on Tuesday, echoing the points made by Unni, adding that what happened was "unacceptable."

I expect the headcount at Palo Alto Networks' marketing department has gotten a spin.  We apologize again for the fault in the subtitles. Those responsible for sacking the people who have just been sacked have been sacked.

* See what I did there?  I crack myself up.