* Posts by Clausewitz 4.0

358 publicly visible posts • joined 22 Jun 2021

Page:

Happy birthday, Microsoft Money: Here's a cashpoint calamity for Windows and .NET

Clausewitz 4.0
Devil

Re: cascaded dialogs

The possibilities are endless, depends also on your mood.

Never mind Russia: Turkey and Vietnam are Microsoft's new state-backed hacker threats du jour

Clausewitz 4.0
Devil

Please remind ppl without prompt access to El Reg backend servers/logs to check your IP address or the IP from your VPN, from which country are you from, when making such assertions.

UK's £5bn National Cyber Force HQ to be sited in Lancashire beside Defence Secretary's constituency

Clausewitz 4.0
Devil

Re: Who wouldn't want an MoD IT spook job?

Reminds me of a quote from Snatch (2000):

Avi: Why do they call him the bullet dodger?

Tony: Because he dodges bullets, Avi.

Some folks are more prone to homicide than suicide

Clausewitz 4.0
Devil

Should be fully operational by 2030

No comments...

State-sponsored Chinese crims targeted India with tax and COVID phishing

Clausewitz 4.0
Devil

The scope and size of activities made by others is only a fraction of those perpetrated by 5-eyes.

Its necessary to keep the balance.

Maker of ATM bombing tutorials blew himself up – Euro cops

Clausewitz 4.0
Devil

Re: Not an ATM but similar

From what I read in an article, this is a common lack of planning done by newcomers.

You need to wait until the machines/branches are replenished ($$) to execute the job - usually before federal/city paydays.

Clausewitz 4.0
Devil

I must say that the use of ricin to kill slugs and other pests is quite an evolution from the previous used methods I am aware of. Gardeners must be very careful manipulating such dangerous substances.

Clausewitz 4.0
Devil

Re: Explosives? Really?

Torches are more common and cost-friendly.

Clausewitz 4.0
Devil

It depends on what your profession is.

You cannot say to a gardener he is not allowed to touch plants.

Clausewitz 4.0
Devil

Re: Depends

@jake - I believe you cannot understand subtlety

@Aussie Doc - I believe it said fiber in the article, not polymer. But I doubt the chemistry-lad is willing to share his process for free

@W.S.Gosset - SMS 2FA if used together with another authentication actually improve security, despite we all know how easy it is to intercept SMS / SIM swap

@John Brown (no body) - God bless the insurance companies. The value is already in place even if there are no withdraws. Those guys are just making their profit smaller

Clausewitz 4.0
Devil

I read it somewhere a while ago (dunno where) that powerful solvents can clean the ink from the notes. Chemistry-lads can make some bucks from the process.

Also, you can still put the inked bill into slot machines and they will be accepted.

Infosec outfit Group-IB's website was defaced in weeks before CEO's arrest over high treason claims

Clausewitz 4.0
Devil

To Sergei Esenin

You have passed, as they say, into worlds elsewhere.

Emptiness...

Fly, cutting your way into starry dubiety.

No advances, no pubs for you there.

Sobriety.

IKEA: Cameras were hidden in the ceiling above warehouse toilets for 'health and safety'

Clausewitz 4.0
Devil

Re: Safety

Forgot Terrorism?

Akamai beefs up cybersecurity portfolio with ransomware-tastic Guardicore acquisition

Clausewitz 4.0
Devil

Reverse Engineering

Some people would LUV to test a 600m defense solution. To my knowledge, these often can be beaten with a $400-dollar notebook and a few brains in an air-gapped room.

REvil customers complain ransomware gang uses backdoors to filch ransoms

Clausewitz 4.0
Devil

Re: Fingers crossed

Or partner up to create a better enterprise.

Clausewitz 4.0
Devil

Re: Turf war?

Eventually online turns physical offline. The most savvy survive. Scars are proof.

Frustrated dev drops three zero-day vulns affecting Apple iOS 15 after six-month wait

Clausewitz 4.0
Devil

Patience is gold

Patience is gold and is rewarded accordingly.

Stop worrying that crims could break the 'net, say cyber-diplomats – only nations have tried

Clausewitz 4.0
Devil

Spoils of War

https://en.wikipedia.org/wiki/Prize_of_war

UK Ministry of Defence apologises – again – after another major email blunder in Afghanistan

Clausewitz 4.0
Devil

Times change, old boy, times change

Clausewitz 4.0
Devil

Re: In real terms

The no-first-use policy for nuclear weapons was a well thought out stand... We don't intend to reverse it.

-Rajnath Singh

Clausewitz 4.0
Devil

SNAFU after SNAFU (2)

I am starting to seriously think maybe there is a reason to that - they want to relocate less people.

More graves = less people to relocate.

Researchers finger new APT group, FamousSparrow, for hotel attacks

Clausewitz 4.0
Devil

Re: I can name a

By "TurdBasket" malware, are you implying some people's code are not real?

If that is the case, I am sorry to disappoint you. Some people's code and capabilities are very real.

Clausewitz 4.0
Devil

This kind of C&C already exist, except for the consensus part.

TIP: https://securebox.comodo.com/blog/pos-security/kasidet-pos-ram-scraper-bot-now-hides-cc-servers-namecoins-dot-bit-service/

Clausewitz 4.0
Devil

Re: Finger

Remember, It's just a game. Just some games are dangerous, I can name a few I used to play:

- Russian Roulette

- Stab Between the fingers game (Knife game)

If you don't like dangerous games, at least respect others who like it !

UK Ministry of Defence apologises after Afghan interpreters' personal data exposed in email blunder

Clausewitz 4.0
Devil

SNAFU after SNAFU

5-eyes Intel programs are seriously been questioned these days.

I am not a fan of shooting ducks in a barrel, but some people are.

Kali Linux 2021.3 released with new tools

Clausewitz 4.0
Devil

Exploit usage, niche and time

QUOTE: For an exploit, you need to have a vulnerability. It's a race against time. Being able to successfully create an exploit and then using it, versus someone coming along and applying a patch."

REPLY: Some market niches do not patch THAT OFTEN. Your bugs are good to go even in a 5/10-year timeframe.

Royal Navy will be getting autonomous machines – for donkey work humans can't be bothered with

Clausewitz 4.0
Devil

Re: What's the end result of incresingly asymmetric warfare? More terrorism?

From what I heard, Russia tried at least 40 times this year to reach American counterparts to solve hacking problems allegedly coming from overseas into Russian territory - no response received.

Upon not receiving answers, someone must have hinted their local cyber-warriors - go there and have some fun too, those guys are already having too much of it.

When big-bad-smelly stuff like SCADA systems hit the fan and affect real life of citizens, govs demand cooperation - which they were not willing to have in the first place.

The rest is just PR.

Clausewitz 4.0
Devil

Re: Amen to that. So be it. And just in the nick of time before or while SHTF.

Already having that beer - local kind of brandy, actually. Have one on me, also.

About SCADA, having the power does not mean to use it. Same with strike capabilities. Deterrence is the main objective - at least should be in the first place. If we are here today, probably someone did a bit of overusing its capabilities.

About Mass Media Reprogramming of Human Assets, we have pretty good scientists to take care of that.

Clausewitz 4.0
Devil

Re: What's the end result of incresingly asymmetric warfare? More terrorism?

QUOTE: "We don't want to escalate"

REPLY: Actually, UK/USA/IL cannot escalate. Better solve the differences like grow ups chatting in a table with a nice brandy.

TIP: https://www.aljazeera.com/news/2021/9/17/iran-denounces-unilateralism-as-it-becomes-full-sco-member

This is AUKUS for China – US, UK, Australia reveal defence tech-sharing pact

Clausewitz 4.0
Devil

Re: Quiet

Better range and endurance, disappearing for short periods is a nice solution, and much more advanced.

Clausewitz 4.0
Devil

Additional Undersea Capabilities

As of "additional undersea capabilities", old but gold.

I heard a story of someone in the pentest business once moved to a new town, and within a few days using his newly acquired fiber-optic ISP, the fiber was broken and then repaired - imagine the rest.

Ransomware crims saying 'We'll burn your data if you get a negotiator' can't be legally paid off anyway

Clausewitz 4.0
Devil

Re: I had a dream...

Some already did.. sorry to disappoint you.

https://sputniknews.com/20170825/afghanistan-cia-heroin-ratline-1056794770.html

Dreamstime is much over.

Clausewitz 4.0
Devil

Plethora of Tools

The "Plethora of Tools" some of those new kids in the block have is so vast .. and generate so much more income and geopolitical goals .. that I honestly do not know why so many people are so much obsessed with Ransomware ?!?!?!

Patch now? Why enterprise exploits are still partying like it's 1999

Clausewitz 4.0
Devil

Why exploits are still partying like it's 1999

Reminds me of Happy99 by Spanska.

I believe exploits are still partying like it's 1999, mainly because its not only a technical situation, but also a creativity one.

Where an average security professional flag a bug as low-risk, a creative professional will, in a few days, chain it with others innocent-looking bugs - and make it high-risk.

ProtonMail deletes 'we don't log your IP' boast from website after French climate activist reportedly arrested

Clausewitz 4.0
Devil

Re: Not quite always...

Nice Somalia idea

US Air Force chief software officer quits after launching Hellfire missile of a LinkedIn post at his former bosses

Clausewitz 4.0
Devil

Emboldened with Discipline

borderline criminal emboldened with discipline, quite useful combination in some areas.

Dissected: A dropper-as-a-service miscreants pay to push their malware onto potentially 1,000s of victims

Clausewitz 4.0
Devil

Re: Linux

I heard some companies already have Linux versions of their software for some models, and they just need to be deployed in the field.

Clausewitz 4.0
Devil

Re: You'd think

Some would say "exploit people's greed", others would say "cooperate in a mutual advantage way".

Boffins find if you torture AMD Zen+, Zen 2 CPUs enough, they are vulnerable to Meltdown-like attack

Clausewitz 4.0
Devil

Re: Meh

Already tried. Questioning under the influence of drugs/chips are unreliable. Usually a win-win pact is the best way to achieve something both parties want.

Clausewitz 4.0
Devil

Re: Errr.

Seems the biggest concern is that similar flaws are yet to unveil, this will generate big profits, and eventually a shift in the global chip scene.

Big tech proud as punch about cameos in Joe Biden's security theatre

Clausewitz 4.0
Devil

Re: Just a game

Agree.

Clausewitz 4.0
Devil

Just a game

The new players are coming to the game.

Better for us all to be cautious and brace for impact.

We'll drop SBOMs on UK.gov to solve Telecoms Security Bill's technical demands, beams Cisco

Clausewitz 4.0
Devil

Congrats, Responsible approach

I would say the childs are growing up.

Instead of banning an equipment or supplier with FUD talking for geopolitical purposes, ask for a fix to the identified weakness.

The world is indeed changing.

Apple responds to critics of CSAM scan plan with FAQs, says it'd block governments subverting its system

Clausewitz 4.0
Devil

Quite good idea, specially if the DB does not contain the size of the file.

Lets wait for the rollout to figure which algorithm is being used for the hashing, and how much processing power one will need to make some collisions.

Apple is about to start scanning iPhone users' devices for banned content, professor warns

Clausewitz 4.0
Devil

Solution

Just like what Signal Private Messenger did with "aesthetic" messages for Israeli-Cellebrite (this chapter isn't finished, expect more news), the solution here is also simple.

Phone-Devs can embed hundreds of digitally-created-naked-children-fake-photos (not real ones) into files not viewed by the user, including fake geotags like for example FBI offices, Apple offices, or even the Pentagon.

I do not endorse adult games with children, but this tech must go.

Clausewitz 4.0
Devil

Re: Don't use your iPhone in church

The Vatican will move against this tech

Russia tells UN it wants vast expansion of cybercrime offenses, plus network backdoors, online censorship

Clausewitz 4.0
Devil

Double Standards

Contrary to what most people believe, the 5-eyes alliance hacks/snoops far more than Russia, China, Iran, DPRK and whatsoever, all together.

The asymmetric response by harboring / protecting non-state actors (Ok, some of these, soon, become full-geared state-actors, actually) is just a drop in the ocean.

It would be much better for Russia, China, Iran, DPRK and whatsoever to actually have a framework curbing baddies online (Ok, sometimes also offline) - but having such a framework, means to hold some not-too-happy-with-cameras 3-letter 5-eyes agencies, accountable.

.. And to politically cut the powers of some of these 3-letter agencies this way, also mean actions Kennedy-Style - and most politicians do not like actions Kennedy-Style, mostly because the stain in the suit is difficult to wash, explain, and takes time to prepare.

I believe no treaty will be signed, and some of the new Kids on the block will take over the kindergarten, blinding the older kids.

Biden warns 'real shooting war' will be sparked by severe cyber attack

Clausewitz 4.0
Devil

Re: Its the ultimate assymetric warfare

I politely disagree.

Such powers NEED to be part of the regular armed forces, the sole coordinators on the use of force.

Otherwise it is just blood and chaos, and nobody wants that.

People want safety and prosperity, force being used only when others are hurting you.

NSO Group 'will no longer be responding to inquiries' about misuse of its software

Clausewitz 4.0
Devil

Re: imperva.com fake certificate?

If you didn't knew before, there is no such a thing as HTTPS-protected for capable parties.

Also, OpenVPN-grade encryption is child's game.

Kaseya obtains REvil decryptor, starts sharing it with afflicted customers

Clausewitz 4.0
Devil

Re: Is there single key ?

QUOTE: "The idea that a decryptor can hold 'all the keys' is too fancyful. Must be more to the story."

No, its not fancy, it is technically viable and has been done in the past already (I believe I read it somewhere).

Supposing 4000 systems were infected and each key has 512 bytes in size, it will add 200Kb to the final .EXE size to hold all the keys, plus the extra algorithm part to test each key for 1 file, succeeding, use that key in the rest of the encrypted files.

Page: