* Posts by loops

19 publicly visible posts • joined 16 Dec 2021

2024 according to Cloudflare: Global traffic up, Google still king, US churning out bots

loops

"The company also reveals that a fifth of all TCP connections (20.7 percent) are unexpectedly terminated before any useful data can be exchanged. Causes of this could vary from DoS attacks, quirky client behavior, or a network interrupting a connection to filter content

Cloudflare says about half of these incidents were connections closed "Post SYN" – after its server has received a client's SYN packet, but before a subsequent acknowledgement (ACK) or any useful data".

Presumably this is a SYN/ACK flood on a third party (not Cloudflare).

You send a single SYN packet with a spoofed IP, and the receiving service replies with an SYN-ACK, when it doesn't receive an ACK in response from the target IP it sends out several more SYN-ACKs before eventually giving up.

On it's own, this does nothing, but if you do this to thousands of high bandwidth hosts, reflecting the SYN-ACK packets to your target, you perform a fairly simple DDOS amplification attack.

These have been common since at least the early 90s (and ironically, is one of the things Cloudflare is designed to protect against).

Why the long name? Okta discloses auth bypass bug affecting 52-character usernames

loops

The most interesting part of this was the revelation (on Xittier) that Cloudflare have dropped Okta and have developed their own identity service.

Google gamed into advertising a malicious version of Authenticator

loops

Did you forget to take your medication again?

India contemplates compulsory dynamic 2FA for digital payments

loops

Re: So OTP is fine, but biometrics is better ?

I can't say for sure what this system entails, because of course, they haven't even decided yet, but most biometric systems don't work that way. In most systems, your face/fingerprint/whatever (voice being the obvious exception to this rule) never leaves your local device (phone, tablet, pc...). You authenticate biometrically locally, then a key-pair exchange authenticates to the remote service.

A large part of the reason for this is that nobody wants the hassle of securing biometric data nor being responsible for it when it leaks.

Windows users left to fend for themselves after BitLocker patch bungle

loops

I'd be happy with that (my employer less so, unfortunately we're invested in MS).

loops

Indeed, that seems to be the way.

loops

Thanks. We've blocked it by policy already, with no notifications.

The recurring error we get is "The function you are attempting to run contains macros or content that requires macro language support."

It's a well documented error across Microsft sites going back 15 years (with a new post as recent as yesterday).

We worked our way through the first few pages of Google results (trying everything short of disabling the policy that blocks macros, including disabling all add ons, office repair, uninstall/reinstall, install 32 bit instead of 64 bit, deleting various files/folders, different versions, complete system reinstall, etc..). Nothing seems to solve it.

It's weird, because it only happens in certain scenarios. You can launch Word, and do file, new, and it opens a new document (this works fine, as expected). However, if you launch Word then open a file, then do file, new, it generates the above error. Another example; tying some equations seems to trigger it, but not others.

This happens on every single PC. The second it pulls down the Intune profile/security baselines/attack surface reduction rules, it starts with the above error.

We've all but given up on finding a solution. Microsoft are simply not interested in trying to help fix this issue, despite it apparently being incredibly widespread (I think they simply don't have a fix for it, so bat people off).

/shrug

loops

We have a recurring issue where Microsoft Office regularly pops up a warning that Macros are blocked (damn right they are!) which we can't suppress, and end users see the error regularly.

We contacted Microsoft Support, they replied and said Microsoft Office issues running on a Microsoft Operating System, connected to the Microsoft Azure, running Microsoft 365, utilising Microsoft SharePoint, controlled by Microsoft Intune is "out of band for Microsoft support".

What can you say to that?

Microsoft to use Windows 11 Start menu as a billboard with app ads for Insiders

loops

If you read the Windows EULA carefully, you'll note the words...

"Kerching. Thanks sucker. One born every minute. ROFL".

Microsoft likens MFA to 1960s seatbelts, buckles admins in yet keeps eject button

loops

Re: authenticator app

Not any more, not by default. Microsoft made their own Authenticator app the only way to Authenticate through the newish (15th September) "Registration Campaign" in Authentcation Methods in AAD/Entra/whatever they call it this week, even for TOTP, certainly for any newly registered accounts.

The generated QR code only works with the Microsoft app and it registers the app to the corresponding user account. You could see this for a few weeks after implementation, because you could see where people were authenticating from in Sentinel (yes - Sentinel was actually tracking personal devices!! since fixed), even when using TOTP, not push!

Interestingly, Microsoft have prevented you scanning the same QR code twice when one account registers through the "campaign" (so multiple people can no longer have the same TOTP code on their devices). More secure, but I bet we're not the only ones who have a real world use for this feature (we have a couple of generic shared accounts, so we want to have the same TOTP on multiple devices).

You can, of course, bypass all this by disabling the registration campaign - at which point the "use other autenticator" link appears again, and the QR codes are just generic TOTP codes rather than Microsoft specific codes.

The reason they're doing this is because they're pushing "Microsoft Managed MFA" and they can't enforce much if they don't control the app that people are authenticating with (+ they almost certainly upload a bunch of "telemetry" from every device the app is installed on, and then sell it - that's the age we live in).

Elon Musk's Twitter moves were 'reaffirming' says Reddit boss amid API changes

loops

Re: He needs an icon -->

Proof indeed that Musk simps are the most embarrassing people on the planet.

Windows 10 paid downloads end but buyers need not fear ISO-lation

loops

Re: Show us the stats

MacOS is predicted to be the dominant business endpoint in 2030.

Windows Subsystem for Linux now packaged as a Microsoft Store app

loops

Re: So what's the improvement in the store version?

None. They keep pushing everything to the Windows store because Windows Package Manager can access the store and they're pushing the Package Manager.

There's a major problem with this: any network administrator worth their salt will block the crappy Windows Store across their network.

In their wisdom they recently pushed Quick Assist to the Windows Store and then obsoleted the old (freely available) app. Microsoft support are now having to use Teams or Teamviewer, because nobody in enterprise can access the Quick Assist app any more.

And these people are supposed to be the intelligent ones.

Microsoft profits rise again despite knocks from China, Russia

loops

"$51.9 billion"

That's roughly how much it costs to fully secure Office 365.

ZX Spectrum, the 8-bit home computer that turned Europe on to PCs, is 40

loops

"Lots of people here at Pi Towers had their first exposure to programming on Sinclair hardware"

Every single C64 owner became a suave, sophisticated, international spy. They are all currently married to Swedish underwear models half their age, and they all drive Ferrari's during the week, and Lamborghini's for the weekend.

(this is an absolute 100% true, verifiable fact).

Netflix to crack down on account sharing, offer ad-laden cheaper options

loops

AKA: "we've reached market saturation, so we're curtailing features in expectation that existing customer accounts will increase their number of subscriptions"

Anyone who thinks this will work is completely nuts. They're just pushing people towards cancelling their existing subscriptions.

We've had a subscription since it started, 5 of us (all the same family). We are frequently geographically spread out, but do live together. The day we start to get warnings, ads, or any other "incentive" is the day I cancel, permanently.

Ubiquiti sues Krebs on Security for defamation

loops

Re: Ubiquiti's strategy...

"enterprise feature set"

Seriously? Their "pro" kit doesn't even allow you to list DHCP leases!

Software engineer jailed for 2 years after using RATs and crypters to steal underage victims' intimate pics

loops

Re: Not again..

> Child abusers/exploiters cannot be reformed

Sexual offences have the lowest recidivism rates of any offence.

You can attribute that to the violence they face when in prison, the monitoring they're subject to on release, the rehabilitation courses they are forced to take when in prison (it's about the only crime where offenders are forced to undertake rehabilitation) or, more likely, a combination of the three.

But the evidence does strongly suggest that a majority are reformed compared to other criminals. The ones that do go on to reoffend tend to make the headlines of course.

Pen Test Partners: Anyone could view Gumtree users' GPS location by pressing F12

loops

Re: In a statement Gumtree told The Register: "We were made aware..."

AKA: In a statement Gumtree told The Register "Fuck off, and when you've fucked off, kindly fuck off again".