Forumi


Povratak   PC Ekspert Forum > Ostalo > Razno
Ime
Lozinka

Odgovori
 
Uređivanje
Staro Jučer, 14:37   #721
Neo-ST
Premium
Moj komp
 
Neo-ST's Avatar
 
Datum registracije: Feb 2007
Lokacija: Croatia
Postovi: 8,414
Citiraj:
Autor Ivo_Strojnica Pregled postova
ajd kupi si stari mobitel. :D
Pa sad imam stari mobitel, S23 Ultra. To je po današnjim standardima staro. Nego šta sam s time onda dobio, opet sam podložan hackiranju 😅
Neo-ST je offline   Reply With Quote
Staro Jučer, 15:07   #722
Ivo_Strojnica
PRO
Moj komp
 
Ivo_Strojnica's Avatar
 
Datum registracije: Apr 2010
Lokacija: Zagreb
Postovi: 4,800
nisi.
Uzmeš stari mobitel, neki tanki, tipa pixel 6a, instaliraš na njega authentificator i to je to.
Taj mobitel nije nikad na netu niti može biti (osim ako nisi dovoljno inteligentan pa ga spojiš malo na wifi da vidiš jel na njemu još uvik dobro radi browser).

Eto ga, riješen problem.
__________________
"Who is your daddy and what does he do?"
Ivo_Strojnica je offline   Reply With Quote
Staro Jučer, 15:18   #723
Neo-ST
Premium
Moj komp
 
Neo-ST's Avatar
 
Datum registracije: Feb 2007
Lokacija: Croatia
Postovi: 8,414
Citiraj:
Autor Ivo_Strojnica Pregled postova
tanki
Najbitniji detalj...


Nego malo mi se čini overkill uzimat mobitel samo za 2fa? I onda ga stalno palit-gasit samo kad mi treba pristup nekom siteu...
Da nema neki hardware key koji može skenirat QR codove?
Neo-ST je offline   Reply With Quote
Staro Jučer, 15:50   #724
xlr
49%winner
Moj komp
 
xlr's Avatar
 
Datum registracije: Sep 2007
Lokacija: PU
Postovi: 10,109
Citiraj:
Autor Neo-ST Pregled postova

Da nema neki hardware key koji može skenirat QR codove?
Mogu i hw kljucevi imati TOTP, ali ti onda treba companion app. Primjer:
https://www.token2.com/shop/product/...pin-complexity

Companion app:
https://www.token2.com/site/page/tok...app-user-guide

Ne znam imaju li Yubico i ostali bolje/lakse rjesen ovaj korak citanja TOTP-a iz kljuca. Ali vjerojatno je i ovaj scenario podlozan prijeopisanom napadu
__________________
Keep calm and fastboot oem unlock.
xlr je offline   Reply With Quote
Staro Jučer, 15:57   #725
Ivo_Strojnica
PRO
Moj komp
 
Ivo_Strojnica's Avatar
 
Datum registracije: Apr 2010
Lokacija: Zagreb
Postovi: 4,800
Citiraj:
Autor Neo-ST Pregled postova
Najbitniji detalj...


Nego malo mi se čini overkill uzimat mobitel samo za 2fa? I onda ga stalno palit-gasit samo kad mi treba pristup nekom siteu...
Da nema neki hardware key koji može skenirat QR codove?
Istina, katastrofa. Radije kupi neki specificirani uređaj koji radi na način koji ti nije intuitivan i vrlo vjerojatno je skuplji.

Čisto da se osjećaš kul.

Čemu jednostavno, jel tako?
__________________
"Who is your daddy and what does he do?"
Ivo_Strojnica je offline   Reply With Quote
Staro Jučer, 16:02   #726
tomek@vz
White Rabbit
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: -
Postovi: 4,951
Citiraj:
Autor Neo-ST Pregled postova
Najbitniji detalj...


Nego malo mi se čini overkill uzimat mobitel samo za 2fa? I onda ga stalno palit-gasit samo kad mi treba pristup nekom siteu...
Da nema neki hardware key koji može skenirat QR codove?

Ideja iza zasebnog moba samo za TOTP je dedicirani uredaj koji koristis samo za to. Dakle ne mora biti biti onlajn, striktno instaliras TOTP aplikaciju i izbacis sve ostalo, kompletni lockdown tako da su gore opisani vektori napada - nemoguci. Night-ovo rijesenje je bolje jer je dovoljno jeftino iskreno i dovoljno glupo (bez ikakavih smart/phone home funkcija).
tomek@vz je offline   Reply With Quote
Staro Jučer, 16:17   #727
xlr
49%winner
Moj komp
 
xlr's Avatar
 
Datum registracije: Sep 2007
Lokacija: PU
Postovi: 10,109
E sad, koliko je jeftino, ne znam... Kazu da baterija traje 4-5 godina ako svaki dan 10 puta citas TOTP i jednom mjesecno upisujes seed preko NFC-a. Bummer je sto kad ode baterija, moras uzeti novi uredjaj i prebaciti seedove

"Will I lose access to the TOTP profiles when the battery is dead?
A. Yes, but you will have enough time to prepare. Molto-1 will have a battery indicator on the display. You should replace your token (and migrate the TOTP tokens by resetting the second factor on each respective service) when the indicator shows the battery level as "empty" - you will still have a couple of months to do this."

Ako zbilja traje po 5 godina, ajde de.

Ali ako stalno pored sebe imas neki stari fon koji samo sjedi u ladici i realno ti ne predstavlja trosak jer si ga vec amortizirao lol, alternativa s Aegisom i prebacivanjem seedova je skroz na mjestu.
__________________
Keep calm and fastboot oem unlock.
xlr je offline   Reply With Quote
Staro Jučer, 16:18   #728
Ivo_Strojnica
PRO
Moj komp
 
Ivo_Strojnica's Avatar
 
Datum registracije: Apr 2010
Lokacija: Zagreb
Postovi: 4,800
ili još bolje, napraviš da ti se ne može otvoriti authentifikator bez da upišeš password/biometriju.
Aegis authentificator, naprimjer.
Čim ga minimiziraš, nema pomoći.
__________________
"Who is your daddy and what does he do?"
Ivo_Strojnica je offline   Reply With Quote
Staro Jučer, 16:39   #729
Neo-ST
Premium
Moj komp
 
Neo-ST's Avatar
 
Datum registracije: Feb 2007
Lokacija: Croatia
Postovi: 8,414
Neo-ST je offline   Reply With Quote
Staro Danas, 07:31   #730
Night
Premium
 
Datum registracije: Oct 2008
Lokacija: Dbk
Postovi: 1,304
Citiraj:
Autor Neo-ST Pregled postova
Ovo mi izgleda iznimno nepraktično.
Npr. u trenutnom 2fa appu u mobitelu imam 30+ 2fa pinova za razne siteove.
Kad mi treba 2fa za neki site, moram u search početi upisivati ime tog sitea da mi izbaci 2fa za njega.
Ovaj uređaj može spremiti samo 10 accountova? To je prvi problem.
Imaš drugi model na koji ide 100 accounta, baterija od sata ima 8g trajanje, a ova glavna se puni preko USBa i ima par mjeseci trajanja :

https://www.token2.eu/shop/product/m...hardware-token

Ako treba i QR onda što ekipa tu već napisa, stariji mobitel, instalirati sve što treba i pogasiti mu mrežu.


Citiraj:
Autor Neo-ST Pregled postova
Ovo izgleda cool. Samo što kad umjesto cijene piše "Business customer request" čini mi se da bi moglo biti iznenađenja

Zadnje izmijenjeno od: Night. Danas u 07:38.
Night je offline   Reply With Quote
Staro Danas, 08:10   #731
Bono
Uptime 99.99%
Moj komp
 
Bono's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb
Postovi: 2,600
Microsoft is adding AI powered facial recognition to OneDrive.

And it can be disabled, but get this:

“You can only turn off this setting 3 times a year.”

https://fxtwitter.com/LundukeJournal...29065421750316

Sent from my SM-S931B using Tapatalk
__________________
“Those who surrender freedom for security will not have, nor do they deserve, either one.”
Bono je offline   Reply With Quote
Staro Danas, 08:24   #732
Libertus
Premium
Moj komp
 
Libertus's Avatar
 
Datum registracije: Jul 2017
Lokacija: Ramura
Postovi: 2,797
Majko mila...
Libertus je offline   Reply With Quote
Staro Danas, 10:14   #733
kopija
DIY DILETANT
 
kopija's Avatar
 
Datum registracije: Jan 2009
Lokacija: Čistilište
Postovi: 3,601
Pa zamisli kolko resursa je potrebno da bi se obradilo npr 15GB slika.
I onda ti to iz fore uključiš pa isključiš, sve ode u vjetar.
Normalno da hoće ljude demotivirat da drkaju po tom switchu.


This guy gets it:
Citiraj:
It probably has to run a pretty heavy workload each time it goes through your gallery so they probably mean you can't just turn it off and on and off and on forever. But that doesn't get as many clicks

Zadnje izmijenjeno od: kopija. Danas u 10:33.
kopija je offline   Reply With Quote
Staro Danas, 10:33   #734
Neo-ST
Premium
Moj komp
 
Neo-ST's Avatar
 
Datum registracije: Feb 2007
Lokacija: Croatia
Postovi: 8,414
Citiraj:
Autor Night Pregled postova
Ovo izgleda cool. Samo što kad umjesto cijene piše "Business customer request" čini mi se da bi moglo biti iznenađenja
Moraš otvoriti stranicu na desktopu pa ti se otvori opcija da dodaš u cart i možeš naručiti kao fizička osoba. Ovaj "Business customer request" je samo ako želiš naručiti kao biznis.
Ne znam zašto na mobilnoj stranici nema "add to cart" botuna.

Također imaju i jeftiniji model sa kamerom, koji doduše nema search opciju (ako ti je potrebna kad npr. imaš puno 2fa accountova).
Neo-ST je offline   Reply With Quote
Staro Danas, 11:01   #735
tomek@vz
White Rabbit
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: -
Postovi: 4,951
Citiraj:
Roughly 200,000 Linux-based Framework laptops shipped with a signed UEFI shell command (mm) that can be abused to bypass Secure Boot protections -- allowing attackers to load persistent bootkits like BlackLotus or HybridPetya. Framework has begun patching affected models, though some fixes and DBX updates are still pending. BleepingComputer reports: According to firmware security company Eclypsium, the problem stems from including a 'memory modify' (mm) command in legitimately signed UEFI shells that Framework shipped with its systems. The command provides direct read/write access to system memory and is intended for low-level diagnostics and firmware debugging. However, it can also be leveraged to break the Secure Boot trust chain by targeting the gSecurity2 variable, a critical component in the process of verifying the signatures of UEFI modules.

The mm command can be abused to overwrite gSecurity2 with NULL, effectively disabling signature verification. "This command writes zeros to the memory location containing the security handler pointer, effectively disabling signature verification for all subsequent module loads." The researchers also note that the attack can be automated via startup scripts to persist across reboots.

---


Citiraj:
Bruce Schneier and Barath Raghavan say agentic AI is already broken at the core. In their IEEE Security & Privacy essay, they argue that AI agents run on untrusted data, use unverified tools, and make decisions in hostile environments. Every part of the OODA loop (observe, orient, decide, act) is open to attack. Prompt injection, data poisoning, and tool misuse corrupt the system from the inside. The model's strength, treating all input as equal, also makes it exploitable. They call this the AI security trilemma: fast, smart, or secure. Pick two. Integrity isn't a feature you bolt on later. It has to be built in from the start. "Computer security has evolved over the decades," the authors wrote. "We addressed availability despite failures through replication and decentralization. We addressed confidentiality despite breaches using authenticated encryption. Now we need to address integrity despite corruption."

"Trustworthy AI agents require integrity because we can't build reliable systems on unreliable foundations. The question isn't whether we can add integrity to AI but whether the architecture permits integrity at all."
tomek@vz je offline   Reply With Quote
Staro Danas, 11:56   #736
Bono
Uptime 99.99%
Moj komp
 
Bono's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb
Postovi: 2,600
Citiraj:
Autor kopija Pregled postova
Pa zamisli kolko resursa je potrebno da bi se obradilo npr 15GB slika.
I onda ti to iz fore uključiš pa isključiš, sve ode u vjetar.
Normalno da hoće ljude demotivirat da drkaju po tom switchu.


This guy gets it:

Jadni ne mogu limitirati resurse, imas pravo 3 puta ugasiti, a oni ce ti 4x godisnje resetirati postavke. Tipicna indijska posla...

Sent from my SM-S931B using Tapatalk
__________________
“Those who surrender freedom for security will not have, nor do they deserve, either one.”

Zadnje izmijenjeno od: Bono. Danas u 12:34.
Bono je offline   Reply With Quote
Staro Danas, 12:55   #737
Neo-ST
Premium
Moj komp
 
Neo-ST's Avatar
 
Datum registracije: Feb 2007
Lokacija: Croatia
Postovi: 8,414
Mislim da bi ovo moglo spadati pod ovu temu ali nisam 100%, pa premjestite ako nije:

GrapheneOS is finally ready to break free from Pixels, and it may never look back
Neo-ST je offline   Reply With Quote
Staro Danas, 13:53   #738
kopija
DIY DILETANT
 
kopija's Avatar
 
Datum registracije: Jan 2009
Lokacija: Čistilište
Postovi: 3,601
Citiraj:
Roughly 200,000 Linux-based Framework laptops shipped with a signed UEFI shell command (mm) that can be abused to bypass Secure Boot protections -- allowing attackers to load persistent bootkits like BlackLotus or HybridPetya.
Vidi vraga, ja mislio da je SecureBoot nekakva urota zlog Microsofta protivu linuxaša, kad ono ispada da je u biti security feature.
Ko što je Tin rekao "krhko je znanje, možda je pao trag istine u me, a možda su sanje".
kopija je offline   Reply With Quote
Staro Danas, 13:58   #739
tomek@vz
White Rabbit
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: -
Postovi: 4,951
Citiraj:
Autor kopija Pregled postova
Vidi vraga, ja mislio da je SecureBoot nekakva urota zlog Microsofta protivu linuxaša, kad ono ispada da je u biti security feature.
Ko što je Tin rekao "krhko je znanje, možda je pao trag istine u me, a možda su sanje".

Moze li malo vise cinjenica bez sarkazma? Grazie


I da - that sucks:
Citiraj:

Roughly 200,000 Linux-based Framework laptops shipped with a signed UEFI shell command (mm) that can be abused to bypass Secure Boot protections -- allowing attackers to load persistent bootkits like BlackLotus or HybridPetya. Framework has begun patching affected models, though some fixes and DBX updates are still pending. BleepingComputer reports: According to firmware security company Eclypsium, the problem stems from including a 'memory modify' (mm) command in legitimately signed UEFI shells that Framework shipped with its systems. The command provides direct read/write access to system memory and is intended for low-level diagnostics and firmware debugging. However, it can also be leveraged to break the Secure Boot trust chain by targeting the gSecurity2 variable, a critical component in the process of verifying the signatures of UEFI modules.

The mm command can be abused to overwrite gSecurity2 with NULL, effectively disabling signature verification. "This command writes zeros to the memory location containing the security handler pointer, effectively disabling signature verification for all subsequent module loads." The researchers also note that the attack can be automated via startup scripts to persist across reboots.
Dakle - vise je Framework problem nego Linux problem. Mozes imati najsigurniji sigurnosni koncept na svijetu ali ako je lose implementiran imas doslovce ovakvo sranje.

Zadnje izmijenjeno od: tomek@vz. Danas u 14:10.
tomek@vz je offline   Reply With Quote
Staro Danas, 15:48   #740
OuttaControl
Premium
Moj komp
 
OuttaControl's Avatar
 
Datum registracije: Feb 2007
Lokacija: Dalmacija
Postovi: 5,848
Citiraj:
Autor Bono Pregled postova
Jadni ne mogu limitirati resurse, imas pravo 3 puta ugasiti, a oni ce ti 4x godisnje resetirati postavke. Tipicna indijska posla...
ja bi reka i ne godisneje nego nakon svakog updatea

jbt prije nekih 15 godina, it firme/korporacije su bile good guys, apple je bio najgori od svih, sad mi se cini da je apple najbolji po korisnike
OuttaControl je online   Reply With Quote
Staro Danas, 17:37   #741
Bono
Uptime 99.99%
Moj komp
 
Bono's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb
Postovi: 2,600
Citiraj:
Autor OuttaControl Pregled postova
ja bi reka i ne godisneje nego nakon svakog updatea

jbt prije nekih 15 godina, it firme/korporacije su bile good guys, apple je bio najgori od svih, sad mi se cini da je apple najbolji po korisnike
Ko da se natjecu tko ce vise zeznuti korisnike, Do no evil sad zvuci kao neslana sala ili kasnije do the right thing.
__________________
“Those who surrender freedom for security will not have, nor do they deserve, either one.”
Bono je offline   Reply With Quote
Staro Danas, 21:40   #742
mkey
Premium
Moj komp
 
Datum registracije: Sep 2018
Lokacija: tu
Postovi: 3,507
Citiraj:
Autor Neo-ST Pregled postova
Mislim da bi ovo moglo spadati pod ovu temu ali nisam 100%, pa premjestite ako nije:

GrapheneOS is finally ready to break free from Pixels, and it may never look back
Bude to po meni dodatni premium za GrapheneOS.
__________________
Citiraj:
Autor George Carlin
But there’s a reason. There’s a reason. There’s a reason for this, there’s a reason education sucks, and it’s the same reason that it will never, ever, ever be fixed. It’s never gonna get any better. Don’t look for it. Be happy with what you got. Because the owners of this country don't want that. I'm talking about the real owners now, the real owners, the big wealthy business interests that control things and make all the important decisions. Forget the politicians. The politicians are put there to give you the idea that you have freedom of choice. You don't. You have no choice. You have owners. They own you. They own everything. They own all the important land. They own and control the corporations. They’ve long since bought and paid for the senate, the congress, the state houses, the city halls, they got the judges in their back pockets and they own all the big media companies so they control just about all of the news and information you get to hear. They got you by the balls. They spend billions of dollars every year lobbying, lobbying, to get what they want. Well, we know what they want. They want more for themselves and less for everybody else, but I'll tell you what they don’t want: They don’t want a population of citizens capable of critical thinking. They don’t want well informed, well educated people capable of critical thinking. They’re not interested in that. That doesn’t help them. Thats against their interests. Thats right. They don’t want people who are smart enough to sit around a kitchen table to figure out how badly they’re getting f*cked by a system that threw them overboard 30 f*cking years ago. They don’t want that. You know what they want? They want obedient workers. Obedient workers. People who are just smart enough to run the machines and do the paperwork, and just dumb enough to passively accept all these increasingly shittier jobs with the lower pay, the longer hours, the reduced benefits, the end of overtime and the vanishing pension that disappears the minute you go to collect it, and now they’re coming for your Social Security money. They want your retirement money. They want it back so they can give it to their criminal friends on Wall Street, and you know something? They’ll get it. They’ll get it all from you, sooner or later, 'cause they own this f*cking place. It's a big club, and you ain’t in it. You and I are not in the big club. And by the way, it's the same big club they use to beat you over the head with all day long when they tell you what to believe. All day long beating you over the head in their media telling you what to believe, what to think and what to buy. The table is tilted folks. The game is rigged, and nobody seems to notice, nobody seems to care. Good honest hard-working people -- white collar, blue collar, it doesn’t matter what color shirt you have on -- good honest hard-working people continue -- these are people of modest means -- continue to elect these rich c*cksuckers who don’t give a f*ck about them. They don’t give a f*ck about you. They don’t give a f*ck about you. They don't care about you at all -- at all -- at all. And nobody seems to notice, nobody seems to care. That's what the owners count on; the fact that Americans will probably remain willfully ignorant of the big red, white and blue dick that's being jammed up their assholes everyday. Because the owners of this country know the truth: it's called the American Dream, because you have to be asleep to believe it.

Zadnje izmijenjeno od: mkey. Danas u 22:26.
mkey je offline   Reply With Quote
Staro Danas, 22:18   #743
Bono
Uptime 99.99%
Moj komp
 
Bono's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb
Postovi: 2,600
Moguce da se radi o Nothing phonu.

Sent from my SM-S931B using Tapatalk
__________________
“Those who surrender freedom for security will not have, nor do they deserve, either one.”
Bono je offline   Reply With Quote
Odgovori


Uređivanje

Pravila postanja
Vi ne možete otvarati nove teme
Vi ne možete pisati odgovore
Vi ne možete uploadati priloge
Vi ne možete uređivati svoje poruke

BB code je Uključeno
Smajlići su Uključeno
[IMG] kod je Uključeno
HTML je Uključeno

Idi na