Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Raymond T. Racing posted:

YOSPOS CA is looking more and more likely

publicly trusted shitposts

Adbot
ADBOT LOVES YOU

NoneMoreNegative
Jul 20, 2000
GOTH FASCISTIC
PAIN
MASTER




shit wizard dad

Antigravitas posted:

YCAPOS is a bit hard to pronounce though.

nah you just do it to the YMCA tune

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



NoneMoreNegative posted:

nah you just do it to the YMCA tune

hell yeah

digitalist
Nov 17, 2000

journey into Kirk's unknown


Certainly Awful Certificate Authority (CACA)

e: but YCAPOS still wins in my books

digitalist fucked around with this message at 15:37 on May 3, 2024

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

SA-CERT-POS

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Wiggly Wayne DDS
Sep 11, 2010



so e-commerce have been under scrutiny since early 2023. i was glancing at their certificate policy statement earlier and it was just worthless so i looked at their -certificate policy- instead and noted an issue


it's a bunch of specific issues i got from just checking what -wasn't- mentioned in their changelogs that should have been. but anyway after that i took a break

going back and then moving on a tiny bit:


how the gently caress have they not been thrown out yet. i thought the 'not not' translation was bad enough

e:

????????????????????????????????????????

Wiggly Wayne DDS fucked around with this message at 16:41 on May 3, 2024

digitalist
Nov 17, 2000

journey into Kirk's unknown


I'm starting to imagine YCAPOS as an oldschool cracking group with cool ASCII art but for CAs

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

definitely a proprietary extension for an ANSI animation field

Raymond T. Racing
Jun 11, 2019

digitalist posted:

I'm starting to imagine YCAPOS as an oldschool cracking group with cool ASCII art but for CAs

honestly I loving love this idea

acme certs only
plain text website
"manage your account? no"
"request delay of revocation? no"

Antigravitas
Dec 8, 2019

Die Rettung fuer die Landwirte:
CSR must be included in an .nfo file.

digitalist
Nov 17, 2000

journey into Kirk's unknown


Subjunctive posted:

definitely a proprietary extension for an ANSI animation field


Raymond T. Racing posted:

honestly I loving love this idea

acme certs only
plain text website
"manage your account? no"
"request delay of revocation? no"


Antigravitas posted:

CSR must be included in an .nfo file.

:hmmyes:

We'll need some music people for chiptunes

Wiggly Wayne DDS posted:

so e-commerce have been under scrutiny since early 2023. i was glancing at their certificate policy statement earlier and it was just worthless so i looked at their -certificate policy- instead and noted an issue


it's a bunch of specific issues i got from just checking what -wasn't- mentioned in their changelogs that should have been. but anyway after that i took a break

going back and then moving on a tiny bit:


how the gently caress have they not been thrown out yet. i thought the 'not not' translation was bad enough

e:

????????????????????????????????????????

And English majors for understanding whatever the gently caress is going on in here

spankmeister
Jun 15, 2008






What is CA? A miserable little pile of shell scripts.

The Fool
Oct 16, 2003


spankmeister posted:

What is CA? A miserable little pile of shell scripts.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Raymond T. Racing posted:

honestly I loving love this idea

acme certs only
plain text website
"manage your account? no"
"request delay of revocation? no"

Winkle-Daddy
Mar 10, 2007
I'll run the poo poo post transparency (SPT) log!

digitalist
Nov 17, 2000

journey into Kirk's unknown


spankmeister posted:

What is CA? A miserable little pile of shell scripts.


Beautiful.

code:


 /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\ 
( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )
 > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ < 
 /\_/\                                                                               /\_/\ 
( o.o )                                                                             ( o.o )
 > ^ <                                                                               > ^ < 
 /\_/\                                ('-.      _ (`-.                .-')           /\_/\ 
( o.o )                              ( OO ).-. ( (OO  )              ( OO ).        ( o.o )
 > ^ <         ,--.   ,--.  .-----.  / . --. /_.`     \ .-'),-----. (_)---\_)        > ^ < 
 /\_/\          \  `.'  /  '  .--./  | \-.  \(__...--''( OO'  .-.  '/    _ |         /\_/\ 
( o.o )       .-')     /   |  |('-..-'-'  |  ||  /  | |/   |  | |  |\  :` `.        ( o.o )
 > ^ <       (OO  \   /   /_) |OO  )\| |_.'  ||  |_.' |\_) |  |\|  | '..`''.)        > ^ < 
 /\_/\        |   /  /\_  ||  |`-'|  |  .-.  ||  .___.'  \ |  | |  |.-._)   \        /\_/\ 
( o.o )       `-./  /.__)(_'  '--'\  |  | |  ||  |        `'  '-'  '\       /       ( o.o )
 > ^ <          `--'        `-----'  `--' `--'`--'          `-----'  `-----'         > ^ < 
 /\_/\                                                                               /\_/\ 
( o.o )                                                                             ( o.o )
 > ^ <                                                                               > ^ < 
 /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\  /\_/\ 
( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )( o.o )
 > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ <  > ^ < 


On a slightly more serious note, Wayne/Amir/whoever, if you need an extra pair of eyes to read through some garbage I'd be happy to help out. I guess I could just pick a CA at random and start digging, I have a feeling it wouldn't be too difficult to find issues.

Either that or I can just keep shitposting.

Raymond T. Racing
Jun 11, 2019

yeah straight up good work to amir/wayne

that's some serious digging y'all have done

Wiggly Wayne DDS
Sep 11, 2010



digitalist posted:

On a slightly more serious note, Wayne/Amir/whoever, if you need an extra pair of eyes to read through some garbage I'd be happy to help out. I guess I could just pick a CA at random and start digging, I have a feeling it wouldn't be too difficult to find issues.

Either that or I can just keep shitposting.
i'll throw you in the deep-end, try and see what makes sense in this: https://service.globaltrust.eu/static/globaltrust-certificate-policy.pdf

you don't need to know the actual baseline requirements or individual root program policies for that, poo poo will jump out a mile. i hadn't read any of that 2 months ago anyway, i'm new too

digitalist
Nov 17, 2000

journey into Kirk's unknown


Wiggly Wayne DDS posted:

i'll throw you in the deep-end, try and see what makes sense in this: https://service.globaltrust.eu/static/globaltrust-certificate-policy.pdf

you don't need to know the actual baseline requirements or individual root program policies for that, poo poo will jump out a mile. i hadn't read any of that 2 months ago anyway, i'm new too

Is the CP 404ing a violation of BR?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

literally yes, IIRC

Raymond T. Racing
Jun 11, 2019

digitalist posted:

Is the CP 404ing a violation of BR?

yeah I thought I was missing something unless that’s the joke

digitalist
Nov 17, 2000

journey into Kirk's unknown


drat we're good

edit: Google turns this up, https://www.globaltrust.eu/static/globaltrust-certificate-policy.pdf

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

the lmaos will continue until distrust occurs

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Captain Foo posted:

the lmaos will continue until distrust occurs

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

that copyright note on the very first loving page is….hmm, nope

Wiggly Wayne DDS
Sep 11, 2010



digitalist posted:

Is the CP 404ing a violation of BR?
it works for me, lmao, but yes:

quote:

2.2 Publication of information
The CA SHALL publicly disclose its Certificate Policy and/or Certification Practice Statement through an appropriate and readily accessible online means that is available on a 24x7 basis.
https://service.globaltrust.eu/static/globaltrust-certificate-policy.pdf is what is linked on https://globaltrust.eu/certificate-policy/ which is -technically- the cps url included on their certs (it's actually http://www.globaltrust.eu/certificate-policy.html which redirects)

digitalist
Nov 17, 2000

journey into Kirk's unknown


lol, it's working now. I'll dig into this later this evening/weekend, I have actual work to do if you can believe it, in between shitposting that is

This kind of stuff is actually related, a bit more on the periphery but still important/necessary to my 9 to 5, so happy to find an excuse to learn more about it.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Captain Foo posted:

the lmaos will continue until distrust occurs

psiox
Oct 15, 2001

Babylon 5 Street Team
this thread has made me wonder if just anyone's dumb racist uncle can get into the root CA stores these days. frankly i trust the internet significantly less now

SIGSEGV
Nov 4, 2010


Definite yes, also every state's national security apparatus which are 90% guys like that.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

we need a series of Wiggly Wayne reaction videos as he scrolls through bugzilla

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

“random tiny company with keys to the whole web sucked me off?!?”

Wild EEPROM
Jul 29, 2011


oh, my, god. Becky, look at her bitrate.
when you click the about us page it just gives you the classic ascii middle finger

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Subjunctive posted:

we need a series of Wiggly Wayne reaction videos as he scrolls through bugzilla

wiggly wayne vtuber with the old wevie stonder avatar

e: or maybe it was never wevie stonder? idk

e2: this guy, didnt you used to have that for an avatar wayne?
https://www.youtube.com/watch?v=vtnk26iyXYo

Aaronicon
Oct 2, 2010

A BLOO BLOO ANYONE I DISAGREE WITH IS A "BAD PERSON" WHO DESERVES TO DIE PLEEEASE DONT FALL ALL OVER YOURSELF WHITEWASHING THEM A BLOO BLOO

Don't worry, the exec have been pitching some great ideas for how to deal with phishing lately like, 'serve all the text on the website as an image so phishers can't copy the text' and 'lets have a meeting with this security company who says that can add DRM to the site so people can't right-click save the website to make a copy'

Phishing is an almost impossible problem to solve from a technical POV (outside of forcing everyone onto passkeys or some other hands-off domain specific credentials) and it's basically all on the users to not be tricked which you should always assume they will be at some point

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

but it means we can pay money to knowb4, so

Wiggly Wayne DDS
Sep 11, 2010



Carthag Tuek posted:

e2: this guy, didnt you used to have that for an avatar wayne?
not that i recall, but uh spoilers i've never bought an avatar for myself (maybe the very first? idr). or gangtags. this username is also from a random namechange thread...

i tried to tackle what should be a very simple question about e-commerce monitoring GmbH "When do they handle revocation of a compromised certificate?": https://bugzilla.mozilla.org/show_bug.cgi?id=1862004#c13

e: also a tiny tiny tiny issue happened: IdenTrust: unintended creation of a Root CA certificate

Wiggly Wayne DDS fucked around with this message at 22:38 on May 3, 2024

Shaggar
Apr 26, 2006

Captain Foo posted:

but it means we can pay money to knowb4, so

our dumbass company signed up for some knowbe4 poo poo and they spammed everyone with a kevin mitnick video. everyone in the company reported it as phishing and they cancelled the training

Adbot
ADBOT LOVES YOU

spankmeister
Jun 15, 2008






Shaggar posted:

our dumbass company signed up for some knowbe4 poo poo and they spammed everyone with a kevin mitnick video. everyone in the company reported it as phishing and they cancelled the training

When they said Free Kevin Mitnick they meant it. You get one with every phishing test.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply