Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. This is gonna catch some folks out πŸ˜…

This is gonna catch some folks out πŸ˜…

Scheduled Pinned Locked Moved Uncategorized
26 Posts 21 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

    RE: https://infosec.exchange/@merill/116203323789181775

    This is gonna catch some folks out πŸ˜…

    theorangetheme@en.osm.townT This user is from outside of this forum
    theorangetheme@en.osm.townT This user is from outside of this forum
    theorangetheme@en.osm.town
    wrote last edited by
    #2

    @GossiTheDog This is a great reminder for me to finally write that TOTP manager for my Cardputer.

    1 Reply Last reply
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      RE: https://infosec.exchange/@merill/116203323789181775

      This is gonna catch some folks out πŸ˜…

      alexhelvetica@toot.catA This user is from outside of this forum
      alexhelvetica@toot.catA This user is from outside of this forum
      alexhelvetica@toot.cat
      wrote last edited by
      #3

      @GossiTheDog I used a rooted device, purely to copy my totp keys out of Microsoft Authenticator, because there's no native way of exporting them to migrate to a different platform.

      I suggest everyone else does too. It's stored in an sqlite database as plain text, so it's trivial to extract them once you have access

      1 Reply Last reply
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        RE: https://infosec.exchange/@merill/116203323789181775

        This is gonna catch some folks out πŸ˜…

        dascandy@infosec.exchangeD This user is from outside of this forum
        dascandy@infosec.exchangeD This user is from outside of this forum
        dascandy@infosec.exchange
        wrote last edited by
        #4

        @GossiTheDog This is still just the authenticator TOTP protocol documented in an RFC?

        natkr@hachyderm.ioN fuzzyfuzzyfungus@cyberplace.socialF 2 Replies Last reply
        1
        0
        • R relay@relay.infosec.exchange shared this topic
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          RE: https://infosec.exchange/@merill/116203323789181775

          This is gonna catch some folks out πŸ˜…

          djgummikuh@mastodon.socialD This user is from outside of this forum
          djgummikuh@mastodon.socialD This user is from outside of this forum
          djgummikuh@mastodon.social
          wrote last edited by
          #5

          @GossiTheDog this is completely idiotic. Let me guess, they also eventually will start ratting out Android devices which no longer receive security updates and wipe them as well? Fuck Microslop

          bernardsheppard@mastodon.auB fuzzyfuzzyfungus@cyberplace.socialF 2 Replies Last reply
          0
          • R relay@relay.publicsquare.global shared this topic
          • dascandy@infosec.exchangeD dascandy@infosec.exchange

            @GossiTheDog This is still just the authenticator TOTP protocol documented in an RFC?

            natkr@hachyderm.ioN This user is from outside of this forum
            natkr@hachyderm.ioN This user is from outside of this forum
            natkr@hachyderm.io
            wrote last edited by
            #6

            @dascandy @GossiTheDog They have some custom push thingy too.

            1 Reply Last reply
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              RE: https://infosec.exchange/@merill/116203323789181775

              This is gonna catch some folks out πŸ˜…

              gvs@rebelbase.siteG This user is from outside of this forum
              gvs@rebelbase.siteG This user is from outside of this forum
              gvs@rebelbase.site
              wrote last edited by
              #7
              @GossiTheDog The irony. It means authenticator will not work on secure smartphones with @GrapheneOS even with the bootloader locked! But it will run fine on commercial phones that have countless holes and are broken into with cellebrite in a matter of hours (yes, when locked)
              1 Reply Last reply
              0
              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                RE: https://infosec.exchange/@merill/116203323789181775

                This is gonna catch some folks out πŸ˜…

                schrotthaufen@mastodon.socialS This user is from outside of this forum
                schrotthaufen@mastodon.socialS This user is from outside of this forum
                schrotthaufen@mastodon.social
                wrote last edited by
                #8

                @GossiTheDog This is going to do wonders for work/life balance πŸ˜„

                C 1 Reply Last reply
                0
                • R relay@relay.mycrowd.ca shared this topic
                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                  RE: https://infosec.exchange/@merill/116203323789181775

                  This is gonna catch some folks out πŸ˜…

                  khoos@infosec.exchangeK This user is from outside of this forum
                  khoos@infosec.exchangeK This user is from outside of this forum
                  khoos@infosec.exchange
                  wrote last edited by
                  #9

                  @GossiTheDog waiting for the first false positive...

                  tock@corteximplant.comT 1 Reply Last reply
                  0
                  • djgummikuh@mastodon.socialD djgummikuh@mastodon.social

                    @GossiTheDog this is completely idiotic. Let me guess, they also eventually will start ratting out Android devices which no longer receive security updates and wipe them as well? Fuck Microslop

                    bernardsheppard@mastodon.auB This user is from outside of this forum
                    bernardsheppard@mastodon.auB This user is from outside of this forum
                    bernardsheppard@mastodon.au
                    wrote last edited by
                    #10

                    @DJGummikuh

                    I have worked for organisations that do just that - their mobile device management platform does a remote wipe of the work profile if you do not keep the system up to date: if you fall more than two versions behind you get a week to upgrade or no work email / teams / access for you.

                    Bliss.

                    @GossiTheDog

                    djgummikuh@mastodon.socialD 1 Reply Last reply
                    0
                    • bernardsheppard@mastodon.auB bernardsheppard@mastodon.au

                      @DJGummikuh

                      I have worked for organisations that do just that - their mobile device management platform does a remote wipe of the work profile if you do not keep the system up to date: if you fall more than two versions behind you get a week to upgrade or no work email / teams / access for you.

                      Bliss.

                      @GossiTheDog

                      djgummikuh@mastodon.socialD This user is from outside of this forum
                      djgummikuh@mastodon.socialD This user is from outside of this forum
                      djgummikuh@mastodon.social
                      wrote last edited by
                      #11

                      @BernardSheppard @GossiTheDog they can do whatever the fuck they want with devices that THEY issued. But they can go fuck themselves if they expect to gain access to my private device for shenanigans like that

                      bernardsheppard@mastodon.auB 1 Reply Last reply
                      0
                      • djgummikuh@mastodon.socialD djgummikuh@mastodon.social

                        @BernardSheppard @GossiTheDog they can do whatever the fuck they want with devices that THEY issued. But they can go fuck themselves if they expect to gain access to my private device for shenanigans like that

                        bernardsheppard@mastodon.auB This user is from outside of this forum
                        bernardsheppard@mastodon.auB This user is from outside of this forum
                        bernardsheppard@mastodon.au
                        wrote last edited by
                        #12

                        @DJGummikuh this was on byod devices - but, yeah, I hear you.

                        This was a major multi-national with, by and large, compliant staff.

                        You could either be given a shitty work supplied locked down device that was several generations out of date, and carry two phones (which personally shits me) or accept that, if you wanted to byod, which you could self-enrol, you had to keep it reasonably up to date.

                        As I was there for only a few months, and I didn't particularly want or need to have work email on my phone, I opted out.

                        @GossiTheDog

                        jti42@infosec.exchangeJ 1 Reply Last reply
                        0
                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                          RE: https://infosec.exchange/@merill/116203323789181775

                          This is gonna catch some folks out πŸ˜…

                          cazzphoenix@social.vivaldi.netC This user is from outside of this forum
                          cazzphoenix@social.vivaldi.netC This user is from outside of this forum
                          cazzphoenix@social.vivaldi.net
                          wrote last edited by
                          #13

                          @GossiTheDog I've always felt weird about using my personal device for anything work related. Fortunately I was never forced to use it for email/teams. If this gets implemented, I hope people just start pushing for companies to provide them devices to use.

                          1 Reply Last reply
                          0
                          • bernardsheppard@mastodon.auB bernardsheppard@mastodon.au

                            @DJGummikuh this was on byod devices - but, yeah, I hear you.

                            This was a major multi-national with, by and large, compliant staff.

                            You could either be given a shitty work supplied locked down device that was several generations out of date, and carry two phones (which personally shits me) or accept that, if you wanted to byod, which you could self-enrol, you had to keep it reasonably up to date.

                            As I was there for only a few months, and I didn't particularly want or need to have work email on my phone, I opted out.

                            @GossiTheDog

                            jti42@infosec.exchangeJ This user is from outside of this forum
                            jti42@infosec.exchangeJ This user is from outside of this forum
                            jti42@infosec.exchange
                            wrote last edited by
                            #14

                            @BernardSheppard @DJGummikuh @GossiTheDog

                            Why would anyone byod or even mix private/business hardware, especially if there's MDM going on. I never got that.
                            Also, work hardware is going into poweroff after the agreed upon hours unless very special conditions and pricing apply.

                            On the other hand: Keeping the MDM'd business hardware up-to-date/updated or lock it otherwise sounds pretty sane.

                            bernardsheppard@mastodon.auB 1 Reply Last reply
                            0
                            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                              RE: https://infosec.exchange/@merill/116203323789181775

                              This is gonna catch some folks out πŸ˜…

                              tock@corteximplant.comT This user is from outside of this forum
                              tock@corteximplant.comT This user is from outside of this forum
                              tock@corteximplant.com
                              wrote last edited by
                              #15

                              @GossiTheDog Compelling reason why my next job in tech under Microslop is paying for a workplace handheld 100% so my rooted phone can stay off of work.

                              1 Reply Last reply
                              0
                              • khoos@infosec.exchangeK khoos@infosec.exchange

                                @GossiTheDog waiting for the first false positive...

                                tock@corteximplant.comT This user is from outside of this forum
                                tock@corteximplant.comT This user is from outside of this forum
                                tock@corteximplant.com
                                wrote last edited by
                                #16

                                @KHoos @GossiTheDog Right? Or a regression where MS believes all is well when millions are affected.

                                1 Reply Last reply
                                0
                                • jti42@infosec.exchangeJ jti42@infosec.exchange

                                  @BernardSheppard @DJGummikuh @GossiTheDog

                                  Why would anyone byod or even mix private/business hardware, especially if there's MDM going on. I never got that.
                                  Also, work hardware is going into poweroff after the agreed upon hours unless very special conditions and pricing apply.

                                  On the other hand: Keeping the MDM'd business hardware up-to-date/updated or lock it otherwise sounds pretty sane.

                                  bernardsheppard@mastodon.auB This user is from outside of this forum
                                  bernardsheppard@mastodon.auB This user is from outside of this forum
                                  bernardsheppard@mastodon.au
                                  wrote last edited by
                                  #17

                                  @jti42

                                  When it was a small IT team, and the head of IT was a peer, and I could discuss, understand the stack, and trust him, a work profile was no big deal.

                                  Otherwise, yeah, nah, you can supply me with a phone. Which I will still turn off.

                                  @DJGummikuh @GossiTheDog

                                  1 Reply Last reply
                                  0
                                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                    RE: https://infosec.exchange/@merill/116203323789181775

                                    This is gonna catch some folks out πŸ˜…

                                    bobo_pk@chaos.socialB This user is from outside of this forum
                                    bobo_pk@chaos.socialB This user is from outside of this forum
                                    bobo_pk@chaos.social
                                    wrote last edited by
                                    #18

                                    @GossiTheDog FreeOTP+

                                    Works fine for #Mircoslop and all other OTP tokens

                                    1 Reply Last reply
                                    0
                                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                      RE: https://infosec.exchange/@merill/116203323789181775

                                      This is gonna catch some folks out πŸ˜…

                                      J This user is from outside of this forum
                                      J This user is from outside of this forum
                                      jackryder@infosec.exchange
                                      wrote last edited by
                                      #19

                                      @GossiTheDog 🀯

                                      Not quite unbelievable, but wow.

                                      1 Reply Last reply
                                      0
                                      • dascandy@infosec.exchangeD dascandy@infosec.exchange

                                        @GossiTheDog This is still just the authenticator TOTP protocol documented in an RFC?

                                        fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                                        fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                                        fuzzyfuzzyfungus@cyberplace.social
                                        wrote last edited by
                                        #20

                                        @dascandy @GossiTheDog It's several different things. Standardized TOTP is supported; two similar looking but distinct('microsoft authenticator(push notification)' and 'microsoft authenticator(phone sign-in)' proprietary things are supported and preferred in default AAD configs; and it's also the client for "Face Check"/"Verified ID" cases, if an org is paying up for that.

                                        1 Reply Last reply
                                        0
                                        • djgummikuh@mastodon.socialD djgummikuh@mastodon.social

                                          @GossiTheDog this is completely idiotic. Let me guess, they also eventually will start ratting out Android devices which no longer receive security updates and wipe them as well? Fuck Microslop

                                          fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                                          fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                                          fuzzyfuzzyfungus@cyberplace.social
                                          wrote last edited by
                                          #21

                                          @DJGummikuh @GossiTheDog If 'play integrity' and similar are anything to go by; ancient and busted will be fine; so long as it's the ancient and busted that your OEM intended. The enemy, after all, is your filthy little hacker fingers; not an industry of pervasively abysmal code quality and more or less open contempt for confidentiality issues.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups