- Feature Articles
- CodeSOD
- Error'd
- Forums
-
Other Articles
- Random Article
- Other Series
- Alex's Soapbox
- Announcements
- Best of…
- Best of Email
- Best of the Sidebar
- Bring Your Own Code
- Coded Smorgasbord
- Mandatory Fun Day
- Off Topic
- Representative Line
- News Roundup
- Editor's Soapbox
- Software on the Rocks
- Souvenir Potpourri
- Sponsor Post
- Tales from the Interview
- The Daily WTF: Live
- Virtudyne
Admin
[quote user="Kuba]Umm, what kind of lame network switch do you use that cannot prevent all that? A rather cheap $300 managed switch, like HP2626 off eBay, will take care of all that for you.[/quote]A switch can't block traffic that don't go through it.
If someone intentionally buy a cheap router with DHCP server, of course he'll also bring in cheap hubs that has no security at all (hub that broadcast any packet it receive on all ports it have, without even both to check the receiptant's IP/MAC address.
[company network] - [switch] - [hub] - [cheap router] | |----- [client PC]
Admin
Emmm... seems the comment box is eating leading space. The "client PC" at above chart should be connected to the "hub".
Admin
So the real WTf here is that Gerald wasted all this time "inventing" OpenID?
Admin
Any proxy or filter worth its shit will serve X-Forwarded-For. Read off that along with certs.
XFF can be trusted if you define the external IP
Admin
just implimented SSO via ADFS for microsoft. ADFS is supported across multiple architectures outside of M$ including sun and IBM
Admin
Fingerprint scanners are easy to spoof (go watch Mythbusters, all you need is the fingerprint, a good flatbed scanner and a laser printer). Also they are not the most reliable devices (if you never have to swipe more than once there's a good chance someone else' finger will work)
Admin
Except the feature is stupid, broken and probably shouldn't have passed the certification mentioned, and someone ever does catch the possible problems with it...
Admin
THIS
Admin
Until someone brings a machine from home... (and don't mention MAC address based dhcp, MAC addresses can be spoofed)
Admin
This seems to be a web app, you don't get to talk to USB dongles from a web app
Admin
So they were doing it wrong, how is the fact that mistakes tend to be repeated relevant?
Admin
The WTF is that this got to production, it's not secure (not even remotely)
Admin
It's a web app... you don't get to talk to a USB dongle...
Admin
Like they would remember that there was a client certificate....
Admin
Through Brittish goggles it is. I'm sure poor illtiz's browser uses the wrong encoding.
Admin
Oh wow, seems pretty reasonable to me dude.
Lou www.anon-vpn.net.tc
Admin
Actually, you can have a smart card dongle and easily use a middleware to access it throught PKCS#11. Firefox supports it straight out of the box. IE, for instance, requires an additional software but still works.
It's equivalent to a client-side certificate, but more secure (multi-factor authentication).
Anyway, besides the obvious client-side certificate solution, they just ended up implementing a simple (and much less secure) version of Kerberos...
Admin
Due to our trustful and professional services, new genlemen & beauties are joining all the time and many are making connections every day. It takes only a few minutes to submit a profile which, however, might change your whole life. and still will bring you more fun!!
____ S e e k I n t e r r a c i a l [DOT] c o m ___
With almost 2 million profiles, ____ S e e k I n t e r r a c i a l [DOT] c o m ___, the Interracial dating site, is the best source of dating profiles for Interracial Singles.
Admin
Had a similar incident where an art director over sold a "Flash" interface for a login screen that had a beautiful rendering of a vault and you had to spin the tumblers for access.
I had to point out that this was the backend login screen.
Admin
Client certs is the obvious solution.
My speculation is that this is a prime example of YAGNI in action. At some point in the future (which never arrives), the client expected more users. Barring clairvoyance, the money would have been better spent elsewhere until (and if) that future arrives.
Admin
This doesn't seem all that secure to me. Don't I just have to unplug the user's computer from the network, and then set my computer to their IP address?
Admin
I'm sorry, but if someone says they can't remember their logins then the IT is responsible for changing their login and sending an email with the new login to them. If this becomes a habit, the person needs to be either trained to help them remember their login, or disciplined otherwise.
But if they REFUSE to remember their logins to systems, they need to be shown to the front door.
Admin
Pharmacie en ligne livraison Europe https://kamagraenligne.com/# acheter mГ©dicament en ligne sans ordonnance