Mniot

joined 5 months ago
[–] Mniot@programming.dev 3 points 3 months ago

Goats sure are neat

[–] Mniot@programming.dev 6 points 3 months ago

To someone watching network traffic, a VPN connection looks like two machines exchanging encrypted packets. You can't see the actual data inside the packet, but you can see all the metadata (who it's addressed to, how big it is, whether its TCP or UDP, when it's sent). From the metadata, you can make guesses about the content and VPN would be pretty easy to guess.

When sending a packet over the Internet, there's two parts of the address: the IP address and the port. The IP address is a specific Internet location, blocks of IP addresses are owned by groups (who owns what is public info) and there are many services that do geo-ip mappings. So if you're connecting to an IP address that belongs to a known VPN provider, that's easy.

The second part of the address is the port-number. Servers choose port-numbers to listen to and the common convention is to use well-known ports. So, for example, HTTPS traffic is on port 443. If you see a computer making a lot of requests to port 443, even though the traffic is encrypted we can guess that they're browsing the web. Wikipedia has a list (which is incomplete because new software can be written at any time and make up a new port that it prefers) and you can see lots of VPN software on there. If you're connecting to a port that's known to be used by VPN software, we can guess that you're using VPN software.

Once you're running VPN software on an unknown machine and have configured it to use a non-standard port, it's a bit harder to tell what's happening, but it's still possible to make a pretty confident guess. Some VPN setups use "split-tunnel" where some traffic goes over VPN and some over the public Internet. (This is most common in corporate use where private company traffic goes in the tunnel, but browsing Lemmy would go over public.) Sometimes, DNS doesn't go through the VPN which is a big give-away: you looked up "foo.com" and sent traffic to 172.67.137.159. Then you looked up "bar.org" and sent traffic to the same 172.67.137.159. Odds are that thing is a VPN (or other proxy).

Finally, you can just look at more complex patterns in the traffic. If you're interested, you could install Wireshark or just run tcpdump and watch your own network traffic. Basic web-browsing is very visible: you send a small request ("HTTP GET /index.html") and you get a much bigger response back. Then you send a flurry of smaller requests for all the page elements and get a bunch of bigger responses. Then there's a huuuuge pause. Different protocols will have different shapes (a MOBA game would probably show more even traffic back-and-forth).

You wouldn't be able to be absolutely confident with this, but over enough time and people you can get very close. Or you can just be a bit aggressive and incorrectly mark things as VPNs.

[–] Mniot@programming.dev 25 points 4 months ago

It's a bad headline: seems easy to believe that there's just a lot more journalists around today than there were in the world wars.

Much better would be to highlight from the body of the article that the death toll is also more than have been killed in the invasion of Ukraine. That one's modern, well-covered by media, Russia has repeatedly targeted civilians, and Russia's been attacking for longer. So to have still killed more journalists makes it clear that it's deliberate.

[–] Mniot@programming.dev 2 points 4 months ago

I wonder if the sleep-change fucks up our brains and that's why more people aren't upset about it.

Until this comment, I'd completely forgotten about how the most recent time-change messed up me and the puppy I've been training, because of course she needs to pee as soon as she wakes up at 6am every day...

[–] Mniot@programming.dev 31 points 4 months ago (3 children)

But note that that's about nudity and sex being the same, and the sex is pornographic (that is, the intent in showing it is to arouse the viewer). The OP is about non-sexual nudity. In fact, OP doesn't mention sex at all, but I feel like it's reasonable to extend the argument to non-pornographic depictions of sex.

[–] Mniot@programming.dev 16 points 4 months ago (1 children)

The subtext of "anti-DEI", though, is that it is not possible to have two competent candidates where one is a woman/minority because conservative Christian English-speaking white men from wealthy families are inherently superior.

[–] Mniot@programming.dev 39 points 4 months ago (5 children)

It's a funny post, but a serious point. The Europe of my childhood was different countries all very different from the US. But over time American media and algorithmic dominance are eroding things toward being America with accents. And what will you get for throwing away that cultural identity? Americans will still sneer at Europe.

I think a trickier question is: if Europe ought to retain its own identity, then shouldn't each European country retain its own identity instead of banding together as "Europe".

[–] Mniot@programming.dev 61 points 4 months ago (10 children)

As a programmer, DST creates tons of bugs for anything using time and is annoying. But whatever, I guess I get paid either way.

As a parent, DST is miserable. It's miserable as an adult, also, but multiplied misery when you have to get up early to ruin your kid's sleep. And then that night they're not ready to suddenly go to sleep an hour early so you lose an extra hour...

I hope Poland succeeds.

[–] Mniot@programming.dev 5 points 4 months ago

Wow! That is a big bean!

[–] Mniot@programming.dev 25 points 4 months ago (1 children)

Torture isn't useful as an intelligence-gathering tool, but that's not what it's being used for here. Torture works quite well for manufacturing confessions to use as propaganda to justify further killing/torture/other crimes.

[–] Mniot@programming.dev 2 points 4 months ago

I don't know. I might say "Matrix" and run a private server? But that's a bunch of IT work. It's attractive to use a SaaS because you don't have to do any long-term planning or hiring; just pay Slack a crazy amount of money and it all works.

Corps also like a commercial paid service because they get a contract with an SLA (even if it's rare to actually get anything from these SLAs).

[–] Mniot@programming.dev 3 points 4 months ago

enough that voted Trump

Fuck those assholes. The ones that break my heart are the ones who didn't vote at all because "the Democrats are terrible too". Yeah, they are. But voting for the least-bad politician is the minimum-effort thing and everyone I know who skipped voting is not spending their time community-organizing or engaged in violent revolution.

view more: ‹ prev next ›