tblFlip

joined 2 years ago
[–] tblFlip@pawb.social 4 points 5 months ago (1 children)

to be fair, the best response to that is just "Greetings!" and then you watch them trying to comprehend. and don't get me started on people that hit send after every other word...

[–] tblFlip@pawb.social 3 points 8 months ago

humans just had to fuck around and find out...

[–] tblFlip@pawb.social 2 points 8 months ago

i'll make a wild guess and say that the true percentage is somewhere around 75%, maybe close to 80%.

a good chunk of players that call the rats are new players that might not have bought odyssey right away and started in horizons 4.0. the raw numbers the fuel rat stats can provide are a bit biased towards underestimating how the 4.0 playerbase is split between horizons and odyssey in favor of horizons. ( i wish there were stats about how many hours players typically log before having to call the rats, but we have no data to do that :/ )

[–] tblFlip@pawb.social 6 points 9 months ago

gruyère... of course that almost ended horribly. shouldve used cheddar...

[–] tblFlip@pawb.social 5 points 1 year ago

love the quote at the end. there are far too many situations where windows is because "because!" where its just the wrong tool for the job. pos, web servers, trains to name a few i can think of...

[–] tblFlip@pawb.social 3 points 1 year ago

eggcelent news!

[–] tblFlip@pawb.social 26 points 1 year ago (1 children)

and i claim that i have a pig in my basement that plays celtic whistle and shits pure palladium every sunday

[–] tblFlip@pawb.social 3 points 1 year ago

ye, dont think ive seen anyone talk about that. sad

[–] tblFlip@pawb.social 10 points 1 year ago (1 children)

wonderful read. ive reached a point where i can do nothing but lean back, sip a drink and laugh while these companies race each other to destroy their platforms. might as well start betting on who does the next stupid decision...

[–] tblFlip@pawb.social 7 points 1 year ago

breaking news: researchers discover that network protocols work as intended. mindlessly connecting to an untrusted network is still a bad idea.

to quote the article: "Do not use untrusted networks if you need absolute confidentiality of your traffic" or use HTTPS and a SOCKS5 proxy

[–] tblFlip@pawb.social 3 points 1 year ago (2 children)

yup yup yup. didnt steam also have some "fun" rm -rf bug a few years ago? proper backups and sandboxing go a long way

[–] tblFlip@pawb.social 7 points 2 years ago

ok, after reading that article fully, it does sound a lot less concerning than the headline would like me to believe. it is early in the morning (almost 13:00) and this is a great chance to expose how little i know about all that, so i will:

They believed SSH traffic was immune [...].

classic. we always think that something is perfectly safe until it breaks. also, looking at the article, the issue with RSA has been known since 1996. there had to be a useful application for this. such as TLS. and now some SSH implementations.

Last year, researchers found that [...] they were still able to passively observe faulty signatures that allowed them to compromise the RSA keys of [...] Baidu.com

no idea how this adds any value in a discussion about SSH, but i chuckled.
now the article also get to some more interesting stats.

5.2 billion SSH records. of that 590k with invalid signatures and 4.9k revealed factorization for a total of 189 unique private keys.

now i would very much prefer that last number to be a solid zero, but out of 590k faults, only 4.9k were usable for the attack. everyone that thinks "oh thats nothing. im safe." is still a fool, but it could be far worse. especially since this only target RSA and leaves ed25519 (and others) untouched.

but it just gets even better:

The researchers traced the keys they compromised to devices that used custom, closed-source SSH implementations that didn’t implement the countermeasures found in OpenSSH and other widely used open source code libraries.

if i was drinking something reading this, i would have spat it out laughing. i am that kind of fun at parties. this also partially explains why there are "only" 590k invalid signatures in over 5.2 billion records total. and judging by how good some companies and organizations handle updates (assuming there will be updates from cisco, zyxel, hillstone and mocana), this will still be enough to be used in some attacks five years from now.

 

If you don't like flying drones, treat them as hardware CTF's instead!

 

Google's browser not only got new chrome, it now also uses keeps track of all websites you visit to generate a topic list for ads that is shared with websites directly. Nobody asked for that.

 

a very interesting talk by Harald Welte about the complex mechanisms and architecture that keep eSIM working. prepare for a lot of acronyms

 

intel now joins the club with their take on GPU driver telemetry. they call it "Computing Improvement Program" and it can thankfully be disabled during a manual install, or in system settings after the installation is complete

view more: ‹ prev next ›