• 0 Posts
  • 21 Comments
Joined 1Y ago
cake
Cake day: Aug 22, 2023

help-circle
rss

Makes me wonder if there are any cyphers that are easy enough that human meat could implement it but hard enough that it would take some serious GPU time to crack?


Computers are hard, can everyone go back to unobfuscated telephone calls and handwritten letters?

  • Cops everywhere

There was a Defcon talk a few years ago (oh god it was 8 years ago) where someone found a way mess with Chryslers because they were all on the Sprint wireless network. Things like lock out the physical controls on the radio then max out the volume, or turn it into a GPS tracker, or disable the brakes! The cars had some service listening on port 6667, there was no way to stop them from accepting malicious connections so Sprint just blocked all traffic on that port on their network at the request of Chrysler. The speaker mentioned they were sorry if you were unable to use IRC any more on Sprint wireless.

DEF CON 23 - Charlie Miller & Chris Valasek - Remote Exploitation of an Unaltered Passenger Vehicle



I read a great post where a guy bit-squatted (bought a domain that was 1 flipped bit away) Google and managed to replace the Google logo on google.com for millions of people. He did the same for facebook and ended up getting thousands of post requests with user data which normally would have failed to resolve or just timed out.

There is still plenty of unexpected fun to be had with domains.


DeleteMe

They seem like a scam. Their “Free Scan” gives the same results on a 20 year old email address as it does on a 2 years old address.



I love Mullvad and recommend them for everything other than torrenting. Once they disabled port forwarding I moved to AirVPN who seem to be pretty legit.

I’m not trying to keep my ratios up but I have a few torrents of media that are not available anywhere for sale and have less than 10 seeds, so I feel like I am helping keep the shows and movies of my childhood alive.


You expect a cop to understand both the threat and entertainment value of a Defcon talk?


As soon as Google bought YouTube they knew who the users were and everything they did online. This was never not true. Their business is to log all the activity of all internet users, not to make them safe or happy, there is nothing broken in their platform as far as they are concerned.


Go to reddit, pick a username from the front page, use that. Any searching into your use of it will lead to that front page post and its reposts on click mills.


Big Clive, Ben Krasnow, Mike’s Electric Stuff, Folding Ideas, Practical Engineering, Nurd Rage, Alpha Phoenix, Ben Eater, Diode Gone Wild, EEVBlog, Huygens Optics, Jeri Ellsworth, Woodgears, every god damned DefCon talk.

The ONLY saving grace of YouTube is that you can fucking learn anything on any subject if you can find the right channel.


Keepass wiht my kdbx in a webdav share with basic auth is the tits. I can access and modify it remotely and it’s easy to detect and block any bots/users who are snooping and trying to access the webdav share. After 3 years of using this setup I’ve only had a dozen hits on that directory out of the hundreds of thousands of bot requests.


For sure if you use a cloud provider, but there are self-hosted and totally offline solutions.


For normies it’s easy:

  1. Password Manager
  2. Firefox
  3. Adblocker

Those three will make up for 90% of peoples bad habits.


Because a billion people clicked “I Accept” over the past 20 years.


How much traffic do you expect? An old laptop and DDNS service would have you covered.


Gotta wait for the seedbox to dl the file THEN dl it again to your local net. Saves time and work to just run at home.


Having 1gb of mail storage in 2004 was epic, having a 25gb profile in 2023 that I can never see is less so.


If someone is unwilling to do business with you via email and require you to use WhatsApp then you dodged a bullet.


You can always use SMS or email, every user has access to one of those services, they just aren’t as quick or convenient as data mining shit-apps.