It's a straight line from Jesusonic to Reaper: Jesusonic JSFX script is in Reaper, and there's a whole selection of stock JS plugins that come with it and it's actually quite easy to program.
HN user
AlyssaRowan
Snarky ex-reverser; often cryptic; occasionally vaguely cryptologic
[ my public key: https://keybase.io/akr; my proof: https://keybase.io/akr/sigs/5gHSklAXllHnQJvYGdQJkduHKCZZ8mQJdvtUAIhJ4HI ]
It is, of course, only a matter of time - just like kernel-level copy protection and Sony's XCP - before something like Vanguard in particular is exploited and abused by malware.
Himata is correct, too. After DMA-based stuff, it'll be CPU debugging mode exploits like DCI-OOB, some of which can be made detectable in kernel mode; or, stealthier hypervisors.
Well, it's less of a technology problem than it is an industry one. You can have multiple entries in the genre list and they're freeform, for example Ambient;Electronic, in both ID3v2.3 and ID3v2.4. For Vorbis Comments, you have multiple GENRE= tags. Some players support this.
In my interactions with distributors, it seems streaming services tend to support up to two genre classifications; though they're pretty outdated and general (even more general and dated than the Winamp genre list). I don't think they use the metadata presented much in the classification; in fact Spotify does its own estimation of 'energy' and other subjective emotions using various classifier algorithms.
I do a similar thing — also with AHK! — and I don’t intend to stop. I think probably the AI/LLM bubble will pop before I consider changing my habits there.
Tip: Patterns like “It’s not just X, it’s Y” are a more telltale sign of LLM slop. I assume they probably trained on too much marketing blurb at some point and now it’s stuck.
All kinds of self-published stuff, lots of which later became commercial. You will have heard of some of it, for sure. Darude - Sandstorm? That was from there. DragonForce were big in the power metal category. The band that became Linkin Park came from there. And then hundreds of thousands of indie artists (including an earlier me).
The RIAA's action there destroyed vast amounts of music, pretty much the equivalent of if someone just aggressively deleted Bandcamp and Soundcloud put together and everything on it because they were upset they didn't control it all. I will never forgive them for that.
Basically all of my friends use it. I insist. I trust it; I don't trust WhatsApp (not because WA's crypto is weak, just because I don't trust who runs it now).
I mean, that brute-forceability was a reason for the newer v3 addresses; the v2 ones just weren't long enough.
(As told to me by Alec, they bruteforced the first bit, but found a very coincidentally attractive one for a backronym among the candidates and chose that.)
They did the first 8 characters of the v3.
Oh yeah, no, that's ridiculous. I'm moving.
You didn't even need Caetla. You could do that straight-up with the original ROMs for some of the cartridge series (FCD), and X-Link from DOS (or, if you were prepared to get involved with a bit of spicy linux 2.3, bitbang the parallel port yourself from the /dev/ interface for it at the time, the protocol was really simple). You get a live memory monitor you can watch (made it really easy to make cheat codes or look inside stuff for fun), and you can write and debug anything you want - in many ways it was nicer than the official Psy-Q kit Sony adopted, I thought.
Except to be fair, I didn't have a C toolchain, but R3000 assembly language is really nice when you get used to the delay slot.
They're all actually AI powered, generally some form of real-time RNN trained on identifying and isolating voice content from background noise or music.
rnnoise2 is an open-source model that does very well. There also are things like Waves Clarity VX, the Nvidia Broadcast (Audio Effects SDK) too, as well as plenty of other solutions like Supertone Clear, Krisp, etc etc etc.
My memory there is a bit fuzzy, but saying there was no official Mozilla web browser feels misleading. The Mozilla Suite (which I used for a while even in the 'milestone' versions) contained a fully functional web browser, Navigator - it was just really heavy and cumbersome because it also had the mail client Communicator and the other stuff like the IRC client and it was very new, very raw, rough-edges software built on this new XPCOM stuff. Very 'kitchen sink', inspired by the Netscape 'SeaMonkey' suite (SeaMonkey I believe lives on under that name). It wasn't based on the OG Netscape source code very much at all - while an attempt was made to develop that, it was so bad it was basically thrown in the bin and rewritten from scratch - which is where Gecko comes from.
K-Meleon and so forth was an attempt to take the core Gecko components out of the Mozilla Suite and just have a small simple browser built in it. Having seen that and a few others which had the same kind of idea but were native, Phoenix, which became Firebird, which became Firefox, was... kind of a grassroots disruptive community effort to try the same sort of minimum-viable-product browser thing in XPCOM as a cross-platform experiment, which rapidly gained adoption when people started realising how much faster and better it was to build it that way from the ground up instead. It certainly didn't feel like it was "AOL Time Warner" sponsored. If anything, it felt kind of chaotic. Nobody did a detailed name search because it was an experimental side project.
That worked so well, Thunderbird the email client was forked off too (during the Firebird era), and if I recall Sunbird (the calendar part)?
If they were restricting controllers from the start, that would be one thing, and controller exclusivity is something every console manufacturer right back to Atari has always thought about from the very beginning - mostly for cash-grab reasons, but also, much later on, with this very excuse. It's why the original XBox's USB controllers were a different shape.
But to me this feels like a clear-cut case of interoperability, unilaterally and unconditionally removed after the fact of the sale of both millions of consoles and controllers (both first-party and not). Are they sure they want to do that? Now?
This also reminds me very much of Sony's removal of OtherOS in the PS3, and I draw the analogy with what happened to the console's security afterwards very much in mind.
Yeep. That is not entirely unsurprising (it’s such a common flaw in basic section/chunk formats that they obviously didn’t research about even the possibility of security flaws, or consider there to be any threat model at all — it was designed to be used internally in games for game assets, perhaps). Still a little disappointing to see they were indeed that lackadaisical. I don’t expect change, they’re very set in their ways.
There is a superior, free, open-source alternative called Inochi2D — https://inochi2d.com/ — developed primarily by Luna the Foxgirl, and used by all of nullptr::live, including Asahi Lina (of Asahi Linux fame). It really should see more love because it’s superior in almost every way.
That was Digital Research’s GEM, which Atari had licenced for the GUI of TOS (they threw it together quite quickly). There was a whole thing about GEM and inspiration from Xerox PARC and Apple; that’s largely the reason why the Atari version was the only version that really made it to any kind of brief success.
It was never unusual for cypherpunks to use nyms. Amongst the many ideological and practical reasons, for example worries about if authorities would treat a creation and its creator hostilely — it separates the creator from the creation and lets you judge the creation purely on its own merits (whatever those may, or may not, be).
I do appreciate your curiosity, but thank you for understanding. To date, to my knowledge, no-one ever guessed correctly, and maybe that's for the best. If they'd have wanted anyone to know who they were: they'd have said. They never have, and likely never will. I don't think you'll ever see anything from the genesis block or those keys. It's got to feel incredibly strange, yes, but remember: they _wanted_ to walk away from the whole thing, and I feel strongly that deserves respect.
There's probably also the issue that there is no _one_ 5GHz band. Suddenly you have to deal with DFS radar detection, and different regulatory compliance domains. It now matters which country you're selling to, or which firmware they're using.
The concept happened way before that too. Even though the Atari ST and Commodore Amiga had different floppy disk formats (and were bitter rivals), because they shared their main processor (MC68000) a great deal of games and software were available for both.
Occasionally, that happened on the same floppy disk, via a horrific sector format interleaving trick invented by Rob Northen (who did a lot of copy protection stuff at the time). Notably, the Future Publishing magazines ST Format and Amiga Format started out as the combined ST/Amiga Format and the "coverdisk" was exactly that - readable by both, with different files on each machine.
Use WPA3-Enterprise (you can use Let's Encrypt to get a valid certificate so it works fine in a home environment).
Don't use SAE (which is, indeed, an instantiation of Dragonfly). I have a strong suspicion that the way it is used, there will be a practical attack.
It does indeed seem to be DRAGONFLY (I'd heard rumours indicating such in advance): a surprising choice for an interactive protocol with attacker-observable timings, I felt, given its already chequered reputation?
I couldn't possibly speculate as to why, but one does feel inclined to agree that the people behind wireless LAN security haven't always generally chosen high quality methods in the past, and this feels to me like it could well be a continuation of that pattern.
Not immediately, but I feel that as those protocols become more ubiquitous, _maybe_ the base Tor transport protocol (for nodes which aren't bridges) might be able to benefit from some of the same upgrades by using them?
I don't know how much (if at all) it might help—but other, similar overlay networks have previously noticed that (intuitively) inefficiency in the transport protocol is likely to be (broadly speaking) multiplied by the number of hops; so any improvements in that might be useful in improving the user experience by using the same available resources more efficiently.
What that might mean for Tor's perceived speed is a somewhat murky issue, as that's a function of the complex interaction of latency and bandwidth and crypto and routing overhead of all the involved nodes in a tunnel put together; which of course is also shared with other tunnels; not to mention it will _also_ be particularly affected by exit node outproxy bandwidth; _and_ any possible packet loss and delay caused by both incidental _and_ deliberate adverse network conditions…
They ported the PICO-8 version line by line to C#. Since there aren't that many lines, apparently it wasn't that hard.
Yes.
This kind of technique, and the exploitation of minor CPU errata, can be used to help differentiate processor models and steppings.
That in turn allows a currently widespread DRM system to download personalised portions of object code that rely on properties specific to the licensed hardware in order to execute properly, in an attempt to counter debugging, emulation and transfer - continuing a tradition practised in copy protection techniques since at least the 6502, maybe even earlier.
Thank you for respecting that. I believe you understand.
I have to say I'm completely unsurprised at your follow-up result - I've always held that view myself. Code style isn't just about variable names and brace placement, it's also about the abstract design and how you choose to reduce the problem you want to solve to the method that you want to solve it with - and the choices made in that process carry through all the way to the object code, data structures, file formats and beyond. That stylometry may be possible to some degree from object code follows naturally from that viewpoint.
A little romantic as that might be, I've always felt that reverse-engineering can sometimes seem like, via the medium of what they've created, being a few steps removed from reading someone else's thoughts.
Two points here, about both the advice and the people giving it.
Regarding the advice, personally I think the advice is bogus. A lot of Mastodon instances have started legitimately using unconventional newTLDs. And I seem to see more URI shorteners, .com and .ru in spam than all the newTLDs put together (zero, from a hacked site, costs less than free). Country K-lining, while attractive to the lazy network operator, only works as an extreme temporary measure in a crisis - spammers adapt, but blocklists tend to only grow. And perhaps Symantec, given their business dealings with Verisign, might not be a 100% neutral party in making recommendations seemingly targeted primarily at severely disrupting the present and future business of cheaply-available TLDs?
Regarding Blue Coat, research shows Blue Coat devices are also used in the censorship/mass surveillance programmes of: Russia, UAE, Bahrain, Iran, and even China. Please also remember Blue Coat devices intercept, log and parse near-everything that goes through them. That puts them at a significantly elevated security risk above a network which didn't have them at all. I know I would find it unethical to report any vulnerabilities to that vendor, and I know I am not the only one who thinks so. And middleboxes like that are incredibly frustrating to the interoperability of the internet and present probably the single biggest hurdle to progress in internet protocols - ask someone in the IETF TLS Working Group currently working on TLS 1.3 just exactly what they think of them!
And indeed (from my skim-read, and please bearing in mind that I know very little about quantum computing) the paper seems to combine that same Grover's algorithm used to speed up just about any brute-force search with ECM, to find small primes more efficiently than Shor's algorithm in this case.
Then it constructs a 1 terabyte RSA parameter, so big neither algorithm can currently attack it using a computer (quantum or otherwise) of practical size, as all known quantum attacks (including the new presented) would still need over a 2¹⁰⁰ workfactor; the 2³¹ factors they would need to find are each 4096 bits long themselves, if I'm reading it right?
Needless to say, that is a trifle on the heavy side and definitely isn't your first practical choice (those would be lattice-, code- or hash-based primitives), but it is possible, and that's impressive (to me) by itself! Nice work.
But what of the equities issue - what to do with that knowledge, once discovered? Might it depend on who "we" are?
My point is that actually helping this particular vendor, for example, may not be everyone's cup of tea.
Reverse-engineer? A middlebox?
Which holds trusted secret keys and which, in its normal unremarkable operation, intercepts, parses, reconstructs, decrypts, re-encrypts, forwards, and optionally logs both confidential and attacker-controlled traffic? And is also known to be used for nationwide bulk internet censorship by regimes often called 'oppressive'?
Why, doesn't it just.
Please consider, very carefully, the ethics and equities issues one might face with any interesting findings here.
One comment I'll make because it's kind of buried in the first paragraph and not really called out: this project is one of the very early adopters of Trevor Perrin's state-of-the-art Noise protocol framework design https://noiseprotocol.org/, so you're looking at something dramatically more modern, auditable and (potentially) secure than older, hairier protocols like IPsec, TLSv1.2, OpenVPN, etc.
Best of luck, Jason!
Looks like it's over in the settings; just under Change Password is Switch to One-Password Mode.
Agreed. Hiring someone specifically to try to do an aggressive, audit hatchet-job on special, star customers that had spent six figures on golden tickets with them doesn't make this story read very sympathetically for American Airlines to me.
Perhaps it's naïveté on my part, expecting a business to have some care for its reputation as well as its bottom line, but as far as I'm concerned, if you're going to promise an elephant, you'd better at least have a pachyderm on backorder and not try to wriggle out of it the moment it inconveniences you, because that just makes you look callous.