HN user

CommitSyn

772 karma
Posts6
Comments287
View on HN

The Q is obviously custom (Q for "Quake") the question is where the starting point for the font was. I agree about the cherry picking, but the font is going to have been modified for the game (as evidenced by the "Q".)

It's your type of black/white thinking, and making the association that everyone in support of a specific idea shares an identical set of ALL values with everyone else interested in that idea, that enables fascism to rise to power.

Someone is interested in privacy? They must be a criminal, better watch closely and prosecute on whatever we can before they get too dangerous.

Someone is interested in crypto? They must be fully anarchist. Better lump them in with the anti-government crowd and make sure they are denied police protection.

These were multimillion dollar trades being done by white collar investors with the trading bots, I don't think they mind the police help one bit, and I think you'd be hard-pressed to find anti-state messages from any of them. They are just rich people taking advantage of a system to get richer. Nothing more nothing less. It is not possible to extrapolate political views based solely on participation in part of a capitalistic system.

Is there a simple DIY? Is it as simple as running a custom router firmware or software on a small mini PC? Last I looked into this a couple years ago, it basically wasn't possible to chain multiple VPN providers on the same machine, even using VPNs, but maybe I'm misremembering. You could of course just use the built-in VPN connection of your router, but that lacks all the benefits of updated software/firewall, and I want my family to be able to watch Netflix, browse the web without running a CAPTCHAthon, etc.

FTA: Importantly, the VPN control channel is maintained so features such as kill switches are never tripped, and users continue to show as connected to a VPN in all the cases we’ve observed.

JWH-018 was a very popular synthetic but of course it got banned so the supply dried up. It's more of a problem in younger lower class urban areas where the newly created not-yet-banned synthetics are sold as research chemicals or legal highs in head shops and gas stations. It's quite widespread, just not talked about often, because when media runs stories, things get banned.

Here's a video from one research chemist (Dr Zee) talking about his work https://www.youtube.com/watch?v=X0NRsaPmVX8

While a very small list compared to the number of available chemicals, there are commercially available EMIT kits for the screening of the synthetic cannabinoids JWH-018, JWH-073, JWH-398, JWH-200, JWH-019, JWH-122, JWH-081, JWH-250, JWH-203, CP-47,497, CP-47,497-C8, HU-210, HU-211, AM-2201, AM-694, RCS-4, and RCS-8 through companies like NMS Labs, Cayman Chemical, and Immunoanalysis Corporation. https://www.sciencedirect.com/science/article/abs/pii/S00032...

If you have a suspected target and you can shape traffic on the internet (state actor) there's a much easier way to gain access to the websites visited by your target than by controlling a large number of nodes. It's still noisy, but doesn't generate any scary warnings in tor browser (unless you look at the logs, or pay attention to your connected nodes like with the Onion Circuit GUI in Whonix).

Use a DoS attack against nodes, like the 2-3 years ongoing attack which has lately progressed to a 100% CPU usage DoS against any targeted node. You still have to control a decent number of nodes, but you simply DoS (or DDoS, much noisier) the nodes that your target is connecting to. Once you have them connected to your guard, relay, and exit nodes, you continue the DoS on other nodes until you get the data you need - shorter time is better. I believe this method is being used currently, as I read a post from someone about it recently and noticed something similar happening when I started paying attention to nodes, although it seems it may have stopped for now.

I'm sure there are many vulnerability chains being exploited in tor. Here's an interesting tidbit from the Snowden leaks, which most people took that screenshot of "tor stinks :(" to mean it's safe. At least with JavaScript completely disabled, right?

Tor users often turn off vulnerable services like scripts and Flash when using Tor, making it difficult to target those services. Even so, the NSA uses a series of native Firefox vulnerabilities to attack users of the Tor browser bundle.

According to the training presentation provided by Snowden, EgotisticalGiraffe exploits a type confusion vulnerability in E4X, which is an XML extension for Javascript. This vulnerability exists in Firefox 11.0 – 16.0.2, as well as Firefox 10.0 ESR – the Firefox version used until recently in the Tor browser bundle. According to another document, the vulnerability exploited by EgotisticalGiraffe was inadvertently fixed when Mozilla removed the E4X library with the vulnerability, and when Tor added that Firefox version into the Tor browser bundle, but NSA were confident that they would be able to find a replacement Firefox exploit that worked against version 17.0 ESR. The Quantum system

To trick targets into visiting a FoxAcid server, the NSA relies on its secret partnerships with US telecoms companies. As part of the Turmoil system, the NSA places secret servers, codenamed Quantum, at key places on the internet backbone. This placement ensures that they can react faster than other websites can. By exploiting that speed difference, these servers can impersonate a visited website to the target before the legitimate website can respond, thereby tricking the target's browser to visit a Foxacid server.

In the academic literature, these are called "man-in-the-middle" attacks, and have been known to the commercial and academic security communities. More specifically, they are examples of "man-on-the-side" attacks.

They are hard for any organization other than the NSA to reliably execute, because they require the attacker to have a privileged position on the internet backbone, and exploit a "race condition" between the NSA server and the legitimate website. This top-secret NSA diagram, made public last month, shows a Quantum server impersonating Google in this type of attack.

The NSA uses these fast Quantum servers to execute a packet injection attack, which surreptitiously redirects the target to the FoxAcid server. An article in the German magazine Spiegel, based on additional top secret Snowden documents, mentions an NSA developed attack technology with the name of QuantumInsert that performs redirection attacks. Another top-secret Tor presentation provided by Snowden mentions QuantumCookie to force cookies onto target browsers, and another Quantum program to "degrade/deny/disrupt Tor access".

From https://www.theguardian.com/world/2013/oct/04/tor-attacks-ns...

Let's not forget about the NSA backdooring internet backbone routers and slurping data from undersea cables https://en.m.wikipedia.org/wiki/ANT_catalog

It's quite clear to me the US (and the other major Western players) are preparing for a large-scale war and know a great deal of spies are already living in the country. Warrantless wiretaps for any connections outside of the USA, and mandatory KYC for any cloud providers (VPS etc) within the US. In other words, the surveillance dragnet is now operating at a complete and full scale. Privacy is dead. If you would like to be an activist or give valid criticisms of the government, just know that your devices are likely going to be hacked and your communications decrypted. Airgapped computers may for now be safe with a faraday cage and components stripped out. Mesh networks like Briar are only useful as long as your phone is secure.

I wish I was simply being overly paranoid.

https://www.brennancenter.org/our-work/research-reports/refo...

https://torrentfreak.com/u-s-know-your-customer-proposal-wil...

https://www.ic3.gov/Media/Y2024/PSA240425

https://www.gov.uk/government/news/new-powers-to-seize-crypt...

Krazam OS 2 years ago

Okay I clicked on an ad. It gave me a discount code, but that's not the first puzzle solution.

So far I've, for example, found my banking app running something called a telemetry service, in the background, even if I set its battery profile to restricted. No way to stop that other than to uninstall the app.

Have you considered creating a new 'banking' user account that you only log in to when you need to access that app? Its incredibly easy with Graphene.

what about paying a small fee OR having someone run a cryptocurrency proof of work check?

Musk: That is much harder than paying a small fee.

Cock.li, a hobbyist-run email/VPS provider, has implemented that exact thing for the ability to send emails (receiving is free). Took about 7 minutes on my laptop. My laptop sat there, did all the work, I paid nothing and became verified. I could even pause it and come back later.

It's clear this is about squeezing money out of every last user even if if means killing the platform.

We are a very compassionate society. There are dating and matchmaking services for people with virtually every kind of disability, including those who absolutely can not care for themselves, and modern health infrastructure affords the mentally disabled and other selective pressures (narrow birth canal and many other issues) to carry to term.

The same evolutionary pressures don't apply to humans at the moment with regard to sex. Not while civilization is a thing, anyway.

Not only did it mandate authentication, but there was also a Killswitch, and there's no other reason for that than because you have reasons to suspect someone may have access to this sensitive world-stopper exploit and use it against you. That leaves simply a (reasonably, but still) paranoid person, and people worried about that+consequences are unlikely to have the mental well-being to pull this off, or, a group of people.

Either way, it's your preference and I will follow your lead. Jia Tan

It's out of the scope for this patch, but it is something worth considering. Just trying to do my part as a helper elf! Jia Tan

Sounds like someone pulling the strings and using the "it's your idea, I'm just following!" strategy.

My hunch from reading over all the language used is that this person spent a good deal of time in America and has a carefully crafted 'customer service' manner of speaking. I may be wrong on the spending time in America part, but they are most definitely used to putting people at ease with their word choice.

I also found this bit interesting, as it's one of the few times they referred to "us" and "we"

https://www.mail-archive.com/xz-devel@tukaani.org/msg00644.h...

Please let us know if there are any concerns about the license change. We are looking forward to releasing 5.6.0 later this month!

Quoting Hitchhikers Guide:

This planet has - or rather had - a problem, which was this: most of the people living on it were unhappy for pretty much of the time. Many solutions were suggested for this problem, but most of these were largely concerned with the movement of small green pieces of paper, which was odd because on the whole it wasn't the small green pieces of paper that were unhappy.

Where did you hear this? Is discovery in his case different from discovery in any other legal case (prosecution is required to share all information they are preparing their case with, so that the defense can prepare a defense.

Or did he/one of his loyalists just /say/ that? I'm genuinely curious because I thought all legal defenses were allowed to read the discovery.

If they have the means and the opportunity, people should try an isolation retreat e.g. go camping in nature with a friend (or solo is personally preferable) for 2-3 days and only power on your cell phone for emergencies. As always, research and take preparations like telling people where you are going and went to expect you back if you're going into the wilderness. It only takes about 30 steps off the marked path to potentially get lost (forever).

People so vastly underestimate the role of their attention-seeking, cognition-theiving phones in their ability to think clearly. I would hazard a guess that most people increased their phone addiction (and psychological importance placed on their phones) during COVID.

However, it's well-known and confirmed that long-covid does cause brain fog. Plus all the other viruses that people got when they started mingling again after the entire population was inside allowing their immune systems to be mostly dormant... Long-covid really kick-started the research into long-virus issues.

You're both using your own internal dictionary differently for the same correct word.

In hacking, compromised means hacked.

In intelligence, compromised means you have someone doing something on your behalf that they feel forced to do.

You seem to understand this so I'm not sure where the confusion lies.