On desktop devices, I'm using Cider.sh which supports scrobbling, and on Android I use Pano Scrobbler.
HN user
caffeinewriter
[ my public key: https://keybase.io/sushi; my proof: https://keybase.io/sushi/sigs/TIhhBjRSP6Xxdh09gFzIFLNIKJYm9Sn8LAs4tR95gKk ]
I imagine it's referencing this story:
https://robindev.substack.com/p/cloudflare-took-down-our-web...
HN Discussion:
Huh. The researchers seemed to gloss over the Cloudflare Pages URL, but it's actually pretty interesting. I haven't had a chance to look at it in depth yet, but it appears to use the search-ms: URL protocol to show an attacker controlled WebDAV server to serve the malware.
The server hosting the malicious files seems to be down now, but this post details a similar attack:
https://micahbabinski.medium.com/search-ms-webdav-and-chill-...
It also seems to be part of a phishing kit, or potentially generated with AI due to the presence of the following comment.
// Замени на свой URL
Which in English is: // Replace with your URL
And various other descriptive comments like // Полностью очищаем страницу (Completely clear the page)
// Создаём новый контейнер с индикатором загрузки (Creating a new container with a loading indicator)
// Через 3 секунды скрываем Cloudflare и запускаем загрузку (In 3 seconds, we hide Cloudflare and start the download.) [Though this was next to a 900ms timeout, so there's definitely been some tweaking]
They're the kind of comments that don't really make sense if the author is writing them themselves, but would if they're using something off the shelf, or asking some LLM to output code. The descriptive comments of what the code's doing definitely makes me lean towards the latter.It could be cumulative users on the addons page, and week-to-week usage statistics for the addons on the data page.
Tangentially related, I just recently found out that Lumberyard actually was spun out[1] into the open source Open 3D Engine[2] under the stewardship of the Linux Foundation. It's a nice surprise to see that Lumberyard didn't just die out, and is joining the ranks of open-source engines.
[1] https://web.archive.org/web/20220614090421/https://aws.amazo...
I'd call D&D more of a framework for collaborative storytelling that can absolutely be played as a game. The DM leads the adventure, the players decide how to respond to things. Everyone plays D&D a bit differently.
The most straightforward adventures that typically have a "win condition" are one shots/self-contained adventures from either WoTC or 3rd Party Publishers, like Curse of Strahd, Waterdeep: Dragon Heist, etc.
However, a lot of D&D groups I've played with might have characters die, but will rarely have a group "lose". However, because every group runs things a bit differently, a different group can drastically change how the game feels.
During the initial kerfuffle, a Unity employee did quote one of their lawyers saying the following[1]:
Our terms of service provide that Unity may add or change fees at any time. We are providing more than three months advance notice of the Unity Runtime Fee before it goes into effect. Consent is not required for additional fees to take effect, and the only version of our terms is the most current version; you simply cannot choose to comply with a prior version. Further, our terms are governed by California law, notwithstanding the country of the customer.
The communication around this rollout was absolute rubbish. Even employees were trying to get clarity, and they were forced to figure it out and real time.
[1] https://forum.unity.com/threads/unity-plan-pricing-and-packa...
I know for me (as someone who would likely never have had to pay a dime under either pricing scheme) the crux of the issue was unilateral, retroactive changes to a license that was supposed to be tied to the software version, as well as the nebulous "we'll know what to charge you because of our proprietary data model, trust us" messaging that they first went with.
That, combined with the fact that there was no safeguard for the install fee to be capped at some percentage of gross revenue made it so clear that they were trying to get something out of their free to play market specifically, which seems to have been to force their F2P customers to use their Unity Ads service over Applovin or similar competitors since they gave credits towards the runtime fee if you vertically integrated with Unity.
Definitely use a battle-tested HTML sanitization library if possible. There's a million different pitfalls and footguns with XSS. See: Some of the insane XSS polyglots out there that can be used for testing.
https://github.com/0xsobky/HackVault/wiki/Unleashing-an-Ulti...
However, if you're the creator of a Firefox/Chrome extension, and want to utilize the WebExtension support in Safari, your deployment workflow can no longer be platform agnostic.
- Plainly Difficult (Short Disaster Documentaries with a significant focus on Nuclear Disasters): https://www.youtube.com/channel/UCb0MyY46T9ZYOzDHkYnIoXg
- Fascinating Horror (More Disaster Documentaries): https://www.youtube.com/channel/UCFXad0mx4WxY1fXdbvtg0CQ
- Half As Interesting (Short Educational-y/Humorous Explainer Videos): https://www.youtube.com/channel/UCuCkxoKLYO_EQ2GeFtbM_bw
- Technology Connections (Deep dives on everyday/vintage technology): https://www.youtube.com/channel/UCy0tKL1T7wFoYcxCe0xjN6Q
- Displaced Gamers (Code analysis and discussion of vintage video games and game systems): https://www.youtube.com/channel/UCWoSKWs8h6lFdiEDAjuIfpA
- ColdFusion (Short documentaries on companies and technology): https://www.youtube.com/c/ColdFusion
- Modern Vintage Gamer (Taking a look at retro tech/gaming): https://www.youtube.com/user/jimako123
- Economics Explained (Explaining Economics): https://www.youtube.com/user/JitaLounge
- Nostalgia Nerd (More vintage tech): https://www.youtube.com/user/nostalgianerdvideos
- LiveOverflow (Reverse Engineering, Hacking, and CTFs): https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w
- styropyro (Lasers and Electricty, taken to extremes): https://www.youtube.com/user/styropyro
- NileRed (Chemistry Experiments): https://www.youtube.com/user/TheRedNile
- The Thought Emporium (Biohacking and other science-y things): https://www.youtube.com/user/TheChemlife
- Fredrik Knudsen (Longer form documentaries about various historical events and internet incidents): https://www.youtube.com/channel/UCbWcXB0PoqOsAvAdfzWMf0w
- bigclivedotcom (Electronics teardowns): https://www.youtube.com/user/bigclivedotcom
- Sebastian Lague (Game development tutorial-ish things relating to procedural generation): https://www.youtube.com/user/Cercopithecan
- Two Minute Papers (Breakdowns of research papers with a particular focus on AI): https://www.youtube.com/user/keeroyz
- VWestlife (Technology, with a focus on audio equipment): https://www.youtube.com/user/vwestlife
- Chubbyemu (Medical case studies): https://www.youtube.com/channel/UCKOvOaJv4GK-oDqx-sj7VVg
- Tech Rules (Video game AI/tech breakdowns and analysis): https://www.youtube.com/c/TechRules
- DIY Perks (Actually interesting/useful DIY projects): https://www.youtube.com/user/DIYPerks
- Biographics (Explainer videos focused on historical people): https://www.youtube.com/channel/UClnDI2sdehVm1zm_LmUHsjQ
- Geographics (Explainer videos focused on geographical locations by the same person as Biographics): https://www.youtube.com/channel/UCHKRfxkMTqiiv4pF99qGKIw
- MattKC (Vintage Tech repairs/mods): https://www.youtube.com/c/MattKC
- LGR (Weird and cool retro tech showcases): https://www.youtube.com/user/phreakindee
- Game Maker's Toolkit (Game design deep dives): https://www.youtube.com/user/McBacon1337
- People Make Games (Stories about games and game design): https://www.youtube.com/channel/UCZB6V9fUov0Mx_us3MWWILg
- Every Frame A Painting (Movie analysis, no longer active, but still worth a watch): https://www.youtube.com/user/everyframeapainting
I was thinking on that. You still need peripherals if you're using a Mac Mini, though that's no different than if you were using another desktop. Still though, if you don't use, or don't want to use a Mac as your daily driver, that's a dedicated machine just to build/publish an extension for a browser. IMO, there's a slightly stronger case for iOS apps, but requiring that for a browser extension is much harder to justify.
Not to mention the $700+ upfront hardware investment if you don't already have an Apple machine.
Synchronous communication typically means something that demands your attention as soon as something is sent. Asynchronous communication is something that typically handled whenever you're ready for it. To put it in programming terms, synchronous communication "blocks" until you deal with it, where as asynchronous doesn't require you to deal with it until you're ready to.
https://www.worldwidelearn.com/education-advisor/questions/s...
https://status.net/articles/synchronous-vs-asynchronous-comm...
I mean, when a lawyer takes a case on contingency, they're essentially gambling their time on hopes of an outcome where their share (30-50% isn't uncommon, if I remember correctly) would make the time and effort spent on the case worth it. Against a company the size of Disney, with incentive to make the case as long and painful as possible to try and discourage other creators from trying to get what they're owed, it would likely take thousands of man hours, and tens of thousands of dollars out of pocket. Between discovery, filing fees, appeals, all for a victory that would result in (and I'm just completely guessing based on essentially no data) only hundreds of thousands of dollars. Lawsuits can very much end up being pyrrhic victories based on the costs incurred alone, not to mention the emotional toll that fighting a protracted legal battle can inflict upon a person.
Alright, since linking the entirety of title 17 isn't exactly easy to refer to as a source, the relevant part is 17 USC 203.^1
It's probably one of the more complex parts of copyright law. There's a few well-known cases of section 203 being used to claw back copyright decades down the line. (Note: I'm am very much not a lawyer)
In 1938, John Steinbeck granted Viking Press rights to publish 13 of his works, including Of Mice And Men, The Grapes of Wrath, and Tortilla Flats, as long as they were kept in print and for sale. In 2005, John Steinbeck's son and granddaughter served notice to Penguin Publishing, who were the interested party at the time, that they were terminating the agreement.^2
This section was originally designed to give artists who may have essentially (or even literally) given away their rights due to inequitable bargaining power a chance to recoup their property down the line with at least several years notice that they are planning on terminating the agreement.^3 In practice, however, it's kind of a mess, and to say that it would allow an artist or their heirs to terminate a grant to the public domain is dubious. It's something that would likely see its way to the supreme court should it ever come to pass.
I've included a couple other articles here just in the general interest of providing more info.^4^5
[1] https://www.copyright.gov/docs/203.html
[2] http://billgablelaw.com/sites/law/files/TakingItBack.pdf
[3] https://abovethelaw.com/2019/05/terminators-mount-up-section...
[4] https://media2.mofo.com/documents/190700-all-shook-up.pdf
Down towards the bottom it seems like it's only presently available in the US, and they're simply using `.sm` as a clever domain name hack/gccTLD (e.g. .io domains, .ly domains, etc)
Quite a few "people" have solved it it looks like, and it's riddled with persisted XSS attacks once you get past it.
Here's the returned response when you succeed: https://hasteb.in/iyifapud.html
I found the "man" category to be the easiest to pretend to be a bot on.
I'll try and put together a collection of great workshop mods when I'm home tomorrow and shoot it your way :)
There are definitely some games that just don't translate as well to Tabletop Sim, but as far as shared tabletop experiences, TTS blows every other one I've tried out of the water on the widest variety of games. I use it for D&D, Wizards' Academy, and I own about half of the official DLC games.
There's a lot more regulation and guidance around taking down a phishing site at the domain level, rather than at the provider level. (E.g. Hosting company, CloudFlare and other DNS providers, etc.) If I remember correctly, ICANN requires takedowns to be either compelled by law enforcement, or done through the UDRP[1], whereas the providers themselves are typically more able to quickly respond to abuse. In addition, phishing domains are typically short lived, as once they're flagged by Google Safe Browsing[2] and the like, they're essentially worthless to the ne'er-do-wells that purchase them, regardless of if they're actually taken down.
[1] http://www.icann.org/en/dndr/udrp/policy.htm [2]: https://safebrowsing.google.com/
Honestly, I'm glad they didn't. There's not much use in a whois privacy service if they'll give up the info just because a company says "this is infringing".
I feel like the title "Facebook sues Namecheap for registering phishing domains" is somewhat misleading.
We found that Namecheap’s proxy service, Whoisguard, registered or used 45 domain names that impersonated Facebook and our services, such as instagrambusinesshelp.com, facebo0k-login.com and whatsappdownload.site. We sent notices to Whoisguard between October 2018 and February 2020, and despite their obligation to provide information about these infringing domain names, they declined to cooperate.
Specifically, they're suing Namecheap and their proxy service for not providing information about the true registrants of the allegedly infringing domains.
It's not uncommon for compromised computers to be used as nodes in DDOS-for-hire networks, (though compromised IoT devices seem to be in vogue at the moment) proxies for ne'er-do-wells, sending spam, and other activities that might not be apparent to the user of the computer in the slightest, but still have effects that reach out to the world at large.
That's a channel-specific option though. You can set per-channel bitrate, but it's not something Discord does automatically to accommodate lower throughput clients.
It looks like Ogg Vorbis has theoretical support in the spec for something called "Bitrate Peeling"[1], but there is no functional implementation for this yet, and there's been an open bounty on it since 2004.[2]
This is a really neat idea though. Truncating the packet to change the bitrate per client without re-encoding.
[1] https://en.wikipedia.org/wiki/Bitrate_peeling
[2] https://wiki.xiph.org/index.php?title=Bounties&diff=196&oldi...
https://explorabl.es acts as sort of a repository for it. Unsurprisingly created by the irreplaceable and aforementioned Nicky Case.
I'm still holding out hope to see Daemon and Freedom™ by Daniel Suarez adapted into a movie, or a miniseries, or really anything.
If you want to see the power of modular synths, I definitely recommend checking out some modular streamers on Twitch. Some use VCV, some use actual racks, but there's a growing community on there.
https://www.twitch.tv/dronehands
https://www.twitch.tv/nitewurx
I think you're quite correct. If you're investing in obfuscation, you're probably making the wrong investment. Malicious actors have to obfuscate to avoid detection for as long as possible, and benign actors would probably be better served focusing on their core tech. That said, obfuscation is very good at increasing the difficulty of interpreting and understanding the purpose of code.