and what i see is a billion serf's getting exploited by a small minority of tech feudal lords. There is no alternative, except opting out of the game entirely. That is the point I wish to make here. There is no making a safe social media. Facebook is irredeemable. Social media is destructive to society by design.
HN user
g45y45
I agree -- we are doomed. I have no cause. I stopped believing in democracy a long time ago. I have zero interest in helping others to understand my perspective, best we can hope for is to slow down the tech parasites from harvesting their digital souls.
Of course I am in the minority. The majority of people on this planet have neither the education, interest or intelligence to understand the cage that is being constructed around them. Are you in the blissful, ignorant majority that cannot see what is actually going on here?
I'm motivated by solving real problems, not artificial climbing wall problems, sorry.
No such thing as good DRM. All DRM is broken by design, and exists to take your rights away. Never make excuses for this garbage software. DRM must die.
climbing walls or being stuck in the wilderness with a bike don't sound like fun at all. pointless. I don't think your suggestion is helpful for people that have depression. The metal working suggestion from parent is far more helpful, as you are actually making something.
Any australian working in the US that is able to obtain PR or citizenship likely has a well paid job that provides health insurance. While I feel for the folks in the US without coverage, lack of access to affordable health care does not really apply to employed, skilled immigrants. In my experience US health care is the best on the planet, its also the most expensive.
From my perspective, US health care is way above the quality of healthcare in Australia. Price, not so much...
You don't need to store 3 hashes, infact, you would need many hashes for all possible cases. It is easier to drop all cases pre hashing, and only store a lower case hashed value.
Its pretty easy, you configure your logging library NOT to log the attribute, key/value pair, whatever containing the credential. If you can't modify it on the server side (which you can lazy bones), you tell your central logging system to mask it out before it is written to disk.
This isn't difficult or non-standard. If you are logging all client request/responses full take including auth creds, credit cards, SSN, etc, you are likely doing it wrong, and possibly violating some industry regulations.
His name is clippit, not clippy :-)
You really want to do this if you use Spectrum Cable. You are locked out of configuring the DNS settings via their cable modems (even if you supply your own). These force a DNS search suffix that leaks all DNS requests to their server, even if you are using another public DNS. I noticed network manager kept forcing the DNS search suffix, even after I manually disabled it. I did the config change to disable it messing with the resolv.conf
Did you update the wikipedia article with the correct citation? Its easy to complain on HN, takes a little more effort to correct misinformation for future internet users.
"Filthy stinking astronauts" -- upright citizens brigade https://www.youtube.com/watch?v=zK-30442RII
This was in 2011. They probably got them finding near hash collisions (by hand, with pencil and paper) for mining cryptocurrency in 2019.
its missing an http to https redirect. this is important! How can i trust this group with identity if they cant even get secure websites right.
Downvoted. If you live in the UK, you will need to buy a 'perverts card' in order to prove your age. This will of course lead building of biggest Blackmail database outside of the Intelligence Community. Nothing could possibly go wrong.
Nope, and this is part of the building case against Porn in the UK. Please ignore the lies coming from the UK, this will only ramp up as the Porn Ban is rolled out - that is correct, porn will be blocked by default in the UK.
1. correct; 2. correct; 3. Kinda but Not quite the only way -- you can convert the values in the coins into another chain, ideally something like monero in which 1. applies, but 2. does not. (Monero uses a different transaction format called RingCT, it hides the true inputs/outputs among decoys and signs the set with a ring sig. It also hides the true amount transacted via Confidential Transaction encoding using a commitment and a range proof). Its much easier to tumble the value when the source/destination and magnitude is obscured.
How feasible to do this with $130 million? Yesterdays trade volume for monero was 75 million (thus actual on chain tx's are much less). So it would take a while to do this without drawing attention. I don't have a lot of faith in pure bitcoin tumblers. Possibly scams or fraud. Im yet to see one that works as expected.
Yeah, I will 'change' my position on this. Satoshis in a single UTXO that are split are fungible - in your scenario you cannot identify the specific sat: either a1->a3, or a1->a4. This is kind of like 'forward fungibility'. You can however trace the value in satoshi's back from A4 to their coinbase at birth. At best, we introduce a UTXO taint percentage from previous inputs. Its this taint from other, external inputs that break backwards fungibility (due to taint).
Kinda. You can use mimikatz to override the checks that the private key is isolated, you can even override 'no export' flag. Timestamping relies on external trusted timestamp providers implementing RFC 3161. There are many out there, maybe you could get a false timestamp out of them. I agree could be stronger than PGP, however it suffers a design flaw in that it considers the geometry of the PE file. PGP signs the whole blob. CVE-2017-0215 is an example of bypass by copying a previously signed header. It is more fragile and has been bypassed historically.
every satoshi can be traced from birth until unspent. There are most certainly individual satoshi. they live in UTXO's.
Not accurate. You can trace the life of a particular 'coin' value -- which is generated in the coinbase reward in a block and spent later on in a UTXO (unclaimed transaction output). We like to pretend that bitcoin is fungible, but it strictly is not; You can trace the life of every 50, 25 and now 12.5 Bitcoin from birth to currently unspent. They all get mixed, so it can be difficult.
Also, what you are describing is the so called 'account' model -- used by Ethereum, EOS, etc. Bitcoin is a 'utxo' model, which allows specific inputs/outputs to be traced.
If i was to guess, i would guess that it was Bitlocker vuln, CVE-2018-12037, where the bitlocker crypto implementation is left to the junk SSD 'self encrypting' feature which is found to be broken. I have my doubts they cracked Veracrypt, LUKS or filevault2 with operator supplied keys. Or they got the keys from Microsoft/Apple (filevault2 and bitlocker will escrow the keys to the OS vendor in home editions).
0days are not magic. Stare enough at code and you will find them. E&Y and the other Professional Services companies have a big pentesting team, and they would have made discoveries on their own regarding system security. Any company with a large security / research team would have 0days. What they do with them, (report, sit, burn, etc) is up the organizational and individual ethics of the operator.
You can't double spend -- you would need to generate 2 conflicting tx's with the private key. Only the person that holds the money can attempt a double spend, the miners only process and include (or exclude) transactions.
And yet we question if MZ ever actually grew up -- he was thrown into a world he did not understand with millions and billions of dollars. I don't believed he has changed, and I don't believe facebookers who are programmed to elicit this response to this talking point. Its so much more than a throw away comment, it speaks to his entire strategy for privacy and respect for users/society, both then, and now.
The only way forward for privacy would be the complete deconstruction of the facebook machine. There is nothing that can be done to salvage this beast. Don't be the last person to delete your account. We can turn facebook into myspace. All it takes is for you to let go of your excuses of why you still use their awful products.
of course they do this (GOOG & APPL). typically the exploits are for older patched versions of ios/android. keep your phone patched and fully up to date!
Also, its not so hard. Oldmate was running doom on the thing. UFED is just another android tablet. Root it and find the l00t. Log all traffic from the mothership if you want to see payloads.
Google, the worlds largest advertising company, abuse market share to crush those that would stand in their way. I stopped using Chrome when this was proposed, and you should too!
Article provides evidence that Google's pretext of performance doesn't hold water.
My mistake, i thought x/crypto was part of the stdlib.