And then there’s Banksy’s “in the future, everyone will be anonymous for 15 minutes“. For pretty much the same reasons you stated above, I assume.
HN user
sslalready
Telecom. Berlin, Germany.
ESPHome is awesome. Any chance you can get MQTT running on RP2040W?
1992 A.D. even.
I was surprised there was no mention of him in the text. There's more of him on YouTube: https://www.youtube.com/results?search_query=walter+lewin+do...
A lot of E-commerce software have data feeds that are ingested by parties like pricespy. These feeds are typically either public or made available after mutual agreements. Scraping a large amount of sites for data is just too much labor in the long run.
Kudos to Spotify for supporting libspotify and its use-cases for so many years. I'm sure it hasn't been easy and that copyright owners haven't been very fond of it.
Anecdata: I’ve found USB powered external drives to be unreliable on the Pi, even when powering the Pi with an official power adapter. I’d recommend using an external drive that comes with its own power adapter.
IIRC, the uTorrent guy (Ludde Strigeus) was employeed by Spotify and worked on, among other things, the P2P feature in Spotify.
Reasons for self-hosting: GitLab.com's not-so-great availability [1], slow code searches (compared to self-hosted with GitLab Advanced Search) and the fact that you can keep your code and resources off the public Internet.
The fact that you do need to upgrade it yourself regularly is indeed a drawback. On the other hand, an Omnibus upgrade has only failed me twice in the last five years or so, so there's little reason to not do automatic upgrades at night and fire off an alert in case something doesn't work as expected afterwards. Their releases are typically solid, so kudos to the team.
[1] https://status.gitlab.com/pages/history/5b36dc6502d06804c083...
I think GOBBLES pioneered this technique in like 1992 A.D. with their “Hydra”. Iirc it was claimed to exploit (jinglebellz.c) .mp3 players on behalf of the RIAA and to spread through file sharing networks. https://www.theregister.com/2003/01/14/is_the_riaa_hacking_y...
I too found this after reading about it here. I contacted them and received the following reply.
Exposure notifications cannot be enabled without user consent, so if you have not turned MassNotify on, then it is not active on your phone. However, a recent Google update, which makes MassNotify available as an option in your phone's settings, is causing some users to see MassNotify in their app list. Apologies if this caused any confusion.
The appearance of MassNotify in the app list does not mean that MassNotify is enabled on your phone. The presence of the app merely means that MassNotify has been made available as an option in your phone's settings if you wish to enable it. For more information about this, please see this help center article from Google: https://support.google.com/android/answer/10775533
You can see whether MassNotify is active by going to Settings -> Google -> COVID-19 Exposure Notifications. The “Use Exposure Notifications” toggle at the top of the page will show you whether MassNotify is active or not. From this screen, you can also enable or disable MassNotify at any time.
Sounds like he hasn’t been introduced to banana with tomato ketchup yet.
You could already download most of the comment data from them by querying their API. Similar to profile pictures on Gravatar, emails were only hashed with MD5. They’re easy to reveal with some wordlist attacks.
Use the download button in the top right of the pdf viewer thingy. That’ll render the actual pdf without html and annoying modals.
Reminds me of the Solaris TTYPROMPT in.telnetd bypass: https://packetstormsecurity.com/files/114491/Solaris-TTYPROM...
I think it’s just a strategy to take advantage of unique content to drive traffic to the site. I’ve seen this before.
This one has been relevant for the last 10 years: https://picturesofpeoplescanningqrcodes.tumblr.com/
I’ve reflected on the fact that some makers on YouTube wear gloves and wondered if this is for privacy reasons. I see globes being worn even when they’re not obviously doing anything that risk getting their fingers dirty.
Not that I'm aware of, but I wish. Memory is getting hazy these days. AFAIK the kernel.org breaches were made by the kind of hackers doing it for fun and games (if you get that thing) and not the kind working for nation states. I'm sure you can (or at least, at some point could) find others who know more details at your favorite compsec conf.
If memory serves me right the CVS bug was originally discovered and exploited by a member of an infamous file sharing site. After descriptions(?) of that bug were leaked in underground circles, an east European hacker wrote up his own exploit for it. This second exploit was eventually traded for hatorihanzo.c, a kernel exploit, which was also a 0-day at the time.
The recipient of the hatorihanzo.c then tried to backdoor the kernel after first owning the CVS server and subsequently getting root on it.
The hatorihanzo exploit was left on the kernel.org server, but encrypted with an (at the time) popular ELF encrypting tool. Ironically the author of that same tool was on the forensic team and managed to crack the password, which turned out to be a really lame throwaway password.
And that's the story of how two fine 0-days were killed in the blink of an eye.
I believe he has claimed that vitamin D deficiency is associated with worse upper respiratory tract infections in one of the earlier videos.
There’s nothing that suggests that those experiments had anything to do with OpenBSD.
Several people have looked into the issue over the years but so far no traces of malicious intent have been found.
I remember ftp.openbsd.org being owned around 2002. Possibly this hostname was pointed to the www.openbsd.org machine, which was running Solaris. I have a vague memory that this machine also hosted something else in addition to the OpenBSD site, and that people managed to get root on it via two (chained) 0day exploits of which at least one involved a Solaris daemon related to printing services. (Feel free to correct me if I got it wrong.)
I also recall cvs.openbsd.org being owned but I no longer remember how that happened. There's a high chance it was made possible thanks to a remote CVS exploit that was making rounds in some hacker circles[1]. FWIW, cvs.openbsd.org is mentioned under "memorable places I've been" in the Phrack #65 prophile of the UNIX terrorist.
2002 was a particular bad year for OpenSSH and OpenBSD. In March, 2002, it was found that OpenSSH 2.x/3.0.1/3.0.2 had an exploitable (post-auth IIRC) integer overflow in its channels handling. In June, 2002 that preauth Challenge-Response vulnerability was made public and shortly afterwards GOBBLES Security made public an exploit (sshutuptheo) for the vulnerability that among other things targeted OpenBSD 3.1 default installations. Early August, 2002 it was discovered that several OpenSSH packages had been backdoored on ftp.openbsd.org on June 30th, 2002 (google: "openssh 3.4p1 trojan").
Incidently the sshutuptheo exploit was written by the Australia division of GOBBLES Security. Later postings on public mailing lists suggests that this division fell off the earth shortly afterwards (can't link).
Some of these things had ties to the community around #phrack and the autonomous Phrack High Council "movement". PHC had nothing to do with the official Phrack magazine and instead was similar (in actions) to the Global Hell (gH) movement that happened earlier (around 2000, I think). PHC kind of spun out of the anti-sec movement that existed at the time, but really it was just a setup to trick kids into thinking they have a common purpose and do damage for the lulz; think early "anonymous" or lulzsec and you'll get the idea.
I know FBI had at least one informant in the #phrack and PHC circles at the time: soupnazi a.k.a segvec a.k.a [2]. So perhaps those contacts mentioned in a child post aren't OpenBSD developers but.. other people?
The nickname of the Hungarian wasn't pipops but I'll leave it out since you got the reference right the first time: "PaX Team" ;) Regarding the feud, you can find some pointers in this poster defacement[3] attributed to the Micke Mouse Hacking Squadron. The picture is from the OpenBSD tent at the Chaos Communication Camp in Berlin, Germany in August of 2003. MMHS was one of several GOBBLES Security copycats. They generally lacked the effort but MMHS was the only one that, like GOBBLES, produced a few (arguably funny) comic strips.
Grsecurity/PaX team did a hell of a job identifying vulnerabilities and working around them or hardening code long before anyone else. It's not surprising that they would've mingled with others interested in that sort of things, possibly sharing hints of vulnerable code paths or having discussions around the vulnerabilities and/or workarounds.
[1] https://news.ycombinator.com/item?id=18179805
[2] https://en.wikipedia.org/wiki/Albert_Gonzalez
[3] https://web.archive.org/web/20060512113602/http://www.grsecu...
Care to expand on why MySQL < 8 will be problematic for analysts? Anything else than the lack of window function?
https://github.com/Unleash/unleash
Unleash is a feature toggle system, that gives you a great overview over all feature toggles across all your applications and services. It comes with official client implementations for Java, Node.js, Go, Ruby and Python.
Thanks for the detailed write up!
Second this. It’s super hard to imagine in what ways things can go wrong before you have seen or experienced them.
Kick-backs would never even have been on my radar, even though I’m seeing myself as a careful person, if it wasn’t for YouTube and people like him taking their time to educate the rest of us.
Wood working newbie here. I recently learned about table saw kick-backs and ordered a Grr-Ripper push block[1] after seeing it being recommended on several YouTube videos. I’m quite happy with it but I’m not really experienced enough to make a fair judgement of the product. Is these kind of things something that more experienced wood workers are using/recommending?