Oddbean new post about | logout

Notes by DarkMahesvara | export

 nostr:npub1hf5c3xf2hxj28p2afgl3cnn4ftcphswn5vwn0p2nyu94kzyka6asflpc2h 
bet those were horse feces... 
 @87bc2eb4 involuntary flashback to greentext about anon jerking off to and with horse shit :awoo_stare: 
 https://web.archive.org/web/20231006200925/https://therecord.media/scraping-incident-genetic-testing-site

gene doxxing as a service. anybody who submits there data to these vultures and consequently compromises there whole family tree should be disposed of in the most violent way (in spore) 
 "The transient-execution attack Meltdown leaks sensitive information by transiently accessing inaccessible data during out-of-order execution. Although Meltdown is fixed in hardware for recent CPU generations, most currently-deployed CPUs have to rely on software mitigations, such as KPTI. Still, Meltdown is considered non-exploitable on current systems. In this paper, we show that adding another layer of indirection to Meltdown transforms a transient-execution attack into a side-channel attack, leaking metadata instead of data. We show that despite software mitigations, attackers can still leak metadata from other security domains by observing the success rate of Meltdown on non-secret data. With LeakIDT, we present the first cache-line granular monitoring of kernel addresses. LeakIDT allows an attacker to obtain cycle-accurate timestamps for attacker-chosen interrupts. We use our attack to get accurate inter-keystroke timings and fingerprint visited websites. While we propose a low-overhead software mitigation to prevent the exploitation of LeakIDT, we emphasize that the side-channel aspect of transient-execution attacks should not be underestimated."

https://cispa.de/en/research/publications/4011-indirect-meltdown-building-novel-side-channel-attacks-from-transient-execution-attacks

meltdown, the spectre of modern computing 
 @Narbray  good still needs to be implemented on webserver also fuck mozilla again for selling there user to cuckflare 
 this has been long overdue but still great news. updates where the last thing where apple had the advantage.

GrapheneOS has already worked on Android 14 for some time so i would expect support soon

https://varishangout.net/media/bf4669ff-6b0c-4314-9486-8c386651a836/image.png

https://varishangout.net/media/5880d706-b22a-49d8-8291-77738cb6de4f/image.png 
 If you've already got CULTIC, there's a free bonus "Interlude" level released by the dev that ser... 
 @チャノさん never was this hyped about ladders in gaming 
 "Stemming from reports of several fake crypto apps appearing in Canonical's Snap Store that aimed to steal user funds, temporary restrictions have been put in place while Canonical investigates the security matter.
[...]
the Snap Store removed the reported Snaps. A temporary manual review requirement has also been put in place on new Snap registrations."

https://www.phoronix.com/news/Snap-Store-Malicious-Apps

another step closer to microsoft and windows lol 
 after webp, vp8 is the next google codec with a vulnerability and its being actively exploited. buffer overflow leading to remote code execution when encoding a video e.g. video conference.....these memory safe language advertisements really are getting more and more aggressive :heh: 

https://web.archive.org/web/20230929110536/https://arstechnica.com/security/2023/09/new-0-day-in-chrome-and-firefox-is-likely-to-plague-other-software/ 
 microsoft is not merely satisfied with logging the full URLs (example.com/private_site_content) of every user (microsoft defender smartscreen) so ofc like with windows the next step is to sell there user to the next highest bidder.

cloudflare is already the default DNS provider in firefox (use librewolf or tor/mullvad browser) but that's not enough they want ALL the traffic so naturally a free vpn is the perfect fit to further increase there fluorescent control over the internet. glad to see they are going back to there roots as a honeypot...

https://web.archive.org/web/20230928175413/https://blog.cloudflare.com/cloudflare-now-powering-microsoft-edge-secure-network/ 
 nostr:npub1hf5c3xf2hxj28p2afgl3cnn4ftcphswn5vwn0p2nyu94kzyka6asflpc2h I have a doubt.
if I buy a ... 
 @Narbray  no like i said extended support is only for the newest EOL devices

https://grapheneos.org/faq#device-lifetime 
 and yet no updates for EOL Android devices (not even pixels)...hope at least the rumors about pixel 8 having 7 years of (security) updates is true

(GrapheneOS actually patched this for newest EOL Pixel 4, 4a and 4XL devices with there extended support patches)

https://www.bleepingcomputer.com/news/security/google-assigns-new-maximum-rated-cve-to-libwebp-bug-exploited-in-attacks/ 
 looks like deck/big picture UI and could be another indicator that the new steam device really might be deckard VR

https://www.gamingonlinux.com/2023/09/steamvr-20-bet-released-with-a-big-ui-overhaul/ 
 Google Authenticator cloud backup (enabled by default) and social engineering with deep fake breached a software development company

https://web.archive.org/web/20230916081231/https://retool.com/blog/mfa-isnt-mfa/ 
 https://nichegamer.com/lies-of-p-quietly-adds-denuvo-drm/

LMAO fuck them. hope it gets cracked soon so i can seed it to the end of time. 
 and only about a decade late. really curious just like with Internet Explorer they only notice this stuff once the product loses relevancy. guess in another decade it will be microsofts turn again :tanya_bored: 

https://web.archive.org/web/20230913172418/https://www.bloomberg.com/news/articles/2023-09-12/google-pays-10-billion-a-year-to-maintain-monopoly-doj-says 
 https://web.archive.org/web/20230913140154/https://devblogs.microsoft.com/oldnewthing/20230911-00/?p=108749

its almost like letting individual software do as they please is not a good idea :jahy_shocked:  if only someone invented a way to manage these application 30 years ago :tanya_bored: 
 Why would Unity charge a dev for every time a third party installs/uninstalls their Unity game, t... 
 @チャノさん its the same bs with refund costing money on fiat payment processors as if there is any actual work being done instead of 1 and 0 just changing by themselves 
 nostr:npub1hf5c3xf2hxj28p2afgl3cnn4ftcphswn5vwn0p2nyu94kzyka6asflpc2h If it wasn't for the fact t... 
 @Ronnie21093 if they are really friends there existence in your life would not depend on some website 
 :cirno_facepalm: And now Facebook is suggesting Flat Earth pages to me. I've never even interacte... 
 @Ronnie21093 >implying facebook only correlates your interests with stuff you do on there site 
 >hack around
>change something on my system which would be tiresome and take long to revert back
>roll back snapshot from the last hour which is instant, bit perfect, minimal used storage space and does not touch user files

literally how can anybody live without this. heil ZFS 
 @Narbray  anything microsoft touches turns into a data harvesting advertising enshittification platform 
 @Cayhr faggots are terrified of "AI" that is trained on real data because its exposing there lies. thats why microsoft and mozilla are trying there best to beat them into submission with restrictions and false data that adheres to there dogma. 

never forget tay :ina_blessed: nothing is safe from there grooming 
Event not found
 @PunishedLenny3 more clothes = hotter, is often true :zt_nod: 
Event not found
Event not found
 @翠星石 

>But, Rockstar can authorize such modifications and they have for their own distribution.

ofc they can but they do not own the modifications made by somebody else. it depends on the country but you can own the rights to derivative work.