Avatar
Dr. Hax
d30ea98ea65e953f91ab93f6b30ea51eb33c506f87d49f600a139aef00aa9511
Cypherpunk. Infosec veteran of about 15 years (vulnerability research, exploit development and cryptography). Cypherpunks write code. :-) Signet maintainer. Self-custody your passwords... in hardware! https://hax0rbana.org/signet Want to see wider adoption so Bitcoin can be used as digital cash and not just an investment vehicle. XMR: 44RDkTFmTeSetwAprJXnfpRBNEJWKvA5dBH5ZVXA4DofgoZ9AgjyZdSa2fo7pMD3Qe3pdKga8X22y3Lyn1xYde5kPQPzVUu

Posted a flier at the local food coop.

#m=image%2Fjpeg&dim=1920x1440&blurhash=%23BGum%7E%25%230em%2CcD-p%3FcRi%251yZ%3Fc%2BxWVNYxvW.n%2CWA00%25g.9V%5BJ-r%5BIB%25MaM%254Ioogxu%25faJX4bctS_4RQMwtRI.ROadM%7Bo%23%3DzkXNdROD%25WAM%7BbbWB%25MxGogSNxuWBi_V%40WC&x=5a2efa9ba8c357e9d1d078096e05354f6348ded2fec127324bda20921b37cd35

This one is especially cool considering the sign they have out front letting everyone know how much money they spend per year in credit card fees.

#m=image%2Fjpeg&dim=1440x1920&blurhash=_SJkYuNGM%7EjcjwRka%23%7ETozRjj%5BWUWBj%3DamWAt7oeoeoxocE0s%3BWEWCRkoeWExaWBoeayWUoLWBRjbajbayofWBoet7RlR*oeWBj%40WBE2ahofofs%3AbFoLt6xaR-WCWBWVjb&x=68d30b073aa528085f6bac3795626c3d63282e07cd852cab07fe6e0f182ed38a

Fun fact from tek: "if you work in #infosec, and you have an education budget, you can almost certainly spend it on 2600. If not, it’s almost certainly tax deductible."

Support the OG hackers if you can.

Source: https://freeradical.zone/@tek/111807243827886810

I don't know who needs to hear this, but Warcraft 2 reportedly runs under DosBox and it's on https://archive.org/details/msdos_Warcraft_II_-_Tides_of_Darkness_1995

Enjoy!

ScareMail is an extension to add scary sounding text to the end of emails to waste the NSAs time sifting through garbage.

https://bengrosser.com/projects/scaremail/

It looks like it's really just trying to make a point instead of attempting to actually be effective, as it puts the text in the signature section, which could easily be filtered out. Plus it identifies itself as ScareMail, which makes it even easier to spot and exclude.

I don't use any web mail, let alone google's webmail, but if you are more interested in making a point to the people you email (to invite them to ask why that text is there), maybe you will find it interesting.

I found the answer in III(a) of their academic paper. It makes an AJAX request and does not load the response into the DOM.

The paper talks about the problem of this being distinguishable from a real click (which would parse the response, render HTML & CSS, execute JS, parse CSS, possibly play audio and video files, etc.).

The additional risk in their current implementation seems minimal. Future versions may depend more on sandboxing technologies for protection.

https://docs.zeusln.app/pos/overview/

There appears to be some JS nonsense on that page that doesn't like the double slash in your URL. It loads for me very briefly before giving the 404 error. 🙄

Replying to Avatar bumi

nostr:npub1gcxzte5zlkncx26j68ez60fzkvtkm9e0vrwdcvsjakxf9mu9qewqlfnj5z what do we do here?

I fear this is more Tor being unreliable or something? do you have an idea how we can better debug these Tor issues?

I have tried it on different days and at different times with different exit nodes. At the same time I am able to load new posts from relays, so I know not all traffic is being blocked/dropped.

When I spun up Tor Browser, and tried to go to getalby .com, I was given a captcha from cloudflare and the browser indicated that it was still loading even after the page was rendered (felt like a comet style pattern).

I realize there could be selective dropping of traffic from an exit node, and the main Alby website might not behave the same as the server that deals with the zaps and so forth, but it's the information I have.

What would be helpful is an error message saying the connection timed out (if that is what's happening). I have seen error messages when zaps get http status codes in the 4xx range, so I know those errors are handled reasonable well.

If you can make a test site that will let me input a nostr note ID and have it simulate what and app usinf NWC would do, I'd be happy to help test with the production network and sending real BTC around. A test site would allow you to see every step along the way and provide some level of confidence that the issue is not on your side.

I know it's hard when you don't control the code involved, and there's two men-in-the-middle (Tor, Cloudflare) before it gets to your servet, but if you try to use Amethyst and enable Tor, I suspect you will be able to reproduce the issue very quickly.

Yeah, that was the first thing they mentioned in their requirements is dealing with malvertising.

I didn't get to the section that covers how they met that goal yet, but if you are interested I can let you know what their approach is so you can see if it sounds sufficient.

I was going to recommend VoltPay, but it looks like voltpay.app just redirects to google's home page now... so, nevermind on that.

I use Zeus wallet and Alby to hold my coins. It's fasy and easy. Using just Zeus and holding the coins myself would be nice, but it is poorly documented, so much so that a person who has been using BTC since 2012 isn't comfortable with it.

Cold brew, medium grind, lightly roasted peruvian coffee from our local food coop. Then I adulterate it with zero sugar powdered creamer and xylitol.

I don't really like coffee, but if it's doctored up enough, it's delicious.

I used to use cream, but the shelf stability of the powdered stuff won out for me. It's just too handy to be able to stock a few month's supply.

Yeah, Google banned them from the app store, seemingly with the express intent to make it more difficult and time consuming to use this app.

It must be incredibly effective.

Do you believe that all apps that do not come from a centralized, corporate controlled app store are viruses?

Replying to Avatar Dr. Hax

I try to post mostly positive things, which can be hard these days, but here's a good one:

https://adnauseam.io/

It is a browser extension that silently clicks on all those ads, polluting the advertisers' data streams.

If used by enough people, it would mean that, to the advertiser, it'll look like they got lots of clicks buy not lots of sales.

This means the value of clicks will go down, which means less profit for people who serve up ads.

If you promote this extension, you will be hurting American companies who are just trying to make ab buck. Companies like Facebook, Apple, Amazon, Google, X, and others. You wouldn't want to make life more difficult for them... would you? 😈🤣

The academic paper looks like a fun read too

"We conclude with thoughts on the broader

issues facing privacy tools ... informed by our experience with AdNauseam’s ban from Google’s Chrome store"

http://ceur-ws.org/Vol-1873/IWPE17_paper_23.pdf

That's why I let people know about StreetComplete. In my area, addresses that I go to (or are near where I go to) are very well populated. 🤗 But when I'm at some place new, yeah, it's pretty sparse.

Some people on #ActivityPub are taking about how open, privacy centered protocols are disrupting the "industrial surveillance engines" at "alarming rates".

They mention #nostr #matrix #Tor #i2p #ipfs and others as being champions of freedom. They also mention that these protocols are building bridges amongst themselves.

https://neenster.org/objects/9ae1ea88-f2ea-41ee-bea9-f20c8b40afda

It's kinda hard to follow, but it just goes to show that there are some good people over there on the #Fediverse