Welcome to Incremental Social! Learn more about this project here!
Check out lemmyverse to find more communities to join from here!

Slotos

@Slotos@feddit.nl

This profile is from a federated server and may be incomplete. Browse more on the original instance.

Slotos ,

I'm not sure if you're calling Putin a stupid man that is easily manipulated or incompetent.

They are parroting Russian propaganda. The one where “the west” is stipid, cunning, strong, and rotting all at the same time.

Slotos ,

Identification != Authentication

As obvious as this sounds, I’ve learned over the years that most people don’t understand what it means exactly.

addressing misconceptions about the recent TunnelVision vulnerability

I've been seeing a lot of confusion around the TunnelVision vulnerability. While I'm no expert, I've done a fair share of research and I'll edit this post with corrections if needed. The goal of this post is to answer the question: does this affect me?...

Slotos ,

If you use HTTPS, the attacker can still see what websites you connect to, they just can't see what you are sending or receiving. So basically they can steal your browsing history, which defeats the purpose of a commercial VPN for many users.

This is blatantly false. They can see IP addresses and ports of you connect to from IP packets, and hostnames from TLS negotiation phase (and DNS requests if you don’t use custom DNS settings). HTTP data is fully encrypted when using HTTPS.

If exposing hostnames and IP addresses is dangerous, chances are that establishing a VPN connection is as dangerous.

Novel attack against virtually all VPN apps neuters their entire purpose (arstechnica.com)

Pulling this off requires high privileges in the network, so if this is done by intruder you're probably having a Really Bad Day anyway, but might be good to know if you're connecting to untrusted networks (public wifi etc). For now, if you need to be sure, either tether to Android - since the Android stack doesn't implement...

Slotos ,

Control of the DHCP server in the victim’s network is required for the attack to work.

This is not a VPN vulnerability, but a lower level networking setup manipulation that negates naive VPN setups by instructing your OS to send traffic outside of VPN tunnel.

In conclusion, if your VPN setup doesn’t include routing guards or an indirection layer, ISP controlled routers and public WiFis will make you drop out of the tunnel now that there’s a simple video instruction out there.

[Thread, post or comment was deleted by the author]

  • Loading...
  • Slotos ,

    I sit at home and when visiting someone as a guest. No mess, no cover positioning arguments, everyone’s happy for a meager cost of me potentially forgetting that this was supposed to be a quick in’n’out and writing this comment instead of rejoining the boring dystopia outside.

    Slotos ,

    In the dark, with the other side obscured (or just broken), you don’t want the blinker to actively prompt you to come to a wrong conclusion.

    It’s better to see a blinking light and think “I don’t see enough, gotta slow down” than see a blinking arrow and potentially not even realize it’s a turn signal.

    Slotos ,

    Don’t compare someone’s highlight reel to your behind the scenes.

    I once convinced someone that they are actually doing a great job by sharing my struggles and showing that they are not an impostor. They now outshine me and will go to even greater heights.

    And while that one episode of dealing with burnout and impostor syndrome is a drop in the ocean of their persistence, it’s a great illustration to how misleading comparison to others is.

    PS: Also, if you have ADHD, you’re nearsighted in time. That doesn’t only mean “you can’t plan well”, it means “your life looks like a hazy blob, where others see a complex scenery”. And that can be devastating when doing a comparison. Be kind to yourself, be kind to others.

    Slotos ,

    actual infrastructure for micromobility

    Right, because Amsterdam, as we all know, is such a shithole in that regard.

    You’re the obsessed one in this case.

    Slotos ,

    Welcome to the world of SPAs. Where every little thing needs its own application.

    Damn it, we even have HTML tags that are impossible to employ in their entirety without use of JavaScript. <dialog> is infuriating and is literally two attributes away from not needing JavaScript.

    Except on Chrome. Dialog is broken on Chrome and you will have to clean up with JavaScript after chrome’s own half assed implementation.

    Slotos ,

    How to I relax? My shoulders get so tense at times that it leads to crippling headaches.

    Slotos ,

    On the other hand, if it works in Firefox, it’s likely to work everywhere else.

    I use Firefox for development and then, barring some weird chrome bug, things just work everywhere.

    Slotos ,

    That’s how engineers think in their free time.

    When the specific goal is something I can do manually, and it’s not pressing, I would rather spend time learning how to make a tool to do it. I might not need the tool ever, I do use the knowledge picked up on those forays every day.

    Slotos ,

    Different disciplines - different thresholds. But yeah, that’s exactly it.

    With software engineering, the unknown space is vast, yet the tools are great. So it’s very easy to start tinkering and get lost in the process.

    Slotos ,

    And if there’s a bug in that code, you’re fucked.

    Safety features should work if everything else fails. Their failure mode can’t be “fuck it, it didn’t work”. Which is directly opposite to the failure mode of a subscription based service.

    Slotos ,

    Thorium reactors have a cleverly dumb failsafe. If reactor control fails, there’s a plug that melts and drains the contents into a container that’s not fit for runoff neutron generation.

    That’s an example of a failsafe that fits its purpose. It’s still possible to fuck it up, but it would take a lot of effort to do so.

    Slotos ,

    Word “respect” means two different things. One of them can only be earned, another can only be given.

    What’s more, the part that can only be given is best described by trust. As in, the only way you can truly know if you can trust someone is to trust and find out.

    In this context, the respect that is given - a regard for the others - is a baseline trust in a reciprocal valuation. The respect that is earned is the collection of outcomes that feed into others’ trust risk assessment.

    Slotos ,

    Every wave is affected by Doppler effect.

    When a car rushes your way, it’s a tiny bit bluer, a little bit hotter, it’s drivers’ phone is operating on a slightly higher frequency and it sounds higher. According to you.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • incremental_games
  • meta
  • All magazines