Natanael

joined 3 years ago
[–] Natanael@slrpnk.net 2 points 4 hours ago

Not too different from the PS4 Spiderman game police surveillance towers which he had access to

[–] Natanael@slrpnk.net 2 points 4 hours ago

Net zero IS HOW YOU DROP BILLS because renewables are cheaper, the lying assholes

[–] Natanael@slrpnk.net 2 points 1 day ago* (last edited 1 day ago)

Was planning to get another Sony now but they stopped selling their phones in my country...

With Asus taking a pause and all other options being random Chinese brands or budget phones there wasn't really a choice left...

The brilliance market justification of "see, people are buying [literally the only thing offered because options were removed], they like it [complaining loudly]"

[–] Natanael@slrpnk.net 1 points 1 day ago

Google's "Material You" is "Material anybody-but-you"

[–] Natanael@slrpnk.net 2 points 1 day ago

So valueless in the metrics that actually matter

[–] Natanael@slrpnk.net -3 points 1 day ago

No better source than RT?

[–] Natanael@slrpnk.net 2 points 1 day ago

Clearly you have your ducklings in a row

[–] Natanael@slrpnk.net 1 points 3 days ago

Fast HDR (not just regular high dynamic range capture) is also technically composite but does capture things that were simultaneously in the scene

[–] Natanael@slrpnk.net 0 points 3 days ago (1 children)

Not with that attitude (unscrews the entire thing and shoves in a UV light on a wire in the gaps)

[–] Natanael@slrpnk.net 0 points 4 days ago* (last edited 4 days ago)

Yeah that's the thing, quantum key distribution can not prove who is on the other end!

It fundamentally can not guarantee that the line is intact before you start communicating. You can in theory detect a break that starts after, but one that happened before is effectively invisible.

Quantum key distribution can not do anything other than key expansion (giving you more secret bits from a few), because the only way to know who is in the other end is to have agreed to a method of validation, such as a signature algorithm (but if you trust signatures you won't care about quantum key distribution) or a shared secret (an authentication tag key). But if you have a large enough secret key, you can just use a regular symmetric encryption algorithm. Some might want forward secrecy from the quantum line, but you can get that with symmetric key ratchets like Signal uses where the ONLY benefit of quantum key distribution is that you avoid key management (but instead you maintain physical infrastructure)

[–] Natanael@slrpnk.net 0 points 6 days ago (2 children)

This is neat, but quantum key distribution is stupid as hell because it's only secure if you START OFF WITH A SHARED SECRET to authenticate the key pad and first round of messages.

And if you have that then you don't need quantum encryption because you can do everything with just symmetric encryption (unless you specifically have some very weird forward secrecy requirements where it isn't approved to use asymmetric post quantum algorithms like McEliece)

[–] Natanael@slrpnk.net 4 points 1 week ago

I call it "breakglass powers". For most it's probably known as "the things I'd do on the last day of my job". Things you can do once and then never again.

 

Just let it die already

 

Include Mozilla's CRLite and daily updates for both and suddenly we have high performance high security certificate validation which includes revocation checking and duplicate certificate discoverability (MITM risk) from the transparency logs

 

In this paper, we undertake a structured security analysis of Wi-Fi client isolation and uncover new classes of attacks that bypass this protection. We identify several root causes behind these weaknesses. First, Wi-Fi keys that protect broadcast frames are improperly managed and can be abused to bypass client isolation. Second, isolation is often only enforced at the MAC or IP layer, but not both. Third, weak synchronization of a client's identity across the network stack allows one to bypass Wi-Fi client isolation at the network layer instead, enabling the interception of uplink and downlink traffic of other clients as well as internal backend devices. Every tested router and network was vulnerable to at least one attack. More broadly, the lack of standardization leads to inconsistent, ad hoc, and often incomplete implementations of isolation across vendors.

 

When an attached image is loaded, then if the loading fails the app should check if it's using proxying (domain belongs to posters'/forums' instance or user's instance & contains redirect format URL pointing to another domain) and give you a button to press to retry, which would suggest bypassing the proxy and requesting the original image directly

Motivation: I keep seeing broken image embeds and can't be bothered to view source and try the redirect section in my browser after rewriting it to a proper link for every failed image load

Let the app do that for me

view more: next ›