testaccount789

joined 3 years ago
[–] testaccount789@sh.itjust.works 11 points 4 days ago (1 children)

Most Slovakian government sites also look like this.

a TV will def not use that much power

Holy hell, I never thought of that.
Our TV defines 33W "typical" and 53W max.
If it had USB-C I could run it from a power bank.

[–] testaccount789@sh.itjust.works 4 points 1 week ago* (last edited 1 week ago)

Jú ken olsou vrajt Ingliš in adr lenguidžis d uey ic red.
("You can also write English in other languages the way it's read." - Slovak.)

Slavic enough to read it, 196 enough to understand.

4L

Oh, I thought it was some special unit. It's just cm^3^ (Cubic Centimeter), so the same thing as milliliters.

[–] testaccount789@sh.itjust.works 6 points 1 week ago (6 children)

Best thing, though unfortunately not quite possible, would be to check each other's ID.

  1. You can be certain about each other's age.
  2. Should they harm you, you now know who the other person is, and they get the same reassurance.

But that conversation wouldn't work.

[–] testaccount789@sh.itjust.works 24 points 1 week ago (1 children)


I don't know what the first one is about. Is it about how the Gemini webpage displays the output?

Don’t like how they’re doing it, you can literally spin up your own for dollars per month.

Not so easy.
Mostly a liability issue.
First there's security - make sure the server doesn't get compromised.
Then you need to figure out how to deal with illegal content like CSAM (was already a widespread issue on Lemmy at least once, causing multiple instances to shutdown) - even on private instance due to content caching.
And legal issues such as minimum age and privacy regulations that you'd have to comply with.

3rd one is not an issue if you only use it yourself, and perhaps with a couple of friends that won't try to sue you when they get mad.

[–] testaccount789@sh.itjust.works 3 points 1 week ago (1 children)

If you once ride in an elevator with glass doors, does the dog understand that's all those other ones do as well?

 

Old news, but I haven't seen it posted here.
The teronlyfans website linked in the article is gone now, but it's been archived: https://web.archive.org/web/20240331051815/https://teronlyfans.com/english/ (SFW)

 

Source: https://www.tatrabanka.sk/en/personal/cards/my-doctor/#MRI

I don't know if it fits here, but getting an earlier appointment because of what bank/CC you use feels... odd.

 

I've used to look for smaller Chinese brands that don't bother removing factory test tools, but after discovering baked-in malware, I don't really feel comfortable with that.

Examples

This is an example from MediaTek Engineer Mode:

And here's an example of selection made with mmcli --set-current-bands (may work on Linux phone OSs like PostmarketOS):

(PostmarketOS may use ModemManager: https://wiki.postmarketos.org/wiki/Modem)

Use cases

Particularly the 800MHz LTE band (B20 and eutran-20 above) tends to be overloaded, and also typically has less allocated RF bandwidth.

Automatic selection may or may not work as desired. For example, I find 800MHz to be favored indoors in my location.
In worst-case scenario, I can use this to jump from B20 to B7, the latter of which does carrier aggregation (20+20MHz) with the carrier (provider) I use, boosting me from 15Mbps to 130Mbps.
This will cost some extra battery use, but meh.

Another is with carriers that have agreement for network sharing with another carrier as to provide coverage extension.
For example, when I used Swan Mobile ("4ka") in Slovakia, the carrier had own base stations in B3 (and thus highly preferred) and coverage extension from Orange on B1 and B8. Since this was no longer implemented as roaming, this was the only method of manual control.

And they're shitty enough to have FUP on something you typically can't control.

Existing solution

There's an app called Network Signal Guru: https://play.google.com/store/apps/details?id=com.qtrun.QuickTest

But I don't know how trustworthy it is to give root access to.

 

TL;DR: If it's also integrated into firmware, it has full-device access. If it's just this specific app, per Kaspersky, it still has "elevated privileges" and can install crap. It cannot be disabled without breaking the UI.

Doing a scan without copying the apk:

As you can see from main screenshot, the APK would have been accessible for scanning.
I copied it to Download directory as that one gets real-time monitoring, but it will pick it up elsewhere after a scan as well.

Anyway:
VirusTotal report

Found 4 months ago by Kaspersky

And I found my device in list on blog post from Sophos. Unfortunately, they only provide a partial list, as they mention this affects "nearly 50 models".

From listed domains, with help of strings I found launcher(dot)szprize(dot)cn, although it doesn't seem to resolve to anything at the moment.

Also something interesting from Kaspersky:

When integrated into the firmware, the malware behaves differently depending on several factors. It will not activate if the language set on the device is one of Chinese dialects, and the time is set to one of Chinese time zones. It will also not launch if the device doesn’t have Google Play Store and Google Play Services installed.

Now what?

I've been using it for nearly 2 years, so there's that...

I am thinking of contacting the retailer I bought this device from, as it's still in sale. But I am not sure if they will care about it. Also, the only way I seem to be able to contact them is via tech support, so there's the chance of just getting a copy-pasted answer.

As for my particular unit, I'll probably try to update the software to newest version to see if it's still (visibly) present.
Unfortunately, updates on these devices are unstable as fuck, so I'll have to deal with that. I also hope it won't make me loose access to MediaTek EngineerMode band selection as that's something I quite want to keep using.
Or perhaps try to return it under warranty.

Since QuickStep also controls navigation (both gestures and 3-button) it can't even be disabled even if I used alternative launcher.

 

As someone who used to like the game and the lore, I was waiting for a while for the (official) FNAF movie.
When it released in 2023, I thought I'd buy it on a DVD because I like physical media (and AACS sounds like crap to deal with).
But it wasn't yet released.

So I found it on Himovies (which is now dead), and decided to watch it later. "Maybe tomorrow."
Eventually it got released, but the price was too high, so I figured it would go down, eventually.
At some point I closed the Himovies tab. Out of tab bar, out of mind.

Now I remembered it when watching a trailer for different movie. Oh damn, let me check the DVD.
Sure thing, I could grab a used one now for a third of the original price.

Let's... go?
Wait, FNAF 1&2 DVD set? There's a second one?

But it's past 3AM now, so, maybe later?

 

Knowledge of this makes me uncomfortable.

If you screw it too hard, it will definitely crack it as the hole is tapered.
If you don't screw it enough, the drive will move around.

At first I felt good about it. I took it out of packaging, cool, aluminum. At least some of it. When I opened it up, painted plastic. Why the fuck is that part plastic?
Product shame: https://www.aliexpress.com/item/1005006193051123.html

Also, the fan is missing.

 

Introduction (to this post)

A week ago there was a discussion on Lemmy shitpost community mentioning Obscura.
It acts as first hop to Mullvad. Fairly limited number of its servers.
As someone mentioned, it only supports macOS, iOS, and whatever does Wireguard.

So I tried to pay for it.
First, I am displeased that there's no way to just upload public key, but instead it generates entire config along with private key in browser.
Second, I can't see list of servers and ports like on Mullvad's site, and the reason is...
Third, only one combination of entry + exit node per config is possible. It seems to just assign a port on selected entry node to forward it to specified Mullvad exit node.

And there's just 3 slots!!!!!!!!!!

I can use same key with other config's combination, but if I remove the config, that port gets closed. So yeah, I can't just have many configs saved for different servers with the same private key.

But then I thought, is the public key allowed on all Mullvad servers? Yes it is.

After all, it should be just a hop through them.


Setting up Mullvad VPN client for Obscura

First, once you have Mullvad VPN installed, open the GUI, and create an account. Perhaps this step can be skipped, but that's a simple way to get the config created.

Next, quit the GUI and stop mullvad-daemon:

sudo systemctl stop mullvad-daemon

Now, open your Obscura Wireguard config in some text editor that you can copy from.
Next, open /etc/mullvad-vpn/device.json as root. E.g.:

sudo vim /etc/mullvad-vpn/device.json

Remove the account number, private key, IPv4, and IPv6 field values. I also removed the "id", though I don't know if that one would have caused issues.
If you keep the account number, you will just get expiration message.

Next, replace the private key, IPv4 and IPv6 with those from Obscura Wireguard config.

Here's an example of how that may look (data in example is invalid):
WG config:

# Exit: Mullvad ca-tor-wg-002 in Toronto, CA

[Interface]
PrivateKey = eNZ0Lr3jpE18o/KSVISHCi/wDWW5DgD6VCCEduKgkFI=
Address = 10.0.0.1/32, fc00:bbbb:bbbb:0:0:0:0:1/128
DNS = 10.64.0.1

[Peer]
PublicKey = iqZSgVlU9H67x/uYE5xsnzLCDXf7FL9iMfyKfl6WsV8=
AllowedIPs = 0.0.0.0/0, ::0/0
Endpoint = 95.173.193.232:46906
PersistentKeepalive = 15

Mullvad device.json:

{
  "logged_in": {
    "account_number": "",
    "device": {
      "id": "",
      "name": "obscura key",
      "wg_data": {
        "private_key": "eNZ0Lr3jpE18o/KSVISHCi/wDWW5DgD6VCCEduKgkFI=",
        "addresses": {
          "ipv4_address": "10.0.0.1/32",
          "ipv6_address": "fc00:bbbb:bbbb:0:0:0:0:1/128"
        },
        "created": "1970-01-01T00:00:00.000000000Z"
      },
      "hijack_dns": false,
      "created": "1970-01-01T00:00:00Z"
    }
  }
}

The name has no effect in this case, it's just what you see in the app. If the other fields matter, I don't know. I left them as they were.

Now you can once again start mullvad-daemon.

sudo systemctl start mullvad-daemon

You should now be able to connect to servers just as usual. But we have yet to add the Obscura server. The account page won't work, as there's no account.

Following the example above, we add an IP override for our exit node:

mullvad relay override set ipv4 ca-tor-wg-002 95.173.193.232

Lastly, we need to use the correct port. As per our example, in Mullvad app go to Settings -> VPN Settings -> Anti-censorship -> Wireguard port -> Custom -> enter 46906

Thankfully, these ports are also valid for Mullvad, so no extra switching will be needed.
You should now be able to connect to the Mullvad exit node via Obscura server, with Obscura account.

Multi-hop within Mullvad (a 3rd hop)

As the port for Obscura's server matters, we can only use it as an entry node. But yes, you can do that too.

Hopping madness

There's no point, but it's possible.
The Mullvad SOCKS5 will allow for, yes, a 4th hop.

And you can add TOR, for 7 hops (to regular sites)

What does that do? From this:

All the way to network quality of your teammates:

 

Introduction (to this post)

A week ago there was a discussion on Lemmy shitpost community mentioning Obscura.
It acts as first hop to Mullvad. Fairly limited number of its servers.
As someone mentioned, it only supports macOS, iOS, and whatever does Wireguard.

So I tried to pay for it.
First, I am displeased that there's no way to just upload public key, but instead it generates entire config along with private key in browser.
Second, I can't see list of servers and ports like on Mullvad's site, and the reason is...
Third, only one combination of entry + exit node per config is possible. It seems to just assign a port on selected entry node to forward it to specified Mullvad exit node.

And there's just 3 slots!!!!!!!!!!

I can use same key with other config's combination, but if I remove the config, that port gets closed. So yeah, I can't just have many configs saved for different servers with the same private key.

But then I thought, is the public key allowed on all Mullvad servers? Yes it is.

After all, it should be just a hop through them.


Setting up Mullvad VPN client for Obscura

First, once you have Mullvad VPN installed, open the GUI, and create an account. Perhaps this step can be skipped, but that's a simple way to get the config created.

Next, quit the GUI and stop mullvad-daemon:

sudo systemctl stop mullvad-daemon

Now, open your Obscura Wireguard config in some text editor that you can copy from.
Next, open /etc/mullvad-vpn/device.json as root. E.g.:

sudo vim /etc/mullvad-vpn/device.json

Remove the account number, private key, IPv4, and IPv6 field values. I also removed the "id", though I don't know if that one would have caused issues.
If you keep the account number, you will just get expiration message.

Next, replace the private key, IPv4 and IPv6 with those from Obscura Wireguard config.

Here's an example of how that may look (data in example is invalid):
WG config:

# Exit: Mullvad ca-tor-wg-002 in Toronto, CA

[Interface]
PrivateKey = eNZ0Lr3jpE18o/KSVISHCi/wDWW5DgD6VCCEduKgkFI=
Address = 10.0.0.1/32, fc00:bbbb:bbbb:0:0:0:0:1/128
DNS = 10.64.0.1

[Peer]
PublicKey = iqZSgVlU9H67x/uYE5xsnzLCDXf7FL9iMfyKfl6WsV8=
AllowedIPs = 0.0.0.0/0, ::0/0
Endpoint = 95.173.193.232:46906
PersistentKeepalive = 15

Mullvad device.json:

{
  "logged_in": {
    "account_number": "",
    "device": {
      "id": "",
      "name": "obscura key",
      "wg_data": {
        "private_key": "eNZ0Lr3jpE18o/KSVISHCi/wDWW5DgD6VCCEduKgkFI=",
        "addresses": {
          "ipv4_address": "10.0.0.1/32",
          "ipv6_address": "fc00:bbbb:bbbb:0:0:0:0:1/128"
        },
        "created": "1970-01-01T00:00:00.000000000Z"
      },
      "hijack_dns": false,
      "created": "1970-01-01T00:00:00Z"
    }
  }
}

The name has no effect in this case, it's just what you see in the app. If the other fields matter, I don't know. I left them as they were.

Now you can once again start mullvad-daemon.

sudo systemctl start mullvad-daemon

You should now be able to connect to servers just as usual. But we have yet to add the Obscura server. The account page won't work, as there's no account.

Following the example above, we add an IP override for our exit node:

mullvad relay override set ipv4 ca-tor-wg-002 95.173.193.232

Lastly, we need to use the correct port. As per our example, in Mullvad app go to Settings -> VPN Settings -> Anti-censorship -> Wireguard port -> Custom -> enter 46906

Thankfully, these ports are also valid for Mullvad, so no extra switching will be needed.
You should now be able to connect to the Mullvad exit node via Obscura server, with Obscura account.

Multi-hop within Mullvad (a 3rd hop)

As the port for Obscura's server matters, we can only use it as an entry node. But yes, you can do that too.

Hopping madness

There's no point, but it's possible.
The Mullvad SOCKS5 will allow for, yes, a 4th hop.

And you can add TOR, for 7 hops (to regular sites)

What does that do? From this:

All the way to network quality of your teammates:

 

I don't know if it fits, but I find it interesting.
First of all, some banks have their own payment methods for online payments, and this is one of them. You may encounter it as alternative to VISA/MasterCard on some e-shops, for example when buying a train ticket at ZSSK.

With an app, you just scan QR code and send the payment.

But, what if I want to do it without an app?

On the left is first major step. Log in with PID + Password + OTP.
And the OTP is when this reader comes into play. Insert card, select code, enter PIN, and re-type the response into the website.

On the right is the second major step, confirming the payment. Ok, you already proved you own the card, so... but anyway.
Select "payment" by repeatedly pressing menu button, enter PIN, amount, recipient account number, and confirm with response.

Probably too annoying if you actually need to use it, but I find it interesting that there's extra hardware for this purpose.

 

A thought I genuinely had in shower. "Huh, the water is basically heated using uranium through a proxy."

view more: next ›