GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    billiam :4chan: (billiam@shitposter.club)'s status on Wednesday, 19-Jul-2023 05:56:01 JST billiam :4chan: billiam :4chan:
    interesting privacy vulnerability on Windows (be careful opening zipped folders)
    https://boards.4channel.org/g/thread/94766106
    In conversation Wednesday, 19-Jul-2023 05:56:01 JST from shitposter.club permalink

    Attachments


    1. https://static.banky.club/shitposter.club/d395476fda8ad151c12a193091025d29d3977bec93b7309db106465d2583ba83.png?name=image.png
    2. No result found on File_thumbnail lookup.
      /g/ - >download a .zip file from Tor >extracts the .zip - Technology - 4chan
      >download a .zip file from Tor >extracts the .zip file without even inspecting the content first >it... - "/g/ - Technology" is 4chan's imageboard for discussing computer hardware and software, programming, and general technology.
    • narcolepsy and alcoholism :flag: likes this.
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Wednesday, 19-Jul-2023 05:56:58 JST Fediverse Contractor Fediverse Contractor
      in reply to
      What the heck is a “desktop ini canary token”?
      In conversation Wednesday, 19-Jul-2023 05:56:58 JST permalink
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Wednesday, 19-Jul-2023 06:06:37 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • meso
      This is exactly why I don’t download anything. Can this happen on mac?
      In conversation Wednesday, 19-Jul-2023 06:06:37 JST permalink
    • Embed this notice
      meso (meso@the.asbestos.cafe)'s status on Wednesday, 19-Jul-2023 06:06:38 JST meso meso
      in reply to
      • Fediverse Contractor
      @bot @billiam when you have a desktop.ini file in a folder in windows it can set an icon from a remote website and therefore make contact with it, logging your ip. clever
      In conversation Wednesday, 19-Jul-2023 06:06:38 JST permalink

      Attachments


      1. https://the.asbestos.cafe/media/d3dfd8f52a110ae249d6f6f8d4a95a9988a7a7bdb12fc8b5714587cfe09d125b.png
    • Embed this notice
      BowserNoodle ☦️ (bowsacnoodle@poa.st)'s status on Wednesday, 19-Jul-2023 06:23:48 JST BowserNoodle ☦️ BowserNoodle ☦️
      in reply to
      @billiam Feels like that should be preventable by literally opening the container and examining before extraction. PEBKAM issue.
      In conversation Wednesday, 19-Jul-2023 06:23:48 JST permalink
    • Embed this notice
      MMS21 :blobcatkirby: (mms21@seal.cafe)'s status on Wednesday, 19-Jul-2023 06:32:14 JST MMS21 :blobcatkirby: MMS21 :blobcatkirby:
      in reply to
      • Fediverse Contractor
      • KitlerIs6"
      • meso
      Does CIA developer mean anything when the entire software is open source
      In conversation Wednesday, 19-Jul-2023 06:32:14 JST permalink
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Wednesday, 19-Jul-2023 06:32:14 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • MMS21 :blobcatkirby:
      • KitlerIs6"
      • meso
      Oh did you look at it?
      In conversation Wednesday, 19-Jul-2023 06:32:14 JST permalink
    • Embed this notice
      KitlerIs6" (kitleris6@seal.cafe)'s status on Wednesday, 19-Jul-2023 06:32:15 JST KitlerIs6" KitlerIs6"
      in reply to
      • Fediverse Contractor
      • meso
      >use CIA designed browser with a glorified VPN built in to download files
      >no vpn on the rest of your system
      lol
      In conversation Wednesday, 19-Jul-2023 06:32:15 JST permalink
    • Embed this notice
      KitlerIs6" (kitleris6@seal.cafe)'s status on Wednesday, 19-Jul-2023 20:15:35 JST KitlerIs6" KitlerIs6"
      in reply to
      • Fediverse Contractor
      • MMS21 :blobcatkirby:
      • meso
      Basically this. Also even if something is open source and doesn't *look* shady, that doesn't mean there's not an intentional backdoor or vulnerability obscured somewhere in the code. Just prevents and obvious one from existing.
      In conversation Wednesday, 19-Jul-2023 20:15:35 JST permalink
    • Embed this notice
      MMS21 :blobcatkirby: (mms21@seal.cafe)'s status on Wednesday, 19-Jul-2023 20:15:35 JST MMS21 :blobcatkirby: MMS21 :blobcatkirby:
      in reply to
      • Fediverse Contractor
      • KitlerIs6"
      • meso
      The inner workings aren’t hidden away and there’s a whole bunch of info including a white paper on the tor protocol. I’ve yet to hear of a high profile case which wasn’t solved due to bad opsec.
      In conversation Wednesday, 19-Jul-2023 20:15:35 JST permalink
      翠星石 likes this.
    • Embed this notice
      MMS21 :blobcatkirby: (mms21@seal.cafe)'s status on Wednesday, 19-Jul-2023 20:21:41 JST MMS21 :blobcatkirby: MMS21 :blobcatkirby:
      in reply to
      • Fediverse Contractor
      • KitlerIs6"
      • meso
      Is it even possible to patch? Seems a reoccurring thing in many places too e.g. 51% attack in crypto, voting systems and p2p
      In conversation Wednesday, 19-Jul-2023 20:21:41 JST permalink
    • Embed this notice
      翠星石 (suiseiseki@freesoftwareextremist.com)'s status on Wednesday, 19-Jul-2023 20:21:41 JST 翠星石 翠星石
      in reply to
      • MMS21 :blobcatkirby:
      • KitlerIs6"
      @MMS21 @KitlerIs6 >Is it even possible to patch? Seems a reoccurring thing in many places too e.g. 51% attack in crypto, voting systems and p2p
      It's impossible to patch, but Tor has been designed to mitigate such attacks as much as possible.

      When it comes to consensus, as sadly no reliable distributed consensus mechanism exists, so Tor uses a select few dedicated servers for consensus handled by trusted parties (you can also run your own consensus servers if you're unhappy with the default).

      BadExits and attacking relays are constantly search for and removed from the network as well.

      The NSA have admitted among themselves that "Tor stinks", as they can't spy on every user, all the time, even with all the traffic interception and MiTM capabilities they have.


      I'd like to note that my Tor relay running 100% free software certainly isn't compromised by proprietary software.
      In conversation Wednesday, 19-Jul-2023 20:21:41 JST permalink
    • Embed this notice
      KitlerIs6" (kitleris6@seal.cafe)'s status on Wednesday, 19-Jul-2023 20:21:42 JST KitlerIs6" KitlerIs6"
      in reply to
      • Fediverse Contractor
      • MMS21 :blobcatkirby:
      • meso
      There's the 50% attack vulnerability that's never been patched.
      In conversation Wednesday, 19-Jul-2023 20:21:42 JST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.