GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Grumpy Website (grumpy_website@mastodon.online)'s status on Monday, 04-May-2026 00:21:35 JST Grumpy Website Grumpy Website

    The fact the I plugged in a physical cable in my physical computer physically is a pretty good indicator that I kinda want to, no? Also that I’ve been using this device for about ten years?

    #Apple #macOS #Popup

    In conversation about 5 months ago from mastodon.online permalink

    Attachments


    1. https://files.mastodon.online/media_attachments/files/116/511/065/074/044/622/original/b71f013c7d86bc21.png
    • Embed this notice
      Aleksander (aleksanderjess@mastodon.social)'s status on Monday, 04-May-2026 00:21:33 JST Aleksander Aleksander
      in reply to

      @grumpy_website the system only enables the trackpad after you consent to it. How would the system know if it's malicious? If it's a bit much or not, idk, but it's a security measure and the annoyance does have a point.

      In conversation about 5 months ago permalink
    • Embed this notice
      Niki Tonsky (nikitonsky@mastodon.online)'s status on Monday, 04-May-2026 00:21:33 JST Niki Tonsky Niki Tonsky
      in reply to
      • Aleksander

      @aleksanderjess you said OS is protecting me, but now you are saying it doesn’t know if it’s malicious or not. So how exactly is it protecting? What is a scenario when a person plugs trackpad to a macbook, sees this window and chooses to press “Don’t connect”?

      In conversation about 5 months ago permalink
    • Embed this notice
      Aleksander (aleksanderjess@mastodon.social)'s status on Monday, 04-May-2026 00:21:34 JST Aleksander Aleksander
      in reply to

      @grumpy_website yes, from that too.

      In conversation about 5 months ago permalink
    • Embed this notice
      Grumpy Website (grumpy_website@mastodon.online)'s status on Monday, 04-May-2026 00:21:34 JST Grumpy Website Grumpy Website
      in reply to
      • Aleksander

      @aleksanderjess And how is that protection working? If my trackpad turns malicious, would that window contain something else?

      In conversation about 5 months ago permalink
    • Embed this notice
      Aleksander (aleksanderjess@mastodon.social)'s status on Monday, 04-May-2026 00:21:35 JST Aleksander Aleksander
      in reply to

      @grumpy_website might be wrong but it could be macOS protecting you.

      In conversation about 5 months ago permalink
    • Embed this notice
      Grumpy Website (grumpy_website@mastodon.online)'s status on Monday, 04-May-2026 00:21:35 JST Grumpy Website Grumpy Website
      in reply to
      • Aleksander

      @aleksanderjess from my own trackpad?

      In conversation about 5 months ago permalink
    • Embed this notice
      GK (gklka@mastodon.social)'s status on Monday, 04-May-2026 00:23:58 JST GK GK
      in reply to

      @grumpy_website USB connection can happen without physical plug in, and in this case your computer is vulnerable. This requester makes sense.

      In conversation about 5 months ago permalink
    • Embed this notice
      Niki Tonsky (nikitonsky@mastodon.online)'s status on Monday, 04-May-2026 00:23:58 JST Niki Tonsky Niki Tonsky
      in reply to
      • GK

      @gklka maybe only show this window then?

      In conversation about 5 months ago permalink
    • Embed this notice
      Niki Tonsky (nikitonsky@mastodon.online)'s status on Monday, 04-May-2026 00:25:48 JST Niki Tonsky Niki Tonsky
      in reply to
      • Aleksander

      @aleksanderjess If I plug a simple USB drive and I see a window saying “Allow accessory to connect” I’ll choose no? Why? It’s basically is relying on “I am dumb enough to plug a drive I found on a parking lot but smart enough to click Cancel in a dialog that pops up immediately after that”. I feel like if you choose plug shit like this you’ll click through any window

      In conversation about 5 months ago permalink
    • Embed this notice
      Aleksander (aleksanderjess@mastodon.social)'s status on Monday, 04-May-2026 00:25:49 JST Aleksander Aleksander
      in reply to
      • Niki Tonsky

      @nikitonsky when you connected a simple USB drive, and you saw that instead.

      In conversation about 5 months ago permalink
    • Embed this notice
      Niki Tonsky (nikitonsky@mastodon.online)'s status on Monday, 04-May-2026 00:27:06 JST Niki Tonsky Niki Tonsky
      in reply to
      • D:\side\>:idle:
      • Aleksander

      @dside @aleksanderjess yeah that window says “Accessory” and a flash drive is definitely an accessory

      In conversation about 5 months ago permalink
    • Embed this notice
      ARGVMI~1.PIF (argv_minus_one@mastodon.sdf.org)'s status on Monday, 04-May-2026 00:27:07 JST ARGVMI~1.PIF ARGVMI~1.PIF
      in reply to
      • D:\side\>:idle:
      • Aleksander

      @dside

      Then the message needs an explainer. Maybe something like “This device claims to be a keyboard. It's probably fine, but there have been cases of malicious devices claiming to be keyboards, then typing in commands to take over your computer when you plug them in. Do you trust this device, or shall I ignore its keystrokes?”

      @grumpy_website @aleksanderjess

      In conversation about 5 months ago permalink
    • Embed this notice
      D:\side\>:idle: (dside@mastodon.ml)'s status on Monday, 04-May-2026 00:27:10 JST D:\side\>:idle: D:\side\>:idle:
      in reply to
      • Aleksander

      @grumpy_website @aleksanderjess that might be a response to BadUSB[0]. In your specific case it could be something else spoofing a trackpad's device ID. If you plugged in a flash drive and see *that* – sound the alarm.

      In either case, the window should probably offer more context than that.

      [0]: https://en.wikipedia.org/wiki/BadUSB

      In conversation about 5 months ago permalink

      Attachments


      1. Domain not in remote thumbnail source whitelist: upload.wikimedia.org
        BadUSB
        BadUSB is a computer security attack using USB devices that are programmed with malicious software. For example, USB flash drives can contain a programmable Intel 8051 microcontroller, which can be reprogrammed, turning a USB flash drive into a malicious device. This attack works by programming the fake USB flash drive to emulate a keyboard. Once it is plugged into a computer, it is automatically recognized and allowed to interact with the computer. It can then initiate a series of keystrokes which open a command window and issue commands to download malware. The BadUSB attack was first revealed during a Black Hat talk in 2014 by Karsten Nohl, Sascha Krißler and Jakob Lell. Two months after the talk, other researchers published code that can be used to exploit the vulnerability. In 2017, a dongle called USG was released, to prevent BadUSB style attacks by acting like a hardware firewall. Criminal usage In March 2020, the FBI issued a warning that members of the FIN7 cybercrime group had been targeting companies in the retail, restaurant, and hotel industries with BadUSB attacks designed to deliver REvil or BlackMatter...
    • Embed this notice
      Niki Tonsky (nikitonsky@mastodon.online)'s status on Monday, 04-May-2026 01:36:48 JST Niki Tonsky Niki Tonsky
      in reply to
      • GK

      @gklka Lol, Apple? They wouldn’t lift a finger

      In conversation about 5 months ago permalink
    • Embed this notice
      GK (gklka@mastodon.social)'s status on Monday, 04-May-2026 01:36:49 JST GK GK
      in reply to
      • Niki Tonsky

      @nikitonsky I believe if they could they would.

      In conversation about 5 months ago permalink
    • Embed this notice
      Niki Tonsky (nikitonsky@mastodon.online)'s status on Tuesday, 05-May-2026 21:02:24 JST Niki Tonsky Niki Tonsky
      in reply to
      • GK

      @gklka on the topic https://www.bugsappleloves.com/

      In conversation about 5 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Bugs Apple Loves
        Bugs Apple won't fix. Why else would they keep them around for so long? We did the math.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.