GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by q3k :blobcatcoffee: (q3k@social.hackerspace.pl), page 2

  1. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Sunday, 05-Jan-2025 02:49:23 JST q3k :blobcatcoffee: q3k :blobcatcoffee:

    Thanks to __gsch's S5Late exploit, the wInd3x tool can now boot RetailOS with signature checks disabled.

    Which means you can now do 1337 h4xx0r sh1t like edit strings and whatnot. Or, you know, come help us port U-Boot and Linux :).

    https://github.com/freemyipod/wInd3x/?tab=readme-ov-file#cfw

    In conversation about 6 months ago from social.hackerspace.pl permalink

    Attachments


    1. https://object.ceph-waw3.hswaw.net/mastodon-prod/media_attachments/files/113/771/069/141/579/300/original/3820de61232b8c05.png
  2. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Tuesday, 31-Dec-2024 05:29:23 JST q3k :blobcatcoffee: q3k :blobcatcoffee:

    If you've been at the #38c3 Onion Cluster assembly, or we've otherwise met in person around congress, get tested for Covid-19 ASAP.

    There has been at least two positive antigen test results, one from me, one from someone else at the assembly cluster.

    In conversation about 6 months ago from social.hackerspace.pl permalink
  3. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Monday, 30-Dec-2024 19:57:10 JST q3k :blobcatcoffee: q3k :blobcatcoffee:

    You have free access to GitHub Copilot

    In conversation about 6 months ago from social.hackerspace.pl permalink
  4. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Saturday, 28-Dec-2024 04:09:20 JST q3k :blobcatcoffee: q3k :blobcatcoffee:
    in reply to

    We are very grateful and honoured to now also be supported by the Chaos Computer Club.

    Incidentally, our talk about the legal repercussions of disclosing the Impuls train DRM system is in less than 4 hours. There might not be many new technical things to talk about, but I'm sure at least some of you will find our story interesting. Especially as we haven't done much of an update in English since last year.

    Watch the talk on https://media.ccc.de/ at 23:00 CET.

    In conversation about 6 months ago from social.hackerspace.pl permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: static.media.ccc.de
      media.ccc.de - home
      Video Streaming Portal des Chaos Computer Clubs
  5. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Saturday, 28-Dec-2024 04:09:13 JST q3k :blobcatcoffee: q3k :blobcatcoffee:

    “The Chaos Computer Club supports the three hackers who explained in detail at 37C3 how the Polish rail vehicle manufacturer Newag had manipulated its trains in such a way that they could only be repaired in the company's own workshops. The manufacturer reacted to the publications with an attitude not seen since the 90s and sued the hackers under both criminal and civil law.

    The CCC is calling for donations to cover the legal and other resulting costs incurred so far.”

    https://www.ccc.de/en/updates/2024/das-ist-vollig-entgleist

    In conversation about 6 months ago from social.hackerspace.pl permalink

    Attachments


    1. https://object.ceph-waw3.hswaw.net/mastodon-prod/media_attachments/files/113/726/227/526/474/918/original/ddba247c03f4c0e1.png
  6. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Tuesday, 08-Oct-2024 21:11:21 JST q3k :blobcatcoffee: q3k :blobcatcoffee:

    I don't know if this is CVE-2024-41585, but this is how I've been getting code exec on my DrayTek Vigor 167 for custom firmware [1] research:

    https://gist.github.com/q3k/46f75dd78b653369640efaa2295f7ecd

    I wouldn't say post-auth code execution on a device you own is a security vulnerability (good network hardware vendors just ship this as a feature), so I never bothered publishing this before.

    This is so trivial I'm sure dozens of other people have been using this, too.

    [1] - https://github.com/q3k/vraytekdigor .

    In conversation about 9 months ago from social.hackerspace.pl permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      GitHub - q3k/vraytekdigor: Experimental custom firmware build infrastructure for Draytek Vigor 167 modem
      Experimental custom firmware build infrastructure for Draytek Vigor 167 modem - q3k/vraytekdigor
  7. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Thursday, 29-Aug-2024 00:42:36 JST q3k :blobcatcoffee: q3k :blobcatcoffee:

    ✅ Attend a legal hearing about train hacking
    ✅ Wait for defense attorney stuck in train for hours because of a railway incident
    ✅ Get in a road collision on the way back from the court (we're fine)

    certainly one of the most days

    In conversation about 10 months ago from social.hackerspace.pl permalink
  8. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Tuesday, 27-Aug-2024 04:19:47 JST q3k :blobcatcoffee: q3k :blobcatcoffee:
    in reply to

    I'd attach Newag's logo to this post for illustrative purposes, but we don't want to be sued for that too. Instead I'm attaching a symbolic representation of their logo as drawn from my memory.

    In conversation about 10 months ago from social.hackerspace.pl permalink
  9. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Tuesday, 27-Aug-2024 04:19:22 JST q3k :blobcatcoffee: q3k :blobcatcoffee:
    in reply to

    The hearing will take place in the 22nd Department of Intellectual Property at Czerniakowska 100 in Warsaw. To those interested are invited to observe on site as audience members, you can refer to the hearing number XXII GW 493/24. Of course, the hearing will be in Polish.

    In conversation about 10 months ago from social.hackerspace.pl permalink
  10. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Tuesday, 27-Aug-2024 04:19:21 JST q3k :blobcatcoffee: q3k :blobcatcoffee:
    in reply to

    We would like to take this opportunity to thank everyone for the massive support we've received so far - especially to the Security Research Legal Defense Fund and other organizations that we're slowly organizing a crowdfunding campaign to cover our legal costs. But even more so, we'd like to thank each and every one of you who keeps reminding us that we're fighting the good fight. Finally, we want to especially thank our attorney, Zbigniew Krüger, who represents us in this bonkers lawsuit.

    In conversation about 10 months ago from social.hackerspace.pl permalink
  11. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Tuesday, 27-Aug-2024 04:18:53 JST q3k :blobcatcoffee: q3k :blobcatcoffee:

    Just two days left until the first hearing in Newag's lawsuit against us (Dragon Sector members) and SPS. It will take place on 28.08.2024 at 10:00. In case you've missed it, we're being accused of infringing upon Newag's intellectual property and unfair competition. This is, of course, bullshit and a great example of a SLAPP case.

    In conversation about 10 months ago from social.hackerspace.pl permalink

    Attachments


    1. https://object.ceph-waw3.hswaw.net/mastodon-prod/media_attachments/files/113/029/054/594/724/923/original/dff41a3506609909.png
  12. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Saturday, 17-Aug-2024 10:01:53 JST q3k :blobcatcoffee: q3k :blobcatcoffee:
    in reply to

    And yes, it's 164 pages (plus likely thousands of pages of attachments). Part of it is of course the inherent verbosity of court paperwork, part of it is also the fact that they repeat everything for each defendant (and that's three of us + SPS), but a significant cause of it is also that the lawsuit is just pure babble. Is it a case of SLAPP? Maybe, definitely feels like one to me.

    We will of course fight this, and we're nowhere near being intimidated.

    In conversation about 10 months ago from social.hackerspace.pl permalink
  13. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Saturday, 17-Aug-2024 10:01:51 JST q3k :blobcatcoffee: q3k :blobcatcoffee:
    in reply to

    I originally tried to make an itemized list of their nonsense, but I ended up with 18 bullet points of bullshit that still made zero sense. It would be disrespectful to others to have them read that.

    So instead of that, here's a symbolic picture of the lawsuit as a whole: them quoting my own code to me as supposedly their IP. :)

    In conversation about 10 months ago from social.hackerspace.pl permalink

    Attachments



    1. https://object.ceph-waw3.hswaw.net/mastodon-prod/media_attachments/files/112/693/918/032/641/036/original/bcd3600f25462ad3.png
  14. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Saturday, 17-Aug-2024 10:00:08 JST q3k :blobcatcoffee: q3k :blobcatcoffee:

    Serious talk though.

    I think NEWAG is upset at us because it turns out a bunch of nerds is significantly better at public speaking and PR than anyone in their company that's paid to be good at this stuff.

    In conversation about 10 months ago from social.hackerspace.pl permalink
  15. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Thursday, 01-Aug-2024 20:42:45 JST q3k :blobcatcoffee: q3k :blobcatcoffee:
    in reply to
    • Sos Sosowski

    @sos @siguza Thanksfully this isn't a legal text ready to be ratified, it's the outline of a petition that, if it gathers enough votes, enables the proposers to engage in a bilateral dialog with the EU commission.

    There's no sense in nitpicking wording at this stage, as the intent is quite clear, especially if you've been following the campaign all along.

    (see https://citizens-initiative.europa.eu/how-it-works_en )

    In conversation about 11 months ago from social.hackerspace.pl permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: citizens-initiative.europa.eu
      How it works
      How it works - a step by step guide to the European citizens' initiative (ECI)
  16. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Monday, 15-Jul-2024 09:36:51 JST q3k :blobcatcoffee: q3k :blobcatcoffee:
    in reply to
    • Obot 50549535 🌺

    @obot50549535 This is surface mount (QFN; edit: actually DFN). You can just reflow it.

    If you're very bored (and hate yourself the exact right amount to do this without optical magnication), you can also dead bug it :).

    In conversation about a year ago from social.hackerspace.pl permalink

    Attachments


    1. https://object.ceph-waw3.hswaw.net/mastodon-prod/media_attachments/files/112/089/419/513/143/952/original/ae5b55a9f8a6cd8d.png
  17. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Monday, 15-Jul-2024 09:36:08 JST q3k :blobcatcoffee: q3k :blobcatcoffee:
    in reply to

    Also this thing runs at 1.7V - 5.5V Vcc. Bonkers.

    In conversation about a year ago from social.hackerspace.pl permalink
  18. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Monday, 01-Jul-2024 16:16:55 JST q3k :blobcatcoffee: q3k :blobcatcoffee:

    It's finally happened! NEWAG IP Management just sued us for copyright infringement and unfair competition. This is a civil lawsuit in Warsaw, parallel to a criminal investigation that's happening in Cracow.

    Of course, they got our postal addresses wrong (they could've just asked!) so we only just got a copy from the court, but hey, we now have 164 pages of content to dive into.

    In conversation about a year ago from social.hackerspace.pl permalink

    Attachments


    1. https://object.ceph-waw3.hswaw.net/mastodon-prod/media_attachments/files/112/693/884/226/767/500/original/d93f85633fc05e07.png
  19. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Saturday, 22-Jun-2024 00:18:16 JST q3k :blobcatcoffee: q3k :blobcatcoffee:
    in reply to
    • Wolf480pl

    @wolf480pl ... if only there was a universally present, globally unique identifier that could be used to track network devices across bus swaps!

    In conversation about a year ago from social.hackerspace.pl permalink
  20. Embed this notice
    q3k :blobcatcoffee: (q3k@social.hackerspace.pl)'s status on Saturday, 22-Jun-2024 00:18:14 JST q3k :blobcatcoffee: q3k :blobcatcoffee:
    in reply to
    • Wolf480pl
    • artemist

    @artemist @wolf480pl What I would like (and I don't mean to sound like some kind of RETVRN TO DEVUAN freak) is the oldschool way of using kernel enumeration as a base (eth0, eth1, usb0, etc), and then pinning it statefully to MAC in userspace.

    I know it's not great for us NixOS folks, but there we could just declaratively pin interface names to MAC via nixos-generate-config. Effectively the same behaviour.

    In conversation about a year ago from gnusocial.jp permalink
  • After
  • Before

User actions

    q3k :blobcatcoffee:

    q3k :blobcatcoffee:

    Documenting the hyperfocus episodes of a soul stuck between hardware and software. THIS CONTENT IS PROVIDED BY THE AUTHOR "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          88259
          Member since
          14 Jan 2023
          Notices
          56
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.