Post B5tHjpBXvpS26D4QwS by mangeurdenuage@shitposter.world
(DIR) More posts by mangeurdenuage@shitposter.world
(DIR) Post #B5t5PYYspTmTIgYU88 by icon_of_computational_sin@mstdn.starnix.network
0 likes, 2 repeats
From: https://lowlevel.fun/posts/tiny-udp-cannon-android-vpn-bypass/The fact that this pretty stupid VPN circumvention exists isn't a big surprise, given how bloated and over-engineered Android (and probably any other L'Eunuchs system) is. The surprising part is these words here:Asked If I am free to discloseWith some uncanny rituals, not at all dissimilar from cults or MLM schemes, big tech corpos have managed to guilt trip a huge crowd of nerds that said corpos are owed the honour of being asked permission to do things. Not because these nerds are paid to do this--most bug bounty programs offer scraps, you can sell these 0days and other secrets to Mossad or CIA for 10x the amount--but because it's somehow "ethical". In quotation marks, because nobody can even tell what ethics system here is usually referred to (deontologists can suck a dingus). All while the same corpos have NO WARRANTY clauses in every single software licence they employ, even in EULAs. And where this isn't possible, they limit the maximum possible compensation to a laughable sum.Remember, boys and girls. You don't owe corpos anything. And you certainly owe their customers even less than that. Full and immediate disclosure is the only way. Let them deal with the consequences of pushing shit code into prod, this isn't your problem.SEE SOMETHING, SAY SOMETHING
(DIR) Post #B5t7v89Ykb0aZStSrI by phnt@fluffytail.org
0 likes, 0 repeats
@icon_of_computational_sin >Let them deal with the consequences of pushing shit code into prod, this isn't your problem.As I've said on IRC, you only say this because you don't have to deal with the chaos and panic in the aftermath of disclosing high severity issues before a fix is released. You never had to sit down and try to figure out which of your possibly hundreds or thousands of systems is affected and how to fix it.
(DIR) Post #B5t7v8O5sYdPIXh4Vs by icon_of_computational_sin@mstdn.starnix.network
1 likes, 0 repeats
@phnt you might think so, but it was you who deployed vulnerable software from an untrustworthy vendor. Yes, you. You put your trust in a corporation that leaks (or worse, sells for profit) data left and right, hires subpar engineers, reluctantly spends pocket change on QA, and in a normal world wouldn't be trusted with candy. So called "ethical disclosure" only upholds this status quo of you and your kin pretending everything is fine. It's not fine. It hasn't been fine for a long time now. Full disclosure only reveals this very uncomfortable fact.
(DIR) Post #B5t8bNeHWqkOnAPTqy by phnt@fluffytail.org
0 likes, 0 repeats
@icon_of_computational_sin Fully trustworthy vendor and non-vulnerable software does not exist. The world you are thinking of isn't real, for many things are you stuck with some vendor and or some other vendor and that's it. You either use that or you can build your own, which usually results in something even worse.Or are you running an OS along with the whole userspace on our computer that has been mathematically proven do that what it says it does without error?
(DIR) Post #B5t8bNoutJFpK9NyQi by mangeurdenuage@shitposter.world
0 likes, 0 repeats
@phnt @icon_of_computational_sin >Fully trustworthy vendor and non-vulnerable software does not exist. That's not the point. The point is transparency that you aren't a piece of scum that leaches out your customers and wish to provide actual problem solving.> The world you are thinking of isn't real,So is the one you describe.>for many things are you stuck with some vendor and or some other vendor and that's itYes and when did you start to work to counter that bs ?Right now I have work so that a city hall can migrate to GNU/linux and they're stuck because they use a SaaSS that requires hard dependency to windows while it's all in a fucking browser.Short them solution: vm microslop to mitigate.Long term: changing software.Longer term: lobby representatives.>or you can build your own, which usually results in something even worse.Worse than default win11 and passwords being 123456 level ?
(DIR) Post #B5t8fOuWmKh5revTFI by bonifartius@noauthority.social
0 likes, 0 repeats
@icon_of_computational_sin > First, nobody checks the payload is actually a QUIC CONNECTION_CLOSE frame. The bytes are whatever you want. who comes up with these ideas.
(DIR) Post #B5t8fPMX6D5zGW1ptg by mangeurdenuage@shitposter.world
0 likes, 0 repeats
@bonifartius @icon_of_computational_sin Probably someone who though "this is practical".
(DIR) Post #B5t96rAfoauLKbZOi0 by phnt@fluffytail.org
0 likes, 0 repeats
@mangeurdenuage @icon_of_computational_sin Btw, the context for this thread is Copy Fail on irc.nishi.boats.It's about trusting Linux and the broader ecosystem around it such as GNU. You cannot fully trust Linux nor GNU as vendor, because you cannot fully audit and prove it.
(DIR) Post #B5t96rOUzBy01U2RG4 by mangeurdenuage@shitposter.world
0 likes, 0 repeats
@phnt @icon_of_computational_sin Yes I'm aware of it. I posted about it previous to this post.>You cannot fully trust Linux nor GNU as vendor, because you cannot fully audit and prove it.Fallacious reasoning. Thank you for the bait. Please go kill yourself.
(DIR) Post #B5tB6TPuKguNZDdmU4 by phnt@fluffytail.org
0 likes, 0 repeats
@mangeurdenuage @icon_of_computational_sin >Fallacious reasoning. Thank you for the bait. Please go kill yourself.lol, lmao even. :puniko_laugh:
(DIR) Post #B5tB6TcJaYpiBhRgp6 by mangeurdenuage@shitposter.world
0 likes, 0 repeats
@phnt @icon_of_computational_sin You know feeding your ego from negative shit like this isn't healthy for you.
(DIR) Post #B5tEUk1uW94Pu5gCZM by lain@lain.com
0 likes, 0 repeats
@phnt @icon_of_computational_sin @mangeurdenuage wiat linux is now something i'm not allowed to install unless i want to get punched in the face?
(DIR) Post #B5tHdZJc1TMP8rrOe8 by phnt@fluffytail.org
0 likes, 0 repeats
@mangeurdenuage @icon_of_computational_sin I'm stating the reality, nobody can fully audit GNU corelibs/gcc/glibc/and friends because they are way too huge for that. You will always have to live with a possibility that a vulnerability will exist in these pieces of software, similarly to Linux, because they are simply too big to be fully correct.The truth that free software/open-source software gives you better security, because you don't need to disassemble it and/or do weird behavior analysis, is only truth to a certain extent.
(DIR) Post #B5tHdZUbMc9Pgx0Am8 by mangeurdenuage@shitposter.world
0 likes, 0 repeats
@phnt @icon_of_computational_sin What is a The big ball of mud paper.pdf.What is the art of software destructibilityhttps://max.hn/favorites/talks/programming/the-art-of-destroying-software/.>The truth that free software/open-source software gives you better security, because you don't need to disassemble it and/or do weird behavior analysis, is only truth to a certain extent.Yes it's not a black box.But it's more than that.You only look at the security aspect of the tools.Tools are much more than just that.
(DIR) Post #B5tHjp0uZMwbZE5wMi by icon_of_computational_sin@mstdn.starnix.network
0 likes, 0 repeats
@phnt @mangeurdenuage all it means is that glibc/gcc/whatever need to be killed with fire like the atrocious disgrace of engineering that they are. Same goes for Linux.Actually, it is possible to build secure systems that incorporate Linux. This has been done numerous times and involves isolating different application domains with paravirtualised kernels. A tad bit harder than installing Booboontu or RHELL and calling it a day.
(DIR) Post #B5tHjpBXvpS26D4QwS by mangeurdenuage@shitposter.world
0 likes, 0 repeats
@icon_of_computational_sin @phnt Depends on your adversaries.
(DIR) Post #B5tO50xFy30APLsFBQ by icon_of_computational_sin@mstdn.starnix.network
0 likes, 0 repeats
@mangeurdenuage @phnt Don’t try to plan for future changes. Focus on the ability to completely rewrite everything from scratch when that change actually occurs.I'm not exactly sure this guy is sane or that his advice on software is to be taken seriously.
(DIR) Post #B5tO51Eyu9BDIKAOoK by mangeurdenuage@shitposter.world
0 likes, 0 repeats
@icon_of_computational_sin @phnt It's the same thing that has been repeated since the 80s smalltalk etc..