ironsoap

joined 1 year ago
[–] [email protected] 1 points 1 month ago

Glad the MLS is no longer used.

[–] [email protected] 6 points 1 month ago

Good write up!

[–] [email protected] 0 points 1 month ago (1 children)

What's the privacy criteria you are thinking about?

[–] [email protected] 1 points 1 month ago

A brief technical summary from iMAP reveals what happens when users attempt to access sites using Cloudflare and Google DNS.

• On Maxis, DNS queries to Google Public DNS (8.8.8.8) servers are being automatically redirected to Maxis ISP DNS Servers;

**

• On Time, DNS queries to both Google Public DNS (8.8.8.8) and Cloudflare Public DNS (1.1.1.1) are being automatically redirected to Time ISP DNS servers.

“Instead of the intended Google and Cloudflare servers, users are being served results from ISP DNS servers. In addition to MCMC blocked websites, other addresses returned from ISP DNS servers can also differ from those returned by Google and Cloudflare,” iMAP warns.

...

"Users that are affected, can configure their browser settings to enable DNS over HTTPS to secure their DNS lookups by using direct encrypted connection to private or public trusted DNS servers. This will also bypass transparent DNS proxy interference and provide warning of interference,” iMAP concludes.

Essentially Malaysia law required ISP to drop DNS entries for some sites, local users started using public DNS. ISP started redirecting public DNS requests, and local users started using DNS over HTTPS.

The pirate wars continue in their arms races.

[–] [email protected] 1 points 1 month ago (1 children)

Should have remembered they do an English version. Thanks!

It was noted that more than half of the KN-23 missiles lost their programmed flight trajectory during flight and likely exploded in the air, as the launches of these missiles were recorded, but their debris was not found.

[–] [email protected] 2 points 1 month ago (3 children)

Translated sources beyond Google?

 

Rostov-on-Don hit again? Anyone have links to visuals?

 

Trump has the magic touch to juice turnout and excite Republicans in a way that his imitators do not. In 2018 and 2022, the two elections in the Trump era when the head honcho was not on the ballot, pro-Trump Republican candidates did poorly, running below expectations and losing winnable races. Meanwhile, even when Trump lost in 2020, he overperformed in public polling.

It’s an interesting puzzle: Many of Trump’s ideas are largely unpopular with voters; without his charisma, his ideological allies are left with policy positions like abortion bans that most Americans don’t really like. It’s Trump’s personality that keeps him happily ensconced at the head of the party.

The result is that candidates like Vance up and down state ballots try to build on Trump’s political legacy without being able to capture his personal one.

[–] [email protected] 10 points 2 months ago (1 children)

What in the world are they digging for?

[–] [email protected] 4 points 2 months ago

Potato Achieved!

[–] [email protected] 4 points 3 months ago

Lines Boeing does not want on it's investor reports, especially after the FAA has been hounding them.

** June 6, 1:27 p.m. ET: ** Starliner’s docking has not gone smoothly, the spacecraft developed trouble with its reaction control system thrusters.

[–] [email protected] 11 points 3 months ago (3 children)

If this request worked, it meant that I could use an “encryptedValue” parameter in the API that didn’t have to have a matching account ID.

I sent the request and saw the exact same HTTP response as above! This confirmed that we didn’t need any extra parameters, we could just query any hardware device arbitrarily by just knowing the MAC address (something that we could retrieve by querying a customer by name, fetching their account UUID, then fetching all of their connected devices via their UUID). We now had essentially a full kill chain.

I formed the following HTTP request to update my own device MAC addresses SSID as a proof of concept to update my own hardware:

...

Did it work? It had only given me a blank 200 OK response. I tried re-sending the HTTP request, but the request timed out. My network was offline. The update request must've reset my device.

About 5 minutes later, my network rebooted. The SSID name had been updated to “Curry”. I could write and read from anyone's device using this exploit.

This demonstrated that the API calls to update the device configuration worked. This meant that an attacker could've accessed this API to overwrite configuration settings, access the router, and execute commands on the device. At this point, we had a similar set of permissions as the ISP tech support and could've used this access to exploit any of the millions of Cox devices that were accessible through these APIs.

Blows me a away that an unauthenticated API with sensitive controls and data was publicly facing. Corporations these days want all your data but wonder why some customers are worry about how it is protected, it let alone if it's being sold. Why should I allow you to control my hardware when you can't protect yourself.

1
Reddit IPO in March (www.theguardian.com)
 

Reddit made an initial public offering filing with the Securities and Exchange Commission on Thursday ahead of its highly-anticipated stock market debut.

The social network plans to trade on the New York Stock Exchange under the ticker symbol “RDDT.” Its listing – expected in March – would be the largest IPO by a social media company since Pinterest went public in 2019.

How social media’s biggest user protest rocked Reddit

The number of shares to be offered and the price range for the proposed offering have not yet been determined, Reddit said in a statement.

The IPO filing revealed that Reddit sustained $90.8m in losses in 2023, as its revenue grew by roughly 21%. The business estimated that its US average revenue per user or ARPU, was $3.42 for the last quarter of 2023 – a decrease of 2% year over year...

 

Guyana's oil production is booming, and it's growing at an unprecedented pace, according to energy expert Dan Yergin.

"Guyana is very important because it is the fastest offshore oil development in the history of the world," he said in a CNBC interview on Monday.

Exxon Mobil and Chevron have both been expanding their footprints in the region. Exxon began production at its third project in Payara, Guyana, this year, bringing its total production capacity in the region to approximately 620,000 barrels per day.

And in October, Chevron signed a deal to acquire oil company Hess, with one big trophy of the agreement being a project off the coast of Guyana.

But long-simmering antagonisms between Guyana and its neighbor Venezuela have resurfaced recently, with Venezuela claiming a big chunk of Guyana's land.

"So far it's more bluster," Yergin said. "Nicolás Maduro, the dictator president of Venezuela, had this farcical referendum where maybe 10% of people voted claiming two thirds of Guyana. But what's really piqued his interest is offshore oil."

The flare-up should be taken seriously in the US, Yergin warned, as Maduro remains in a weak position with the country seeing a large refugee crisis.

That's after years of economic collapse have sent millions of Venezuelans fleeing the country, landing mostly in other part of Latin America.

"The risk is that he might do something, he might seize a piece of territory, plant a flag," he said. "And of course, you have to keep in mind that Maduro's close allies are Russia, Cuba, and increasingly, Iran."

For now, hostility between Venezuela and Guyana is more words than action, Yergin added.

In terms of geopolitics, the real threat to oil markets is in the Middle East, at the strait of Bab-el-Mandeb, which connects the Red Sea to the Gulf of Aden and the Indian Ocean.

That waterway sees about 9 million barrels of oil pass through every day, especially with Russian oil shifting south after Western sanctions were imposed.

Meanwhile, Houthi rebels in Yemen have declared they would target Israel-bound vessels that do not stop in Gaza to deliver humanitarian aid.

"The Houthis seem to feel that they're invincible, that they can attack US naval ships," Yergin said. "That's a thing to watch as a geopolitical factor that could affect [oil markets]."

 

Defence Blog Magazine Russia uses tactics of strategic deception DEFENSE & SECURITYNEWS By Dylan Malyasov Dec 7, 2023

In a geopolitical landscape dominated by shifting alliances and strategic maneuvering, the Russian approach to conflict resolution often veils ulterior motives. Despite calls for peace and temporary ceasefires, the Russian modus operandi seems rooted in exploiting diplomatic processes to buy time for economic recovery and military resurgence.

At present, while global attention is fixated on the Middle East, Moscow actively advocates for “peace talks” concerning Ukraine, enlisting partners from Turkey and the UAE.

Ukrainian intelligence has previously indicated Russia’s contemplation of freezing the conflict—a move that could grant Russia until 2028 to rebuild its military might, potentially expanding aggression beyond Ukraine to the Baltic states.

This practice of tactical maneuvers is not new for the Kremlin; Putin himself has adeptly manipulated public statements and actions. Drawing parallels, the Russian-Chechen conflict saw a similar pattern, dividing the bloody conflict into phases after significant losses suffered by Russian forces against local resistance. Initially aiming to annex the Chechen Republic of Ichkeria, Russia faced staunch opposition, leading to a divided conflict. Ultimately, the conflict resulted in the withdrawal of Russian forces and the preservation of Chechnya’s independence.

Post the Russian defeat in the first Chechen war, discontent brewed within Russian political circles, particularly the military, regarding the outcome. Concerns surfaced that the Chechen issue remained unresolved, setting a precedent for other national autonomies historically annexed by force.

To reinitiate hostilities, a formal pretext was utilized, purportedly combating non-governmental armed formations considered a terrorist threat. The second war proved more successful for Russia, primarily due to active targeting of civilian populations. Mass clearances of settlements resulted in substantial civilian casualties. Between 1999 and 2002, an estimated 16,000 lives were lost, a significant toll for the relatively small population of the republic.

Russia’s hybrid tactics extended beyond direct engagements. Signing agreements with other states, it employed proxies to destabilize regions, providing a formal pretext for resuming hostilities. This was evident in the 2008 Russo-Georgian war, where Russian intervention followed actions by South Ossetia and Abkhazia—regions under Russian influence—creating conflict with Georgia’s armed forces.

This intervention was preceded by formal appeals from the separatist groups of Abkhazia and South Ossetia to the Russian parliament for recognition. Simultaneously, Georgia proposed international peacekeeping forces in the separatist regions, prompting escalated Russian actions post-April 2008. Despite Western initiatives for peaceful resolutions, rejected by separatists and Russia, the conflict escalated into a full-scale war with Russian forces occupying significant Georgian territory, termed by Russian propaganda as “peace enforcement.”

Throughout history, Russia has demonstrated a pattern of ceasefire simulations only to resume conflicts under diverse pretexts. Understanding this historical context becomes imperative in assessing current geopolitical tensions and forecasting potential escalations in global security.

In a similar vein, the crisis in Ukraine unfolded along analogous lines when, employing their proxies and even involving, for the first time, the deployment of the private military company (PMC) “Wagner,” Russians gained control over Crimea and parts of eastern Ukraine. Notably, at that juncture, official Moscow distanced itself from Wagner and the separatist factions, labeling them as “little green men.”

Moscow and Putin consistently denied direct involvement in Ukraine. On March 4, 2014, Russian President Vladimir Putin asserted that the forces in Ukraine were not Russian Federation troops but rather “self-defense units” who acquired weapons from local Ukrainians. Simultaneously, media reports analyzing the armaments of the “little green men” revealed Russian weaponry.

It wasn’t until April 17, 2014, that Putin publicly acknowledged Russian military presence in Crimea. The direct involvement of state institutions in creating and managing the PMC “Wagner” was only acknowledged in 2023 during an attempted coup led by the group’s leader, Yevgeny Prigozhin, who subsequently perished in an explosion aboard his private plane over Russian territory.

Initially, the Kremlin denied the existence of the PMC “Wagner,” later referring to it as a “volunteer group” before eventually acknowledging its direct involvement. Putin personally confirmed Russia’s full support and provision of the private military company on June 27 during a meeting with the Ministry of Defense officials.

During the period from 2014 to February 2022, Ukraine pursued diplomatic avenues to resolve the conflict, resorting to ceasefire agreements, notably the Minsk Agreements. These agreements, signed by parties in the Normandy Format, involved Russia and Putin himself as negotiators. However, they were consistently violated, primarily by Wagner mercenaries and proxy forces controlled by the Russian Ministry of Defense.

The tenure of Russia under Putin’s leadership has been characterized by the use of clandestine hybrid tactics, propaganda, and a blatant disregard for international law and legal accountability. Adopting a modus operandi akin to organized crime syndicates, the Kremlin feigned agreement signings only to breach them using its hybrid forces. Furthermore, on the international stage, Moscow reneged, denounced, and terminated several crucial agreements concerning human rights, disarmament, and the prevention of global conflicts.

Therefore, the likelihood of Russia, under Putin’s helm, adhering steadfastly to its commitments in the future appears improbable. Expecting the Russian regime to acknowledge its mistakes and engage in talks to create a foundation for a long-term peaceful process might not align with its historical patterns.

Hence, it’s imperative not to don rose-colored glasses and anticipate that the Russian regime will concede its errors or engage in negotiations for the establishment of a prolonged peace process.

 

Bill Gates name-checked Elon Musk and Steve Jobs during a fireside chat on Thursday. The Microsoft founder said he considers himself "very nice" compared to his fellow tech leaders. But Gates acknowledged that a certain level of intensity is required in innovative fields. Bill Gates said he considers himself a more relaxed boss than many of his tech compatriots at the top.

The Microsoft founder name-checked Elon Musk and Steve Jobs during a fireside chat on Thursday after being awarded the Peter G. Peterson Leadership Excellence Award by the Economic Club of New York.

The talk's moderator asked Gates about the lessons he learned in creating a culture of innovation during his time at the helm of Microsoft.

The billionaire, who co-founded the technology company with his childhood friend Paul Allen in 1975, said leaders like himself have to think about how "hardcore" they should be when spearheading innovative companies.

"Everybody is different. Elon pushes hard, maybe too much," Gates said, referencing Musk. "Steve Jobs pushed hard, maybe too much."

"I think of myself as very nice compared to those guys," he added with a laugh.

Jobs co-founded Apple in 1976 with Steve Wozniak, while Musk is the founder and SpaceX and the Boring Company, and cofounder of OpenAI and Neuralink.

Gates has a checkered history with both men. He and Jobs nursed a decades-long love-hate relationship, going from allies to rivals and back again several times. Their back-and-forth competitive spirit is often credited with spurring major innovations at both Microsoft and Apple over the years.

Steve Jobs Bill Gates Steve Jobs and Bill Gates. Beck Diefenbach/Reuters; Mike Cohen/Getty Images for The New York Times

After Jobs died in 2011, Gates said he respected the Apple founder and was grateful for their competition.

The philanthropist's relationship with Musk has been even more turbulent in recent years. The two men have publicly poked at each other and frequently disagree on everything from space travel to climate change.

Gates told Musk's biographer, Walter Isaacson, that the Tesla CEO was "super mean" to him in 2022.

"Once he heard I'd shorted the stock, he was super mean to me, but he's super mean to so many people, so you can't take it too personally," Gates told Isaacson.

But Gates acknowledged during the Thursday discussion that a "certain intensity" is required to succeed as an innovative leader.

"In my 20s, I was monomaniacally focused on Microsoft," he said. "I didn't believe in weekends or vacations.'

The moderator asked Gates to confirm an urban legend that has circulated in recent years in which the billionaire memorized all of his employees' license plates during the early days of Microsoft so he could track who was putting in long hours at work.

"It wasn't that many license plates. We only had a few hundred employees," Gates said, seemingly confirming the tale.

"I can still tell you when they came in and out," he added.

Gates cites his intensity with the "positive experience" he had at Microsoft, which he said still guides his thinking today.

"I view every problem through this innovation lens," he said.

 

"For most markets where DoorDash operates, customers are prompted to tip on the checkout screen, with a middle option already selected by default. If they want to, they can adjust the tip later from the status screen while awaiting their food, or even after it’s delivered. That’s changing today; while blaming New York City’s minimum wage increase for delivery workers, DoorDash announced that for “select markets, including New York City,” tipping is now exclusively a post-checkout option"

It seems so ridiculous given tipping fatigue, that DoorDash is making what should be a given sound like a negative.

 

The Fifth National Climate Assessment is the US Government’s preeminent report on climate change impacts, risks, and responses. It is a congressionally mandated interagency effort that provides the scientific foundation to support informed decision-making across the United States.

 

Ukrainian forces claim to have destroyed a Russian 2S19 Msta-S self-propelled howitzer with a highly maneuverable racing drone rigged with explosives.

Shared on X (formerly known as Twitter) by civil rights activist Serhii Sternenko, a video showing a Russian 2S19 Msta-S self-propelled howitzer which was destroyed by a Ukrainian First-Person-View (FPV) racing drone laden with explosives.

In dramatic footage, the Russian self-propelled howitzer is being blown to pieces in a huge blast.

Ukrainian Soldiers are strapping rocket-propelled grenades (RPGs) and self-made bombs to cheap racing drones and using them to attack the Russian armored vehicles and trenches.

https://twitter.com/sternenko/status/1712764228837224856

The inexpensive racing drones are apparently so effective that Ukrainian forces can quickly locate and destroy enemy heavy armored vehicles with minimal cost and risk to themselves.

 

Article from a few weeks ago, but now that G. Elliott Morris is taking over without Nate's models, I'm curious what lemmy's think about political polling analysis from FiveThirtyEight?

 

Verge interviewed the maker of Relay for Reddit and says he might survive on a subscription only model of $2-3 USD per month. Lots of limitations inherent in that, but maybe.

How do lemmies feel about this?

view more: next ›