borari

joined 1 year ago
[–] [email protected] 9 points 1 month ago* (last edited 1 month ago) (1 children)

My dude, I am positive. My cake day: June 8 2023. Your cake day: June 12, 2023. Do you not realize that people can have multiple accounts? Dick measuring and attempts at gate keeping based on time on a platform is super cringe.

I created the community you’re posting in right now. You should probably get off the internet and chill bro. You woke up and made the choice to behave this way, and it’s pretty fucking embarrassing tbh.

[–] [email protected] 1 points 2 months ago (1 children)

Ah, like just set up a guest account for each instance i’m interested in, then browse by local for each one?

That sounds like a potential workaround, but unless i’m missing something I’m still subject to only seeing the communities that are hitting the feed based on whichever sorting algorithm I’m using right? It seems like adding something like“view all communities by instance” tab to the app search page then using similar logic to that in the instance selection field on the signup page would be more useful and useable as a user to me personally.

[–] [email protected] 3 points 3 months ago

I obviously pulled a lot from Apollo into Arctic, which if in being honest, I feel a little guilty about.

Sorry to respond to such an old post, but I wouldn't feel guilty about this. Christian said he absolutely did not want to convert Apollo to Lemmy, and that he was done with the project. I'm really glad that you've made an app that feels so familiar and comfortable for me coming from Apollo, I wouldn't use Lemmy nearly as frequently without your app.

 

While browsing through the 'All' subscription feed I'll occasionally see a post from an instance that looks interesting to me, for example programming.dev, and I would like to browse the communities that are hosted on that instance.

The search functionality within the app only allows for me to find communities with programming.dev in the community name. Currently I have to navigate to the instance directly in a browser using the httx://*/communities?listingType=Local endpoint to view all its local communities.

Even if incorporating such a view is a possibility I'm not sure where you would integrate it in to the UI. Maybe an Instance sub-menu with a nested Local Communities menu item underneath the existing Community menu item in the ... Options menu at the top of the screen while viewing a post?

On a semi-related note, would it be possible to add an option to view the community sidebar while viewing a post and its comments? I currently have to scroll up to the top of the post, click on the link to follow though to the community directly, then open the sidebar from the Options menu there.

[–] [email protected] 2 points 3 months ago

That’s been my life for the past 10 years, you won’t regret it at all.

[–] [email protected] 12 points 3 months ago

And leaded gasoline and leaded diesel and leaded aviation fuel and lead pipes in household plumbing. Probably lead in the cigarettes everyone smoked literally everywhere.

[–] [email protected] 17 points 3 months ago

Saying they banned VPNs isn’t completely, technically correct I’d guess. If I were another country then VPN’d in to my house, I would probably be fine. A pedantically correct statement would be that they banned known VPN IP ranges, so if you’re attempting to connect while your traffic is routed through one you get blocked.

[–] [email protected] 11 points 3 months ago (1 children)

Oh damn. Yeah fuck that place, glad I left.

Semi-related, I was searching for some hyper specific job related technical cybersecurity stuff a few weeks ago and the first result with the verbatim error message was a reddit post, so i clicked. No dice, loads a reddit branded error page. My employer has their own ARIN number/ASN. As far as i could tell every connection from an IP in one of our blocks was being blocked by reddit. My employer isn’t a faang type tech company, they don’t work in ai, they don’t scrape content for datasets or anything else. I can’t figure out why kind of business would cut off entire swaths of customers from accessing their site during the workday, a prime “take a shit and dick around on the phone” audience. I’ve just made a point to search with stack exchange site dorks since then.

[–] [email protected] 9 points 3 months ago* (last edited 3 months ago) (2 children)

We got 4 mainline games in the first 18 years, which works out to a game every 4.5 years on average. We have been getting ports and remasters of a single game for the remaining 12 years. Idk what happened over there. Did the main TES devs just burn out? If so why all the ports and rereleases? Maybe they’re just sticking a revolving door of interns on those?

Edit - Oh I guess the TES mmo. Still though.

[–] [email protected] 2 points 3 months ago

Absolutely filthy prodigy remix in the first video. Gotta love the russian at 1:15 looking like he’s trying to get a rewind for that drop but really just can’t move his leg or floppy foot lol.

[–] [email protected] 6 points 3 months ago* (last edited 3 months ago) (2 children)

Yeah, the answer here is cancel prime and pirate whatever amazon video content you want. if you absolutely have to have prime for some reason, don’t sign in to amazon video on any of your devices and pirate the stuff you want to watch so at least your not contributing to views or their prime video ad revenue.

Edit - I see in another comment you said you unsubscribed, good on you.

[–] [email protected] 15 points 3 months ago

I’m slightly less mad now that I know this has precedent. I’m still fucking furious that the only precedent I’ve heard about is corporations and Trump, since the law should be equally applied regardless of absolute amounts of money and I’m pretty sure that someone living in poverty isn’t going to get the same treatment for a $50k (or whatever is a proportional amount) judgement against them.

[–] [email protected] 12 points 3 months ago (1 children)

That wasn’t what was at stake here. Trump was already found guilty, he wasn’t bonding out of pretrial detention he was having to post bond in order to appeal the ruling, which typically requires the person making the appeal to post a bind to make sure they don’t spend all their money fighting on appeal, just to lose the appeal and not have any money left to pay the original judgement.

So my expectation was that yes, he would have to follow the same court rules as everyone else and put up the bond in order to appeal. While I do think we should get rid of requiring pretrial detention bond, I don’t necessarily see an issue with requiring pre-appeal bond. I don’t know, you don’t want to create a situation where you’re means testing the right to appeal, but you don’t want people to indefinitely delay enforcement of judgement against them or to allow them to spend away their ability to pay the judgement on appeals. Maybe forcing either the entirety of the judgement to be paid into a more traditional escrow account, or a payment plan for the judgement to be accepted and that paid into escrow, before an appeal can be started?

Any way you cut it though, I can’t fault this chuckle fuck for playing the court game but I’m fucking incensed the court is enabling it.

 

Team Cymru published a report detailing infrastructure and configuration changes to the Vidar info-stealer malware that were made in an attempt to evade detection and anonymize activities.

 

ESET researchers identified an updated version of the Android GravityRAT spyware being distributed as the messaging apps BingeChat and Chatico.

 

It seems like attackers have discovered a way to leverage NPM packages to deliver malicious binaries without needing to make any changes to the NPM package itself.

 

This is an interesting report by Symantec about a Russian 'Cyber Campaign' against Ukraine, targeting security services, military, and government organizations.

It's crazy that we're witness to the first case in history of cyber warfare campaigns being waged alongside, and in support of, a hot war, in real time.

 

Looks like Mandiant has discovered active exploitation of CVE-2023-20867, which was given a CVSS score of 3.9 when it was assigned.

9
submitted 1 year ago* (last edited 1 year ago) by [email protected] to c/[email protected]
 

This new malware strain, written in Go, has been seen compromising systems across Europe, Southeast Asia, an the U.S. It's stealing sensitive information from Discord, web browsers, etc.

 

This won't apply to anyone here, because we're all reviewing any code we clone from GitHub prior to executing it on our system, right?

 

This new stealer has five stages, and shows a high level of sophistication, akin to APTs. Targeted victims have been seen in Europe, the USA, and Latin America.

Several pieces of Russian text were found in the malware.

The first part of the C2 URL is “Privetsvoyu” which is a misspelled transliteration of the Russian word for “Greetings.” Secondly, we found the string “salamvsembratyamyazadehayustutlokeretodlyagadovveubilinashusferu.” Despite the weird transliteration, it roughly translates to: “Greetings to all brothers, I’m suffocating here, locker is for bastards, you’ve messed up our area of interest.”

MD5 sum and C2 URL IOCs are included at the end of the report.

 

The researcher chained an insecure password reset API route to bypass authentication, then discovered an IDOR vulnerability could be leveraged to access sensitive customer data.

For everyone that says "The real world can't be as easy as training labs make it seem out to be!", sometime it really do be that ez.

view more: next ›