I try to respond to every genuine engagement. I block trolls, contrarians, and provocateurs because life is too short.

  • 1 Post
  • 996 Comments
Joined 1 year ago
cake
Cake day: January 29th, 2025

help-circle



  • Cool, now we’re definitely on the shitlist with Iran.

    Just what we need - being dragged into another stupid US conflict. One in ten crew members on US attack subs is Australian, according to the Royal Aus Navy - as part of training for the $368 billion AUKUS program.

    I feel like people don’t realize how rare and against norms this kind of unprovoked attack is. Only four ships have been attacked by subs since world war 2 in all the military engagements that have occured over that time. This act is a massive escalation of hostilities.

    The Iranian frigate was unarmed (no missiles or anti-air arms), as it was returning home after a friendly military training exercise with India that required Iran’s ship to follow “peace protocol”. So also it’s yet another US war crime. India is pissed about this too because their guests were murdered - they rushed rescue boats and helicopters to the site, but were too far away to be effective. Sri Lanka was closer and managed to rescue just 32 survivors of the 180+ crew in their rapid response.



  • It’s a great idea if you’re a billionaire and have a diverse team of qualified teachers to manage the schooling of your child(ren) at your home, you can spend more time with them and keep them guarded from kidnappings.

    For everyone else it’s usually a disaster, and they find out that teaching isn’t just a matter of babysitting and reading a few textbooks with them, it’s actually hundreds of years of knowledge distilled into design, practices and pedagogy - none of which your average homeschooling parent knows much about. Then they give up homeschooling after 2-3 years and bring a kid back to grade/primary school or high school who has now been set back multiple years behind their peers.

    Then… there’s also the abuse that goes on outside of the view of the government-supervised schooling system (with mandatory reporting laws, welfare checks, etc).






  • If you believe the AI hype there won’t be any programming jobs soon - so those that do (believe) think they need to become highly-proficient AI-wranglers to maintain employability.

    I too think it’s the wrong approach, but it’s hard to say what hirers will be looking for in the medium to long term, and devs whom adapt to ‘the new thing’ faster have typically been more hirable.

    Personally hoping the big players crash and burn asap because the benefits just haven’t been anywhere near worth the costs across various domains.





  • Face scan is actually much easier to defeat than CC details.

    Nowadays with VISA ‘3D Secure’ and the equivalent on Mastercard you have to validate your legal name attached to the credit card, this is done via third-party which can request details your bank has on file (often your home address or mobile number), and even while those details are not supposed to be shared with the merchant (we know how careful banks are about keeping control of PII), the core detail - your legal name, is confirmed. It is not hard to tie a user to other data via data brokers once you have their legal name, and credit card number, and any other details they may share with the service (email, phone, etc).





  • If you’re worried that this may have hit your PC I’d say first of all be aware that this is a state-level backdoor, intended to be persistent and evade detection. You are likely not the target and are very unlikely to find any evidence even if you were targeted, as it is capable of clearing its tracks.

    Actions I’d suggest if you’re still worried this could have hit your PC:

    1. Grab the list of Indicators of compromise from the bottom of this article. Disconnect the PC from the Internet now that you have the list.
    2. Search for any instances of these files locally and SHA-256 hash them if found, and match to the hashes on the list. If you find any matches, your system is compromised.
    3. Check the DNS cache for any hosts mentioned in the indicators, and if you have network traffic logging you could check there also. Indicators are very likely signs of prior/active attack on your PC.
    4. If nothing found, reconnect to the net and continue…
    5. uninstall Notepad++, or if you want to keep using it, update Notepad++ via a method other than their internal update method. I suggest powershell using winget as its preinstalled in Win10 & 11.
    PS > winget list -q Notepad++
    (will show you available updates)
    PS > winget upgrade -q Notepad++
    (Will install the update if available) 
    
    
    1. (Optional) disable Notepad++ internal update mechanism, and use winget or another method moving forward. Settings -> Preferences -> MISC: Auto-updater: Disable.

  • This advice is not accurate:

    The Rapid 7 post says if you have a hidden folder in “%AppData%” named Bluetooth. You got hacked. So if you don’t have said folder, you’re good.

    Their post says that the Bluetooth hidden folder in AppData was only used as the initial access vector.

    After initial access, an advanced persistent backdoor they’ve named “Chrysalis” is delivered and installed via significantly obfuscated methods to minimize chance of detection. The backdoor allows arbitrary code execution via a CMD.exe reverse shell, with additional modes for remote file write, read, and a full self-removal mechism that attempts to delete any trace it was ever on the system.

    The Indicators of compromise section at the bottom contains a list of any files you can check for on your system, and their corresponding SHA-256 values, as well as network indicators if you have logging or wish to check your DNS cache. If you have any files that match or other indicators, then your system is/was compromised. But there is a very good chance that many systems which were compromised now have no remaining trace of breech.

    https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/