• 0 Posts
  • 786 Comments
Joined 3 years ago
cake
Cake day: July 29th, 2023

help-circle



  • I really hate that the exaggerated future of Watchdogs is becoming reality but not the exaggerated group of highly experienced black hat hackers doing crazy post compromise shenanigans that would make national news.

    The problem is the same reason why a Robin Hood type of character already doesn’t really exist in modern history. There will always be thousands of highly skilled people in defense of the very system you wish to see dissolved.

    You would need the resources of at least a highly advanced APT, which often means you’re funded by a nation state which has very specific compromise goals.

    Everyone else falls into cybercrime, which is much less sophisticated and is almost always after money.

    Hence why most highly publicized attacks end in bitcoin ransoms.

    EDIT:

    Also at the risk of giving too much info about my career, big banks are absolutely notorious for having extremely tight security. Even if you managed to jump over the custom EDR, pivot your way through a massive amount of proprietary systems, and land in a suitable position to carry out the motherload of a supply chain attack, the bank could just halt their infrastructure and manually nullify whatever transactions they want with full backing from the government.

    The closest I ever hypothetically witnessed was being able to manipulate the loan data for a small credit union. And emphasis on hypothetical, a real attacker would have needed some hard internal access to a heavily restricted subnet.

    The only way I can see this successfully happening is like if the Chief Network Architect of say Chase also happened to be a highly competent hacker who uses his decades of experience to formulate a plan with an APT over the course of several years.



  • I miss unmonetized youtube in general. Too many channels make it big and end up committing to youtube as a profession which leads to burn out or a significant drop in video quality.

    Youtube’s (and Facebook) revenue system incentivizes content that gets lots of views in a very short period of time, and way too many people get hooked after seeing the cash flow from a handful of good uploads.

    And the revenue provided is a minimized running cost for Google, YouTube takes home a fat 11 billion dollars a year in profit.






  • You know the funny thing is there’s actually a biblical calculation that puts the end of the world around 204X that several well known Christian Theoloegians calculated including Isaac Newton.

    It seems odd to me that fanatics ignore this prediction and insist on accelerating the end times or claim that the rapture is tomorrow.

    The other funny thing is all the insane level of violence and corruption that both Christian and Islamic eschatologies warn about in great detail.

    If you’re familiar with either source, the irony is astounding. People read a big fat warning about the end times and then decided “We can accelerate this and make it into heaven by playing the explicitly evil guys in this big fat warning”.




  • Sideloading APKs is an easy vector but so is the Google Play Store. It’ll take scammers like 5 minutes to just perma move to GPlay shenanigans, and its already well known to have poor quality control and tons of malware available to download with the useless play protect logo.

    This is just Google’s public justification for creating their walled garden. They already pulled this exact scam with Chinese OEMs which is how Huawei got banned, and others stopped selling in the US. They huffed up some story about CCP spyware and then mandated that GPlay be installed in full, otherwise face consequences from congress.

    Even Samsung got pulled in and they essentially agreed to use GApps as the de facto communication suite for their phones in exchange for allowing Samsung to continue to use their Galaxy store.

    They see stuff like AOSP as a threat because anyone can just fork the OS and make their own non google Android, and they don’t want any OEM to replace GPlay like what Motorola is attempting right now (hence the increased urgency to lock down Android).

    Google’s monopoly in the mobile space revolves around every phone using GPlay, so they’ll do anything to maintain their control.





  • The fact that CachyOS more or less successfully replaced Manjaro’s purpose I guess is evidence of Manjaro’s issues.

    I forgot but I think Bazzite had similar complaints (due to its use of silverblue) in which case it was just more straightforward to use Fedora or OpenSUSE if you don’t want to work with the read only root system.

    Downstream distros need to bring additional value to the table to be worth using, otherwise there’s really no need if you can make a package group that accomplishes the same thing in one go.