lurch

@lurch@sh.itjust.works

he/him

This profile is from a federated server and may be incomplete. Browse more on the original instance.

lurch,

There are sites that respect the “do not track” setting of the browser and just display a small timed info on your first visit that cookies have been rejected. Examples: geizhals.eu , geizhals.de

lurch,

There is, but if one gets through, they want us to forward it to this account that will be used to train, fine tune and improve the scanner for all mailboxes, as well as security training for employees.

lurch,

You sure you want to use LUKS? It has a specific format that can be probed for almost like a known plain text.

lurch, (edited )

I mean that any attack gets more easy when you know, after it’s decrypted there are the bytes A, B and C at the locations X, Y and Z. It helps with brute force as well as hybrid attacks to find the master key.

LUKS does exactly have those specific Bytes at specific locations PLUS it has a marker that basically says “I am in this format and encrypted with this algorythm”.

lurch,

A good pasphrase helps the same for non-LUKS, but they still don’t have that specific weakness.

You can use cryptsetup without LUKS. However, something that starts to decrypt has to be unencryoted, so you can enter the password. Depending on how convenient it is for the user, it will leak some helpful info, like for example that the target is a valid file system that can be mounted or what cipher had been used.

to conceal this, you’d have to enter all it does manually in a shell/script without history. You could also add a number of bytes to skip as a sort of extra password and fill the start with random bytes, so it’s harder to find the start of the payload that is peobably a file system.

lurch,

If you use X and need to restart it, you can probably preemptively use XPRA to proxy your Xclients and move them to the new Xserver, except maybe for those that need low latency or DRM (e.g. games)

lurch,

I don’t actually use it that much to input commands, but many scripts I made pop one up to show details of what’s happening, e.g. how opening the VPN connection is going, what crypto module it’s currently loading or how many more iterations a macro will do.

lurch,

Someone needs to do some fitness ngl

lurch,

As long as you do not use root privileges (indicated by sudo or that password promt pkexec) you cannot destroy the system in a way that can’t be fixed by deleting a few files in the users home directory.

lurch,

I’m not familiar with your package manager, but some have logs detailing what exactly they did in chronological order.

lurch,

I think that’s only true for the programs, not for the JVM/JRE code. The JVM/JRE doesn’t support Wayland without the xwayland compatibility layer. Also, some games use “native” libs that do optimized 3D stuff. Those are special Java classes, not part of the JVM/JRE that interface with C libs, kernels, system calls and hardware directly. Some will stop working without an X window to connect to. Some are long forgotten and won’t be ported.

lurch,

This reminds me of the last episode of “The Continental” of all things. A follow up of this side plot would be nice.

lurch,

Their stupid ass logo looks too much like the old X11 logo. At least Xorg has a cirlcle thing. 😤

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #