NuXCOM_90Percent

joined 11 months ago
[–] [email protected] 0 points 2 days ago

It isn't about being "evergreen". It is about having historical evidence.

Because maybe someone will do a study in 2030 and want to be able to compare to your UX research in the 2000s. If you wrote your paper properly they can reproduce your experiments (to the degree reasonable) and actually demonstrate progress.

[–] [email protected] 9 points 2 days ago (2 children)

Its the inherent disconnect between "News" and "Science".

Science requires rigorous study and incremental advancement. A 2023 article based on 2022 data is inherently understood to be.. 2022 data (note: I did not actually check but that is the timeline I assume. It is in the study).

But news and social media just want headlines that get people angry and reinforce whatever nonsense people want to Believe.

It is similar to explaining basic concepts. Been a minute since the last time I was properly briefed, but think stuff like "Do NOT say 'theory' of evolution. Instead, talk about how evolution is the only accepted justification based on evidence and research"

[–] [email protected] 5 points 4 days ago (1 children)

I have sprinted without this being an issue so color me very confused.

Do you wear very loose fitting clothes by any chance?

[–] [email protected] 6 points 5 days ago (2 children)

Good on the workers. But my worry is that Boeing is a sinking ship and this will end up as anti-union propaganda when they (not the doors that fall off mid-flight) are what is blamed for Boeing collapsing.

[–] [email protected] 5 points 5 days ago (2 children)

No. There is every reason to "defend yourself". The key is to actually be aware of what research and efforts are out there and minimizing your risk profile any time you are dealing with a black box.

I mean, it is known that people can pick locks. Do you plug your ears every time you hear someone talk about how doors can be compromised? Or do you give up on everything and remove every single deadbolt in your home?

Or... do you do a bit of research and figure out what you can do to make your home harder to break into. Whether it is sturdier screws, a reinforced doorjam, or other methods?

[–] [email protected] 12 points 5 days ago* (last edited 5 days ago) (5 children)

I can't speak to monero specifically

But:

  • Why aren't they catching more criminals? They are. They just are finding alternate sources of evidence. Dick Wolf shows love to talk about how cops need to protect themselves from any poison fruit and blah blah blah. The reality is that they immediately go to the poison fruit and use that to make a plausible excuse for why they investigated something else that can confirm information they got from the illegal source. If you've ever wondered why they would think to investigate a random unrelated company that ends up being the smoking gun...
  • Why didn't anyone claim the bounty? Because the CIA and the like don't want people to know they compromised it?

Back in my pure research days it was always fun to guess what the latest "big thing" was actually about. It was especially fun when you would be looking for funding opportunities and see really weird stuff that made no sense for the org sponsoring it but would have made perfect sense for a different 3LA.

It was ALSO real fun to totally never notice when certain funding opportunities dried up and then there was a big push in the news about how we need to outlaw technology those opportunities totally didn't already compromise.

Like, for the better part of a decade The Big Thing was graph analysis techniques. And the number of kids who had no idea they were basically writing algorithms to process social media (especially twitter) was downright sad. And the people who DID realize what their work was geared toward? They applied for jobs where they got paid a lot more to do exactly that without needing to pretend it is actually about data storage technologies or optimizing cell tower load.

And... let's just say that most of those algorithms ALSO apply toward cryptocurrencies and transaction logs (since they had great applications for bank transactions...) and even doing a number on tumblers and so forth.

[–] [email protected] 11 points 5 days ago* (last edited 5 days ago)

While I agree this definitely feels like more of a threat than an action, it IS worth understanding the many times that tor nodes have been compromised. Exit nodes are a well documented mess (and have many of the same vulnerabilities normal VPNs do) but eavesdropping and traffic analysis are also probabilities based upon how much of the network any given org has access to.

If that NGO was doing hinky stuff or just doing a sloppy job? Those cops might actually have a LOT of actionable data that just needs a bit of processing.


Which is why it is always important to understand what your risks and benefits from a privacy related tool are. People often think "I'll just put everything through a vpn/tor" which DRASTICALLY increases their risk profiles. But they also don't understand how tor works well enough to even know what it gives them over a traditional vpn (as opposed to "Dark Web" stuff which is a different mess).

[–] [email protected] 7 points 6 days ago (3 children)

It very much sounds like ifixit are actively asking influencers/reviewers to compare it to at least one of those in the videos.

[–] [email protected] 2 points 1 week ago* (last edited 1 week ago)

Doesn't really change much.

You NEVER connect to sensitive resources via wifi. Different orgs and levels have different rules about whether a device capable of wifi can even be in the same room, but the key is to not connect it to the secure network. This is commonly referred to as "an airgap". And if you are wondering how different ships can communicate with each other and The US? Don't ask questions!

For less sensitive resources? YOLO that shit. But it is also incredibly trivial to set up a security model where users cannot connect to arbitrary networks.

So StinkyNet would, presumably, only be usable by personal devices. Which should have absolutely nothing sensitive on them to begin with. And if anything on any of the ship's sensitive networks was even able to connect to StinkyNet then... the Navy done fucked up.

Which... might explain the rapid action to punish those who violated policy.

[–] [email protected] 4 points 1 week ago* (last edited 1 week ago)

And if there is not immense amounts of "do not have a fucking fitbit" levels of warnings and policies, that is a problem for the US Navy itself. Because a lot of those will also cache data and send the last N days once they get back to shore.

Again, unless they were ACTUALLY doing sensitive stuff (rather than just "sensitive by default" to protect Leadership(TM) from having to think and make decisions) then we are looking at the same problem the russians have in Ukraine.

Otherwise? It is a policy violation, not a security violation, in and of itself. What people then share on social media is on them.


And a friendly reminder: Policy is made to minimize the risk of a security issue and you should follow it (if only because you are paid to). But it is VERY important to understand what you are actually protecting yourself from so that you understand if policy is even doing anything. Otherwise you get complete insanity as more and more bureaucrats and Leaders(TM) add bullshit so they can get a bonus for being "security minded".

[–] [email protected] 6 points 1 week ago (2 children)

Itself? Not really.

If a ship is close enough to pick up an SSID they are close enough for any number of other methods. And starlink is theoretically trusted by the us government.

But if they were actually locked down for a real mission (not the stuff you do to make people feel important) then we could have seen the same kinds of telegram leaks Russian has near constantly.

[–] [email protected] 5 points 1 week ago

Yup.

It is not an exoneration of the average soldier. A lot did some really heinous shit... like all soldiers in all wars. But a lot were also just there because they were drafted and had no choice. And that is what investigations are for.

People like the black and white of "You wore a uniform, you are pure evil". And governments ESPECIALLY love that and a lot of media has been funded to specifically reinforce that so it is super easy to Other the other guys (We have always been at war with Eastasia and all that). But when you actually think things through? What is the difference between a conscript terrified in their bunk at night and a civillian who gleefully makes shells and tanks in a factory?

All of which is kind of moot. Because, to reference the great dril: You do not "gotta hand it to them" to ISIS, Nazi German, or Stalin and his cronies in the USSR.

 

So I finally broke down and made a very poor purchasing decision and ordered an e-ink writer to be a notepad/e-reader hybrid. Partially so that it is less of a hassle to read books I got from kickstarters and the like while still using the kindle app for the disturbing amounts of money I throw at Amazon.

Historically? I loved goodreads because theoretically I would get good recommendations based on what I liked. In practice, that has never happened but it is still nice to see if I read something in the past. And once I have multiple ebook ecosystems, it will be nice to actually check that rather than spend the first 100 pages wondering if this is familiar.

So any good recommendations? I suspect what I SHOULD do (and will likely start doing more as a self betterment thing) is just put a note in my personal nextcloud every time I finish a book with a quick summary and some thoughts. But having the big database is also really nice.

Thanks

 

So I've been grabbing a few shows I want to watch reruns of while playing Balatro that don't have good blu ray releases. My piracy is fairly limited these days so I don't bother with private trackers (do have a VPN though). In the past, I never really had an issue with grabbing a few one offs off the popular, maybe honeypot, sites like rarbg and 1337x.

But over the past month or so, I've noticed I have gotten a lot of shitty files. Skips here and there or garbled colors for a scene or two. At first I though it was just a bad file since re-downloading the torrent had the exact same problem.

But, on a whim, I did a recheck and had to download like 40% of a torrent. And then 20% the next time. Which made me assume my NAS was fucked or I was dealing with a lot of packet lsos (... I AM dealing with a lot of packet loss from my ISP). But when I redownloaded a "known bad" torrent I had the exact same corrupted file.

So am I just REALLY unlucky? Or is there an epidemic of shitty/malicious seeds on the public trackers these days?

 

Looking for a solution to manage and access the directory on my NAS that is full of ebooks. Optimally I want to be able to web reader them but also automagically send it to the email that sends it to my kindle. And e-book wise, the majority of mine are epub/mobi that I got from various kickstarters or humble bundles. But I also have some RPG books (so PDF with a LOT of pictures) and manga (PDF or CBR).

Did some research and checked the various reference lists. Mostly narrowed it down to

  • Weird-ass Calibre running in Kasm and accessed through a god awful web UI: This is actually what I used for the past year or two because there was a solution that was fairly plug and play with unraid. I... would rather never do this again
  • "Calibre Web" https://github.com/janeczku/calibre-web. This seems to be what I actually want (an actual web interface to Calibre!) but it looks like the lead dev lost their shit with obnoxious demands from users. And while I appreciate they are still supporting it, "I am going to ignore the issues unless I feel like it" seems like a good way to get a bunch of unacknowledged CVEs...
  • Kavita https://www.kavitareader.com. Only found out about this today but it looks clean and efficient (plex-like). REALLY not a fan of the subscription model already being there but I also don't want any of those features.

Thoughts? There anything better I am missing because none of these look all that great?

 

So for the past few years (?) I have been using wireguard to vpn into (effectively) my firewall and a dynamic dns setup to access that remotely. But with the shitshow that is google domains and the like, this seems like a good opportunity to look into a few of the alternatives. I am not entirely opposed to just going in and changing the dns server once I figure out what I am going to do on that front, but wireguard has always been a bit of a mess to set up for less "tech savvy" people who need access to the home network.

Every so often I see some cloud based solutions get suggested. Which is sketchy but I already have a few alerts set up to be able to remotely shut my network down if wireguard is acting up when it shouldn't be and shutting down a VM is a lot less of a "do I really need to do this?" than shutting off the entire network. But most of those solutions seem built around selling seats which means they want you to add individual devices rather than just setting up a tunnel.

So is wireguard still the gold standard? Or is there a more user friendly solution that will let me compromise a bit but also have a setup that doesn't require me to be physically on site to fix the inevitable hiccups because it takes hours of reading articles to understand the setup?

Thanks

 

Framework as in the laptop company, just for clarity. https://frame.work/. For those unaware, the idea is that these are laptops built with a high degree of modularity so that you can replace far more than a single stick of SODIMM with the goal of even upgrading your CPU and mainboard a few years down the line.

Also, Framework is partially owned by Linus Sebastien (Linus Tech Tips) so their marketing is "off the chain" as it were.

Over the past few years I have tried to convince myself to get one a few times. But... the pricing never made sense. As a quick exercise:

But I still like the fundamental concept (of the marketing...) of upgradable laptops.

But then I finally watched the Tested teardown video with Norm (the heart and soul of Tested and has been since the Whiskey days) https://www.youtube.com/watch?v=drxOpMsr6sM and... the general takeaways were that there is a LOT of cool tech involved in the modularity but that the vast majority of people would never mess around with it after assembling their laptop for the first time. Also, Adam Savage has stickers.

Combine that with all of their modular ports being 20 dollar USB-C dongles with single ports and... this feels a lot more like the kind of bullshit Apple does than anything else. Why use the USB C dongle/hub that works with all your other devices when you can buy a 20 dollar HDMI port instead?

Same with stuff like the (honestly insanely cool) modular keyboard layout. Basically, the keyboard, touchpad, etc are all panels that can be popped off and swapped around. So if you want stupid LEDs, you can have them. If you want an offset keyboard, you can do it. If you want a 10key numpad, you can do that too. It is a genuinely awesome idea but... it is a lot of engineering for something that people will use maybe twice in their ownership of the laptop (once to configure, one to replace when they spill their drink). Same with things like being able to swap out the back module to have a GPU when you want it. You do that once.

Which... makes it feel like people are paying a premium for easier assembly at a factory.

And as for the upgradable hardware? Storage and ram are on point and they should be praised. But you are basically buying whole new modules for the CPU/mobo and the GPU and so forth. Which... is kind of necessary because it is so rare to find an actual mobile sized GPU in a consumer available format. But it continues to just feel like you are buying proprietary parts from a company (Framework want other companies to make parts but I have not looked through the terms and licensing).

But also? A friend pointed out: How many sticks of DDR3 ram do you still have? Because I know that I have a big bin of computer parts "just in case" that I will never use but also can't be bothered to throw away because maybe I will. And that is what these modular parts become. You COULD recycle your old mainboad+cpu... or you can keep it in case you want to do a project that you never will and that would be perfectly fine with a raspberry pi or a cheap nuc anyway.

Contrast that with wiping your laptop and giving it to a nephew or dropping it off in an e-waste bin (and many stores offer incentives to do that).

All of which combines to... this feels a lot like the kind of "poison pill" compliance that Apple is doing on the right to repair side. They make a big deal about how they allow people to repair their shit now (that various governments threatened action...). But they tightly control the parts and rent out the hardware AND price it to strongly discourage hobbyists to the point that it mostly feels like they are just squeezing out the third party shops even more.

I'm torn because I do think the stated ethos is awesome. I... also have had no issues replacing my storage or upgrading my ram in my last few laptops but I tend to not get "flagship" models so there is that. But it is increasingly feeling like Framework is just building up IP to sell to manufacturers while having a net negative on the amount of e-waste in the laptop space.

view more: next ›