Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)L
Posts
5
Comments
347
Joined
2 yr. ago

  • Webp

    Jump
  • Though you couldn't set the bar any lower without it turning into a joke.

    Anyhow, to quote Wikipedia:

    Comparing different encodings (JPEG, x264, and WebP) of a reference image, she stated that the quality of the WebP-encoded result was the worst of the three, mostly because of blurriness on the image. [...] In October 2013, Josh Aas from Mozilla Research published a comprehensive study of current lossy encoding techniques and was not able to conclude that WebP outperformed JPEG by any significant margin

    All while having significantly increased complexity. The blurriness problem was inherited from the video codec webp was based on. When you can't beat an 18 years old format, don't be surprised when people get irritated when you use your position to get it mandated into a standard, while later stalling actual improvements (JPEG XL).

  • Look through the cockpit

  • I like that none of my local devices are externally addressable unless an outgoing connection has been established.

    This can also be achieved using (other) firewall rules.

    but then it's essentially just maintaining a NAT table without the translation piece.

    So... a firewall?

    NAT isn't a security feature and shouldn't be relied on for managing access to hosts.

    It also breaks the assumption of IP that connections between hosts are end-to-end, which requires sophisticated solutions so that everything works (more or less).

    I too employ NAT to make services accessible over IPv4. But only because it doesn't work otherwise. Not because it "makes sense". I don't use it at all for IPv6.

  • Idk man, NAT makes a lot of sense once you get used to it.

    That's a lie, NAT is bullshit, sometimes necessary, but it will never "make sense".

  • Well, technically, there's a second time

  • The best mini stroke they've ever seen.

    I might have to agree.

  • A twitch chatter used the same term in Atrioc's stream where this was presented, saw it on YouTube and had to laugh

  • The 4k you find on streaming services can't really be compared to the 4k you find on Blu-ray. It's a different league. Turns out bitrate actually matters

  • Maybe if we curve the TV?

  • First shampoo bar I tried was garbage, I tried a different brand and had much better results

  • Client data absolutely is encrypted in TLS. You might be thinking of a few fields sent in the clear, like SNI, but generally, it's all encrypted.

    I never said it isn't, but it's done using symmetric crypto, not public key (asymmetric) crypto.

    Asymmetric crypto is used to encrypt a symmetric key, which is used for encrypting everything else (for the performance reasons you mentioned).

    Not anymore, this was only true for RSA key exchange, which was deprecated in TLS 1.2 ("Clients MUST NOT offer and servers MUST NOT select RSA cipher suites"). All current suites use ephemeral Diffie-Hellman over elliptic curves for key agreement (also called key exchange, but I find the term somewhat misleading).

    As long as that key was transferred securely and uses a good mode like CBC, an attacker ain't messing with what's in there.

    First, CBC isn't a good mode for multiple reasons, one being performance on the encrypting side, but the other one being the exact reason you're taking about: it is in fact malleable and as such insecure without authentication (though you can use a CMAC, as long as you use a different key). See https://pdf-insecurity.org/encryption/cbc-malleability.html for one example where this exact property is exploited ("Any document format using CBC for encryption is potentially vulnerable to CBC gadgets if a known plaintext is a given, and no integrity protection is applied to the ciphertext.")

    As I wrote in my comment, I was a bit pedantic, because what was stated was that encryption protects the authenticity, and I explained that, while TLS protects all aspects of data security, it's encryption doesn't cover the authenticity.

    Anyhow, the point is rather moot because I'm pretty sure they won't get a certificate for the IP anyways.

  • Public key crypto, properly implemented, does prevent MITM attacks.

    It does, but modern public key crypto doesn't encrypt any client data (RSA key exchange was the only one to my knowledge). It also only verifies the certificates, and the topic was about payload data (i.e. the site you want to view), which asymmetric crypto doesn't deal with for performance reasons.

    My post was not about "does TLS prevent undetected data manipulation" (it does), but rather if it's the encryption that is responsible for it (it's not unless you put AES-GCM into that umbrella term).

  • Right, and for the challenge, you need to have access to a privileged port (which usually implies ownership), which you won't get assigned.

  • Let's Encrypt are rolling out IP-based certs, you may wanna follow its development. I'm not sure if it could be used for your forwarded VPN port, but it'd be nice anyhow

    It shouldn't be because you're not actually the owner of the IP address. If any user could get a cert, they could impersonate any other.

    I believe encryption helps prevent tampering the data between the server and user too. It should prevent for example, someone MITM the connection and injecting malicious content that tells the user to download malware

    No, encryption only protects the confidentiality of data. You need message authentication codes or authenticated encryption to make sure the message hasn't been transported tampered with. Especially stream ciphers like ChaCha (but also AES in counter mode) are susceptible to malleability attacks, which are super simple yet very dangerous.

    Edit: this post is a bit pedantic because any scheme that is relevant for LE certificates covers authenticity protection. But it's not the encryption part of those schemes that is responsible.

  • What a terrible day to be able to read

  • Very cool

  • But only so.

  • The whole thing is super dumb, as you said, burning the flag is the proper way to get rid of one no longer for for display (imagine the flag hanging out of a bin or something).

    You know what's also against the flag code? Plastering it everywhere that's not a flag, like towels or whatever. But the flag code is only binding for government bodies if I'm not mistaken.

    But yeah, the whole thing is just stupid.

  • The second y in Syyu is almost always unneeded and just wastes time and bandwidth. Is i remember correctly, it only makes sense when for example you switch mirrors