• 1 Post
  • 148 Comments
Joined 3 years ago
cake
Cake day: July 7th, 2023

help-circle

  • Sort of. The program uses a specific part of the website for its auto update. And it also didn’t do any kinds of TLS (https) validation (which would prevent changing the destination). They also signed their installers (which would throw an error if the file had been modified) but the auto update didn’t check for a valid signature. So basically the two big things that a browser would do when you visit the site to download the installer, the auto updater just… Wasn’t doing.

    So people who visited the site to manually download the installer were fine. They would have been alerted if the TLS cert was invalid or if the installer wasn’t properly signed. But if you used the auto updater, you wouldn’t get any of those errors and it would happily install the malware.



  • Take their assets and put $10M towards keeping the bounty program going. Take another $15M and put it towards a second (even bigger) bounty. Every day a billionaire’s name gets lottery’ed and killing them wins the big pot plus the original $10M bounty. So every single billionaire has a constant bounty on them, plus the chance of getting lotto’ed… At first that lotto may only be $25M. But as more and more die, that bigger pot continues to grow.

    Their private security teams may not be willing to turn against their masters for only $10M… But for $25M? $40M? $55M? $70M? Everyone has a price, especially the billionaires’ mercenaries. Of course, the billionaires would probably start requiring bomb collars for their private security at that point, to ensure they remain loyal. But that means the teams would inevitably weigh the price of a bomb collar vs an easy $10M payout in the first place. And that $10M alone would be enough to have them gunning down the billionaires before they put the collars on.

    The rest of their assets go towards a fund for reducing homelessness, bolstering food stamp programs, unemployment insurance funds, getting people back on their feet, forgiving debt, funding Social Security, expanding Medicare and Medicaid, maybe even UBI if the fund is large enough to be self-sustaining, etc…




  • As someone who occasionally has to scrub through hours of security camera footage, these cops need to learn what a binary search is. We had some art get stolen from our gallery, and I had to search through ~5 days of footage to find it. I found it in about 3 minutes with a binary search.

    Start by defining your timeline. In my case, it was about 5 days (so roughly 120 hours) over the course of a long weekend. Then divide that time in half, (60 hours) and start at the middle. Is the artwork still there? If so, you know you don’t need to bother scrubbing through the first 60 hours at all. Or if it’s already missing, you know you don’t need to bother searching through the second half. Then divide the remaining half in half again, (30 hours) and do the same. Repeat, each time dividing the potential search by half. With only 10 divisions, (each taking only a few seconds to figure out what the next halfway point is and jump to it in the security camera program), I have already narrowed my search down from 5 days to ~7 minutes. And it only took me a few minutes total. And at that point, I just scrub through manually until I find the culprit.

    My boss was just sitting at her computer, watching the video at like 2x speed from hour 0, hoping to eventually catch the person. After like 20 minutes of that she gave up and passed it off to me. And I had the incident found in like 3 or 4 minutes total.

    The only real reason the cops have to avoid scrubbing through footage is laziness.






  • Yup. For minor issues, first aid is all that is needed; you don’t need to see a doctor for a minor cut, as long as the first aid ensures it’s not infected. But for larger things, secondary aid is what provides more long-term recovery.

    If someone dislocates a shoulder, first aid is putting it in a sling and bracing it against the body, so it doesn’t get worse (for instance, the tendons and ligaments in the shoulder joint can tear) before they can get to a hospital.

    If someone is massively bleeding, first aid is stopping the bleeding to keep them alive until they can get rescued.


  • It can be, yes. One of the largest complaints with Docker is that you often end up running the same dependencies a dozen times, because each of your dozen containers uses them. But the trade-off is that you can run a dozen different versions of those dependencies, because each image shipped with the specific version they needed.

    Of course, the big issue with running a dozen different versions of dependencies is that it makes security a nightmare. You’re not just tracking exploits for the most recent version of what you have installed. Many images end up shipping with out-of-date dependencies, which can absolutely be a security risk under certain circumstances. In most cases the risk is mitigated by the fact that the services are isolated and don’t really interact with the rest of the computer. But it’s at least something to keep in mind.




  • Yeah, toxins are often the bigger risk when dealing with bacterial or fungal issues.

    For instance, botulism is caused by the toxin produced by botulinum bacteria. The toxin is a paralytic. The bacteria itself can typically be dealt with by the immune system, but the toxin wreaks havoc on the nervous system.

    That’s also why you should never feed honey to babies; botulinum is commonly found in honey. Babies’ immune systems aren’t equipped to deal with the botulinum bacteria, which allows it to bloom and start producing the toxin after they ingest it. This causes something called Floppy Baby Syndrome, from the baby being paralyzed by botulism toxin.


  • I heard a very similar story, except it was one Italian grandma with a bunch of dudes in suits. She proceeded to serve him the single largest, most elaborate, and most delicious Italian dinner he had ever had. Apparently he could see into the kitchen, and she was making everything from scratch. He was there for like two hours, and she just kept bringing more plates out even though he hadn’t actually ordered anything. All because she was so excited to finally have someone to cook for. She even sat with him to chat, and was clearly happy to just have someone except the angry-looking dudes in suits to talk to. IIRC the suits didn’t even take payment before he was ushered out of the door.

    He tried to go back like a week later, but the place was totally deserted.