Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Shaggar
Apr 26, 2006

haveblue posted:

it doesn't, apparently what happens is they try to open an application url and then figure out if it popped a "do you want to open this app" overlay. not sure exactly how they do that but the presence of the overlay probably has side effects on the dom they can detect through JS

yeah i saw that and i didnt understand how the page knows that UI is popped. does it block the rest of the UI preventing any input to the dom? did they do something idiotic and implement it as part of the dom?

either way its definitely lovely browser design. also javascript was a mistake

Adbot
ADBOT LOVES YOU

Main Paineframe
Oct 27, 2010

Shaggar posted:

yeah i saw that and i didnt understand how the page knows that UI is popped. does it block the rest of the UI preventing any input to the dom? did they do something idiotic and implement it as part of the dom?

either way its definitely lovely browser design. also javascript was a mistake

it's not really based on checking for the UI

each browser's response to canceling the popup different from the browser's response to not opening the popup at all, in a way that can be detected in javascript

let's use Firefox as an example. if you try to open a known scheme handler and the user clicks "Cancel" on the popup, the result is a blank page. on the other hand, if you try to open a protocol that doesn't have an assigned handler, you get an error page. it's possible to distinguish between those two cases in JS, and therefore determine whether a handler was installed or not

tor browser was set up to auto-deny these handler requests without showing them to the user, but that actually made the exploit worse, because it still worked exactly the same as in vanilla Firefox, except now it was also invisible to the user because they wouldn't get nagged with a bunch of spurious popups

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed
tor browser ships noscript but it isn't enabled by default

BlankSystemDaemon
Mar 13, 2009




fins posted:

that's it.. i'm switching back from links to lynx
w3m is the superior console browser tho

Chalks
Sep 30, 2009

Main Paineframe posted:

it's not really based on checking for the UI

each browser's response to canceling the popup different from the browser's response to not opening the popup at all, in a way that can be detected in javascript

let's use Firefox as an example. if you try to open a known scheme handler and the user clicks "Cancel" on the popup, the result is a blank page. on the other hand, if you try to open a protocol that doesn't have an assigned handler, you get an error page. it's possible to distinguish between those two cases in JS, and therefore determine whether a handler was installed or not

tor browser was set up to auto-deny these handler requests without showing them to the user, but that actually made the exploit worse, because it still worked exactly the same as in vanilla Firefox, except now it was also invisible to the user because they wouldn't get nagged with a bunch of spurious popups

yeah, i was going to ask how this sort of fingerprinting could be effective if it involved popping up hundreds of application open prompts, but i guess their auto deny default makes tor uniquely susceptible to it.

geonetix
Mar 6, 2011


rip mcafee I guess

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
https://twitter.com/gregotto/status/1407780858833125380

Kazinsal
Dec 13, 2011
man spent two decades hiding in south american jungles to avoid paying taxes while making his own drugs and faked two heart attacks to avoid being extradited for murder, then casually walked into a country that has an extradition treaty with the US and got arrested

mcafee was a secfuck og

redleader
Aug 18, 2005

Engage according to operational parameters

cinci zoo sniper posted:

for water boilers coil is perfectly efficient, since water surrounds it - your efficiency is 100% minus minuscule bit of technicalities. doing that via induction would be much more expensive to maintain, for no gains in efficiency

the pro move for water heaters is - once again - heat pumps

unless you actually need to heat it up to near boiling, in which case i'm not sure. maybe a combo heat pump/regular resistive heater?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

i'll never believe it. not mcafee.

i'd put good money on him faking his own death overseas to get out of criminal charges

cinci zoo sniper
Mar 15, 2013




redleader posted:

the pro move for water heaters is - once again - heat pumps

unless you actually need to heat it up to near boiling, in which case i'm not sure. maybe a combo heat pump/regular resistive heater?

heat pump is just energy delivery, heating element that’s inside water is still the same basically. and yeah it won’t get you coffee-hot water, but it’s more than fine for how hot you could want your tap water to be, unless your fetish is getting 2nd degree burns in shower

Agile Vector
May 21, 2007

scrum bored



infernal machines posted:

i'll never believe it. not mcafee.

i'd put good money on him faking his own death overseas to get out of criminal charges

yeah, i've tried to uninstall mcafee on a fresh machine too

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Agile Vector posted:

yeah, i've tried to uninstall mcafee on a fresh machine too

Bet you never thought of threatening extradition though.

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed

cinci zoo sniper posted:

heat pump is just energy delivery, heating element that’s inside water is still the same basically. and yeah it won’t get you coffee-hot water, but it’s more than fine for how hot you could want your tap water to be, unless your fetish is getting 2nd degree burns in shower

what if i need to make coffee in the shower?

cinci zoo sniper
Mar 15, 2013




Plorkyeran posted:

what if i need to make coffee in the shower?

cold brew

ewiley
Jul 9, 2003

More trash for the trash fire

HERE LIES
JOHN MCAFEE
HE NEVER SCORED (with a whale)

necrotic
Aug 2, 2005
I owe my brother big time for this!

haveblue posted:

it doesn't, apparently what happens is they try to open an application url and then figure out if it popped a "do you want to open this app" overlay. not sure exactly how they do that but the presence of the overlay probably has side effects on the dom they can detect through JS

the prompt would block the js thread, you could detect with some basic timing stuff I’d think.

edit whoops shoulda refreshed

FlapYoJacks
Feb 12, 2009

ewiley posted:

HERE LIES
JOHN MCAFEE
HE NEVER SCORED (with a whale)

Here lies Joh Mcafee: Gone but never fully uninstalled

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

ewiley posted:

HERE LIES
JOHN MCAFEE
HE NEVER SCORED (with a whale)

Here lies John McAfee
His trial 75 year subscription finally ran out

Shame Boy
Mar 2, 2010

i can never forgive him for not eating his dick

also the murder thing

spankmeister
Jun 15, 2008






Shame Boy posted:

i can never forgive him for not eating his dick

also the murder thing

the worst thing is he blocked me on Twitter :mad:

An cruiscin lan
Mar 4, 2020

BlankSystemDaemon posted:

w3m is the superior console browser tho

MononcQc
May 29, 2007

w3m is absolutely the best console browser and I use it as an HTML rendered for Mutt as well

Cybernetic Vermin
Apr 18, 2005

just accept that the world has moved on and use browsh.

Sir Bobert Fishbone
Jan 16, 2006

Beebort

Cybernetic Vermin posted:

just accept that the world has moved on and use browsh.

quote:

Browsh is available as a single static binary on all major platforms. The only dependency is a recent 57+ version of Firefox.

That's a heck of a dependency

xtal
Jan 9, 2011

by Fluffdaddy

Shame Boy posted:

i can never forgive him for not eating his dick

Maybe that's how he died

Cybernetic Vermin
Apr 18, 2005

Sir Bobert Fishbone posted:

That's a heck of a dependency

did i mention how you should accept that the world has moved on? just let go and install a full web browser on everything.

cinci zoo sniper
Mar 15, 2013




https://arstechnica.com/gadgets/2021/06/mass-data-wipe-in-my-book-devices-prompts-warning-from-western-digital/

Western Digital, maker of the popular My Disk external hard drives, is recommending customers unplug My Disk Live devices from the Internet until further notice while company engineers investigate unexplained compromises that have completely wiped data from devices around the world.

flakeloaf
Feb 26, 2003

Still better than android clock

our disk live

haveblue
Aug 15, 2005



Toilet Rascal
my disk dead

Kesper North
Nov 3, 2011

EMERGENCY POWER TO PARTY
Well that's no good in My Book

Soricidus
Oct 21, 2010
freedom-hating statist shill
he’s doing it, he’s come back from the grave to eat my disk live on tv

faxlore
Sep 24, 2014

a blue star tattoo for you!

lol apparently the vuln used has been public and unpatched since 2019
https://nvd.nist.gov/vuln/detail/CVE-2018-18472

dregan
Jan 16, 2005

I could transport you all into space if I wanted.

faxlore posted:

lol apparently the vuln used has been public and unpatched since 2019
https://nvd.nist.gov/vuln/detail/CVE-2018-18472

Thought this was about McAfee and was going to be a link to this exploit

Dylan16807
May 12, 2010

cinci zoo sniper posted:

heat pump is just energy delivery, heating element that’s inside water is still the same basically. and yeah it won’t get you coffee-hot water, but it’s more than fine for how hot you could want your tap water to be, unless your fetish is getting 2nd degree burns in shower

a heat pump won't have a heating element though, and you can get something like 400% "efficiency"

BlankSystemDaemon
Mar 13, 2009




MononcQc posted:

w3m is absolutely the best console browser and I use it as an HTML rendered for Mutt as well
w3m is used to render the freebsd status reports to text for the mailing list posts

Sir Bobert Fishbone posted:

That's a heck of a dependency
the only dependency is a few tens of million lines of code, no biggie

Cybernetic Vermin posted:

did i mention how you should accept that the world has moved on? just let go and install a full web browser on everything.
a m68000 cpu running netbsd will build firefox in a few years, i'm sure - so naturally you'll be providing binary packages for it, right?

Kazinsal
Dec 13, 2011
esoteric netbsd forks are not computing environments, they're nerd j/o material

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

Dylan16807 posted:

a heat pump won't have a heating element though, and you can get something like 400% "efficiency"

the condenser is the "heating element" in this context. the refrigerant condenses, dumping heat into the condenser itself, which is then transferred into the water touching it, pretty identically to how an electric heating element gets hot and then transfers that heat into the water.

shame on an IGA
Apr 8, 2005

faxlore posted:

lol apparently the vuln used has been public and unpatched since 2019
https://nvd.nist.gov/vuln/detail/CVE-2018-18472

The product has been declared EOL and unsupported since 2015 lol at everyone still using it 7 years after WD said "no more updates, GLHF"

Adbot
ADBOT LOVES YOU

mystes
May 31, 2006

There's no way this many people were affected unless they're still operating a service that provides remote access or it's using upnp to open a port by default or something. If it has known vulnerabilities wd probably should have at least done something to make it not be remotely accessible by default.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply