Nope. I don’t talk about myself like that.

  • 0 Posts
  • 18 Comments
Joined 2 years ago
cake
Cake day: June 8th, 2023

help-circle
  • And I’m addressing your statement that “an IP address is 4 bytes” in specific. I understand their example is IPv4, but you just blatantly said that “An IP address is 4 bytes” when that’s not the case for IPv6 which a good chunk of the world is using now (still not a majority though…).

    His code takes the base64 of anything that’s returned in both (together) ip and timestamp. So the long string is both values concat’d then encoded. Most of that string is going to be the timestamp…

    Specifically MTEuMjIuMzMuNDQ is 11.22.33.44
    Where ---KIApTdW5kYXksIDI3LUFwci0yMDI1IDE1OjA0OjM5IENFU1QK is the date string Sunday, 27-Apr-2025 15:04:39 CEST.

    While it’s still a “bigger” value than it needs to be, it’s not like it’s the end of the world for an email address. I mean, if we really want to get “fancy” most people don’t know that you can just go to an IP address in it’s decimal form…

    1.1.1.1 -> 16843009 (http://16843009) No need to encode anything special at all in that case. But that’s neither here nor there… Can always make your own with blackjack and hookers of course.




  • Right but my point is they would just submit the request to the host server. If the original is taken down then all the federated service will lose the comments as well.

    Not how federation works. Let’s take a lemmy post as an example. If a server is federated with another and a new post is made, all subscribed servers are notified and a copy of the item is sent in that notification. If the original is “taken down” the copies still exist on the other servers and any deletion event is in ALL of their modlogs. ANY instance can “undelete” or revert the removal, or just ignore the deletion request all together (or roll back the database, or any number of operations to revert a change). The items doesn’t just go away. The “origin” doesn’t have all that much power to force other listening servers to do anything.

    This also extends to comments. I run my own small instance with me and a few friends. My server never had serious downtime because it’s just us. Our access to larger instances never “vanished” even as their sites went completely down. The local content is effectively cached regardless of the state of the origin server.

    If the host server just straight up ignores turkey then they’ll block all servers that host Mastodon

    Good luck with that… There’s a lot of servers that can talk the same federation protocol. You’re not going to get them all. Forget all the normal means of bypassing blocks… you have so many fediverse and threadiverse servers to attach to in order to access largely similar content.



  • I was going to leave this alone… your original comment was correct enough that it wouldn’t matter and your “dedicated attacker” left it fine when i read it before.

    but your edit has a gaping flaw. you assume that all content in the library would be physically released. lots of shows and movies are not physically released now. Can’t claim “backup” for those. The moment a movie studio finds your stuff and can map a few titles and one of them never had a physical release… your in the shit.

    but yes you can be much harder to scan overall with a few steps. fail2ban is a great answer that makes it deeply unlikely to be an issue.

    but i wish that they’d just fix it.

    edit: OR that they wouldn’t try to go after you for distribution…


  • All of these “vulnerabilities”, require already having knowledge of the ItemIDs, and anyone without it poking around will get banned.

    Which are simply MD5 hashes… You can precompile (rainbow tables) those. The “knowledge” here to get a valid video stream is “What path is the file on” which is pretty standardized. This is a good way to have a major movie studio’s process server knocking on your door.



  • They can also crawl this publically-accessible social media source for their data sets.

    Crawling would be silly. They can simply setup a lemmy node and subscribe to every other server. Activitypub crawler would be much more efficient as they wouldn’t accidentally crawl things that haven’t changed, but instead can read the activitypub updates.



  • You using crypto to buy your toilet paper is not a mass scale use case and it is irrelevant.

    So then you claim that being able to buy stuff isn’t a “mass scale” use case…

    You realize that’s fucking stupid right?

    As I said, I can and do buy things regularly (though “rare” comparatively with the normal fiat purchases) with crypto. Other’s can do with me as well as the sites that I do it on do it as well. I can prove that by looking at the block chain and seeing the traffic in their wallets.

    So “way to go man!” Unless you actually have something more meaningful than “nuh uh”. You’re kind of full of shit.

    Edit: Lack of “big” vendors doing it != not possible at mass scale.

    Dell at one point accepted crypto. They stopped because of regulation, not because of technical limitation. And sites like Newegg still accept it.


  • Over the 15+ years that we’ve had crypto, there have been only two viable uses. All others have failed:

    Criminal activity (including brutal stuff like enabling NK/Russia and drug cartels)
    Financial speculation (in of itself often a malicious activity where the goal is to dump your worthless bags on a mark)
    

    Huh, Weird… Every use I’ve ever used crypto for doesn’t fall into these two categories. So I guess your assumptions and thus everything you based your logic/responses on must be faulty and incorrect.

    I use Crypto much like I use my second language/citizenship. Rarely… However, that doesn’t mean I don’t use it legally. And simply holding onto the crypto != financial speculation. Nobody treats a savings account as “financial speculation”.

    I’ve paid for plenty of things from my crypto wallets. Ranging from several to thousands of dollars.

    And yes, I would like my payment for toilet paper and bell peppers to be private. Strictly for the fact that I don’t want Mega-corpo stores to be able to track and advertise to me based on my payment method. “Club cards” to advertise/track you are a thing. Large chains can do this same thing with payment methods details. So yes, being “real” here, I not only require it, but demand it.

    Your premise is bad. And based on your other responses you don’t care to address it at all.




  • yes. windows xp was a fully local OS, and when you installed it, you stilled owned your computer. these things are not true of windows 10.

    Yes you can? It’s windows 11 that tries to lock you out, and even then you can install it without internet if you know the magic incantation…

    But windows 10 will just install with a local account if you don’t give it internet (unplug ethernet and never setup a wifi).

    sure, and I could say you’re a chainsaw juggling pedophile lizard person who came from the future to make sure flavored foams don’t have a resurgence in upscale dining at any cost because the consequences, drawn out 200 years, are so much worse than fascism and several possible extinction events. saying shit is easy. doesn’t make it true.

    The fuck? Any linux install will eventually become unsupported. That is my claim to counter your nonsense claim of Windows becoming unusable.

    Go take your pills.