* Posts by Evil3eaver

18 publicly visible posts • joined 15 Jul 2013

United States Congress stormed by violent followers of defeated president, Biden win confirmation halted

Evil3eaver

Re: ...and where exactly do you live in the US?

Canada (426/1000000)100 = % 0.0426... %99.9574 recovery rate

USA (1059/1000000)100 = % 0.1059... % 99.8941 recovery rate

Japan (31/1000000)100 = % 0.0031... % 99.9969 recovery rate

Canadian's are in general healthier people than Americans, obesity and diabetes are two big factors in deaths below the age of 70.

Italy had many deaths as well but they are a country known for having some of the longest lived people in the world... Age is another factor.

Not trying to defend anyone here just trying to show some of the logic behind the numbers. Personally I think all governments have taken a facility approach to society in general. The measures being used work well for a facility/lab but horribly for society at large.

Take Japan for example they have a low death rate but they only suggested the lockdown (not enforced) of the most vulnerable (the elderly) and they have some of the lowest death rate in the world. So your numbers don't have much meaning unless to bring it into context.

I have seen demonisation on both side of the political isle so if you argue a point that can be backed up with facts don't forget the most important thing is logic. Just spewing numbers like it has meaning is pointless to those who do their homework but only confuse the rest.

Biden won, he will be inaugurated. It is done, go home relax and keep the peace. Gas lighting will only get innocent people killed whether you are red or blue.

<<<Be careful when hunting monsters lest you become one>>>

JetBrains' build automation software eyed as possible enabler of SolarWinds hack

Evil3eaver

Re: The good news is...

You should have wrote:

from Russia import WithLove as backdoor

Why make games for Linux if they don't sell? Because the nerds are just grateful to get something that works

Evil3eaver

Honestly as a Linux user I don't care if it is native (dxvk works extremely well) to Linux as long as it plays in Linux (smoothly of course). I don't understand why game companies will develop for a console which other than Microsoft is a *nix system. What allows a game company to "develop" for specific platforms all they need is a good test environment and considering proton are static releases I don't see why these companies don't test for steam play. Yes it adds a bit of time but I don't see how it could be that detrimental. I would think that if it works gravy smooth in proton then it will guarantee to work on windows no problems. At any rate the devshops just need to add one more set of test cases. Considering that steam provides a known baseline and I'm sure that steam has testing harnesses for their platform I don't see the issue in putting steam play as a test case.

So just make it work with steam play and you are guaranteed to have at least an extra buyers even at 100K users worldwide and since most new AAA games sell for around 80.00 CND that isn't a bad deal (100000 * 80 = 8 million). 100K users is not a big number in at least 4 billion people that would be potential buyers.

Think how cool would it be if you had a "SteamPlay certified" label on games.

Donald Trump extends ban on Huawei, ZTE telecoms kit in US companies to May 2021

Evil3eaver

RE: Legitimate Question

You make a valid point, yes you can encrypt but depends on the encryption. Many of what is called end-to-end encryption services have a proxy in the middle. Now depends on where the equipment is placed you may be able to spoof that proxy. These days people have forgotten that they can host their own stuff cause "The clouds", plus most corps employ in-house the lowest common denominator because they are unwilling to pay what "experts" expect. So in-house hosting is usually out of the picture, and when you use 3rd party services then well you hope they don't get hacked or someone figures out how to spoof that service's proxies.

That said this doesn't include if a flaw has been discovered in the crypto your using, or computing power is powerful enough to decrypt in reasonable (usable) time frame. That said regarding this issue the real threat (at least the only threat) isn't so much what Huawei provides to countries to do security evals on but what auto-update mechanisms exist within it allowing the CCP to mandate a "special build" or intentionally embedding obscure flaws that can be exploited to facilitate certain attack types. I guess there is also the concern that if equipment is implemented in the field by a bad actor they could be maliciously configured as well.

AFAIK the only one's that are even checkable would be the code flaws but those become very difficult when they are intentionally spread across many libraries that provide a multitude of functionality. The computing power, CCP mandated "special firmware" edition, maliciously implemented configuration are very difficult to guarantee and maybe unknowable but preventable except computing power issue. With computing power you can't just rely on crypto to protect you but on the very equipment it is running on. Although the malicious configuration is an issue for all technology not just Huawei.

You can make the most secure OS the least by disabling security features and the least secure OS the most secure by disabling services (worst case pull the power... ultra secure, just not usable).

Microsoft frees Windows Subsystem for Linux 2 from the shackles of, er, Windows?

Evil3eaver

Re: But excessive diarrhea is not one of the symptoms.

I'll take TP not BTC thank you very much ... I'm making a killing ;)

Evil3eaver
Facepalm

But excessive diarrhea is not one of the symptoms.

BTW here is my new escape room, what you think:

https://s3.amazonaws.com/img.kh-labs.com/eRbXvs5e2fa8a0349ed4.02691959

Evil3eaver

Re: @Martin Gregorie - Or bigger still..

Microsoft makes more money from cloud services than they do on OS (mutiples more) so it isn't too much a stretch to think that they could sell the windows shell as gui for linux... if that came with a Microsoft version of Wine/DXVK then I would have zero problems paying the same price I do for windows but have a base OS that I have control over.

IMHO I would rather this than having all these silo's working on kernels instead of having what we currently have two major camps (Unix/Linux) that are very similar in how they work (often it means fixes for one are almost carbon copies for the other) and the one odd one out Microsoft with their very own (unique) kernel.

There would be less security issues over time and rock solid OS stability (GUI's may crash but the base OS is still functioning, and can recover from it without total BSOD explody stuff you get with Windows.)

That said I would prefer that MS chooses Linux instead of BSD just because of its free/Open nature but they would probably choose the later like Apple for obvious reasons. I would still be okay with it and probably buy it anyway... mind you VM's with HW passthrough would be less of a pain getting to work reliably :)...

Rockstar dev debate reopens: Hero programmers do exist, do all the work, do chat a lot – and do need love and attention from project leaders

Evil3eaver

"manage these people more efficiently by retaining them"

Honestly with all the COCs flinging around over the last couple years, how can you be progressive and inclusive if you treat one or a few better than the rest cause they are just better than the rest.

BTW I do agree that everyone should be treated the same under the law but I don't believe everyone is "the same" though. People just have different talents thus making them better at certain things and less so at others. So no people are not equal but all people should be subject to the same rules.

Equality of opportunity yes

Equality of outcome no

Microsoft picks a side, aims to make the business 'carbon-negative' by 2030

Evil3eaver

Re: I call marketing bullshit

Item 6 if not kept a close eye will destroy all life on this planet... 418 ppm will be more like 800ppm if we don't get a handle on them.

Evil3eaver

Re: Truly hope this is not just a marketing ploy

Drivers is the reason, and almost always the reason.

GNU means GNU's Not U: Stallman insists he's still Chief GNUisance while 18 maintainers want him out as leader

Evil3eaver

Re: The deep IT

WTF are you talking about 99% of industrial computers are linux... yes in the office where people use word and excel yes that is proprietary but all the iot sensors out there... seriously where in hell do you get your information.

What about the billions of Android devices out there. Has anyone ever heard of AWS, or Facebook, or Google, or Twitter, or Snapchat or Instagram, or or or or.... All linux ALL of them.

Seriously what is wrong with you, even Microsoft realises it, making and Android phone, and bringing many things to native linux not to mention the most recent desire to bring IE to linux.

Holy crap you are delusional to think that anything serious is doable in windows. Maybe Mac OS sure cause BSD not cause Apple. Heck any time I have to do binary reversals or profile a system it is always infinitely better from Linux than Windows, windows with all its "that folder is too deep" and "that filename is too long" and "I can read anymore cause, I don't fucking know I'm windows use a real system to figure it out".

I don't know how many times that I'm tearing through TB's of data and windows blows up and I have to start over again. Never have anywhere near the same issues on Linux, it just works.

So yeah any serious works does not get done on Windows. Those who do, are kinda like people kept their 8-track cassette players decades past their utility or these days DVD's and CD's. So yeah people who think "It must be done from proprietary" are complete dumbasses. It should be "what ever gets it done, I don't give a fuck just get it done" which Linux has and will always be the quickest and easiest path there. Its free, no need for approval from finance just do it. No need to deal with problems of deployment cause licenses or how about license servers like flexlm or ace... no worries about that anymore just git-your-chit-going.

The mod firing squad: Stack Exchange embroiled in 'he said, she said, they said' row

Evil3eaver

Got one question about the following excerpt:

"The disagreement stemmed from an interpretation of a certain policy, but our CoC is not up for debate."

How does a CoC come into existence if it is not up for debate?

Four-year probe finds Foxconn's Apple 11 factory 'routinely' flouts Chinese labour laws

Evil3eaver

Re: Don't worry iPhone users will...

So your good with child labour then.

Electric vehicles won't help UK meet emissions targets: Time to get out and walk, warn MPs

Evil3eaver

Re: Alternatively,

Would be the worst thing though methane is known to be a much strong green house gas than carbon dioxide. And then there is:

https://99percentinvisible.org/app/uploads/2017/10/poop.png

Would not work.

Microsoft: Reckon our code is crap? Prove it and $30k could be yours

Evil3eaver

Re: Not very profitable.

First thought I had was... 30k really like real hackers make millions how you gonna think your going to attract anyone for 30K most companies pay 10K per bug cause it actually costs that but considering they are saving heaps of time on top it is still a deal. 30k Total ain't gonna git you much.

There's Huawei too many vulns in Chinese giant's firmware: Bug hunters slam pisspoor code

Evil3eaver

Re: So, how does this conpare with other mfgs of similar products?

Does it really matter if they are better or not than others, the Brits have more than one report on the matter and it iterates several times about engineering practices and things aren't getting better. Does anyone understand what a "smart" future means regarding these type of vulnerabilities... green lights in ever direction at intersections, Baltimore (need I say more, https://en.wikipedia.org/wiki/2019_Baltimore_ransomware_attack), banking systems taken out over night, power grids, trains, plains and automobiles.... never mind someone hacking your facebook type stuff is of negative concern. I don't care who makes it, even the guy sitting beside me, all critical infrastructure technology must be audited by 3rd party so these tech companies better be ready to hand over source or no critical infrastructure contract at all, that is my opinion and full disclosure I do white/black box auditing but having seen some of the stuff I have seen is why I feel this way.

Imagine buying a car without a crash test rating, black/grey/white box is the technology equivalent of crash test and if the auto industry is forced to do this before they can even advertise a model then all critical infrastructure appliances/IoT/computer/digital/electronic/telecoms.. must be audited.

Large Redmond Collider: CERN reveals plan to shift from Microsoft to open-source code after tenfold license fee hike

Evil3eaver

Re: Its the updates

There is your problem don't use 3rd party repos. I know it is hard sometimes to not do this but you will have an extremely stable experience. FYI what you can do is install synaptic and select the library in question and press ctrl-E (or select Package in the file menu and then select "Force Version") which will let you revert back to original ubuntu repo version so you can undo the 3rd party repo changes. It's a bit of pain in the a$$ but things can be fix ... unlike windows where your pretty much F'ed and clean install is by far the easiest and quickest way to a fix.

Advice to the linux noobs, only use big vendor 3rd party repos like oracle (cringe, don't like to say it but...) google (again cringe, do(n't) be evil) or repos that have had many years of existence.

I know it is a bit tough at first for everyone who has made this transition has had these pains but it does subside.... talking from experience.

It took me about 5 years to go from "WTH just happened, black screen, WTF is going on", or "What is this kernel panic thing repeating on my screen, WTH is a kernel..." or being told (post 2005) "be careful if you don't set things properly in linux you could burn out your hardware" to being the linux expert in the office. Now I run my own lab and only use Windows where I am forced to (and believe me I fight to get a linux desktop every time). Was recently told that my workstation in the lab are going to upgraded and since this is my lab and I am responsible for everything within it I demanded linux, and the excuse what about new people that come in... my response is "This is security engineering, there is no such thing as I don't know linux and if that is the case why did you hire him/her... I don't want them". Like seriously anyone who has graduated any security course like anywhere in the world has heard of Kali so no excuses. If you passed your course then you know linux, period.

Analyst: Tests showing Intel smartphones beating ARM were rigged

Evil3eaver

Has anyone thought it could be the old "if not genuine intel take the slowest path" "optimization" (they forced all non-intel CPU's to only use i386 microcode instead of any newer optimization that could do the work in 1/4 of the time) ... they have been found guilty before in the PC world, why wouldn't they play this game again ;)

http://www.agner.org/optimize/blog/read.php?i=49#49

http://download.intel.com/pressroom/legal/AMD_settlement_agreement.pdf