4,353 karma · joined November 3, 2016
At best, their algorithm flagged it, and a human rubber-stamped it.
But then they were sloppy enough to use the 360-based audio encryption path (which had an extra step versus the PS3) on later non-360 consoles and include the needed HvKeys to decrypt the keymask in cleartext, even though they could have successfully decrypted every single audio file that wasn't RB1 on-disc or early DLC by using the PS3 path and not revealing those keys. I don't care about public discussion of this at this point because there are a dozen tools that can decrypt every single Rock Band audio file ever created (and even audio for games that aren't RB but used "mogg" format which is just multichannel Ogg Vorbis with a Harmonix-specific header with security values and an OggMap to aid in seeking). There's even one tool that can decrypt audio that uses the "red" keys which have never been seen to be used publicly. Game dev is fun.
If you've ever heard of Guitar Hero II Deluxe, that debug ELF made that possible. Also if you've played it, you're welcome.
However, the headline itself does not say anything like that. It simply says they "killed" the website. Which they did, via legal threat. I think the specific wording they used was more engagement bait than anything, and honestly a quite mild version of it compared to many. Might even have been completely unintentional.
If anything, now you can say that EA is doubly the worst company, especially in gaming.
Anyone got a Tampermonkey script or tiny extension to re-override this to make such sites actually center in the viewport, like I prefer?
Your viewpoint enables billions of dollars of fraud every year, worldwide. Mine doesn't.
Email has similarly been destroyed by HTML email, at least partially.
It's like there is a coordinated effort to destroy every single legacy protocol and replace it with something centrally controlled. No fucking thank you.
Let's ask Vint Cerf whether the web was meant to run logic, or just be a document format. I bet no matter what he answers, the world would be like the GIF pronunciation "I don't care if the original creator said it's pronounced like giraffe, I'm gonna say it like gift because I KnOw BeTtEr"
Internet 3 when (because I know that academia does already have an "Internet 2", although I bet due to Internet 1 security issues, Internet 2 is already compromised too)
We're losing general-purpose computing like frogs in a slow cooker, and millions of people don't even notice. Fuck TPM, fuck hardware attestation, no internet company should get a single bit from me that I don't authorize. Any site that requires hardware attestation will be a hard "no" for me to ever visit again.
I maintain this all started when commerce was introduced to the internet. Things were better before money was transferred digitally. Allowing that was a major fuckup.
I bet the world would crumble. Good.
To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.
This can heavily be mitigated through technique. If you walk straight and just turn? Yeah, the corner is missed. If you explicitly come to a stop and do your best to do a full 90-degree turn before moving? The only curve there is going to come from the shape of the blade, and is almost guaranteed to be a tighter curve than just walking and turning without stopping.
Yes, it takes longer. But if it's worth doing, it's worth doing right, even if it takes twice as long, no?
I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).
JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.
Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.