75 karma · joined March 25, 2012
Also this: https://lineage.microg.org/ so you can run a less-google-ish phone, but also run maps if need be.
> Disables native privacy and anti-tracking features
> Disables DNS-over-HTTPS
Why?
Eg I could respond in Pig Latin to you right now because I can see that's what you're asking, but if that particular request were masked or hidden or behind a puzzle, and you received a Pig Latin response well, maybe it's a bot (or a capture the flag sort of a person)
The link went to an imgur image. The image consisted of a bunch of numbers. The numbers were a simple off-by-n alphabet cipher (eg a=8, b=9...) which when decrypted, spelled out a message to the AI. Oh, and also the image looks very dark, a human might not even see the numbers.
This is all ridiculous. But I am wondering about other approaches to see if I can get a bot to bite and reveal itself.
ps: the message once decrypted, suggests that the commenter is incorrect about the thread. I am hoping this would give the bot the necessary pushback it craves to continue the conversation aggressively.
From GitHub comments: https://github.com/signalapp/Signal-Android/issues/10247
Greyson:
> Hi there, sorry, this issue was fixed in 5.17 (which hit 100% production on 7/21)
They had a difficult to reproduce problem reported in late December 2020, and got the fix rolled out seven months later.
Not sure your criticism "absolutely inexcusable slop code" is well considered.
(the rest of us edit and re-edit)
Btw on the second suggestion, I think there's a command named `command` that can help with that sort of thing, avoids recursive pitfalls.
There has been a suggestion that maybe the free plan could just be a time-limited trial instead.
But it feels like there is some risk associated with that - as often a customer will use the free plan for (eg) six months, before hitting the limits and becoming a paid account.
https://www.youtube.com/watch?v=WRS9Gek4V5Q
But my takeaway was more like "Give yourself permission to be bad"
Felt good to be reminded that if you want to make interesting things, it's ok to flail around. It'll feel foolish and that's completely ok, perhaps necessary.
a) a cloud-based password service (eg 1password) or
b) a local-storage password database (eg pass, KeePassXC)
My preference is not to store personal account details with an internet accessible third-party (but I can see the value in it for an organization).
And with the local solutions, it doesn't really seem pleasant to manage, use, synchronize and backup password databases across multiple machines. Also it seems like you're just one laptop disk dying away from possibly losing credentials.
To be clear I'm not suggesting anybody should use my hacky script - the article is meant to be more like: "well I don't love this, but here's how I do things".
Got another approach?
This article documents the setup for AWS SES to handle incoming/outgoing mail delivery.
Eg: one could piggy-back an entirely new file onto an existing file (it might have to be text encoded?).
It looks like the kernel might impose a limit of 64KiB on a file's metadata, but that's still quite a lot of room for data smuggling...