18 karma · joined August 2, 2023
The company made some basic port scan and established that we're running outdated and vulnerable version of Apache. I found the act of explaining the concept of backports to a "pentester" to be physically painful.
They didn't get paid and another company was entrusted with the audit.
Even their server libraries are obfuscated, and hooking open() turned out to be just easier than trying to patch the binaries themselves.
[0] https://medium.com/@prizmant/hacking-punkbuster-e22e6cf2f36e
To this day, I can't comprehend how this is supposed to be safe. So someone can just type in my username and wait until i eventually misclick in the Authenticator app? If it was from a browser I have used before at least, but I was getting these challenges from around the globe.
I can definitelly see pages with lists of candidates, but I couldn't find a single one that would also link their websites and thus satisfy the query, at least indirectly.
Page 1: Biden, Williamson and link to an article Google hides campaign sites of Trump, RFK Jr. and other Republican candidates
Page 2: Biden again, Pence
No further pages. 5th result contains an article that claims to be linking all presidental candidate websites, but it's a Medium, hidden behind sign-up. I haven't find any result with a comprehensive list of the websites of interest. Kagi does aggregate results from Google and Yandex, so this is probably not too surprising.
I'd be more concerned about everyone else: https://iknowwhatyoudownload.com
Actually yes, C&C Red Alert 2 was running slow, but the community came up with patches that make it play nice, including the multiplayer which now works better than it did back in 2000.
It's purely anecdotical, but I'm convinced that Google CAPTCHA (which I don't see more often only because I rarely use Google Search) punishes me for being fast. I can half-ass it or do a perfect score, but if I'm done with it in less than 3 - 5 seconds, I'll only get another puzzle as a reward.
For now. But we're slowly walking towards the future where you can only consume web using an official and conformant browser running on a locked-down platform. That'd make it considerably harder for spammers, but of course spam isn't what this is about, it's more like a cherry on top.
For e-mail, I use a domain with a catch-all mailbox. I rot13 the service name or whatever in the local-part to identify where the e-mail got leaked/sold from, which I feel like happens more often than not when buying anything from small e-shops.
I also try to keep my browser's headers more generic, especially the Accept-Language header (not applicable or particulary helpful for US residents, though). The rest (VPN, [and therefore] no Google and no social networks) I wouldn't consider an obfuscation.