This should prevent against replays. Throw in some rate limits somewhere maybe to not get DDoSed, especially if you let socat `fork`.
55 karma · joined March 21, 2018
This should prevent against replays. Throw in some rate limits somewhere maybe to not get DDoSed, especially if you let socat `fork`.
~ % gpt4 'write a very short bash script that takes the number stored in ~/.ssh/knock_seq, increments it by 1 and saves it to the file. It then takes the new number and concatenates it with the value stored in the file ~/.ssh/secret. It pipes the resulting string to sha1sum, spitting out binary. It then takes both the resulting sha1sum and the number used and pipes their concatenation to "nc -u $host $(cat ~/.ssh/knocking_port)". be brief'
knock_seq=$(cat ~/.ssh/knock_seq)
let knock_seq++
echo $knock_seq > ~/.ssh/knock_seq
concat_seq_secret=$(echo -n "${knock_seq}$(cat ~/.ssh/secret)")
sha1_output=$(echo -n $concat_seq_secret | sha1sum -b | awk '{print $1}')
final_output="${sha1_output}${knock_seq}"
host=localhost
knocking_port=$(cat ~/.ssh/knocking_port)
echo -n $final_output | nc -u $host $knocking_portThe attacker doesn't have remote code execution in the xz case unless they can speak to your port 22. Port knocking prevents them from doing so, provided they don't know how to knock.
A = OP supports Mozilla making money from address bar ads
B = Mozilla is honest about making money from address bar ads
"B -> A" (OP supports Mozilla if Mozilla acts a certain way) makes sense. "A -> B" sounds confusing in a sentence, but its contrapositive, "!B -> !A", also makes sense.
However, for:
B = Mozilla decides to make money from address bar ads and is honest about reasons
"A -> B" no longer makes sense, since OP can support Mozilla having the address bar ads with an honest justification, but Mozilla can still decide to not have the address bar ads.
"I'd be willing to entertain, or even support, this way of them making money iff they spelled out honestly what they're doing and why" implies both of these:
- "If they spelled out honestly what they're doing and why, I'd be willing to entertain [...]"
- "If I'd be willing to entertain [..] then they will honestly spell what they're doing and why".
The second of which doesn't make sense to me, unless I'm missing something? He should have used "only if" rather than "iff" here.
It's not too difficult to do so, when there are examples of courts banning satirical poems of a foreign leader from being uttered: https://www.bbc.co.uk/news/world-europe-38934027
Would something like this ever happen in the US? Could you provide an example?
Websites such as http://panopticlick.eff.org/ showcase how fingerprinting works. They tell you how many bits of information they can extract from various datapoints they get out of you when visiting their site, such as User-Agent.
Panopticlick does not use your IP address as a datapoint, but actual trackers most likely do. If not your IP directly, then a prefix thereof (such as your /24), to account for ISPs w/ dynamic IP allocation.
If you have a static IP, there's a lot of bits of entropy in it, i.e. it's great for fingerprinting. It's basically sufficient, by itself, to uniquely identify your home. The handful of devices in your home can then likely be distinguished by the User-Agent.
If you're part of your ISP's small dynamic IP pool (e.g. a /24), there's probably still a lot of entropy in there. How many people in your neighborhood are also on Linux and have the same set of fonts installed? Probably just you.
Your VPN's dynamic IP subnets, OTOH, can be a lot larger, and the members of the pool are not geographically close to one another, so there's probably a lot less fingerprinting entropy in your IP in that case.
Even if you don't have a static IP, I suspect the entropy of your /24 (IPv4) is also a lot smaller when over VPN.
I think this bit of advice is at odds with OP's statement: "I don’t think I’d come across very well (or as sharp as I usually) in interviews at the moment without a break."
I was quite burned out at my previous job, as well, and decided (against most people's advice) to quit without an offer. I had similar "I'd rather give it a shot at being a bartender than write more code" thoughts. I was unemployed for a few months, but ultimately ended up with a few good offers. Leaving without a backup was definitely the right choice in my case.
register: send (username, user_salt, HMAC(user_salt, pwd))
login: send (username). retrieve user_salt. retrieve a server_salt generated randomly. send HMAC(server_salt, HMAC(user_salt, pwd))
But now your password is effectively just HMAC(user_salt, pwd), and the server has to store it in plaintext to be able to verify. Since plaintext passwords in the db are bad, this solution doesn't sound too attractive, unless you were suggesting something else.
How would the server even verify the hash, then?
The issue is that the last employee has to have the moral integrity to fire himself.
I know everyone here wishes this to be true, but what data are you basing this claim on?
Wordpress asks for your name and e-mail to post a comment, doesn't it?
I guess the tuple (ip,name,email,comment_text) is PII?
They claim that they're only striking "chemical weapon research facilities". Looks like it's 4am there, so I guess not a lot of people in research facilities (plus they've been forewarned of the potential strikes)
The base weight for their portable 14.1" one is 1.6kg, but switching from i3 to i7, adding more RAM and choosing a bigger SSD would probably bring it closer to 2kg (compared to ~1.2kg on the x1).
I think the x1 does things like soldering the RAM to the motherboard, which makes upgrading hard, but also makes it really thin (1.5cm compared to 2.2cm for the System76 one).
Since the number of possible configurations on a build your own is quite high, I imagine it's more likely that you'll run into issues on getting everything to work on Linux.