169 karma · joined February 3, 2013
I suspect the actual reason for it coming up in law was because of the XSS company somebody registered some time after my meme went around. That one actually did work*, and as I understand it, there was no recourse available to companies house - they are legally obliged to accurately record company names, and the law specifies which characters can be in company names, meaning you could always serve XSS there, which they're not a fan of.
That said, they forced my company name to show as 'name available on request' now (even on letters they send me, which is kind of funny), so apparently they did find a workaround.
* On third party systems consuming the data*
Not that I've ever done that
Professionally nowadays I'm a pen tester/security consultant.
Basically true, though:
- Aryan wasn't the first clientmod, not even the first to deob - probably the first to go fairly 'mainstream' and end up being well known outside the circle of people using it, though (being free probably helped here)
- No legal action, tbh. Well, the same amount of legal action that all of the cheating scene got (some C&D's, domain takedown attempt type stuff at various times, but not the scary kind of legal action in the way other bots got)
- The banwave backdoor did happen, and basically as you say (iirc it was the actual UID but negative, rather than -1) but was more of a conscious decision, there wasn't an 'agreement' beforehand - it was proactively taken. Jagex were informed about it in order to detect it though, as far as I'm aware.
EDIT: Nevermind they added something to the countermeasures repo that goes against that.
Bank account was actually incredibly easy, that is the one I expected to be difficult, too. I had no problems at all, I made an account with the usual process. Should note I'm using one of those new-fangled 'challenger banks' so they're probably quite tech savvy/their systems aren't 50 years old, that probably helped.
The worst one has been the domain name, oddly. I wanted to get the .ltd.uk domain name (only available to registered companies in the UK) to basically complete/highlight the joke. But, I have been waiting for over a year or something now for it to actually be registered, it keeps being rejected by the registrar (there is a weird validation process to make sure you're a real company, etc). I could have sped it up by trying with a better registrar who are more aggressive at getting things done, probably, I had a few offers from smaller registrars - but I just went for the .co.uk in the end instead.
Not that risky though - it looks more like an SQL injection than it actually is. I actually didn't think it would get this much attention - I went to bed!
If you like irssi, but wish you had a better way to use it on mobile, you might like Weechat - that's how I use it currently, terminal over SSH on desktops, mobile client over the relay protocol on the go.
I found that it took a few 'goes' at the vaping thing before I properly 'got it'. I enjoyed and saw the benefits of the vape from the first time I used it, but went through a few cycles of vaping-and-the-odd smoke, then a few weeks of only vaping, then back again, and almost gave up on the whole thing. Then for some reason last February, it clicked and I ditched the smokes completely. Not had one since then. No interest in smoking again, ever.
I've described it to friends and family as being a bit like I imagine methadone is to junkies, though no personal experience there. It doesn't initially fill all the holes in quite the right ways (for me anyway, some love it immediately but I suspect those are the 'odd ones out') but is 'good enough' that it can work - it does however take a little effort to make work, it's not a magic silver bullet.
It certainly was a lot more effective than any time I've tried to stop smoking using anything else, though.
Technical: SNI breaks older browsers (IE on XP, older mobiles). Also requires a modern (ish) OS on the server, if using CPanel, which like, every shared host in the world is pretty much.
User Education: Explaining exactly which clients will be broken is hard, etc.
#2 is basically gone now, because the users who would be broken are broken by the removal of SSLv3 and insecure crypto anyway - so we've now already killed them and can SNI without having to explain anything complicated to the user.
"If you want to be a Millionaire, start with a billion dollars and launch a new airline."
How do you have a language spoken by so many wildly different people, who bring in their own vocabulary with each generation, and not end up with irregularity in spelling and pronunciation?
English is a mongrel, certainly, but that is a product of it being so widely 'deployed', not an inherent feature of the language. Sure, Italian is regular. Italian also doesn't have germanic roots all over the place mixed in with the latin and chinese and whatever else.
That said, isn't 'IaaS' like Heroku basically 'shared hosting for other stuff'?
What about all the browser sandbox escapes that rely on kernel vulns?