1,021 karma · joined June 8, 2014
Micro is like nano re-built for the 2020's. It feels really natural to use with sane key bindings and text selection. I like that it's written in Go and has a nice plugin framework. I might have used it more if a file manager / code tree off to the side was a built-in feature. I found a plugin that could do it, but I had some hassles with it iirc - https://github.com/NicolaiSoeborg/filemanager-plugin
Here's the Python script I cooked up: https://gist.github.com/vesche/ada491d63d77d8afa55a599c787df...
This is interesting and something I hadn't thought about. I have a PinePhone that I've been hacking around on for the past few months. If I had this phone a decade ago I would have been over the moon. I'd really like to make it my daily driver, but I simply can't because of the experience I'm now accustomed to on modern smartphones. My future of being a happy hacker with a fully open-source Linux smartphone in my pocket still seems a few years away, but the future is bright.
Works great for me. I use dark themes via Stylus for most of the common websites I visit like HN, GitHub, StackOverflow, etc. All other websites that cause me to squint I just toggle Dark Reader: https://darkreader.org/
It seems that this Mozilla article is too vague, open-ended, and short to be processed correctly. I personally interpreted the article differently than you did, which doesn't mean either of us interpreted it incorrectly.
I will indeed test both browsers, if Brave is objectively better obviously I want to use it... However, I wish there was just stats on both browsers we could see side by side.
I did find this, https://www.mozilla.org/en-US/firefox/browsers/compare/brave...
Obviously biased because it's from Mozilla, however- I think this argument is moot. They're both better than what else is out there.
I'm not being harsh, you just haven't presented anything beyond empty words.
Everything I hear is just hollow words- "I just disagree with some of Mozilla's business decisions" / "it's more privacy-focused than Mozilla Firefox" / "it's less politically focused than Mozilla Firefox" / "Brave seems to be a little bit better in some aspects"
The article is perhaps poorly titled, and the modern age headline-skimmers will take it at face value. The article isn't calling for more extreme action or censorship... It's saying that deplatforming isn't the solution and what we should do is have transparency of advertisers & algorithms and support / fund research into studies on disinformation. I'm not sure how anyone can disagree with the substance of the article.
Ok, so no political issues... Still waiting on the privacy argument.
Original Tweet came from @vinodsparrow - https://twitter.com/vinodsparrow/status/1338431183588188160
Keep in mind the binary files that contained the backdoor were digitally signed by SolarWinds after being tampered with. So this FTP credential leak might be part of the supply chain compromise, but is not the whole enchilada.
He woke up in the middle of the night not able to breathe with some sort of toxic gas permeating his hotel room.
> "During this time, two hackers contacted Sullivan by email and demanded a six-figure payment in exchange for silence. The hackers ultimately revealed that they had accessed and downloaded an Uber database containing personally identifying information, or PII, associated with approximately 57 million Uber users and drivers."
The hackers were demanding a ransom from Uber to keep silent about a data breach. Which is a whole lot different than paying a ransom to decrypt valuable, internal data. If a company has been breached, while it will almost certainly cause damage fiscally & to their reputation- they have a responsibility to notify users/customers. I'm unfamiliar with the law on this, but it should be illegal for a company to pay a ransom for malicious actors to keep silent about data they stole.
> A lot of exploits are two-stage. Stage one is usually the vulnerability, usually written in C given the low-level and tightly controlled instructions required. The exploit breaks security to run an executable or otherwise gain control. Stage two is usually downloading a python executable to grab the goods.
This seems like a gross oversimplification & commonly incorrect. Often times a "stage one" vulnerability to gain initial access would be network code written in a high level language such as Python or Ruby (see Metasploit). And an executable payload to interact with the system would be generally written in a compiled language like C or C++. My article is detailing the uncommon rise of interpreted languages (especially Python) being used over the past ~5 years as malware dropped on an endpoint in an attack.
> Just seems like a minor observation, rather than some doom trend.
I wouldn't say this is a minor observation or a "doom trend." I'd say it's a very interesting and insightful observation that is worth keeping an eye on. Malicious actors are no longer operating in a world of slow endpoints and lack of resources. They instead are operating in a world of high-speed internet, very fast endpoints, and have a rich ecosystem of open-source tools at their disposal.
I find it highly interesting that malicious code written in interpreted languages, bundled with their interpreters into an executable, are finding their way into the arsenal of high-tier malicious threat actors over the past few years. Just as the web browser is slowly eating away at the operating system, interpreted languages are slowly eating away at compiled languages in a variety of domains- including malware.
> Packaging with PyInstaller to create a single (but large) executable is easy and helps avoiding detection as the interpreter is embedded in the PE
If you look down further in the article it explores detecting PyInstaller generated executable using simple YARA rules. So, I'd disagree a bit there. I personally think that Nuitka (talked about in the article) in conjunction with a packer would be the best compilation method to use in-order to evade detection. It's actually quite surprising to me that limited malware samples have been seen in the wild using Nuitka, but as the title of the articles states- it's on the rise.
I do hope that those reading this will use this knowledge to do good.