leds

joined 1 year ago
[–] leds@feddit.dk 2 points 2 days ago

Yeah a pull request should be formatted corectly, build, documented, pass all tests and have changes covered in tests.

Your own branch? Do whatever you want, will get squashed anyway in the pull request.

[–] leds@feddit.dk 5 points 3 days ago

Oh they have considered the costs, he is going to use them for slave labour , work camps.

[–] leds@feddit.dk 4 points 1 week ago (1 children)

Even better is that it depends on your instance , for me the preview text is some German text becuase the instance I'm using happens to be hosted in Germany

[–] leds@feddit.dk 3 points 1 week ago* (last edited 1 week ago)

Please see this excellent comment from @athairmor on another thread : https://lemmy.world/comment/13188256

 

I dont know who needs to hear this bit qBittorrent has a nasty vulnerability ( and there are some older ones too)

qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024. If it failed to verify a cert, it simply logged an error and proceeded.

To be exploitable, this bug requires either MITM access or DNS spoofing attacks, but under those conditions (seen regularly in some countries), impacts are severe.

The primary impact is single-click RCE for Windows builds from 2015 onward, when prompted to update python the exe is downloaded from a hardcoded URL, executed, and then deleted afterwards.

The secondary impact for all platforms is the update RSS feed can be poisoned with malicious update URLs which the user will open in their browser if they accept the prompt to update. This is browser hijacking and arbitrary exe delivery to a user who would likely trust whatever URL this software sent them to.

The tertiary impact is this means that an older CVE (CVE-2019-13640 https://www.cvedetails.com/cve/CVE-2019-13640/) which allowed remote command execution via shell metacharacters could have been exploited by (government) attackers conducting either MITM or DNS spoofing attacks at the time, instead of only by the author of the feed.

Full write up is here: https://sharpsec.run/rce-vulnerability-in-qbittorrent/

[–] leds@feddit.dk 4 points 2 weeks ago

Yep I guess old tricks will still work , attack with the sun behind you and they'll never see you coming

[–] leds@feddit.dk 49 points 2 weeks ago

"Who is the current president?"

Yeah that one might be an issue for him..

[–] leds@feddit.dk 1 points 2 weeks ago

How else would they get in your ear?

[–] leds@feddit.dk 8 points 2 weeks ago

Smells like SAP

[–] leds@feddit.dk 1 points 3 weeks ago

I read that as genitals...

[–] leds@feddit.dk 3 points 3 weeks ago (2 children)

Best I could find

[–] leds@feddit.dk 1 points 3 weeks ago

The GOP is recruiting an "army" to monitor the vote

The GOP is recruiting an army to "monitor" the vote

Or

The GOP is "recruiting" an army to monitor the vote

[–] leds@feddit.dk 1 points 3 weeks ago (1 children)

Dems deluded themselves the same way with Obama. You started to see the economic rebound practically the day he stepped into office. Either Obama was a wizard or we were experiencing a natural market rebound before he'd done anything.

That's not so strange , businesses are nervous before the election and will hold off investing. As soon as a reasonably sane politician is elected they will start investing again.

 

so.. i'm running lineageOS on my phone (a Oneplus 6T) , have been for a very long time. Usually i'm really happy with this but not tonight:

  • Phone suggest a update of OS , just a weekly build. Sure why not, so it does it thing and i reboot, all good.
  • Open a app to listen to some podcast: screen goes black flickers a couple of times showing empty launcher. thankfully power button long press shows shutdown menu (but looks different from normal?) and lets me restart
  • do same thing again , ok looks like latest update broke something
  • update app, same
  • go to settings , updates to try to revert to previous version: no option to install older version , only option is export. weird ok lets try to export old version . Now it lets me install that
  • installation loops , seems it failed
  • try app again, same black screen , hold power button to get boot menu again : now phone says ERASING .. wait what stop no .. (does lineage have a panic wipe my phone key combo i didn't know about?)
  • rebooting , rebooting again
  • welcome setup your phone screen :(
  • remember that my cloud server disk burned last week , no way to restore backups :( :(
 

Merged

 

Last paragraph makes a good point

But now it’s been a decade. Everything he knows is old and out of date. Everything we know is old and out of date. The NSA suffered an even worse leak of its secrets by the Russians, under the guise of the Shadow Brokers, in 2016 and 2017. The NSA has rebuilt. It again has capabilities we can only surmise.

 

Hi All, I recently got myself some proper headphones and DAC but now I realise I don't have much high quality music , my collection is mostly flac but only very few higher than 48k. So where do you get your music? does it even matter beyond that?

view more: next ›