• 0 Posts
  • 19 Comments
Joined 2 months ago
cake
Cake day: June 8th, 2026

help-circle

  • No, the cold wallets were using a predictable algorithm to generate key phrases. When you set up the wallet, you use the generated key phrase to pair it with your coins. So this wallet is supposed to live offline, keeping your coins safe because the key is kept offline. No way to hack it if it’s entirely offline. But a flaw caused the generated keys to be predictable, meaning hackers were able to brute force the keys and initiate coin transfers without even messing with the cold wallet.

    Imagine you lock a million dollars behind a super secure vault door. This vault is impervious to all kinds of physical and digital attacks. The only way to open it is with the key. The vault is in a public area, but (again) there is no way to open it without the key. This vault only has one key, which you keep safely stored in a separate secure facility. Additionally, this key has like a thousand pins and tumblers, so it should be nearly impossible for a hacker to guess the correct key. The hackers essentially realized that due to a flaw in the lock’s design, there were only like three dozen potential key combinations. The thousand pins didn’t actually matter, because they were predictably arranged at the factory that built the lock. So the thieves just made like two dozen fake keys (until they got the correct one,) then took the money. All without touching (or even seeing) your key.



  • The issue is doing one at scale, with proper access controls. Also, let’s not skip past the whole “network isn’t air gapped anymore” side of things. Now you’re having to maintain firewalls, patch firmwares, manage users, enforce good password hygiene, etc… All without any additional IT support or hardware, because management is doing this as a cost cutting measure.

    I can pretty much guarantee that the systems that get hacked aren’t the ones that do everything right. They’re the ones who have a single shared VPN password, haven’t updated their firewall since it was installed 8 years ago, and they haven’t even changed the default passwords for their control systems. Because they got tired of answering phone calls about what the password was, so they just made every username and password something stupid like admin/admin.




  • The scary part about this is that he likely has zero actual support from any kinds of disability, because chronic Lyme disease isn’t officially recognized in the medical world. Or rather, they recognize that there is a correlation between Lyme and long-term impairment, but they have no treatment nor palliatives for it. So they just sort of say “deal with it. Most people can return to work after a few weeks, so you can too.”

    Sort of like how long COVID affected (and still continues to affect) a sizable part of the population, but government disability in America didn’t recognize it as official so patients with long COVID had to keep going to work even when they were dealing with debilitating long-term symptoms.




  • Monopoly isn’t an awful game if you actually play by the rules. It’s not great, but it’s not awful either. But most people don’t know all the rules, make up a bunch of stupid house rules, etc… And as a result, the game drags on for hours even after it’s clear who the winner will be. In reality, playing by the rules has each game lasting like 20-45 minutes.

    For example, most people know that when a player lands on an unowned square, they get the option to buy it. Straightforward, right? But most people don’t realize that if that original player turns it down, it goes to auction. The players can submit bids to purchase the square, and they can start far below market value. Meaning that all of the squares should get bought relatively quickly, instead of taking like ten rounds. There is actually a strategy to refuse to buy a square, to intentionally send the property to bid, just so you can then potentially buy the properly below market value. Basically, Player A lands on a square. Player A refuses to buy the square at the market price of $1000. Player A then wins the bid at $800. Player A effectively got a $200 discount, simply by sending the property to auction.

    Also, the bank can’t go bankrupt.

    You can run out of houses to build. Know how you can upgrade four houses to a hotel? And the game only has 32 houses? The hotel increases the square’s rent, but returns the houses to the available pot. It’s actually a perfectly valid strategy to upgrade all of your properties to four houses, and then refuse to upgrade any of them to hotels. Since the game only has 32 houses, you can use ~7 properties to effectively lock out any hotels from being built. And since nobody can build any hotels while you’re sitting on all of the houses, your 4-house properties are effectively the most expensive in the game simply because nobody can upgrade their properties while you’re hoarding all the building materials.


  • Nope, I’ll spoiler the story (in increasing levels of graphic detail) below:

    Low detail

    It’s from a post by a male escort, who was supposedly hired by Graham. The escort found an interesting skin condition on Graham’s nether-area. Graham then referred to it as “my ladybugs”.

    Medium detail

    Graham supposedly hired a male escort. They got back to Graham’s hotel room, and the escort saw something odd in his ass/taint area. The escort asked Graham if he could wipe everything down before they began, and Graham agreed. The escort got a damp towel, but nothing was coming off with the towel. That’s when the escort realized Graham’s butthole and taint weren’t dirty, they were covered in moles. Graham then referred to them as “my little ladybugs”.

    High detail

    Graham was (in)famous for supporting anti-LGBTQ+ legislation. He was also supposedly a pretty prolific male escort customer. One escort made a post accusing Graham of such, essentially saying he was a hypocrite and asking other escorts to share their stories.
    Another escort made a follow-up post, to share a bedroom story: Graham had gotten… In position to be intimate. The escort saw something weird around Graham’s asshole, so he asked if he could wipe things down before they started. Graham agreed. So the escort dampened a towel and went to work, but nothing was wiping off. That’s when the escort realized his asshole wasn’t dirty. Graham supposedly had tons of moles all over his ass and taint. As the escort was trying to comprehend what he was seeing, Graham chimed in with “Hope you don’t mind, those are just my little ladybugs.”

    The full context of the original post

    Male Escort 1’s Post: There is a homophobic Republican senator who is no better than Trump, who keeps passing legislation that is damaging to the LGBT and minority communities. Every sex worker I know has been hired by this man. Wondering if enough of us spoke out if that could get him out of office? I cannot do this alone. If you’d be willing to stand with me against LG, please let me know.
    Male Escort 2’s Post (made in response to the first post): When I came out of the bathroom, he was on the bed, naked, on all fours. I noted that there were dark marks around his anus. I asked if he had showered (he said yes). I asked if it was OK if I wiped him down (he said sure). I wet a face towel and wiped and wiped between his buttocks, and nothing was coming off. Then I realized that his taint wasn’t dirty, it was just FULL OF MOLES.
    Dark moles, in dense clusters up and down the length of his taint. ‘Aw,’ he said. ‘Hope you don’t mind. Those are just my little ladybugs.”

    I can’t believe I actually typed that out three separate times… I suffered so hopefully some curious user can be spared.


  • In a statement, Murphy cited the recovery amount, personal payments by former executives, a commitment for $7 million to go to nonprofits and the absence of a confidentiality provision in a system where “wrongdoers too often hide their misdeeds by dangling compensation in front of those they victimized and trading that compensation for confidentiality or an NDA.”

    Glad they stuck to their guns. I’ve been following this case for a few years now. This all began as an attempt by eBay’s C-level executives to bully a few reporters into silence. It makes perfect sense that those reporters would refuse to accept an NDA as part of the settlement, because reporting on things like this is exactly what landed them on eBay’s radar in the first place.




  • And that’s a large part of the issue. The frontend doesn’t actually disclose this blocklist at all. In fact, it actively takes steps to obfuscate things and make it appear as if the blocklist doesn’t exist at all.

    For example, attempting to view a blocked instance shows a generic network error, rather than a “this instance is being blocked by your frontend” error. And blocked users aren’t simply flagged and/or collapsed. They’re entirely hidden, as if they don’t exist at all. So someone using this as their primary frontend wouldn’t even know that they’re missing entire posts and/or comment chains, because anything from the blocked users is simply gone.

    Additionally, the blocklist is downloaded (in plaintext, over http) when the frontend is booted, so it’s not a file that gets updated with the git version updates. Meaning the dev can silently update it even if users haven’t pulled new versions. Simply rebooting your frontend would be enough to pull an updated blocklist. This gives the dev an extreme amount of censorship power, because they can effectively change users’ configs without any action on the users’ part.

    It was only originally discovered because the admin for db0 used the frontend. And notably, db0 is on the block list. They were previously using an old version of the frontend that didn’t include the hidden blocklist yet. They updated their Lemmy stack a little while ago, and suddenly their entire frontend was broken (the entire feed was completely empty) and showing a generic version incompatibility error.

    After lots of troubleshooting, the db0 admin eventually discovered that the frontend was downloading a hidden blocklist and automatically blocking the instance that it was running on. Because when they updated their stack, the new version of Tesseract included the secret blocklist. So it downloaded the blocklist when it booted up, found that db0 was on the list, and silently hid every single post because they were all from a blocked instance. This resulted in a completely empty feed.


  • Some high profile instances were added to the blocklist alongside unrelated changes and not mentioned in the git commit message… Also apparently the error you’d get when going to the blocked instance was a generic error…

    Yeah, the combination of those two issues are exactly why the hidden blocklist was noticed in the first place. The site admin for db0 noticed that their frontend was broken after they updated their Lemmy stack. But the “incompatible” version of Lemmy they had just updated to was supported. So what was causing the incompatibility? Maybe an API issue? Nope, API is fine.

    After some digging, they eventually realized that it was happening due to an instance block at the frontend’s level. But they didn’t have their own instance blocked in the frontend, so why was it being blocked? Turns out, it was because they were previously running an old version of Tesseract from before the blocklist was implemented. When they updated their stack (which also updated Tesseract), the new version suddenly included the hidden blocklist code. So when they tried to start their stack after updating, the new version of Tesseract quietly downloaded the hidden blocklist (which can’t be disabled) and blocked the instance it was currently running on. This effectively broke the frontend for db0, which is what led to the investigation and subsequent hidden blocklist discovery.