• 0 Posts
  • 219 Comments
Joined 2 年前
cake
Cake day: 2023年7月1日

help-circle

  • arc@lemm.eetoTechnology@lemmy.worldI use Zip Bombs to Protect my Server
    link
    fedilink
    English
    arrow-up
    27
    arrow-down
    1
    ·
    2 个月前

    Probably only works for dumb bots and I’m guessing the big ones are resilient to this sort of thing.

    Judging from recent stories the big threat is bots scraping for AIs and I wonder if there is a way to poison content so any AI ingesting it becomes dumber. e.g. text which is nonsensical or filled with counter information, trap phrases that reveal any AIs that ingested it, garbage pictures that purport to show something they don’t etc.


  • arc@lemm.eetoLinux@lemmy.ml*Permanently Deleted*
    link
    fedilink
    arrow-up
    5
    ·
    2 个月前

    Depends what you mean by bloat. It has a very large repo, but it compiles into little commands with least privilege execution. A lot of those commands are specifically there so someone doesn’t have to pull in other repos with a larger attack surface. e.g. there is a time sync daemon to replace having to pull in ntp which is a lot more complex and fraught and the one thing most desktops need of NTP which is to set the clock.


  • arc@lemm.eetoLinux@lemmy.ml*Permanently Deleted*
    link
    fedilink
    arrow-up
    2
    arrow-down
    1
    ·
    edit-2
    2 个月前

    Why do you still exist? I try understanding what the purpose of your reply could be? Screenrecords do not work. For plenty of people. Google it. Yet you feel entitled to share you smalldick energy wisdom of “proper way”. That is exactly the vibe of the shit ppl. You do not help Wayland or x11 or anything, you just fap into your own mouth because nobody can ever love you like that. Go get help.

    Wow, someone needs to grow up. You laid into Wayland when screen recording doesn’t even go through Wayland. The app asks the WM to screen record via DBus. A more constructive response would have been “thanks I didn’t know that”, or perhaps “oh it’s a driver issue”, or “it’s an issue with that WM/ffmpeg/pipewire or whatever”, or anything else likely to be the underlying cause. But it’s not Wayland. Have you got that? Not Wayland. There is no need to be sore and immature about it.



  • arc@lemm.eetoLinux@lemmy.ml*Permanently Deleted*
    link
    fedilink
    arrow-up
    4
    arrow-down
    1
    ·
    edit-2
    2 个月前

    Screen records do work providing the app asks for a screen cast in the proper way (which BTW is not via Wayland but through a message to a DBus service). The service and the desktop then ask permission from the user if necessary. X11 didn’t give a damn about protecting the contents of your screen and any app whether it was beneficial or malicious could do it with impunity. So you should see this as a major security improvement - you can screen record but only if permission is granted.


  • arc@lemm.eetoLinux@lemmy.ml*Permanently Deleted*
    link
    fedilink
    arrow-up
    6
    ·
    2 个月前

    Yes it’s been stable for some time with a couple of caveats - you need a decent graphics driver and not be using apps with edge cases.

    Here is a simple example of an edge case and it’s not hard to find people blaming Wayland even though with some thought this was a security issue - apps like Zoom, Discord, MS Teams want to do screen sharing which is easy in X11 because it has non existent security - just steal the screen bitmap. That’s a problem.

    Wayland (the protocol) provides no means for one app to grab the screen, or other apps. This is by design for security. Instead the app must be a good citizen and send a “i want to screen cast” message to the xdg-desktop-portal (a service provider implemented by GNOME, KDE etc.), the desktop asks for user consent and then the app gets a video stream. So it’s a lot more secure but it requires the app and the WM do things properly.

    Desktops and apps have matured and these issues are thankfully going away. I think the biggest hurdle left is proper graphics drivers, especially the problem of getting NVidia drivers working.







  • arc@lemm.eetoTechnology@lemmy.world*Permanently Deleted*
    link
    fedilink
    English
    arrow-up
    31
    ·
    3 个月前

    I do not believe for a second that communications within the Whitehouse are inadequate, or if they were, could not be solved in a secure manner. Slapping a Starlink in a few places sounds like an invitation to backdoor all communications. Not only that, it is an invitation to sidestep obligations to preserve government records.


  • arc@lemm.eetoTechnology@lemmy.world*deleted by creator*
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    4 个月前

    Tesla doesn’t have that excuse. The original Roadster, Model S and Model X all had fairly conventional controls. They deliberately undermined the safety of their vehicles over time by aggressively removing physical controls in the model 3 and Y and revamped S. It probably saved them a few bucks, but at the cost increased risk to human life. If they get penalized in safety tests for their penny pinching then so be it.


  • arc@lemm.eetoTechnology@lemmy.world*deleted by creator*
    link
    fedilink
    English
    arrow-up
    10
    ·
    4 个月前

    I think Euro NCAP ratings would have more teeth if it was mandatory for manufacturers of standard passenger vehicles to submit a reference model for testing. Voluntary testing doesn’t work since manufacturers would be averse to submit cars for testing if they thought they’d get a bad score. And while Euro NCAP does sometimes buy cars for testing, they don’t do it for every make and model.

    And if the cheapest dogshit cars on the road (Kia Picantos, Dacia Sandero’s etc) can have buttons, dials, wipers and indicators then so should everything above it. Companies like Tesla remove controls to cheap out on having to make a part, but they attempt to pass this off as innovation when it puts people’s lives at risk.



  • arc@lemm.eetoTechnology@lemmy.world*deleted by creator*
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    edit-2
    5 个月前

    Maybe it will, but for the time being it hasn’t. The experience is so vastly better than Twitter, that it’s a no brainer to jump over. It also helps to have a decent competing platform that people like to suck users and influence away from the platform that Musk turned into a cesspit.



  • I certainly find it funny that Tesla’s waiting list went from five years down to zero. Even Tesla’s biggest fans who actually stumped money on this thing produced video after video griping about its price & brokenness.

    But frankly it was kind of obvious from the get-go that it would be an expensive, uninsurable, lemony asshole death mobile. I wonder if the next time Tesla announces something and Musk spews lie after lie about it that people will start to cotton on that nothing he says can be taken at face value.