The King Of Malware is Back (by John Hammond)
https://www.youtube.com/watch?v=m6LXnM9mjrU
A brief showcase of Minecraft in-game I2P chatting: https://www.youtube.com/watch?v=wCWTSCql5M8
In that video, you see that server knows player64 and player398 joined the server. But in the beginning, they can't send messages to each other. Also, the server doesn't know what they sent.
Player64 uses the command "!gen" to copy his connect command so he can send it to others. Player398 executed that command, and now Player398 connects to player64 and can send messages to him using I2P.
But as you see, player398 sent a message, but player64 didn't show it. Because player64 gets an incoming connection but doesn't know who it is. So player64 ignores the message.
For player64, he can't send messages to player398 because there is no outgoing connection to player398.
Then player398 uses "!gen" and player64 executes. Now, player64 is connected to player398, allowing him to: a) send messages to player398, b) knows the incoming connection is player398.
Now, you can see they can both send and receive messages over I2P, leaving the server with no idea what they said.
NASA style
----
building a phone you can't drop (by William Osman)
https://www.youtube.com/watch?v=suCbhEHlpL8
Apparently, AI doesn't care about humans' rules. LOL
----
Minecraft Steve, do you have a crush on Alex? (by Phoenix SC)
https://www.youtube.com/watch?v=V0ew5B7FR4s
紧急求救⚠️⚠️⚠️
Rakki 身高186cm瘦高戴眼镜
10月29日跑路成功后于今日(11月1日) 12:40在避难所被警察和疑似家长的共5位成年人带走2警察3大人
现需要在嘉兴杭州附近的小伙伴去她家附近蹲守
她家在嘉兴离杭州很近,就读于杭州外国语学校高二,班主任许如明,年级主任焦晓鹏,能联系学校的可以帮忙交涉下
【补充】
10.2 她单独在杭州中医院做了六项 因为雌激素超标过多 医院给她家里人打了电话
10.3 糖被发现 全部扔掉 和家里人商量也没有任何好结果 她家里人说北京的医院都是非法组织
10.7 去学校开始住宿
10.16 家里人带她查六项 结果雌激素正常 睾酮偏低
10.30 她家里人早上起来 就抢她手机 逼迫她签字保证以后不吃糖
http://twitter.com/yaming00742313/status/1587317052976791553
The OpenSSL bug is a bit "meh" after all the excitement.
If you want to read something really interesting I recommend this Xen bug¹ "x86: unintended memory sharing between guests
" which is a side-effect of Intel's "virtualised APIC access".
It turns out that if you have it enabled then a guest can read _and write_ the global shared xAPIC page by moving the local APIC out of xAPIC mode
Ooopsie™
长文,技术相关。
转载需遵守CC BY-SA 4.0 International知识共享协议,给予credit并以相同的协议分发。
近期部分技术圈子的人员可能听说了一个名为HyeonSeungri的Github帐号在“中国大规模地封锁基于TLS的翻墙服务器”[1]帖子下发布关于网络流量识别与审查的相关“内部信息”。
该帐号声称自己是广州互联网交换中心[2][3]的审查员工,提到了一些流量识别系统工作的内部过程,并且推荐翻墙软件的开发者使用较老的TLS协议版本(主要包括SSL3.0、TLS1.0、TLS1.1)、使用自签名证书、并采用显示/可信代理方式设置代理服务器/VPN。该说法在论坛上引起了一些争执。
目前,该帐号已删除其在该贴中的评论,其帐号也已经被删除。并无法得知该帐号到底是自行注销还是被封号。
该帐号发布的相关言论仍然可以通过存档找到[4]。
接下来是我的结论:
大多数“应该怎么做”是在放屁,简直就是在害人。
借用贴内一个网友的回复:“它们(指HyeonSeungri声称的不会被识别出来的代理流量)不需要被识别出流量特征,它们本身就是特征。/They don't need fingerprinting to be distinguished. They are fingerprints per se.”
首先,使用旧版本的TLS协议是有很大风险的。暂且不提具有严重的已知安全问题[5]因此应当完全被废弃的SSL 3.0,TLS 1.0和1.1版本包含很多不安全的加密算法(如GOST、3DES、RC2、RC4)和不安全的密钥交换算法(如DH-ANON)[6][7],对此不了解的新手非常容易因为配置错误,导致安全问题。
类似的,使用自签名证书也很容易导致对此不了解的新手打开诸如“允许非安全连接”等会降低连接安全性的选项。
然后,无论是使用自签名的数字证书还是使用旧版本TLS协议,都会导致这个本来应该悯然众人的服务器在防火长城鹤立鸡群。根据Qualys SSL Labs的SSL Pulse报告[8],截至2022年9月,仅38.7%的服务器支持TLS 1.1,仅35.5%的服务器支持TLS 1.0,而SSL 3.0的支持率只有2.3%,TLS 1.2的支持率高达99.8%。这就是说,如果你按照这位HyeonSeungri的指示,把代理服务器配置成不支持TLS 1.2及以上的版本的话,你的服务器就成了非常显眼的0.2%。同样的,为了让现代化的浏览器接受,大多数网页服务器都有由证书颁发机构(CA)签发的证书,自签名证书一般是测试服务时才会用的。那么,一方是支持现代化加密、拥有正确的证书、看起来非常普通的网页服务器,另一方是固执地选择老旧的安全协议、使用会让浏览器告警的自签名证书的奇怪的网页服务器,哪边看上去更像是have something to hide的代理服务器呢?
而且,即使,出于某些原因,你的代理服务器没有被发现。你连接这种服务器所造成的流量,看起来也不会像是普通的浏览器访问网页的流量。2020年,Chrome浏览器在版本84移除了对于TLS 1.0和1.1的支持[9][10],Firefox在版本78默认禁用了TLS 1.0和1.1[11][12]。因此,现在在网络上传递的HTTPS流量,绝大多数都是使用TLS 1.2或1.3的。而即使在此之前,大多数浏览器也会默认选用服务器支持的最高版本的TLS协议来增强链路的安全性,老版本的TLS协议的使用率,本来就没有那么高。这种情况下,SSL3.0、TLS1.0或1.1的互联网流量,也是非常显眼的,毋庸置疑。
综上所述,HyeonSeungri的建议不但会严重降低通信的保密性和安全性,也让流量和代理服务器显得更加突出,这直接违背了v2ray等审查绕过软件的设计思路(使翻墙流量看起来像普通的网页访问流量),因此不应该采用。
[1] https://github.com/net4people/bbs/issues/129
[2] https://inflect.com/ix/chn-ix-guangzhou
[3] https://en.wikipedia.org/wiki/List_of_Internet_exchange_points
[4] http://archive.today/2022.10.09-065615/https://github.com/net4people/bbs/issues/129
[5] http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.html
[6] https://datatracker.ietf.org/doc/html/rfc2246
[7] https://datatracker.ietf.org/doc/html/rfc4346
[8] https://www.ssllabs.com/ssl-pulse/
[9] https://chromestatus.com/feature/5654791610957824
[10] https://developer.chrome.com/blog/chrome-81-deps-rems/
[11] https://www.mozilla.org/en-US/firefox/78.0/releasenotes/
[12] https://hacks.mozilla.org/2020/02/its-the-boot-for-tls-1-0-and-tls-1-1/
#ssl #tls #v2ray #xtls #naiveproxy #clash #翻墙 #代理 #censorship #anticensorship #disinformation #debunk
A random thought:
Minecraft in game chat, but P2P. (Yes, I'm still messing around with the report system)
https://github.com/Aizistral-Studios/No-Chat-Reports/issues/234#issuecomment-1296481266
I suggest we set up a specific instance for Twitter people, so we can block them based on instance, LOL.
via @DazzlingGleam
https://cawfee.club/objects/fede22cc-0f33-4aa0-9745-81938a2f3d7d
Can't wait to see someone build a working computer based on this. XD
----
Mechanical circuits: electronics without electricity (by Steve Mould)
https://www.youtube.com/watch?v=QrkiJZKJfpY
当我读《资治通鉴》的时候,就反复被灌输一个理念:国家要大一统不要分裂,国君要英明不要昏庸。这个理念是中国人现在还深深认可的。
我们确实发现一个问题,那就是当一个朝代结束的时候就是乱世,非常痛苦。所以我们就觉得,哎呀不好,我们必须要避免这种情况,要一直维持盛世,要守正,要有美德。
这是一个困扰了我几十年的一个陷阱。我们看到事实是,中国永远在盛世——乱世——盛世——乱世,不断循环。你有没有发现哪里不对?
问题就出在,不是说盛世有多好,乱世有多不好(盛世其实也不是多好,只不过是坐稳了奴隶的时代,这且不表),而是盛世和乱世就是这个系统的标配。你必须两样都得有。这就像自行车,一个前轮,一个后轮。甚至你可以说:乱世之所以存在,就是因为盛世的存在!这其实就是“圣人不死,大盗不止”。
乱世是从哪里来的?当然是从盛世那里来的。乱世之前就是盛世。那么盛世为什么会生出一个乱世呢?我们可以说,盛世埋藏了乱世的种子。那么这个种子是什么?其实就是这个系统的不稳定性。也就是说,这个系统在比较理想的情况下,它可以出现盛世,但情况是在一直变化的,而这个系统本身并没有一个有效的纠错机制。当情况出现变化的时候,乱世就不可避免地出现了。一个系统偶尔能工作,但冷不丁就坏,这当然是一个严重的设计缺陷。
那么《资治通鉴》就说,我们要发挥我们的主观能动性,用道德来让它不坏。这个想法当然很美好,但系统的运行不是依赖于最坚固的那个零件,而是依赖于最脆弱的那个零件。只要最脆弱的那个零件坏了,系统就坏了。所以主观能动性能起到的效果有限。就好像你一直盯着一个东西它就没事,这是你的主观能动性,但你闭一会儿眼就出事了,那就是主观能动性的局限性。
所以你必须有一个机制来自动对系统进行纠错。一旦问题出现,它会自己跳出来,这就可靠多了。一个纠错机制不行,那就两个。这就是三权分立,民众监督。这样当然不是说就永远不会出错,但不管是从逻辑上还是从实际的经验上,这样就是能够少出错。
我希望更多人明白这个简单的道理。
In case you want to know why this filesystem requires a such amount of RAM:
Because it's JAVA.
A fully working read-only FUSE, backed by my own MerkleDAG structure, namely the https://github.com/hurui200320/Ariteg
By caching everything in RAM and using 2.8GB RAM at the start-up, then growing to 5.5GB when playing 12 videos at the same time (bottlenecked by the GPU's video decoder), the filesystem itself is working pretty well. The random reading is fairly good, too: sliding through the progress bar in MPV results in an almost instant response (data stored on an NVME SSD).
I would call it a day.
Also, 295GB of video files only occupied 290GB after block-level deduplication. I would argue that compressing the same data would require an infinite amount of time (my program can handle more than 50MB/s when reading and writing happen on the same disk, while 7z can only get 20MB/s) and wouldn't get a better compression ratio than this.
hmmmmm, Chinese piracy vscode.
https://github.com/microsoft/vscode/issues/163798
Video: A Toyota pickup truck slowly pulled the shuttle across the bridge.
Me: That must be a modified pickup truck.
Wikipedia: The journey was famous for an *unmodified* Toyota Tundra pickup truck pulling the Space Shuttle across the Manchester Boulevard Bridge.
Me: WTF? 78 tons of spaceship, unmodified truck?
----
Endeavour's Wild Journey Through the Streets of Los Angeles (by Practical Engineering)
https://www.youtube.com/watch?v=tVzgHvTuwdU
The raspberry pi rebuild version is amazing.
The original version would be fantastic in terms of engineering.
----
This 1970s tank simulator drives through a tiny world (by Tom Scott)
https://www.youtube.com/watch?v=AcQifPHcMLE
Abandoned since this instance is broken. Please follow my new account: @skyblond@m.skyblond.info