Just your normal everyday casual software dev. Nothing to see here.

  • 0 Posts
  • 65 Comments
Joined 3 years ago
cake
Cake day: August 15th, 2023

help-circle
  • Dude, we’re already long past that point. I went back to Reddit after three years of boycotting it just to see its current state a couple weeks ago. Every community seems to be a ghost town. Like the subs that I had participated in and enter daily has gone from like 10 plus posts a day to maybe a post every 11 days if that.

    Many of the entertainment style subs that I had gone in have been radio for silent weeks.

    And then the actual public popular subs are an absolute dumpster fire. It’s either obvious bot posts or people flaming others in the comments, which don’t get me wrong, Reddit always had, but to me it seems like it’s worse. I don’t know if it’s just because I’ve gotten used to a much lower traffic system like Lemmy, or if it has actually gotten worse though.


  • honestly what it’s likely going to end up happening is that developers of the alternative front ends/apps are going to start masquerading as the official Reddit client and then claiming that they don’t have a Reddit account so therefore they haven’t violated any terms of service. We saw that a little bit when the API got locked down in the first place.

    And then leave it as a use at your own risk-style system. Much like how grayjay, tizen and the Revance Project works when you decide to log in your Google account.

    Yeah, it violates policy, however, it’s not on the application because they only provided the means of being able to do it its on the user to decide to actually use said means





  • Yeah, I do agree your jurisdiction may vary.

    In the US at least, you can’t change a terms of purchase via a terms of service.

    So if it was stated at point of purchase that your system will be getting 10 years of updates, and then they decided six years in, you know what? We’re actually only going to do six years of updates, and then posted a terms of service that changed how long they were able to update it. That wouldn’t be legally binding.

    In this case, though it doesn’t sound like they’re changing existing buyer’s agreements, it sounds like they are changing the purchase agreement for new consumers who haven’t purchased the product. which is far more legally enforceable as no agreement has been done in that case.

    Still a shitty thing for them to do though, considering that they had promised that Chromebooks would have 10 years of updates but I don’t think they’re in violation of anything since it sounds like it’s only going to new consumers.








  • That would make sense, although I think it’s unlikely that it embeds itself into the mods. It would probably replace itself. Since in order to embed itself into the mod, it would have to know how the mod is made/structured but I guess it would be possible if it was able to completely replace the existing mods with the worm.

    edit: Yeah, a post-work summary was posted today, and it basically did exactly that, it replaces all workshop mods created by the user with a copy of the worm, which then spreads. Honestly, I feel like this is also a vulnerability on Steam’s behalf as well because I don’t see any realistic use case of why it shouldn’t require either a 2FA or some form of validation before pushing an update to the game, especially one that changes the entire mod out for something else.

    This one happened to be allowing C-sharp integration, which is how the original infection happened, because that allowed for compilation at runtime. However, this vulnerability could technically happen with any Steam Workshop-enabled game. It’s really concerning that there’s no check system in place. The Steam depot should not allow you to be able to do a full mod replacement using a session or with token.







  • Said backdoor isn’t possible with the current day key exchange process. Without the servers in use private key, the most law agencies can do without acquiring the private key is force the CA to revoke a cert, which will disallow properly configured clients from accessing and transferring data with the server.

    LE doesn’t have enough information to recreate the private key based off the public key, the only key distributed during the CSR process is the servers public key via a certificate signing request which is signed using your private key, which the CA then signs with it’s own intermediate key (which is signed by it’s root server certificate) and hands back to the private server.

    The CA doesn’t have the ability to create that private key, and as such doesn’t have a way to decrypt traffic that is using that key. There is no concern for a backdoor in that process.

    In order for the “backdoor” to exist, they would need to either copy the private key as part of the signing process (which it doesn’t), or somehow force the server admin to use a new private key (that the CA also holds) or somehow compromise the servers key generation process to allow for an escrow on the private key when it was generated which would allow the CA to be able to recreate the private key using the master & public key.

    Now don’t take me wrong, you can still have a MiTM impersonation attack or a full impersonation bypass by the CA issuing a new certificate and having the DNS registrar have the web address go to a new server that is using the new key but, that’s not something the CA alone has the capability of doing, and any traffic that is issued to the original server still wouldn’t be compromised, its just clients visiting your site will end up at the other site and as such will end up using keys that the other side generated instead of your own keys and additionally said new keys would also be appearing in Certificate transparency logs, or modern day clients would refuse to use them.