Shoot the breeze, anything goes.
User avatar
!
30%
Posts: 3263
Joined: 2013-02-25 18:36

2014-02-11 14:12 »

MasterOne wrote:...You also gotta love how the new ads are named "Ad Choices"...yeah, like people really have a choice...

Got to love those Orwellian "choices".

User avatar
!
30%
Posts: 3263
Joined: 2013-02-25 18:36

2014-02-11 14:14 »

I'm sure they do this because Google care so much about humanity. 8-)

Google reveals its smart contact lens for people with diabetes.

Google announced yet another upcoming eye-themed wearable product...

Ah yeah, that's exactly what I want. Something from Google inside my body.

hands22holdingewwe223.jpg
hands22holdingewwe223.jpg (18.87 KiB) Viewed 9011 times

MasterOne

2014-02-12 16:03 »

Mozilla will now be delivering ads right into your web browser when you open up a new tab. I'm not sure how large the shit storm will be in terns if this idiotic move, but users are already writing in about their hatred towards this boneheaded idea. The best part of the article I read, however, is here, and came straight from the mouth of a Mozilla employee:

"We wanted to get away from being this window into the web that doesn't bring value," to users, she said.

"We looked at it from the perspective of how much value are we bringing to the user? We're not focused on bringing the most revenue into Mozilla," she said.


Yeah, sure. I'm real confident that they are doing this to bring "value" to the users, and are not focused on revenue. That's the stupidest load of horse shit I've heard in a while, and it's pretty funny that that dumb lady would say that and think people wouldn't notice her dumb lie! Open source software should not have any ads, and there will just be a fork of Firefox that has no ads. It also opens up a potential security hole. The more an application does, the larger the code is, and the more it talks to the internet, the weaker it is. It's really sad the direction things are going in computing.

http://www.zdnet.com/mozilla-to-deliver ... 000026216/

User avatar
TmEE
VIP
Posts: 229
Joined: 2013-08-09 16:52
Contact:

2014-02-12 20:21 »

Long ago Opera was doing similar stuff, and then dropped it... now others decide its good stuff... ::crazy::

User avatar
!
30%
Posts: 3263
Joined: 2013-02-25 18:36

2014-02-18 05:16 »

As always, for your own protection... well, this time seems OK, we can rest assured knowing Valve are not watching people fap but what will be next? ;) I personally still trust Valve but even though I have spent good many $$$ on my Steam account, I will stop using it if they go too far.

Valve Anti-Cheat (VAC) system now reads all the domains you have visited and sends it back to their servers hashed.

Valve DNS privacy flap exposes the murky world of cheat prevention. Company denies any breach of privacy, as angry gamers cry foul..

Decompiled module: http://i.imgur.com/z9dppCk.png

What it does:

Goes through all your DNS Cache entries (ipconfig /displaydns)

Hashes each one with md5

Reports back to VAC Servers

So the domain reddit.com would be 1fd7de7da0fce4963f775a5fdb894db5 or organner.pl would be 107cad71e7442611aa633818de5f2930 (Although this might not be fully correct because it seems to be doing something to characters between A-Z, possible making them lowercase)

Hashing with md5 is not full proof, they can be reversed easily nowadays using rainbowtables. So they are relying on a weak hashing function

You dont have to visit the site, any query to the site (an image, a redirect link, a file on the server) will be added to the dns cache. And only the domain will be in your cache, no full urls. Entries in the cache remains till they expire or at most 1 day (might not be 100% accurate), but they dont last forever.

We don't know how long this information is kept on their servers, maybe forever, maybe a few days. It's probably done everytime you join a vac server. It seems they are moving from detecting the cheats themselves to computer forensics. Relying on leftover data from using the cheats. This has been done by other anticheats, like punkbuster and resulted in false bans. Although im not saying they will ban people from simply visiting the site, just that it can be easily exploited

Original thread removed, reposted as self text (eNzyy: Hey, please could you present the information in a self post rather than linking to a hacking site. Thanks)

EDIT1: To replicate this yourself, you will have to dump the vac modules from the game. Vac modules are streamed from vac servers and attach themselves to either steamservice.exe or steam.exe (not sure which one). Once you dump it, you can load the dll into ida and decompile it yourself, then reverse it to find the winapi calls it is using and come to the conclusion yourself. There might be software/code out there to dump vac modules. But its not an easy task. And on a final note, you shouldn't trust anyone with your data, even if its valve. At the very least they should have a clear privacy policy for vac.

EDIT2:Here is that vac3 module: http://www.speedyshare.com/ys635/VAC3-M ... ypoink.rar It's a dll file, you will have to do some work to reverse it yourself (probably by using ida). Vac does a lot of work to hide/obfuscate their modules.

EDIT3: Looks like whoever reversed it, was right about everything. Just that it sent over "matching" hashes. http://www.reddit.com/r/gaming/comments ... and_trust/

GabeNewellBellevue wrote:Trust is a critical part of a multiplayer game community - trust in the developer, trust in the system, and trust in the other players. Cheats are a negative sum game, where a minority benefits less than the majority is harmed.

There are a bunch of different ways to attack a trust-based system including writing a bunch of code (hacks), or through social engineering (for example convincing people that the system isn't as trustworthy as they thought it was).

For a game like Counter-Strike, there will be thousands of cheats created, several hundred of which will be actively in use at any given time. There will be around ten to twenty groups trying to make money selling cheats.

We don't usually talk about VAC (our counter-hacking hacks), because it creates more opportunities for cheaters to attack the system (through writing code or social engineering).

This time is going to be an exception.

There are a number of kernel-level paid cheats that relate to this Reddit thread. Cheat developers have a problem in getting cheaters to actually pay them for all the obvious reasons, so they start creating DRM and anti-cheat code for their cheats. These cheats phone home to a DRM server that confirms that a cheater has actually paid to use the cheat.

VAC checked for the presence of these cheats. If they were detected VAC then checked to see which cheat DRM server was being contacted. This second check was done by looking for a partial match to those (non-web) cheat DRM servers in the DNS cache. If found, then hashes of the matching DNS entries were sent to the VAC servers. The match was double checked on our servers and then that client was marked for a future ban. Less than a tenth of one percent of clients triggered the second check. 570 cheaters are being banned as a result.

Cheat versus trust is an ongoing cat-and-mouse game. New cheats are created all the time, detected, banned, and tweaked. This specific VAC test for this specific round of cheats was effective for 13 days, which is fairly typical. It is now no longer active as the cheat providers have worked around it by manipulating the DNS cache of their customers' client machines.

Kernel-level cheats are expensive to create, and they are expensive to detect. Our goal is to make them more expensive for cheaters and cheat creators than the economic benefits they can reasonably expect to gain.

There is also a social engineering side to cheating, which is to attack people's trust in the system. If "Valve is evil - look they are tracking all of the websites you visit" is an idea that gets traction, then that is to the benefit of cheaters and cheat creators. VAC is inherently a scary looking piece of software, because it is trying to be obscure, it is going after code that is trying to attack it, and it is sneaky. For most cheat developers, social engineering might be a cheaper way to attack the system than continuing the code arms race, which means that there will be more Reddit posts trying to cast VAC in a sinister light.

Our response is to make it clear what we were actually doing and why with enough transparency that people can make their own judgements as to whether or not we are trustworthy.

Q&A

1) Do we send your browsing history to Valve? No.

2) Do we care what porn sites you visit? Oh, dear god, no. My brain just melted.

3) Is Valve using its market success to go evil? I don't think so, but you have to make the call if we are trustworthy. We try really hard to earn and keep your trust.

z9dppCk.png
z9dppCk.png (105.28 KiB) Viewed 8981 times

User avatar
!
30%
Posts: 3263
Joined: 2013-02-25 18:36

2014-02-20 05:27 »

prison-butterfly.jpg
prison-butterfly.jpg (3.89 KiB) Viewed 8975 times

One manufacturer after another, add two more fingers and it will be just... like... prison.

Here is how Samsung plans to implement the fingerprint sensor in the Galaxy S5.

According to a report published by SamMobile based on information from their sources, Samsung will be shipping the Galaxy S5 with a fingerprint sensor embedded in the device's home button similar to the one on Apple's iPhone 5s.

Up to eight fingerprints can be stored on the Galaxy S5 with one mandatory for unlocking the smartphone.

prison fingerprint.jpg
prison fingerprint.jpg (11.54 KiB) Viewed 8975 times

fingerprint-1.jpg
fingerprint-1.jpg (179.53 KiB) Viewed 8975 times

User avatar
!
30%
Posts: 3263
Joined: 2013-02-25 18:36

2014-02-24 18:46 »

Lumia phones are leaking private data to Microsoft.

Two independent sources inside Nokia have confirmed that Nokia Lumia phonessend private information to Nokia and Microsoft servers around the world. Location data, SMS-messages and browser identification is uploaded. The Nokia leadership has known about the privacy violation since 2011 when the Lumia phones were introduced. In spring 2013, after suspicions of leaks and during the negotiations for selling off the mobile phone branch to Microsoft, the Finnish state communications department sent an inquiry to Nokia regarding leaking of private data, asking Nokia to assure that users' private data is not leaked. Nokia did not want to (or could not) provide an assurance due to the delicate business negotiations. After two more inquiries with narrower demands, Nokia assured that the phone, excluding third-party software such as the operating system, did not violate Finnish privacy laws. Microsoft is apparently also following Lumia user accounts. On one occasion a parent's Lumia account was closed without warning when they uploaded pictures from the phone displaying their kids playing naked on the beach at their summer cottage.

3803.jpg
3803.jpg (38.65 KiB) Viewed 8966 times

User avatar
!
30%
Posts: 3263
Joined: 2013-02-25 18:36

2014-03-09 18:19 »

Microsoft Lync gathers data just like NSA vacuums up info in its domestic surveillance program.

Microsoft's Lync communications platform gathers enough readily analyzable data to let corporations spy on their employees like the NSA can on U.S. citizens, and it's based on the same type of information - call details. At Microsoft's Lync 2014 conference, software developer Event Zero detailed just how easy it would be, for instance, to figure out who is dating whom within the company and pinpoint people looking for another job.

wolf_in_sheep__s_clothing_by_mewtant_307k-d4g4r172.jpg
wolf_in_sheep__s_clothing_by_mewtant_307k-d4g4r172.jpg (52.79 KiB) Viewed 8940 times

behindbeauty_87726f.jpg
behindbeauty_87726f.jpg (110.41 KiB) Viewed 8940 times

User avatar
!
30%
Posts: 3263
Joined: 2013-02-25 18:36

2014-03-12 18:30 »

Walled gardens are wonderful things! They won't even allow you to ride a hype! Stupid as it may, why is it their business, these corporations, to dictate to you what application you are allowed to build and publish? What's that? Oh, that's right! Because you are a slave! That's why!

If I want to ride a hyper, then I want to ride a hyper motherfuckers! :evil:

Apple and Google are now rejecting applications with "Flappy" in title.

jail-prison.jpg
jail-prison.jpg (35.96 KiB) Viewed 8934 times

App developers hoping to make a quick buck piggybacking on the Flappy Bird craze that somehow has been able to simultaneously entertain and frustrate scores of gamers will have to be at least a little more creative than building an obvious clone and calling it "Flappy" something or other. In an attempt to fend off a barrage of clones, it appears both Apple and Google are now rejecting games with "Flappy" in the title.

The folks at TechCrunch went and collected a handful of Twitter posts from developers claiming their apps (or apps from people they know) were denied entrance into iTunes or Google Play because they used "Flappy" in the title. For example, Ken Carpenter of Mind Juice Media from Vancouver says Apple turned down his "Flappy Dragon" app with a note telling him "we found your app name attempts to leverage a popular app."

Flappy_Bird.jpg
Flappy_Bird.jpg (35.79 KiB) Viewed 8934 times

User avatar
!
30%
Posts: 3263
Joined: 2013-02-25 18:36

2014-03-19 13:38 »

LOL!

Google and Microsoft agree that "cloud" is now safe enough to use.

The two Internet powerhouses agree that it's time to stop fearing cloud security and embrace the future at the annual RSA Conference.

Two Wolves and Lamb.jpg
Two Wolves and Lamb.jpg (64.86 KiB) Viewed 8920 times

Post Reply