• 1 Post
  • 161 Comments
Joined 2 years ago
cake
Cake day: June 11th, 2023

help-circle






  • He doesn’t give me gun nut vibes either…

    • he actually did gray man correctly
    • he probably didn’t test fire his gun setup
    • his gun setup was extremely minimalist
    • he seems to have used a Temu fuel filter sort of suppressor instead of assembling one with a booster (no it wasn’t a fucking welrod lmao)

    The gun part feels a bit like an afterthought that he spent a couple nights googling on and then threw together. The fact that he’s eluded capture for so long on the other hand suggests that’s where he put all his effort. I’d bet he’s probably an intelligence/cyber security/IT/SWE professional with an axe to grind and less to lose than he should.


  • To add to this, a lot of what keeps us safe is the friction of bureaucracy. Authoritarians cannot micromanage every decision you make or round up every person they want because those actions take time and resources that aren’t infinite. But you can reduce the time and resources required if you make identification more convenient and therefore enforcement more targeted. Maybe now they can justify making you present ID every time you pay cash at Starbucks, buy a backpack, get on a bus, use a bike share, watch hot snuff porn, you name it.





  • Nothing is perfect. Your goal is to make attacks expensive as shit. Like ideally requiring dozens of hours of electron microscope time to pull off.

    You can do a lot to that end though.

    Use a mostly read only OS if you can, if you’re enterprising, a custom yocto build with most of the rootfs read only, otherwise a statically defined system like nix that can be readily deleted and rebuilt in minutes. There are configs out there for deleting root on every bootup and having the system automatically repopulate the filesystem. Enable secure boot if you can, it’s frankly your best line of defense. Any of these options are sufficiently weird that designing exploits for them would be a suffer fest.

    Forget nail polish, fill screw holes with RTV and if you’re enterprising, the USB ports. At that point you can still get into the system but it’ll be obvious that someone scraped the shit out. You can simply swap the ports for fresh ones with a solder job if needed. If you don’t need this, use epoxy, get some all over the case seam. For the charging port, if it’s USB C PD, I’d need to reread the spec but you should be able to cut D-/D+ and the SS lines with an exacto blade right next to the connector and still be able to charge, just don’t hit the VCC, GND, and CC lines.

    Finally, make a kwikset key trap and use it as either a lockbox lock for your stuff or the lock to your house. Kwikset should lull people into a false sense of insecurity but if they try to pick it they’ll suddenly be in a situation where they either need to go overt or somehow replace your lock before you get back. Keep things weird, your goal is to get an adversary, even one with infinite resources, to make ridiculous mistakes.





  • The DCS Ka-50 isn’t a real aircraft, it was a development platform that was abandoned by the Russians and only a few were made, all in different configurations. The devs made it then made a paid upgrade package that slapped a bunch of random stuff like missile sensors and air to air missiles onto it. They did this while staunchly maintaining that all the western aircraft had to be perfect to the rivet, including removing weapons systems and features from aircraft that verifiably had them but not within the absurdly narrow window of the one they wanted to model.





  • Did you read the article? There were a couple cases were very early Android phones were modified to appear to be off but stayed on. This is fairly common knowledge, but it’s not particularly hard to defeat.

    Everything your phone does requires a deterministic amount of power. Spying on people in particular requires even more power than normal because you need to run the power hungry gps in addition to the modem and cpu.

    If you turn off the device it should be significantly cooler to the touch, not a degree above ambient. If it’s at 100% charge but a power bank with a read out is showing it still charging, that’s a problem. Is the bootloader image different? You can verify that to some extent. When you turn it back on has it been drawing down the battery anyway? Does it require an unlock password instead of biometrics as it normally would (assuming a particularly sloppy setup)?

    This isn’t rocket surgery, in reality nobody is modding everyone’s phone to stay on forever because unless you’re an absolute troglodyte (aka the fucking old school mafia bosses they did this to) it’s going to be painfully obvious your phone is acting weird.