Protecting against rogue devices with Full Disk Encryption and TPM
Fde Rogue Devices
Protecting against rogue devices in openSUSE with Full Disk Encryption openSUSE have now multiple ways to configure a Full Disk Encryption (FDE) installation...openSUSE News
Meta apologizes after auto-translation mistakenly announces Indian state chief minister’s death
Tech giant Meta has apologized and said it has fixed an auto-translation issue that led one of its social media platforms to mistakenly announce the death of Indian politician Siddaramaiah.
Israel levelling thousands of Gaza civilian buildings in controlled demolitions - BBC News
Verified footage shows large explosions unleashing plumes of dust and debris, as Israeli forces carry out controlled demolitions on tower blocks, schools and other infrastructure.
Multiple legal experts told BBC Verify that Israel may have committed war crimes under the Geneva Convention, which largely prohibits the destruction of infrastructure by an occupying power.
An Israel Defense Forces (IDF) spokesperson said it operated in accordance with international law; that Hamas concealed "military assets" in civilian areas, and that the "destruction of property is only performed when an imperative military necessity is demanded".
Israel levelling thousands of Gaza civilian buildings in controlled demolitions - BBC News
Investigation by BBC Verify using satellite images and verified footage to show the extent of destruction in Gaza, where the Israeli military have carried out demolitions to raze entire towns and suburbsBBC News
like this
In criminal law, mens rea (/ˈmɛnz ˈreɪə/; Law Latin for "guilty mind"[1]) is the mental stateof a defendant who is accused of committing a crime. In common law jurisdictions, most crimes require proof both of mens rea and actus reus ("guilty act") before the defendant can be found guilty.
All caught up? Good. Because a) OP is an asshat for not contextualizing this thing they felt we should all hear them say in public / b) I also have no idea what they mean by it either
[No PHPun Intended] "I code in PHP"
"I code in PHP"
Yes, you can still use PHP to create your website. But you can also build an enterprise-grade web app with Laravel or Symfony. While some still see PHP through WordPress, it has one of the most mature web frameworks.nophpunintended.com
like this
Roll Call 212 Roll Call 212, Bill Number: H. R. 4016, 119th Congress, 1st Session
VOTE QUESTION: On Passage, DESCRIPTION: Department of Defense Appropriations Act, 2026, VOTE TYPE: Yea-And-Nay, STATUS: PassedOffice of the Clerk, U.S. House of Representatives
copymyjalopy likes this.
US could run out of missiles in eight days
US could run out of missiles in eight days
TEHRAN, Jul. 18 (MNA) – Ex-Pentagon adviser Douglas Macgregor added that President Donald Trump should be briefed on how low the US missile stockpile "really is."Marzieh Rahmani (Mehr News Agency)
like this
They cite Douglas MacGregor
Col. Douglas Macgregor USA (Ret.) is a decorated combat veteran with a PhD in international relations from the University of Virginia. He is the author of five books and is the executive vice president of Burke-Macgregor Group LLC, a defense and foreign policy consulting firm in Northern Virginia.
[No PHPun Intended] A Brief History of Web Development
Yep, PHP is turning 30 this year! Wondering if "PHP is still relevant?" Ever since we have been hearing that PHP is dead. It was “dead” 10 years ago, 5 years ago, and “is dead” today. But somehow - it isn’t. Anyway... happy birthday!
A Brief History of Web Development
Yep, PHP is turning 30 this year! Wondering if "PHP is still relevant?" Ever since we have been hearing that PHP is dead. It was “dead” 10 years ago, 5 years ago, and “is dead” today. But somehow - it isn’t. Anyway... happy birthday!nophpunintended.com
like this
Flirty AI chatbot app leaks 160,000 DM screenshots
The publicly accessible bucket contained data from the iOS app FlirtAI - Get Rizz & Dates. It mainly included private chats that users wanted the AI wingman to help them reply to.
- FlirtAI wingman app leaked 160K chat screenshots through unprotected cloud storage.
- Teenagers frequently used the app, making the breach more concerning for minors.
- Some individuals were likely unaware their conversations were screenshot and sent to third parties.
https://cybernews.com/security/iphone-flirtai-app-leaks-chat-screenshots/
EU bans Czech Republic from importing oil from Russia
EU bans Czech Republic from importing oil from Russia
EU officials have decided to cancel permission for the Czech Republic to import oil from Russia via the Druzhba pipeline. ‘The Council decided to cancel the import authorisation,’ the EU said in a related document.newsmaker1 newsmaker1 (English News front)
So they need all EU states to sanction Israel but they can non-concensually sanction a country which does not want to participate in a sanction against Russia.
Makes perfect sense.
ChatGPT’s new AI agent can browse the web and create PowerPoint slideshows
ChatGPT’s new AI agent can browse the web and create PowerPoint slideshows
New “agentic” AI feature combines web browsing with task-execution abilities.Benj Edwards (Ars Technica)
Microsoft Office is using an artificially complex XML schema as a lock-in tool
An artificially complex XML schema as a lock-in tool - The Document Foundation Blog
A document format is a tool for sharing knowledge and, as such, should be as simple and accessible as possible in relation to the complexity of the document content itself.Italo Vignoli (The Document Foundation)
pignaggio grafico non ufficialmente concesso (non esiste emoji della pigna…)
La settimana scorsa (che sento come fosse l’altro giorno, e infatti stavo per dire così… ops?), quando cercavo di mettere in fretta Pignio online, e quindi non c’era il tempo di creare un’icona vera (anche se comunque poi sarebbe servita), cercavo almeno l’emoji della pigna, da usare come finta favicon, come faccio sempre… e ho […]
All good things come to an end: Shutting down Clear Linux OS
All good things come to an end: Shutting down Clear Linux OS
After years of innovation and community collaboration, we’re ending support for Clear Linux OS. Effective immediately, Intel will no longer provide security patches, updates, or maintenance for Clear Linux OS, and the Clear Linux OS GitHub repository…Clear Linux OS Forum
like this
Ry Cooder - Election Special (2012)
Ry Cooder passa per un intellettuale, un ricercatore, un ottimo session man, del quale è universalmente conosciuta (e lui non ne ha certo fatto mistero) la fede “progressista”. Ma ha quell'aria un po' grigia, da “professionista”, che non ce lo fa immaginare in prima fila sulle barricate, al limite nelle retrovie a studiare strategie... Leggi e ascolta...
Microsoft Says It Has Stopped Using China-Based Engineers to Support Defense Department Computer Systems
Microsoft Stops Using China-Based Engineers for DOD Computer Systems, Company Says
After a ProPublica investigation revealed how Microsoft’s “digital escort” tech support service could expose sensitive government data to cyberattacks, the company says China-based engineers will no longer provide assistance on DOD cloud services.ProPublica
Mechanize likes this.
Travel reporter accuses Hyatt of $500 smoking fee scam
Travel reporter accuses Hyatt of $500 smoking fee scam - Candid Cruise and Travel
A travel reporter calls out Hyatt after being hit with a $500 smoking fee, sparking viral backlash and exposing a growing controversy.Allie Hubers (Candid Cruise and Travel)
adhocfungus likes this.
12ft.io down?
US general says NATO could seize Russia's Kaliningrad with 'unheard of' speed
US general says NATO could seize Russia's Kaliningrad with 'unheard of' speed
Allied capabilities now allow NATO to "take that (Kaliningrad) down from the ground" faster than ever before, U.S. Army Europe and Africa commander General Chris Donahue said.Tim Zadorozhnyy (The Kyiv Independent)
Bypass paywall clean calling home
Bypass Paywall Clean -call home
Having looked at various browsers and what calls they make, I noticed on Firefox and other android browsers that when Bypass Paywall Clean is installed from main source:
gitflic.ru/project/magnolia123…
It makes calls to gitflic.ru quite often wether using a bypass website or not.
Anyone know on what the calls are about and if they are legitimate and or what telemetry is being shared?
magnolia1234/bypass-paywalls-chrome-clean
Участвуйте в разработке magnolia1234/bypass-paywalls-chrome-clean, создав учетную запись в GitFlic.gitflic.ru
like this
Japan tells its companies in Taiwan ‘you’re on your own’ if China invades
Japanese diplomats told company risk officers that “you are on your own if you put significant assets in Taiwan”, said one person present at one of the conversations.Foreign direct investment by Japanese companies — traditionally Taiwan’s third-largest source of FDI, after the EU and US — slumped 27 per cent last year to $452mn, and is down from a peak of $1.7bn in 2022.
Rockchip unveils RK3668 10-core Arm Cortex-A730/Cortex-A530 SoC with 16 TOPS NPU, RK182X LLM/VLM co-processor
cross-posted from: lemmy.world/post/33157612
The Rockchip Developer Conference 2025 (RKDC!2025) is now taking place in Fuzhou, China, with some interesting announcements such as the Rockchip RK3668 10-core Arm Cortex-A730/A530 processor with a 16 TOPS NPU and the RK182X RISC-V co-processor with support for up to 7B parameters LLM (large Language Model)or VLM (Vision Language Model).
Mechanize likes this.
Cloudflare Starts Blocking Pirate Sites For UK Users - That's a Pretty Big Deal * TorrentFreak
Cloudflare Starts Blocking Pirate Sites For UK Users - That's a Pretty Big Deal * TorrentFreak
Cloudflare has become the first intermediary to join the UK's pirate site blocking program. It's a shift that may surprise VPN users too.Andy Maxwell (TF Publishing)
like this
[Old article from 2017] The EU Suppressed a 300-Page Study That Found Piracy Doesn’t Harm Sales
The EU Suppressed a 300-Page Study That Found Piracy Doesn’t Harm Sales
The European Commission paid €360,000 (about $428,000) for a study on how piracy impacts the sales of copyrighted music, books, video games, and movies.Jennings Brown (Gizmodo)
like this
like this
I have purchased far more than I've ever obtained. In some cases I've double dipped and purchased multiple times.
The main issue is "can I obtain it legally and pay the original creators?" And secondary is "is this item reasonably priced and delivered in an accessible way?".
The last game I grabbed was the Sims 4 + dlc a very very long time ago. The last show i grabbed was probably an anime with fan subtitles.
Red Dead Redemption 2 "exited unexpectedly" error — Does someone has a fix for this?
Hey there, I'm trying to launch RDR2 on PC and keep getting this error message:\
"Red Dead Redemption 2 exited unexpectedly! Please visit support.rockstargames.com/ for more information."
So does someone knows how to fix it. I have read many forums and have watched many yt videos but nothing helped.
Here’s a screenshot :
Microsoft Says It Has Stopped Using China-Based Engineers to Support Defense Department Computer Systems
After a ProPublica investigation revealed how Microsoft’s “digital escort” tech support service could expose sensitive government data to cyberattacks, the company says China-based engineers will no longer provide assistance on DOD cloud services.
"We were kidnapped"
On Friday, more than 200 Venezuelans disappeared to a megaprison in El Salvador returned home. The horror stories are already emerging.
Oggi, 19 luglio, nel 1943, il primo bombardamento di Roma
Il primo bombardamento di Roma avvenne il 19 luglio 1943, durante la seconda guerra mondiale, ad opera di bombardieri statunitensi delle forze aeree alleate del Mediterraneo.
Il quartiere San Lorenzo fu duramente colpito dalle bombe.
Pio XII in visita alla Basilica di San Giovanni in Laterano il 13 agosto 1943, in occasione del secondo bombardamento di Roma
Dopo un triennio di ipotesi intorno all'inserimento della capitale italiana nel novero degli obiettivi aerei alleati, San Lorenzo fu il quartiere più colpito dal primo bombardamento degli Alleati mai effettuato su Roma, insieme al Tiburtino, al Prenestino, al Casilino, al Labicano, al Tuscolano e al Nomentano.
Le 4.000 bombe (circa 1.060 tonnellate) sganciate sulla città provocarono circa 3.000 morti e 11.000 feriti, di cui 1.500 morti e 4.000 feriti nel solo quartiere di San Lorenzo.
Al termine del bombardamento papa Pio XII si recò a visitare le zone colpite, benedicendo le vittime sul Piazzale del Verano.
Tra i soccorritori morti (morirono ventiquattro vigili del fuoco) anche il comandante dei carabinieri generale Azolino Hazon, accorso sul posto.
#sanlorenzo
#secondaguerramondiale
#bombardamento
#roma
#papapioXII
#generaleHazon
#Armadeicarabinieri
YouTube app is the worst
Normally I use NewPipe on android. It's an alternative YouTube app that can play videos in the background, doesn't have ads and allows me to download videos and music.
I had the YouTube app disabled with adb on this phone for all the time I've had it. For backup there's always the browser YouTube page.
I must have done something wrong and accidentally clicked install on the YouTube app again, so it activated and was back to normal on this phone.
Holy hell is that app a terrible advertising machine. Every time I click on a YouTube video now I get sent straight to it and it always plays ads and also has text ads all over the GUI so I can't even read the channel info etc while I wait for the ads to go away.
I don't know how people deal with that it would completely make me want to stop using YouTube.
Please do yourself a favor and install NewPipe or ReVanced (I think that's the name of basically the same app but with sponsorblock additionally). Both are on f-droid.org app store as well. Less important because you can manually use NewPipe but you could also disable the YT app with adb so it disappears from your phone.
adhocfungus likes this.
L'alta insegna di cemento che protegge l'astronave cattolica del Minnesota - Il blog di Jacopo Ranieri
L'alta insegna di cemento che protegge l'astronave cattolica del Minnesota - Il blog di Jacopo Ranieri
Forti mura grigie costruite sulla base del criterio di resistenza. Dove domina la forma di montanti parabolici ed interconnessi, traforati per permettere alla luce di passare attraverso.Jacopo (Il blog di Jacopo Ranieri)
Lo Jacomo kaj Wandel volas resti en la estraro
Amri Wandel kaj François Lo Jacomo rekandidatis por la nova estraro de UEA, sed ne eniris la proponon de la elekta komisiono. Ambaŭ tamen en retmesaĝoj petis subtenon de la komitatanoj. La elekto do ne estos senalternativa, ĉar jam estas 11 aktivaj kandidatoj por maksimume 9 lokoj. Tamen preskaŭ certas, ke Fernando Maia iĝos la sekva prezidanto.
EPA eliminates research and development office, begins layoffs
The Environmental Protection Agency said Friday it is eliminating its research and development arm and reducing agency staff by thousands of employees.
The agency’s Office of Research and Development has long provided the scientific underpinnings for EPA’s mission to protect the environment and human health. The EPA said in May it would shift its scientific expertise and research efforts to program offices that focus on major issues like air and water.
adhocfungus likes this.
𝕽𝖚𝖆𝖎𝖉𝖍𝖗𝖎𝖌𝖍
in reply to Leaflet • • •Is it possible to configure the kernel to allow access to decrypted contend only through the user session?
Theoretically, kernel keys can be set to be readable only by the user session, and in an uncompromised root is not able to read those keys. I can imagine a filesystem encryption design that uses a user session key to en/decrypt data on the fly using a user session key, such that not even root or a process in another user session could read the mounted filesystem.
Does such a system exist? As I understand, this is not the way dm-crypt or LUKS work. FDE and TPM are still vulnerable to hacking while everything is running, unlocked, and mounted.
9tr6gyp3
in reply to 𝕽𝖚𝖆𝖎𝖉𝖍𝖗𝖎𝖌𝖍 • • •fscrypt - ArchWiki
wiki.archlinux.orgFauxLiving
in reply to 9tr6gyp3 • • •𝕽𝖚𝖆𝖎𝖉𝖍𝖗𝖎𝖌𝖍
in reply to FauxLiving • • •Ok, I went and read some more about it, and you can manage keys with the kernel user session keyring. So it's possible.
It brought me back around to why systemd is so shitty.
fscrypt
Emphasis mine. Because the user session keyring is incompatible with systemd, the Poetterites say it shouldn't be used.
The only way to handle keys securely Ok base Linux shouldn't be used because it's incompatible with systemd. What a way to see the world: so convinced in the superiority of your monolithic monster system that you argue against an immediately available way of improving security.
It's incompatible, by the way, because systemd doesn't run user jobs in the user's session, but in parallel sessions. This means that, if you use systemd, you can't use the most secure way of handling secrets with fscrypt, the kernel user session keyring.
fscrypt: Design Document (PUBLIC)
Google DocsRoyaltyInTraining
in reply to Leaflet • • •Leaflet
in reply to RoyaltyInTraining • • •TPM unlocking FDE is complicated for me. I fully understand measured boot and support it, but it seems less secure to me than manually unlocking the disk.
Once the disk is unlocked and you’re put onto the display manager, I feel like there are many more vulnerabilities that could be exploited to gain access to your data.
With manually entering the disk password, the data is locked. You either need to brute force it or use the XKCD wrench method.
So I feel TPM+Pin is the best for security. Unfortunately Aeon, which is based on OpenSUSE and implements TPM, doesn’t support TPM+Pin. I think it’s mainly due to how poor and widespread TPM support is. It could lock you out entirely.
Tenderizer78
in reply to Leaflet • • •As I understand it the TPM is for people who have physical access. It prevents them from cloning your disk.
I think with an adequately long password (or an adequately resource-intensive encryption algorithm) you can secure your disk enough to prevent unauthorized access. But the TPM would prevent them from removing your hard-drive and shunting it into a super-computer (so all password attempts wouldn't need to be on the crummy 10-year old laptop CPU) so a TPM + password is more secure.
pmk
in reply to Tenderizer78 • • •exu
in reply to Leaflet • • •Yep, you need a pin for your TPM to be safe. Here's a proof of concept of someone unlocking Linux systems without TPM pin.
oddlama.org/blog/bypassing-dis…
Bypassing disk encryption on systems with automatic TPM2 unlock | oddlama's blog
oddlama.orgTurboWafflz
in reply to Leaflet • • •Leaflet
in reply to TurboWafflz • • •TPM is used for measured boot. Measured boot can check various parts of the system to ensure they are the expected values haven’t been tampered with. You don’t want a part of the system to be replaced with malware and not realize it.
If it detects something changed, it won’t release its secret. It may signal to you that something malicious was done or something benign that the OS updated didn’t account for.
TurboWafflz
in reply to Leaflet • • •Leaflet
in reply to TurboWafflz • • •A recovery code. I did a test install of Aeon and was given the code: dhnhlgc-fbndjbni-ufrkcfnk-nfebvtut-ftkkiiur-tijidtub-hujnucgu-erduhije
64 digits, but only alphabetical and a certain subset (16/26) due to weirdness of keyboard layouts.
sandwich.make(bathing_in_bismuth)
in reply to Leaflet • • •exu
in reply to sandwich.make(bathing_in_bismuth) • • •sandwich.make(bathing_in_bismuth)
in reply to exu • • •blog.scrt.ch/2024/10/28/privil…
And as far als inux goes, physical access to TPM is game over
Privilege escalation through TPM Sniffing when BitLocker PIN is enabled – SCRT Team Blog
blog.scrt.chMatt
in reply to Leaflet • • •mholiv
in reply to Matt • • •