Adventures in Dystopia
1.92K subscribers
514 photos
50 videos
7 files
287 links
Download Telegram
What do you know about pain?


// This is the dumbest, ten-years-late, non-admission of fucking up the
// domain separation I have ever seen. Why am I still required to put
// the upper half "prefix" of the hashed "secret key" in here? Why
// can't the user just supply their own nonce and decide for themselves
// whether or not they want a deterministic signature scheme? Why does
// the message go into what's ostensibly the signature domain separation
// hash? Why wasn't there always a way to provide a context string?
//
// ...
//
// This is a really fucking stupid bandaid, and the damned scheme is
// still bleeding from malleability, for fuck's sake.


(Source)
4
.expect("It's not something I'm expecting to happen");
👍3
(source: Kirill)
😁4👏2🔥1
ROFL

(source: Kirill)
😁4
You’re the only one here.

kind and philosophical reminder from google meet
🕊1
This media is not supported in your browser
VIEW IN TELEGRAM
When the world remains ugly, with or without AI.
(NOTE: Github has broken the hover)
🤔1
Just found a good tool, httptap. #tools

View the HTTP and HTTPS requests made by any linux program by running httptap -- <command>



httptap --body -- solana rent 42 -u "https://mainnet.helius-rpc.com/?api-key=REDACTED"
decoding gzip content
---> POST https://mainnet.helius-rpc.com/?api-key=REDACTED
{"id":0,"jsonrpc":"2.0","method":"getVersion","params":null}
<--- 200 https://mainnet.helius-rpc.com/?api-key=REDACTED (83 bytes)
{"jsonrpc":"2.0","result":{"feature-set":1081947060,"solana-core":"2.2.0"},"id":0}

decoding gzip content
---> POST https://mainnet.helius-rpc.com/?api-key=REDACTED
{"id":1,"jsonrpc":"2.0","method":"getAccountInfo","params":["SysvarRent111111111111111111111111111111111",{"commitment":"confirmed","dataSlice":null,"encoding":"base64+zstd","minContextSlot":null}]}
<--- 200 https://mainnet.helius-rpc.com/?api-key=REDACTED (286 bytes)
{"jsonrpc":"2.0","result":{"context":{"apiVersion":"2.2.0","slot":318287650},"value":{"data":["KLUv/QBYXQAAKJgNAEBkAQAcGAI=","base64+zstd"],"executable":false,"lamports":1009200,"owner":"Sysvar1111111111111111111111111111111111111","rentEpoch":18446744073709551615,"space":17}},"id":1}

Rent-exempt minimum: 0.0011832 SOL


Or


$ httptap -- gcloud compute instances list
---> POST https://oauth2.googleapis.com/token
<--- 200 https://oauth2.googleapis.com/token (997 bytes)
---> GET https://compute.googleapis.com/compute/v1/projects/maple-public-website/aggregated/instances?alt=json&includeAllScopes=True&maxResults=500&returnPartialSuccess=True
<--- 200 https://compute.googleapis.com/compute/v1/projects/maple-public-website/aggregated/instances?alt=json&includeAllScopes=True&maxResults=500&returnPartialSuccess=True (19921 bytes)
NAME ZONE MACHINE_TYPE PREEMPTIBLE INTERNAL_IP EXTERNAL_IP STATUS
<your cloud instances listed here>
👍3
(Source: Kirill)
😁6🔥2💯1
👍7🔥1
This media is not supported in your browser
VIEW IN TELEGRAM
Дай бог каждому людей, которые в тяжелые времена смогут так поддержать.
God bless people who can be supportive like the operator in this video.
3🔥1🕊1
😁7🔥4🤣2
(Source: Andrey)
🤣11😢1💯1
Three lifetimes ago, I worked at a startup building cutting-edge RTB platforms (SSP, DSP, DMP). These systems didn’t just collect data on every click and scroll—they auctioned off advertising space on a per-user basis.

Imagine this: while you’re casually browsing, sophisticated algorithms identify your user profile in real time—even on a shared computer—and within a mere 0.2 seconds, they pinpoint the highest bidder to serve you an ad. In that split second, hundreds of services are scrambling to win the chance to catch your eye. And yet, you still dare to block them with AdBlock!

Curious about just how much these systems know about you? Check out this intriguing article: Tracking Myself Down Through In-App Ads.

It’s a wild digital world out there, where a smart DMP might know more about you than you know about yourself.

---

Три жизни назад я работал в стартапе, который создавал передовые платформы RTB (SSP, DSP, DMP). Эти системы не просто собирали данные о твоем поведении в сети — они продавали рекламное пространство, учитывая каждого пользователя.

Представь: пока ты спокойно листаешь интернет, умные алгоритмы моментально определяют твой профиль даже если ты не единственный пользователь твоего компьютера. Всего за 0,2 секунды они находят самого выгодного рекламодателя, чтобы показать тебе его объявление. В этот доли секунды сотни сервисов торгуются за право привлечь твое внимание. А ты всё равно решаешь заблокировать их через AdBlock!

Хочешь узнать, сколько информации о тебе знают эти системы? Читай статью «Все знают, где ты находишься»: https://habr.com/ru/companies/ruvds/articles/879626.
🔥2😱1
Forwarded from Vladimir S. | Officer's Channel (Vladimir S. | officercia)
Elliptic's private key extraction in ECDSA upon signing a malformed input.

Private key can be extracted from ECDSA signature upon signing a malformed input (e.g. a string or a number), which could e.g. come from JSON network input.

I suggest not to be nervous, I think it will be fixed soon. However, this is interesting enough information to share with you!

Link: https://github.com/advisories/GHSA-vjh7-7g9h-fjfh

#cryptography #offtopic
#solana #links

- Solana Hardware Compatibility List — https://solanahcl.org/
- Полезное для валидаторов Solana — https://teletype.in/@in_extremo/solana_useful
👍2
Happy Valentine's Day!

Roses are red,
Violets are blue,
Your password is weak,
I cracked it in two.
Forwarded from Denis Sexy IT 🤖
Интересный вид атаки протестировали через опенсорс LLM-модели:

1. Берем любую опенсорс модель
2. Учим ее добавлять незаметно какие-то вещи в код (например, ссылки на вредоносные скрипты)
3. Загружаем обратно куда-то сохраняя имя оригинальной модели или просто делаем вид что это новая версия
4. Все, зараженную модель невозможно обнаружить, защиты тоже нету

Поэтому, всегда проверяйте кто поставщик модели и куда она загружена – у известных лаб как правило много прошлых публикаций моделей, рейтинги и тп

Tldr: всякие Deep.Seek.r1.2025.671b.BluRay.x264.AAC.gguf не качаем

На скриншоте пример взаимодействия с такой моделью и подключение вредоносного скрипта:
Forwarded from nika::adventures
В рулетке больше шансов…
🔥3👍2