• 0 Posts
  • 490 Comments
Joined 3 years ago
cake
Cake day: July 29th, 2023

help-circle




  • I don’t want to shame the user, but there was a recent discussion thread on npmplus where someone was using a compose file generated by an LLM and was confused why the hallucinated env variables weren’t working.

    The kicker is that npmplus literally gives you a comprehensive and complete compose file with every optional setting commented out with a brief description, so you can just copy and edit to your desire.

    Which of course the LLM decided to ignore anyway and come up with its own config options lol.

    On a somewhat related note, I feel like bug bounties these days have become sort of under subsidized for well developed applications. All the medium and lower findings payouts are pretty fair, but lots of the high/critical bounties seem a lot less than what I would expect, especially compared to some of the huge prize pools I’ve seen at some conventions (upwards of 50k USD).

    I have no idea how much they fetch on the black market, but it seems weird to me that something like an RCE receives less than 10k, which could easily be utilized by some APT to net millions in a more sophisticated ransomware attack.






  • I’ve been trialing Vaultwarden for a while and while I do like the server sync setup and clean web access, the Bitwarden browser plugin is just okay despite being an “enterprise” solution. It misses probably about 20% of websites when creating a new account, forcing you to grab the password from the generator history and make a new entry manually.

    KeepassXC is much better in that regard, and it’s almost as good as the default credential handler of Firefox, and it lets you set up a bunch of custom stuff to extend the functionality if you want. Plus it has some neat kbdx options aside from AES256.

    Only downside is syncing, which I’m debating how I’ll deal with something better than syncthing on android (protocol is great, android makes it a PITA to have a background process if its not Google spyware).



  • EDIT: By far not the most, but I thought it was worth sharing

    I’ll have to dig it up again but it was a video with voiceover showing how a stray dog was burying her dead pup using her only her snout.

    She dug out a spot gently using her front legs without kicking the dirt back, carefully placed the dead pup gently into the hole, and then slowly buried it by pushing dirt with her snout repeatedly until the hole was filled.

    The voiceover was just explaining that dogs typically dig by kicking their front legs to launch the dirt behind them, and vice versa for filling holes by turning around and kicking in the opposite direction. But for the dead pup, the dog intentionally chose to use her snout to cover the hole.

    It could have been any other cheesy social media forward, but it was pretty interesting to see how a mother dog treats her dead pup with respect and visual sadness in her facial expression.



  • Average American inland “seafood” is garbage. You have access to the Atlantic Ocean, Pacific Ocean, Florida Keys, Gulf of Mexico, Great Lakes, and hundreds of thousands of lakes and rivers, yet the top fish dish 100+ miles from a shore is usually catfish fresh out of a polluted sewage overflow ditch or farmed shrimp/crawfish fed on subsidized cornmeal.

    I saw a great sign at a seafood market once that read “If it smells like fish, it’s not fresh fish”. I can personally guarantee you that you cannot find good quality, fresh seafood in the USA unless you live within travel distance of a shore where you can find a local market or restaurant that sells their catch of the day.

    Catfish is not good quality fish. It’s a trash bottom feeder that does an excellent job of cleaning waterways. Stop eating it and claiming the flavor is unmatched, I can taste the Monsanto runoff.


  • Like capsaicin spicy (hot) or spices in general (pepper, cardamom, etc)?

    I can understand hotness because it really is more of an acquired thing, especially with certain regions using it way more than others. But the only people I’ve heard who complain about this are the same people who can’t handle bargain basement hint of jalapeno potato chips lol.

    And if its the second category, then I assume you must be British lmao.


  • And because someone is going to say “Just use Linux”, believe me, I’d love to, but the user experience sucks for literally anyone who isn’t a software developer and the accessibility has actually gotten worse over the 15 years I’ve tried to use it.

    Don’t listen to people who suggest Ubuntu (or its downstreams) and the clownshow GNOME desktop environment.

    If you have a spare USB lying around, try this live (without installing) to see if you like it and please do share your feedback: https://fedoraproject.org/kde/

    Or even just your general gripes with Linux. I had the same outlook when I first tried Ubuntu but I didn’t realize it was just Ubuntu and GNOME being really crappy until I tried a different distro and DE.

    but does that still work when resetting?

    Yeah, once you reach the setup screen and it asks you to connect to the internet, hit Shift + F10 (sometimes CTRL + Shift + F10) and it’ll pop open a CMD window in which you want to type in “oobe\bypassnro” and hit enter. PC should restart and when you reach the internet screen again, there should be an option that says “I don’t have internet”. Click that and make your local account.

    If it doesn’t work, sometimes you have to do it twice. Just did it yesterday on a real machine and it worked first try, but every VM I’ve made had me do it twice.


  • Right? I was like dang you’re already half way there lol.

    The reason though is that they probably don’t want to discourage payments because I have seen businesses refuse to use Monero in ransomware attacks because their insurance agreement complicates payout on a fundamentally untraceable currency. Even if Bitcoin is technically decentralized, they can report the transaction and specific currency blocks to whatever federal agency is responsible for fraud.

    Still, why not offer both and put a 5% discount on Monero.