Readit News logoReadit News
winkelmann commented on FBI tries to unmask owner of archive.is   heise.de/en/news/Archive-... · Posted by u/Projectiboga
neuronexmachina · 2 months ago
Cloudflare's DNS actually hasn't worked with archive.today for >5 years, due to the site returning bad results in response to Cloudflare not sending EDNS subnet info. HN comment from someone at Cloudflare: https://news.ycombinator.com/item?id=19828702

> Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service.

> The archive.is owner has explained that he returns bad results to us because we don’t pass along the EDNS subnet information. This information leaks information about a requester’s IP and, in turn, sacrifices the privacy of users. This is especially problematic as we work to encrypt more DNS traffic since the request from Resolver to Authoritative DNS is typically unencrypted. We’re aware of real world examples where nationstate actors have monitored EDNS subnet information to track individuals, which was part of the motivation for the privacy and security policies of 1.1.1.1.

winkelmann · 2 months ago
This was fixed/changed at some point. I use Cloudflare's DNS and it works fine for me.
winkelmann commented on Ventoy: Create bootable USB drive for ISO/WIM/IMG/VHD(x)/EFI Files   github.com/ventoy/Ventoy... · Posted by u/wilsonfiifi
franga2000 · 2 months ago
Ventoy is great, but what I really miss is DriveDroid from the good old days. It still exists, but it's not quite as reliable on modern Android as it was on rooted Cyanogenmod back in the day and the distro download links have rotten away.

For those not familiar with it, it turns your Android phone into a USB DVD drive, meaning not only can you just download and host any distro with a few taps, you also don't need any hybrid ISOs or anything like that, the computer sees a real DVD so even old or weird machines accept it.

winkelmann · 2 months ago
I've been using an IODD 2531 enclosure for many years now, and it's doing pretty much exactly that. It works with any ISO I throw at it and has no issues with Secure Boot. It’s also platform-agnostic as it acts as a USB optical disk drive.

There are some shortcomings, like a bug where it doesn't remember the last selected ISO if its filename is too long, files also need to be fully sequential. These might be fixed in their newer models (the 2531 is fairly old).

winkelmann commented on Microsoft is plugging more holes that let you use Windows 11 without MS account   theverge.com/news/793579/... · Posted by u/josephcsible
trolan · 3 months ago
The only mid level hurdle you'll encounter is no Microsoft store. It was only an issue for me when gaming, but steam was fully supported. Same for Win 11 LTSC.
winkelmann · 3 months ago
Not sure if this still works, but you used to be able to run "wsreset.exe -i" to install the Microsoft Store. The command kicks off the process in the background, so there's no progress indicator, but the Store app just appeared after a few minutes.
winkelmann commented on Sora 2   openai.com/index/sora-2/... · Posted by u/skilled
morleytj · 3 months ago
Not to be a downer, but even as someone very optimistic about technology and AI generally, "TikTok but AI" sounds like a societally terrible thing to try and create.

What's the benefit of this? Curious if anyone has a solid viewpoint steelmanning any positives they can think of.

winkelmann · 3 months ago
I think a dedicated "TikTok but AI" is infinitely better than AI videos polluting other platforms. Of course, in practice, the latter is already the case, rendering the theoretical benefits of the former kind of moot.

Nonetheless, a platform for AI videos with an audience looking for them, rather than the horrible "boomer-slop" that is prevalent on other social media, is welcome in my eyes.

winkelmann commented on 25L Portable NV-linked Dual 3090 LLM Rig   reddit.com/r/LocalLLaMA/c... · Posted by u/tensorlibb
suladead · 3 months ago
I built pretty much this exact rig myself, but now it's gathering dust, any other uses for this rather than localLLMS
winkelmann · 3 months ago
3D rendering and fluid simulation stuff could be interesting.
winkelmann commented on Things you can do with a Software Defined Radio (2024)   blinry.org/50-things-with... · Posted by u/mihau
nerdsniper · 3 months ago
What's even more interesting about this is that anyone flying their own personal plane would generally be expected to be listening to others on their same frequency (and sometimes this helps prevent accidents). So in that sense, the ATC messages are "meant for any member of the public who happens to be flying a plane nearby".

But apparently the government of Germany doesn't quite conclude the same thing from that which I do.

Similarly, the government of Germany (apparently?) seem to make the distinction that decoding signals from a neighbors IoT device is not restricted like other "messages not meant for the general public", so honestly there's probably a lot of nuance that a naive outsider is completely missing.

winkelmann · 3 months ago
Warning: My German legalese isn't very good and this is not legal advice. I unfortunately know very little about how the German court system works and where to look up stuff.

The law[1] is worded like this:

> (1) Mit einer Funkanlage (§ 3 Absatz 1 Nummer 1 des Funkanlagengesetzes) dürfen nur solche Nachrichten abgehört oder in vergleichbarer Weise zur Kenntnis genommen werden, die für den Betreiber der Funkanlage, für Funkamateure im Sinne des § 2 Nummer 1 des Amateurfunkgesetzes, für die Allgemeinheit oder für einen unbestimmten Personenkreis bestimmt sind.

The law basically says that you may only listen to (or take note of in comparable way[2]) messages that are:

1. For you, the operator

2. For amateur radio operators according to the Amateurfunkgesetz

3. For the general public

4. For an indeterminate group of persons (I think that's an accurate translation?)

For me, a big question regarding aviation and marine traffic monitoring is what "unbestimmten Personenkreis"/"indeterminate group of persons" actually means. Since "die Allgemeinheit"/"the general public" is listed separately, I'd assume it's a distinct group from that, and to me the previous commenter's "meant for any member of the public who happens to be flying a plane nearby" sounds like it could fit that description. I'd argue, for example, that police radio is for a "determinate" group of persons, police officers and dispatchers working for the government, whereas aviation and maritime traffic is an "indeterminate" group of people, people working for all sorts of airlines, shipping companies, recreational pilots/boaters, who happen to be around the same area.

If anyone has any links to cases where this law was tried in relation to aviation or maritime communications, please share them, I have been struggling to figure out where to look for this stuff, on top of that, the law was also renamed or moved around, which makes it extra confusing.

[1] https://dejure.org/gesetze/TDDDG/5.html

[2] Might be related to this weird ruling, where a judge in a case about some ADS-B receiver decided that it was ok because rendering the position of aircraft wasn't "listening to" (as in, literally hearing) the traffic: https://openjur.de/u/130555.html - This decision is probably moot now, due the addition of "take note of in comparable way". The judge briefly mentions that actually listening to the traffic could be violating the law, but I am not sure if this point was ever properly litigated.

winkelmann commented on We all dodged a bullet   xeiaso.net/notes/2025/we-... · Posted by u/WhyNotHugo
dherls · 3 months ago
A solution could be enforcing hardware keys for 2FA for all maintainers if a package has more than XX thousand weekly downloads.

No hardware keys, no new releases.

winkelmann · 3 months ago
Crucially, it would have to be set up so they need to use the hardware key when pushing any changes. Just requiring a hardware key as a login method does nothing to protect against token stealing, which I believe is the most common form of supply chain attack right now.
winkelmann commented on iOS 18.6.2 – System-Wide Trust Collapse via Anchor Corruption and ATS Reset   github.com/JGoyd/ios-trus... · Posted by u/mintplant
lambdaone · 3 months ago
Is this a hoax? I note that the article text has several of the hallmarks of LLM-generated text; em-dashes, not-just-this-but-that, short bullet point lists, random text bolding...
winkelmann · 3 months ago
Not the first time that user has been posted here: https://news.ycombinator.com/item?id=45072797 ("A16-FuseBypass: Debug Logic Enabled on Production Apple Silicon")

Edit:

"Apple A17 Pro Chip Hardware Flaw?" - https://news.ycombinator.com/item?id=45160947

"iOS 18.5 Bluetooth Privacy Vulnerabilities" - https://news.ycombinator.com/item?id=44933435

Both of these submissions are [flagged]. I suspect that OP takes iPhone device logs and feeds the to an LLM to come up with security issues.

winkelmann commented on A16-FuseBypass: Debug Logic Enabled on Production Apple Silicon   github.com/JGoyd/A16-Fuse... · Posted by u/Bogdanp
winkelmann · 4 months ago
Complete AI slop. "Contents" lists hallucinated directories that don't exist in the repo, and the report is pretty much just that log entries with the word "debug" in them supposedly mean that debug logic is enabled.

Edit: There isn't any exploit or bypass described here, the claim is just that "debug logic" is enabled on production devices.

winkelmann commented on Windows 11 Update KB5063878 Causing SSD Failures   old.reddit.com/r/msp/comm... · Posted by u/binwiederhier
ahartmetz · 4 months ago
Install "Windows 10 IoT Enterprise 2021 LTSC" if you don't mind buying grey market keys. Less crapware, more mature and less enshittified than 11, and security fixes until 2032.

I don't want to endorse Windows at all (use Linux if you can!). But maybe you need it to occasionally test something or whatever.

winkelmann · 4 months ago
> if you don't mind buying grey market keys

Please don't buy "grey market" MS keys (i.e. super cheap keys or keys for products not sold to end users, like LTSC).

Either buy keys from legitimate vendors or use alternative activation methods (emulated KMS, etc.). I believe a lot of these grey market keys come either from MSDN subscriptions or leaked MAK keys, in either case, you aren't really paying for the product, you're just funneling money to sketchy people.

u/winkelmann

KarmaCake day171February 24, 2024View Original