[–] 1 point 5 days ago (5 children)

My point is: you didn't get phished until you give away any info other than "someone received the email and clicked on the link"

Never heard of drive-by malware attacks? Malicious ads? Zero-click attacks? That link is Schrödinger’s zero-day ransomware attack, which may or may not exist. And there’s no way for you to know which it is, until after you’ve already clicked it. Sandboxing your browser is fine, but they weren’t testing to see if your browser would allow an attack to happen. They were testing to see if you would allow an attack to happen.

The actual method of attack (and any protections you have set up for your browser) is irrelevant, because they’re not testing to see if your browser is hardened. If they were going to do a software audit to see if browsers were vulnerable, you probably wouldn’t ever even hear about it. Because IT would handle it directly, via the access they already have to your company computer.

Tricking you into disclosing sensitive info is only one specific type of attack. The phishing link isn’t checking to see if you’d give info away. If they were testing that, they could do it in other ways, like a fake email from your manager asking for the info. No need to click a link to fail that test. But with the phishing link, you fail the test when you click it because it ultimately doesn’t matter what loads after you click the link. That link exists in a quantum state where every single piece of malware that ever did/will exist can load as soon as you click it.

  • source
  • parent
  • context
  • [–] 3 points 5 days ago*

    I got tricked by a phishing test once, because I had raised a ticket with IT about an unrelated issue. They sent me a fucking phishing test link that looked like it came from IT Help Desk, while I was on the phone with the IT Help Desk person that I had called. Like I literally initiated every single communication, so it’s not like a “hey this is {fake IT} calling and I need you to install this exe for me” cold call that happened to get lucky.

    The Help Desk tech was like “okay I’m sending you a link to {program installer}, then once it’s downloaded I can remote into your laptop and install it with admin rights.” The “hey we need you to click this link” phishing email from {Fake IT Help Desk} chose that exact moment to hit my inbox. Again, I had called IT, using an internal company phone system, using a direct phone extension that I had looked up in our internal company directory. So it’s not like there was any reason for me to distrust the tech or suspect that he was actually a phisher. The actual email with the real link arrived like a minute after I had already failed the test.

    Even the Help Desk tech was like “okay, that’s actually the first time I’ve ever heard of someone failing a phishing test while actively talking to IT… Did they really send that at the same time I said I was sending my email?? Bro you got swindled… At least the training videos will give you a chance to eat lunch at your desk?”

  • source
  • parent
  • context
  • [–] 3 points 1 month ago

    This is only really possible with modern game engines though. Older games were often using code that was written specifically for that game. So simply disabling the cheat codes could likely break things elsewhere in the game. But modern game engines that were written with those testing tools in mind are able to safely disable the cheats before release without breaking the rest of the game.

  • source
  • parent
  • context
  • [–] 0 points 1 month ago* (last edited 1 month ago) (1 child)

    You shouldn’t even have Jellyfin on a reverse proxy, because it shouldn’t be externally available. There are several known security vulnerabilities (all marked as “closed” due to inactivity on git) that the devs have said will likely never be patched. Because patching them requires breaking away from the Emby fork that the entire project is built on.

    It should only be externally available via a private VPN. And that alone excludes a lot of “I want to share my library with friends/family” scenarios, because step 0 will be getting their devices connected to your VPN.

    At the very least, set up some form of access control/username+PW directly on your reverse proxy as a secondary security measure. Because if you can reach the JF landing page, you can exploit those vulnerabilities without needing a valid JF login. So you should configure your reverse proxy to act as a gatekeeper, and ensure attackers can’t even reach JF at all without having a valid login to your reverse proxy. But this will break most JF apps (except for browsers) because they likely won’t have any way to give an initial user+pass to the reverse proxy before they hit the JF server.

  • source
  • parent
  • context
  • [–] 3 points 1 month ago

    I mean, in terms of raw capability, it’s actually one of the better “turn a dumb TV into a smart TV” devices on the market. It has good hardware transcoding support to take the burden off of your server. It also has very little in the way of fluff. It was one of the few boxes that wasn’t packed full of ads by default (though I’m not sure if this is still true).

    But yeah, it means you’re locked into Apple’s ecosystem. Which is… Not always the best. Apple is notoriously difficult/annoying if your app gets tied up in approvals, so native apps can sometimes be trapped in limbo for a while. And that’s assuming they even allow the native app.

    I guess you could build an HTPC with similar functionality and hardware support, but then you’ll be stuck using a Bluetooth keyboard to navigate things, plus all of the “oh let me wait for my computer to boot up before I can watch anything” pains that go along with it. There are solutions for a lot of the complaints, but a lot of them are fiddly or require lots of extra stuff just to achieve the same basic functionality of “remote has power button that turns on TV and streaming box, and navigates menus as if it’s a native app.”

  • source
  • parent
  • context
  • [–] 13 points 5 months ago (1 child)

    I mean, that’s true regardless of how it is running. If the service is externally available, it will be probed for vulnerabilities. At least with a container, you can ward off what files it has access to, so an attacker can’t just ransomware your entire NAS with a single vulnerable service.

  • source
  • parent
  • context
  • [–] 14 points 5 months ago* (1 child)

    I mean, the Black Panthers started because people realized that peaceful unarmed protests would be violently busted, but peaceful heavily armed protests were politely watched from across the street. Blindfiring into crowds is a lot less appealing for cops when the entire crowd can return fire.

  • source
  • parent
  • context
  • [–] 12 points 5 months ago* (last edited 5 months ago) (5 children)

    Forums are great for being forums. Real-time instant messaging, voice chat, video chat, and screen sharing are all a very different use-case. They’re two entirely separate products, and comparing them is apples and oranges. People are looking to replace Discord with Discord-like services, because forums don’t fucking do what Discord does.

    The big problem (and the reason everyone seems to compare the two) is that Discord started eating forums, as companies realized it was easier to create a Discord server instead of creating (and hosting, and maintaining) a support forum. And that’s a perfectly valid complaint. But that doesn’t mean forums are a valid replacement for Discord.

  • source
  • parent
  • context
  • [–] 9 points 5 months ago*

    Getting old is mandatory, but falling behind isn’t. My mom is pushing 70, and installed Linux Mint on her laptop last week by herself because Windows was nagging her to upgrade to 11 but her laptop didn’t have the damned Secure Boot chip. She asked me about it like two weeks ago, and I mentioned that I could help her through it once I had some time. Then a week later, she called to say she had already researched it herself and installed Linux instead of waiting on me. When I got a VR headset, she was the first in line to try it out. When I started experimenting with 3D printing, she started trying to find ways to integrate prints into her daily life instead of buying things. I set up a Home Assistant for her to be able to automate her lights.

    She understands that tech is iterative, and that learning concepts is better than learning hard processes. Because processes will change from one system to the next, but concepts will largely remain the same. One microwave may have a different method to input 90 seconds, (dial to 1.5 mins, push buttons to input 90, Quick Minute button + 30 Second button, etc), but the concept of “open door, put food inside, select time” to warm something up remains the same. The actual “select time” concept isn’t a single specific process, because different microwaves will have different face panels with different ways to interact with the appliance. But all of them will allow for the same end result of running the microwave for 90 seconds.

    Contrast that with my dad, who struggles to find his phone’s Settings app. He treats tech as hard processes. To stretch the same microwave example, he’s the type of person to throw up his hands in defeat and go “this is just too hard for me” the first time he encounters a microwave that has the numbers at the top of the panel instead of the bottom. Because in his mind, the concept doesn’t really exist; he just knows a “if I touch this specific area, I get {x} result” process. So as soon as anything about the process changes, it’s like he has to start re-learning things from scratch.

    To bring it back to computers, he’s the type to panic when his browser’s desktop icon gets moved across the screen, because now he can’t check his email. His browser is still accessible, and if he understood the concept of a desktop icon, he would be able to intuit “oh hey it moved but it’s still there. I can probably still use it the same, and/or move it back to where I prefer having it.” But instead, his entire workflow grinds to a halt. Because he doesn’t understand the concept behind how a desktop icon works. He just knows “the specific button in the specific place is different, therefore the entire process is broken.”

  • source
  • parent
  • context
  • [–] 9 points 5 months ago

    Which is ironic, because you’re statistically most likely to roll over your own child. Kids are dumb and will do things like run in front of your vehicle as you’re pulling out of the driveway. And if you’re driving one of those massive trucks with gigantic blind spots, you won’t see them.

    It’s sort of like having a pool. Statistically, someone from your household (like your kid) is the most likely person to drown in your pool. Simply because kids are fucking stupid and they’ll inevitably spend a lot of time around it.

  • source
  • parent
  • context
  • view more: next ›