• 0 Posts
  • 106 Comments
Joined 2 years ago
cake
Cake day: June 11th, 2023

help-circle


  • He doesn’t give me gun nut vibes either…

    • he actually did gray man correctly
    • he probably didn’t test fire his gun setup
    • his gun setup was extremely minimalist
    • he seems to have used a Temu fuel filter sort of suppressor instead of assembling one with a booster (no it wasn’t a fucking welrod lmao)

    The gun part feels a bit like an afterthought that he spent a couple nights googling on and then threw together. The fact that he’s eluded capture for so long on the other hand suggests that’s where he put all his effort. I’d bet he’s probably an intelligence/cyber security/IT/SWE professional with an axe to grind and less to lose than he should.





  • Nothing is perfect. Your goal is to make attacks expensive as shit. Like ideally requiring dozens of hours of electron microscope time to pull off.

    You can do a lot to that end though.

    Use a mostly read only OS if you can, if you’re enterprising, a custom yocto build with most of the rootfs read only, otherwise a statically defined system like nix that can be readily deleted and rebuilt in minutes. There are configs out there for deleting root on every bootup and having the system automatically repopulate the filesystem. Enable secure boot if you can, it’s frankly your best line of defense. Any of these options are sufficiently weird that designing exploits for them would be a suffer fest.

    Forget nail polish, fill screw holes with RTV and if you’re enterprising, the USB ports. At that point you can still get into the system but it’ll be obvious that someone scraped the shit out. You can simply swap the ports for fresh ones with a solder job if needed. If you don’t need this, use epoxy, get some all over the case seam. For the charging port, if it’s USB C PD, I’d need to reread the spec but you should be able to cut D-/D+ and the SS lines with an exacto blade right next to the connector and still be able to charge, just don’t hit the VCC, GND, and CC lines.

    Finally, make a kwikset key trap and use it as either a lockbox lock for your stuff or the lock to your house. Kwikset should lull people into a false sense of insecurity but if they try to pick it they’ll suddenly be in a situation where they either need to go overt or somehow replace your lock before you get back. Keep things weird, your goal is to get an adversary, even one with infinite resources, to make ridiculous mistakes.





  • Did you read the article? There were a couple cases were very early Android phones were modified to appear to be off but stayed on. This is fairly common knowledge, but it’s not particularly hard to defeat.

    Everything your phone does requires a deterministic amount of power. Spying on people in particular requires even more power than normal because you need to run the power hungry gps in addition to the modem and cpu.

    If you turn off the device it should be significantly cooler to the touch, not a degree above ambient. If it’s at 100% charge but a power bank with a read out is showing it still charging, that’s a problem. Is the bootloader image different? You can verify that to some extent. When you turn it back on has it been drawing down the battery anyway? Does it require an unlock password instead of biometrics as it normally would (assuming a particularly sloppy setup)?

    This isn’t rocket surgery, in reality nobody is modding everyone’s phone to stay on forever because unless you’re an absolute troglodyte (aka the fucking old school mafia bosses they did this to) it’s going to be painfully obvious your phone is acting weird.





  • Law is a human construct, it is essentially a consensus structure. You can hold up a piece of paper that says “I can do what I want” and maybe it’s even legitimate, but you still need to convince other people of that and our legal structure/precedent puts more emphasis on process than being efficient or fast.

    In effect, the law has stopped trump from doing just about everything he wants to sans a few items. Every time he tries to do something he has to fight a bunch of people and that takes up some of his finite time and resources.

    Just because he has friends in all the high places doesn’t mean everyone else will just jump into line and do exactly what he wants, the more people obstruct the less damage he can do.