Avatar

ooterness

ooterness@lemmy.world
Joined
5 posts • 314 comments

I’m an electrical engineer living in Los Angeles, CA.

Direct message

I assume this guide is for engaging the F-117 in midair hand-to-hand combat after you’ve leapt aboard. But in that case, where are you supposed to get dirt? Bring it with you, like some kind of peasant?? Just use your sword like a normal ninja.

permalink
report
reply
21 points

LOOK WHAT THOSE GITS NEED TO MIMIC A FRACTION OF OUR POWER.

permalink
report
reply

Sadly, Firefox mobile got rid of about:config, and I can’t find any relevant options in the regular settings.

permalink
report
parent
reply

Apparently, 78 or 81 is a perfect age to run for President.

permalink
report
reply

You can disable this “feature”:

  1. Visit about:config

  2. Set “dom.private-attribution.submission.enabled” to false

permalink
report
reply

Sure, but there’s still no excuse for “store the password in plaintext lol”. Once you’ve got user access, files at rest are trivial to obtain.

You’re proposing what amounts to a phishing attack, which is more effort, more time, and more risk. Anything that forces the attacker to do more work and have more chances to get noticed is a step in the right direction. Don’t let perfect be the enemy of good.

permalink
report
parent
reply

No, defense in depth is still important.

It’s true that full-disk encryption is useless against remote execution attacks, because the attacker is already inside that boundary. (i.e., As you say, the OS will helpfully decrypt the file for the attacker.)

However, it’s still useful to have finer-grained encryption of specific files. (Preferably in addition to full-disk encryption, which remains useful against other attack vectors.) i.e., Prompt the user for a password when the program starts, decrypt the data, and hold it in RAM that’s only accessible to that running process. This is more secure because the attacker must compromise additional barriers. Physical access is harder than remote execution with root, which is harder than remote execution in general.

permalink
report
parent
reply