In my case it was soundcore's app (no, openscq30 didn't work), so it had a need for network access to update the firmware, for example, I just didn't want to give it at the moment. As for being poorly made, also not exactly: as I've mentioned, android gives this permission by default, and it's reasonable to assume it stays so. Graphene basically "breaks userspace" here.
I remember some particular apps not liking that one. Basically it exposes the permission that's otherwise always granted, and if the developers didn't make a catch all for network errors, the app crashes. Mobile data usage → allow network access favors better in that regard.
As always, the answer is "depends". It shouldn't hurt unless you're dual-booting windows (they used it last year as a weapon in their "mess up grub" game), but, Imo, it's worth the trouble if:
- your data is also encrypted -- otherwise one just removes the HDD/SSD and reads what they need;
- you provision your own keys -- to not depend on Microsoft signing shims for you;
- you delete the already provisioned keys -- Microsoft signed a few vulnerable things, like one kaspersky's (iirc) live CD with grub not locked down, so one can boot up literally anything anyway;
- you lock down grub or whatever bootloader you're using -- otherwise you become that vulnerable live cd;
- you password lock the uefi -- otherwise one can simply disable the secureboot;
- your vendor's implementation isn't terribly buggy -- iirc, some MSI laptops would just ignore all the discrepancies.
So, a lot of ifs, and a necessity to store the uefi password somewhere safe, as those may be a pita to reset.
As for standalone stuff -- idk, it might protect you from malware injecting itself into the bootloader or something, but given there's likely no chain of trust (I.e. the bootloader doesn't check what it bootloads), it can move in on some later step.
This, but backtrack 5 (the one just before kali). On a laptop that'd take several eternities to brutforce an md5 🤣
Reminded me one of the vids of f4mi, although that ladiy's approach is far more beautiful. Basically, she took advantage of ai scrapers relying on subtitles and YouTube allowing for pretty advanced styling of those very subtitles to insert garbage that only bots will see.
To those interested in the details, https://www.youtube.com/watch?v=NEDFUjqA1s8 (selecting a working invidious instance is left as an exercise for the reader)
Quite simple, actually. If you want to do a thing that violates a law, you modify the law to allow the thing.
All clothes are no-iron clothes if you DGAF enough :)
Incorrect: the backdoored version was originally discovered by a Debian sid user on their system, and it presumably worked. On arch it's questionable since they don't link sshd
with liblzma
(although some say some kind of a cross-contamination may be possible via a patch used to support some systemd thingy, and systemd uses liblzma
). Also, probably the rolling opensuse, and mb Ubuntu. Also nixos-unstalbe, but it doesn't pass the argv[0]
requirements and also doesn't link liblzma
. Also, fedora.
This is good, but I prefer this
Should've installed linux 🤷
Yeah, those mailing lists used to have some quite funny stuff; my favorite so far is smth along the lines of "whoever thought this was a good idea should be retroactively aborted".
But, on the other hand, damn it's toxic. Should've really sucked to work on the kernel back then.
It's feRd