tomalley8342

joined 7 months ago
[–] [email protected] 12 points 1 week ago* (last edited 1 week ago) (1 children)

From what I understand, the end of the URL string is just one of the clues the browser uses to determine the "type" of received data (https://mimesniff.spec.whatwg.org/), and the true behavior depends on the browser's specific implementation. A part of the process involves actually reading and analyzing a small portion of the received file to see if the file really is the type that the URL claims it is. For example, I started a quick python server, and made it serve the OP image, except I renamed it as a jpg file (without actually converting the image of course). When saving the picture inside the browser, Firefox correctly identifies the file as a png image: While edge incorrectly tries to save the image as a jpg image:

Regarding your "MP3" file specifically, opening it in a hex editor reveals that the actual file contents identifies itself as an M4A file, despite what the URL claims:

So, you should be good to download them any way you find convenient, and then just renaming them to the proper extension afterwards.

[–] [email protected] 1 points 1 week ago* (last edited 1 week ago)

It's an exploit path to a UEFI bootkit, so at the very least you'd have to throw your motherboard away or find someone that can physically overwrite it through an external flash programmer or something. And the patch should be delivered through a UEFI firmware update, so if your motherboard is no longer supported you would have to buy a new one. And for laptops and embedded devices having everything soldered in, the motherboard is basically the whole computer, so I don't think it's that much of an exaggeration.

I guess it's true that if you have ring 0 access you're boned, bug if your ring 0 access gets upgraded into ring -2 access you are even more boned. They put those security boundaries in place for a reason after all.

[–] [email protected] 32 points 3 weeks ago (9 children)

You probably discussed it because you were aware and interested in it, and your awareness and interest showed through in your other trackable habits outside of your chatroom. You only notice when they guess your interests correctly.

[–] [email protected] 7 points 1 month ago* (last edited 1 month ago) (1 children)

What do you mean brother? The whole point of this paper is that the youth of age 18-24 in 2024 are not behaving like the youth of age 18-24 in 2009 up to 2018.

[–] [email protected] 4 points 1 month ago (3 children)

Unfortunately this analysis is a year over year comparison over the same age groups, not an age over age comparison in the same year. So your claim would not apply in this case.

[–] [email protected] 2 points 1 month ago

Sure, if they were designed that way, I would not call them defects either.

[–] [email protected] 19 points 1 month ago (4 children)

Just because all defect stock are routed to the US inventory, doesn't mean that US inventory is made up of all defect stock.

[–] [email protected] 3 points 1 month ago

but nowhere in North America.

Every single time 😭

[–] [email protected] 11 points 1 month ago

In both those cases you still have to pay one thousand dollars in rent every month to the actual property owner, so I don't know if I would call that home ownership except only in the most generous sense.

[–] [email protected] 4 points 1 month ago* (last edited 1 month ago)

Proton/wine makes no security assurances, so it will be able to do anything that any other program you run is able to do. If a trojan or rat recognizes that it is running under wine, it can bring in some native Linux malware as well and it will execute just fine. https://forum.winehq.org/viewtopic.php?t=34573

[–] [email protected] 6 points 1 month ago (5 children)

If something happens I'll make a switch.

To what?

[–] [email protected] 1 points 2 months ago* (last edited 2 months ago)

Yes, I understand. I am claiming that colossal weapon users simply have less gaps to exploit and aren't provided with enough advantages to compensate for the lack of attack opportunities for most bosses. And after playing the other souls games, this lack of opportunity is made even more readily apparent in comparison.

My time with bloodborne (saw cleaver) and sekiro (there is only one playstyle) gave me a taste of From Software's design when they decide to treat your playstyle as a first class citizen, and I had a wonderful time. I just didn't get that same feeling at any point in Elden Ring is all.

view more: next ›