frongt
@frongt@lemmy.zip
- Comment on Company sues manager for leaving without serving full 6-month notice, wins S$36,000 1 day ago:
Must be nice. Here in the US you can just walk in one day and get told you’re fired and have to clean out your desk.
Does German law or contract account for stuff like if a person working with children is found to be abusing them? Like that’s an instance where you really need it done immediately. (Or if that’s not a great example because they get suspended pending a court trial, insert some other example.)
Also, in the UK and probably other countries, when you leave work but still get paid for that period it’s called “garden leave”.
- Comment on Any politician who disagrees needs to go 4 days ago:
We literally already have that en.wikipedia.org/…/United_States_Public_Health_Se…
- Comment on My security camera shipped a GitHub admin token in its login page 6 days ago:
is this just a coincidence and one of those weird instances where people have taken IP space for internal services when they know they will never interact with it
It’s this one. It’s a fairly common and fairly bad practice.
I hope the author pulls the next firmware bin and checks it for keys again.
- Comment on Return to office propaganda floating around LinkedIn 1 week ago:
Owl cameras area great, they follow speakers around the room. You could even mount a plain old security camera on the ceiling and attach it to the videoconference system.
Does that guy just flip his video so that he can write forwards and you still see it forwards? Writing equations backwards would be a hell of a skill. I’d probably end up forgetting how to write them forwards.
- Comment on Return to office propaganda floating around LinkedIn 1 week ago:
“slop on linkedin? better put the slop on lemmy too”
- Comment on Can the state minimum wage be changed by a ballot initiative? 2 weeks ago:
Depends on the state, if it has that mechanism.
- Comment on FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances 4 weeks ago:
Neat. Maybe this will open up locked-down devices.
- Comment on Arena Employees have unionized! 5 weeks ago:
Magic: The Gathering: Arena is a free-to-play digital collectible card game developed and published by Wizards of the Coast
- Comment on CVE-2026-42530 & CVE-2026-42055: NGINX RCE Flaws Explained. Patches Released 5 weeks ago:
Major distros like Ubuntu backport security fixes to the stable version.
- Comment on How a USB-connected speaker can infect a PC without ever being touched 1 month ago:
Right. The common one is an initially malicious device given to an unsuspecting user. This is a stock device that a user already has and trusts. It’s a huge vulnerability that an unauthenticated user can completely take it over. This is a 9.3 CVE, without even considering pivoting to the PC.
- Comment on How a USB-connected speaker can infect a PC without ever being touched 1 month ago:
I was able to totally remotely, over the air, upload a custom firmware to my speaker which I hadn’t paired with, which would reboot, flash the custom firmware, and after rebooting type in the command echo pwned and execute it.
So an attacker can hack someone else’s speaker, turn it into a keyboard to the paired PC, and from there attack the paired PC.
- Comment on He Blew the Whistle on DOGE. Then His Brakes Were Cut 1 month ago:
You don’t even need to make it look like an accident. You can murder a cyclist by hitting them with your car and get just like six months in prison.
- Comment on He Blew the Whistle on DOGE. Then His Brakes Were Cut 1 month ago:
Yes, regenerative braking
- Comment on Rideshare drivers unionize in Massachusetts, creating the App Driver’s Union 2 months ago:
Where did it lead?
- Comment on The rich convinced us that taxing them is too complicated but everyday people can be taxed pretty easily 2 months ago:
That pay cap would hit at about $1.5m. I think that’s okay. I did some napkin math and eyeballed it to graph the proposed tax rates vs 2018’s marginal and effective (because that’s what was available): lemmy.zip/…/61835557-1968-4d28-be95-493de6de6900.…
It’s not the worst idea I’ve heard, but I’d want to scale by the number of taxpayers in each bracket to find out how much tax revenue we’d win or lose. A real congressional study would also consider what is considered “income” for tax purposes, and whether this would cause anyone to get creative with their compensation to avoid paying more tax (well, even more than they already do).
- Comment on The rich convinced us that taxing them is too complicated but everyday people can be taxed pretty easily 2 months ago:
Twitter screenshot meme slactivism aside, it’s because private land is a limited resource. The more you keep for yourself, the more you pay (generally).
- Comment on Work wifi access 2 months ago:
I would never connect my personal devices to a company network. They can inspect your traffic.
- Comment on American workers are tired of waiting. 2 months ago:
Useful content. This content does not meaningfully advance work reform.
- Comment on American workers are tired of waiting. 2 months ago:
Can you not repost trash memes from reddit? There’s a reason we left.
- Comment on Democratic Socialism in the Workplace and Hierarchy by Consent (OC) 2 months ago:
So a worker-owned co-op?
- Comment on Thoughts on Darktrace or MS Sentinel? 2 months ago:
What fucking kind of school allows sales pitches in classes? Alignment with corporations is bad enough.
In the real world, companies generally don’t use them unless required. I’d recommend starting with the open-source products like wazuh.
- Comment on Wireshark tutorial: Capture vs. Display Filters 3 months ago:
I wish Wireshark had a filter builder. Display filters are fairly easy to write, because you can build them from captured packets and it makes suggestions as you type, but there’s nothing for the more important capture filters. Having two sets of syntax doesn’t help.
- Comment on Millennials Owe 500% More in Student Debt Than Their Parents Did 3 months ago:
Same reason as the rest of college being expensive. The can charge whatever they want because the government will loan the money to pay for it.
- Comment on Despite Apocalyptic Warnings, California Fast Food Wage Hike Didn’t Kill Jobs 3 months ago:
Isn’t that literally what people were forecasting?
- Comment on Someone has publicly leaked an exploit kit that can hack millions of iPhones 4 months ago:
Had to use duckduckgo to find it, but just “darksword site:github.com” worked. It’s not showing up in Google results.
github.com/htimesnine/DarkSword-RCE
There’s also an implementation in objc: github.com/opa334/darksword-kexploit
- Comment on PC MLA says hackers accessed and shared intimate images on his devices 4 months ago:
Progressive-conservative member of the legislative assembly, the provincial legislature in Nova Scotia, Canada. Guy’s name is Rick Burns. Also he’s the ministerial assistant for cybersecurity.
No, I don’t know what the fuck a progressive-conservative is either.
- Comment on Farming for self sustainance 4 months ago:
Very realistic. You can do that right now. Lost of people around the world rely on subsistence farming.
But it’s not particularly enjoyable. And you’ll still be working a lot. Plants and animals don’t take days off.
- Comment on Arbitrator settles flight attendant wages at Air Canada, as labour dispute comes to official end 5 months ago:
So they’re still getting paid less than thair wage for work on the ground. At least they’re getting paid; I know some airlines don’t pay them for their work at all until the door closes.
- Comment on N00b wanting to get into this field - NL Cybersecurity 5 months ago:
In the US, the cert most often expected is sec+.
Generally you should look at job listings and work backwards from there. Most companies use software like nessus and splunk, and there are plenty of free alternatives to those and others that you can play around with.
Competency in networking (firewall rules/acls, routing, subnetting) and programming (python, powershell, bash, batch script) are a big benefit.
- Comment on Update: Remote Access Trojan backdoored through WINE 5 months ago:
That’s a lot of words and no actual evidence. Like you see 20copyfiles, but what does it actually do? You see privoxy installed, but how is it configured?
Like 80% of this is just you seeing something and making wild assumptions. Like a trivial google search for “kernel drop_monitor”, since I’ve never heard of it:
www.kernelconfig.io/CONFIG_NET_DROP_MONITOR
This feature provides an alerting service to userspace in the event that packets are discarded in the network stack.
I know remote-fs is normal because it’s part of every install I’ve seen: ubuntu-mate.community/t/…/24640
Neither of these are evidence of compromise.
And while privoxy can be used with tor, it’s by no means a good way to do anything, and certainly not the primary way to use Tor (that would be their own client).
The stuff clamav is picking up could certainly be malware, if you downloaded some cracked software or something. But as I mentioned last time, exploiting Linux via Wine is an extremely unlikely attack vector.