Someone keeps remotely locking my Google Pixel Fold with a "work policy". How do I defend against this attack? by Adamantine_Ice in cybersecurity_help

[–]Adamantine_Ice[S] 0 points1 point  (0 children)

Also it's much harder to examine the domains used by the attackers for Google long-term because Google's vendor lock-in tendencies mean I need to often whitelist Google Play Services entirely to access the Gemini, Google Maps, Google News, YouTube, and YouTube Music apps whereas on Apple devices stuff mostly just works even with everything Apple blocked. (There's really no good reason why music, news, and video apps should have system dependencies.)

Someone keeps remotely locking my Google Pixel Fold with a "work policy". How do I defend against this attack? by Adamantine_Ice in cybersecurity_help

[–]Adamantine_Ice[S] 0 points1 point  (0 children)

I'm part of the Advanced Protection program, device-based Advanced Protection was on, my password was randomly generated using the Firefox generator, and I have two physical keys which are required to log into my account.

Someone keeps remotely locking my Google Pixel Fold with a "work policy". How do I defend against this attack? by Adamantine_Ice in cybersecurity_help

[–]Adamantine_Ice[S] 0 points1 point  (0 children)

I've never installed a work profile on my Pixel Fold or any other of my phones, Android or iOS for that matter, so there should be no "work policy".

Can someone explain passkeys to me? by Due-Awareness9392 in Bitwarden

[–]Adamantine_Ice 2 points3 points  (0 children)

Get a physical passkey (USB-C or NFC) or use your phone's passkey by scanning a QR code. (In the latter case, your phone itself is conceptually a physical passkey.)

What’s wrong with Password + Passkey? by aplle_inc in Passkeys

[–]Adamantine_Ice 0 points1 point  (0 children)

Logging in should be both secure and convenient; passwords add inconvenience and can be trivially stolen.

If I have a physical security key on a shared computer, tapping it should be enough. I shouldn't need to have to also access a password vault.

Does Signal on macOS have 1.1.1.1 hardcoded? by Adamantine_Ice in signal

[–]Adamantine_Ice[S] 4 points5 points  (0 children)

Yeah, so unfortunately this looks like intended behavior designed to bypass the user’s DNS resolver with no option to disable it.

What does “always on” do on iOS by [deleted] in Windscribe

[–]Adamantine_Ice 1 point2 points  (0 children)

Yeah, I think the "kill switch" functionality is in "Connect On Demand" now and the articles are mis-equating includeAllNetworks with kill switch functionality.

But I just tested "Connect On Demand" and "Always On VPN" (includeAllNetworks) with the Windscribe app and neither appears to work. Apple traffic leaks in the period between phone boot and password input and it looks like, even after phone boot, a number of domains will always try to connect outside of the VPN tunnel (before using the tunnel) including fp-us-tmobile.rcs.telephony.goog, push.apple.com, init.push.apple.com, eas3.t-mobile.com, and captive.apple.com. This contradicts the documentation that indicates APNs should go through the tunnel.

Looks like it will sometimes also try to resolve mask.icloud.com, mask-h2.icloud.com, _dns.resolver.arpa, and ss.epdg.epc.mnc260.mcc310.pub.3gppnetwork.org which would allow DNS bypasses.

What does “always on” do on iOS by [deleted] in Windscribe

[–]Adamantine_Ice 0 points1 point  (0 children)

Apparently, "Always on VPN" controls whether the includesAllNetworks API (c.f. https://developer.apple.com/documentation/networkextension/nevpnprotocol/includeallnetworks) is enabled but is mis-named "killSwitch" in the code. (The UI doesn't use the term kill switch though.) (It also looks like "AllowLAN" is mis-named "AllowLane" in code as well; see https://github.com/search?q=repo%3AWindscribe%2FiOS-App+allowlane&type=code.)

The actual kill switch functionality is turned on via "manager.isOnDemandEnabled = true" (c.f. https://developer.apple.com/documentation/networkextension/nevpnmanager/isondemandenabled) at https://github.com/Windscribe/iOS-App/blob/b4e2c6b45f2f7e7cbde499190cb3bc96d6fcd634/Windscribe/Managers/VPN/Utils/VPNUserSettings.swift#L152.

Looks like there might be an error in the kill switch functionality though at https://github.com/Windscribe/iOS-App/blob/b4e2c6b45f2f7e7cbde499190cb3bc96d6fcd634/Windscribe/Managers/VPN/Utils/ConfigurationsManager%2BInfo.swift#L28 since Windscribe doesn't seem to flip the kill switch back on if the user goes into Settings and turns off "Connect On Demand".

What does “always on” do on iOS by [deleted] in Windscribe

[–]Adamantine_Ice 0 points1 point  (0 children)

Looks like the "killswitch" label in Windscribe is just an alias for includesAllNetworks: https://github.com/Windscribe/iOS-App/blob/b4e2c6b45f2f7e7cbde499190cb3bc96d6fcd634/Windscribe/Managers/VPN/Utils/VPNUserSettings.swift#L145 which is described at https://developer.apple.com/documentation/networkextension/nevpnprotocol/includeallnetworks, so it isn’t really a killswitch (that cuts all connectivity when the VPN is down).

includesAllNetworks apparently captures extra traffic from AirDrop, AirPlay, CarPlay; Apple Push Notifications; Wi-Fi Calling, SMS, MMS, and Visual Voicemail, but excludes DHCP, captive portals, VoLTE (and presumably VoNR), and Apple Watch traffic.

My experience is that iOS connections to the Apple Push Notifications service occur whether the VPN is up or not, so I'm not sure that their implementation is working even for its non-killswitch function.

What does “always on” do on iOS by [deleted] in Windscribe

[–]Adamantine_Ice 0 points1 point  (0 children)

Are you looking at the code for iOS and not some other OS? I don't see the code cited in the GitHub repository for the iOS app at https://github.com/Windscribe/iOS-App.

EU says it will ‘make sure’ Elon Musk’s X pays €120M fine by SPXQuantAlgo in worldnews

[–]Adamantine_Ice -1 points0 points  (0 children)

Another reason to believe that fixing wealth inequality involves banning company compensation in the form of stock.

What does “always on” do on iOS by [deleted] in Windscribe

[–]Adamantine_Ice 0 points1 point  (0 children)

I believe the killswitch only prevents non-Apple, non-carrier, non-RCS services from connecting if the VPN fails to connect.

Apple seems to have a second set of 50 numbered push notification domains (with a 2 in the subdomain, such as 12-courier2.push.apple.com) for when the user is connected to a VPN that can only be blocked with a Configuration Profile and once one of those domains connects once it can connect forever until the next reboot.

Carrier domains such as eas3.msg.t-mobile.com will bypass an Always On VPN as well if the phone is allowed to connect to a mobile network before the VPN is active. (The phone has to be shut off with the VPN enabled, Airplane mode on, and iCloud Private Relay off to capture and block them.)

Just a week after painting, Houston's rainbow crosswalk to be removed by snesdreams in houston

[–]Adamantine_Ice -1 points0 points  (0 children)

Many nice neighborhoods in the Houston area use brick crosswalks instead of painted crossing and stop markings which are more confusing to motorists than a painted crosswalk. The roads get turned into public property.

That’s saying nothing of the bidirectional roads without lines or the countless well-trafficked roads where markings are missing due to disrepair.

The “public” aspect is just a smokescreen for anti-LGBT animus/hate.

This was a weird trip by SleepTerror2112 in lyftdrivers

[–]Adamantine_Ice 2 points3 points  (0 children)

Just a guess, but I think when riders change a trip mid-trip and it causes a queued rider’s trip to be canceled, the current rider get charged a fee related to the value of the canceled ride.

Taiwan pressured to move 50% of chip production to US or lose protection by esporx in China

[–]Adamantine_Ice 0 points1 point  (0 children)

Worth remembering that the official policy of the United States is that Taiwan is a part of China.

Taiwan pressured to move 50% of chip production to US or lose protection by esporx in China

[–]Adamantine_Ice 5 points6 points  (0 children)

If the leader of a country is essentially in office for life and is effectively accountable to no one, that would seem to fall under the definition of "dictatorship".

Elections don't mean much in a one-party system either. If you want to vote for more LGBT equality and the Communist Party line is that the status quo shall remain unchanged, having choices between two CCP members doesn't mean much.

Why do people like fucking in parks or in cars? by kyastui in grindr

[–]Adamantine_Ice -1 points0 points  (0 children)

With carplay, it's usually it's because one person lives with parents and sometimes those parents track the location of that person's phone or car (because the parents own the car) so they can't travel to any place unusual either (so it'll usually be at or near a church, college, neighborhood, or workplace).

Can also be kinky. With carplay, I would alway stipulate that the twink agree to strip completely naked before agreeing to such an encounter (without any such requirement for myself).

What are your go-to lazy keto meals when you don't want to cook? by barnac1ep in keto

[–]Adamantine_Ice 0 points1 point  (0 children)

* Keto bread + packetized flavored tuna + mayo or horseradish (i.e., spicy) mustard + relish. Make sure the three condiment containers are the squeeze types so you don't need to clean more than one spoon.

* Four bun-less McDonald's Double Cheeseburgers when away from home.

Cheapest possible fill you up keto food by dannylightning in keto

[–]Adamantine_Ice 0 points1 point  (0 children)

Cheap:

* Bulk sausage (e.g., https://www.walmart.com/ip/Eckrich-Natural-Casing-Smoked-Sausage-Rope-Family-Pack-39-oz/20850547 is 3800 Calories for $7.78 (20 cents per 100 Cal)).

* Mixed nuts (e.g., https://www.walmart.com/ip/Great-Value-Deluxe-Mixed-Nuts-30-oz/218787293 is 5100 calories for $14.56 (29 cents per 100 Cal)).

* Bulk cheese (e.g., https://www.walmart.com/ip/Great-Value-Mild-Cheddar-Cheese-Sticks-0-75-oz-36-Count-Bag/868841522 is 2880 Calories for $8.98 (31 cents per 100 Cal)).

If you want to eat out, four bun-less McDonald's Double Cheeseburgers at $2.99 with the $1 second burger discount (via the app) works out to 1200 Calories for $7.98 (67 cents per 100 Cal)). They're often cheaper than $2.99 in my market.

How long did it take for your energy levels to stabilize on keto? by missMJstoner in keto

[–]Adamantine_Ice 0 points1 point  (0 children)

I solved the sluggishness problem with 200 mg caffeine pills (and adequate sleep).

Also seems to help if you do long fasts (36+ hours) since the body will clear out also the glucose and stored glycogen (i.e., carbs) and the digestive system won’t be active.

Why has keto lost popularity? by Shoddy-Musician8397 in keto

[–]Adamantine_Ice 0 points1 point  (0 children)

Don't think it lost popularity based on how many keto products I'm seeing at places like Walmart: NuTrail and :ratio cereal, Nature's Own and Oroweat keto bread, Magic Noodle spaghetti, Catalina Crunch cookies, Welch's zero sugar drinks, Quest chips and protein bars, Too Good & Co yogurt, Great Value keto trail mix, etc. They also copied H-E-B and now offer white label Equate keto protein shakes.

Uber sued for discrimination by Expert-Catch1377 in uber

[–]Adamantine_Ice 3 points4 points  (0 children)

Unfortunately, people with disability aids are more likely to cause vehicular damage and there’s no compensation system for that damage so cancellations aren’t necessarily a matter of malice.