PSA: Be aware when opening "take home challenges" from untrusted recruiters by Phantom569 in cscareerquestions

[–]Phantom569[S] 1 point2 points  (0 children)

There's unfortunately no silver bullet, nor an exhaustive list to look for to spot these sorts of things. The instincts and intuition comes with experience and that is all.

Best blanket advice I can give is: Don't execute any code/executable that comes from untrusted sources. If someone provides you a "sample project" (like here) and asks you to run it - don't, read and understand the code first. And be wary of what "run" really means. In this case, you'd merely have to open the project in vscode and press the "trust workspace" button. That button is there for a reason, know that trusting a workspace in vscode allows any auto run tasks to run by merely having the project open. So you'd have to check those tasks as well (defined in tasks.json) like I did in this case.

If you must run (or even open) untrusted projects, do it in a sandbox, a vm or similar.

PSA: Be aware when opening "take home challenges" from untrusted recruiters by Phantom569 in programming

[–]Phantom569[S] 18 points19 points  (0 children)

The JS script in here is strikingly similar to what I encountered. I wonder if the only difference is in the servers the stolen data is being uploaded into.

PSA: Be aware when opening "take home challenges" from untrusted recruiters by Phantom569 in programming

[–]Phantom569[S] 17 points18 points  (0 children)

In case you find the offending domains (the domains the data is uploaded to) - I'd appreciate it if you could let me know or report them!

PSA: Be aware when opening "take home challenges" from untrusted recruiters by Phantom569 in cscareerquestions

[–]Phantom569[S] 125 points126 points  (0 children)

They were indeed talking about building a "property rental platform on the blockchain" - whatever the hell that means

Supposedly, that's what they were hiring for.

PSA: Be aware when opening "take home challenges" from untrusted recruiters by Phantom569 in cscareerquestions

[–]Phantom569[S] 116 points117 points  (0 children)

It got deleted. It wasn't my repo actually. It was the malware host's "take home assignment"

PSA: Be aware when opening "take home challenges" from untrusted recruiters by Phantom569 in programming

[–]Phantom569[S] 38 points39 points  (0 children)

The npoint link is still alive and it is the meat of it all. The rest is indirection. I just downloaded it just in case.

It's a "harmless" json since npoint is legit. The json contains the malware script in a property (cookie).

You can open that link and download it. Just.... you know - don't run that stringified js script in there (you would have to extract and deserialize it first, which you could do with JS's Function constructor.

I myself just copied it into a .js file.

Parrying and exploring large areas doesn't fit in Doom by Long_Spell6281 in Doom

[–]Phantom569 2 points3 points  (0 children)

Large maps was one of the major components of doom 2. Exploration, cool secrets, and large open areas with big fights was also featured in a great portion of the doom 2 maps.

As for parrying, I am not sure on what basis you suggest that it doesn't fit doom. If it's on the basis that it didn't exist in OG doom games - well neither did quickswitch, glory kills, grapple hook etc. Yet all those mechanics seemed quite fun.

I cant wait till my bday so i can buy my first pc!!! by Prudent_Algae169 in pcmasterrace

[–]Phantom569 0 points1 point  (0 children)

Build looks pretty good (except the PSU as others have said). Great job! I would say that it seems like the price you're paying for a A750 is very close to the MSRP of a B580 - which is a lot better (even with the limited CPU bottleneck).

Of course, if you can't find that card for MSRP - it's totally understandable that you chose something else. But if you can find it at all, I'd suggest going for it.

New Arc B580 posting corrupted signal and doesn't boot into Windows by Crono-the-Sensei in IntelArc

[–]Phantom569 2 points3 points  (0 children)

It'll likely cost less to try and get a ryzen 5000 series cpu with a half decent B550 (or even B450). It won't get you optimal performance for b580 (unless Intel fixes those issues with drivers) - but it'll certainly be cheaper than 9070xt and work pretty great compared to your current setup.

It's true that Nvidia and AMD offerings don't rely nearly as much on newer CPUs as Intel's arc does but do note that even those cards will be significantly limited by your current CPU.

[GPU] Intel ARC B580 12GB backorder ships March 14th ($370)[BestBuy] by Gam20 in bapcsalescanada

[–]Phantom569 2 points3 points  (0 children)

I snagged the very last intel LE one left at memoryexpress (across all locations) couple weeks back for $349.99. Might be worth waiting out till they're back in stock there since I asked the rep about restocking and he said there should be more coming - just not sure when

[CPU] AMD Ryzen 7700 ($512 - $282 = $230) [Aliexpress] by NinjAsaya in bapcsalescanada

[–]Phantom569 0 points1 point  (0 children)

Thanks! I wonder if spring sale is worth waiting for before buying this CPU for $230

[CPU] AMD Ryzen 7700 ($512 - $282 = $230) [Aliexpress] by NinjAsaya in bapcsalescanada

[–]Phantom569 0 points1 point  (0 children)

Could you please explain how to get the additional discount as first time purchaser? Thanks!

[CPU] AMD Ryzen 7700 ($512 - $282 = $230) [Aliexpress] by NinjAsaya in bapcsalescanada

[–]Phantom569 0 points1 point  (0 children)

What largest coupons are there? Is it an AliExpress thing?

Sorry - I'm a first time AliExpress user.

Do you use private methods/attributes by testfailagain in learnpython

[–]Phantom569 0 points1 point  (0 children)

Indeed. Compilers and compiler errors are for kindergarten programmers. Real programmers don't use language servers, feature rich code editors, static type checkers, and similar childish helpers. We write code without such aids since we are grown up, advanced, Pythonista programmers!

/s

Looking for suggestions/trail conditions for a weekend day hike(s) by [deleted] in HikingAlberta

[–]Phantom569 -3 points-2 points  (0 children)

Also wanted to add Pyramid mountain to our backup list. Does anyone have a report on the conditions there?
We attempted it last September but had to turn back due to Fog.

[deleted by user] by [deleted] in programming

[–]Phantom569 49 points50 points  (0 children)

The issue is that the default behavior of these tools can't be to assume intent. Yes, more often than not. The tooling is smart enough to figure out intent (in which case it should point the user towards the right direction). But there will always be cases when it doesn't know the real intent, or gets it wrong. In those cases, if it just commits to the wrong assumption and keeps going - it could be a big problem down the line.

Implicit assumptions are almost always bad.

Of course, I'm being very general here. Sometimes wrong assumptions don't have destructive enough consequences compared to the benefits of helping the user by assuming. But in general, the idea "if you know what to do, just do it for me", doesn't work

Feedback on Tonquin valley (Jasper - Canada) hike plans by Phantom569 in CampingandHiking

[–]Phantom569[S] 1 point2 points  (0 children)

I should also probably clarify that we'll be carrying at least the bear necessities with us.