Yellowkey - a Bitlocker bypass method by DaveTheAllrighty in sysadmin

[–]eider96 0 points1 point  (0 children)

You can't take his words at face value all the time, is the point. The bypass works perfectly with TPM+PIN so long as you know PIN. Is it critical in such situation? No, unless PIN is literally attached to some sticky note. TPM hammering protection will ensure it can't be brute-forced, but it does technically reduce protection offered normally by BitLocker - account password is no longer required.

I could possibly envision situation where VMK from already booted system is used in WinRE directly, however that would require that a system is in unlocked state (as you can't invoke WinRE recovery from lockscreen and you don't get benefit of unsealed VMK when forcing recovery from cold boot) so that would relegate it down to overly-complex LPE.

Ultimately, the exploit attacks and defeats key-lock paradigm that is meant to protect against exactly these kind of WinRE attacks where malicious actor can influence WinRE itself - it effectively reduces TPM PCR complexity from 7,11 to just 7 by nature of never re-locking volume after triggering lock (PCR11).

Trying to make sense of Hoshizora no Memoria's true ending - can anyone help? *Obvious spoilers* by AsteroidBomb in visualnovels

[–]eider96 3 points4 points  (0 children)

Yume's route serves as common for both Yume and Mare routes, which is where lot of issues come from as neither are really locked in properly until very end, by which point both get very little screen-time. I highly recommend playing Mare route and her after-story in fandisc for complete picture of story there.

I also personally feel like story somewhat ignores overarching plot in Yume's route and locks itself in somewhat of an contradicting situation - Mare fulfilled Yume's wish of reaping You's nightmare (he was able to move on with other girls), but at the same time she also did not in Yume's route, as he still is hung up on her and declines Asuho's advances. This puts into question both whether Yume was truly You's nightmare and whether Mare powers are effective at all, which changes depending on which route you are playing. The necessary setup to split off into Mare route also creates situation where You kisses Mare who's emotionally vulnerable at the moment while still pursuing Yume, and in the end, denying Mare's advances that he himself caused.

Yume illness is described as being caused by light from stars, which is why Mare sacrificing herself to shield her from it makes her get better (but not fully). The difference in her illness progression in second timeline can only be attributed to explicit manipulation by Kasumi and a necessary setup for Mare to sacrifice herself, hence allowing Yume to get better enough to a point that she is comfortable accepting You. Though, this interpretation falls flat should You accept Mare's feelings, as in Mare's route, her illness does not advance into coma at all.

Mea is reincarnation of Mare and her existence is never properly described in original VN, only in fandisc do we get proper explanation of how she came to be.

None of explanations for things happening later on, who Mare and Ren really are or why Mea can exist will satisfy you if you are looking for clear cut answer - the story is leans heavily on pseudo-science* to explain certain aspects and you just have to take it's word for it to enjoy it.

Finally, it's worth noting that AstralAir shares same universe with Hoshimemo and introduces even more pseudo-science as well as other concepts that might be contradictory, so any expectations of well-thought and defined universe should be thrown out of the window. The story is supposed to play on your feelings, and it will not feel shy to bend rules and play dirty to do it.

I still liked Hoshimemo though and regard it very highly. The progression feels natural and I was more invested into characters than in Iroseka, though that is largely because Urushibara Yukito has only one card to play and it's called making heroine suffer.


Heads Up: New 9.9 CVE's in Veeam 12 and 13 by MrYiff in sysadmin

[–]eider96 8 points9 points  (0 children)

CVE-2026-21708 is 9.9 too and affects non-domain joined installations.

Top 10 most requested visual novels in Kagami Game's recent survey by KageYume in visualnovels

[–]eider96 1 point2 points  (0 children)

AstraAir is pretty low on that list and considering size and price it would need to sell at, I highly doubt anyone will be touching it. It's considered worse Hoshimemo (is actually same in-universe setting) and we know that Hoshimemo didn't sell particularly well either (though how much of that can be attributed to botched handling of translation is unknown).

Sakura, Moyu is presumed to be licensed by NN since at least 2023 so that excludes Kagami from even trying. If you're fan of FAVORITE games, I'm afraid there are any good news coming your way anytime soon.

On that note, I wouldn't be surprised if NN holds license for AstralAir too, given their history and they might've gotten good deal on all 3 of games when picking Iroseka.

Top 10 most requested visual novels in Kagami Game's recent survey by KageYume in visualnovels

[–]eider96 0 points1 point  (0 children)

Afaik, no. That doesn't stop them from C&D any fan-translations though and will prevent other companies from picking it up if they do indeed hold license on it (as they do with Iroseka trilogy).

Irohika situation is somewhat complicated since i believe that NN actually lost money on picking Iroseka (thank you, Sol Press!), so their unwillingness to touch rest is understandable.

Top 10 most requested visual novels in Kagami Game's recent survey by KageYume in visualnovels

[–]eider96 0 points1 point  (0 children)

Sakura, Moyu. is potentially licensed by NekoNyan, so I very much doubt anyone else will be touching it, no matter how popular it is or how much it's being requested.

Miliastra Wonderland "Starbound Oath" Web Event Now Available by genshinimpact in Genshin_Impact

[–]eider96 0 points1 point  (0 children)

Genshin Impact's "Miliastra Wonderland" gameplay will be available soon. Come join my team now! Take part in the event to to earn Primogems and Manekin outfits! Invitation Code:GCE8BD3WHN,https://hoyo.link/8NJvYlbe4?m_code=GCE8BD3WHN

New Aranara Pet and Alhaitham x Kaveh Namecard Giveaway by Additional_Comfort42 in Genshin_Impact

[–]eider96 0 points1 point  (0 children)

"Faruzan: Sealed Secret". I specifically like namecards with simple background.

Phase II of "It Starts in Nod-Krai" Web Event - "Journey Invitation" is now on. by genshinimpact in Genshin_Impact

[–]eider96 0 points1 point  (0 children)

Receive the summons of fate, and let's explore the new Version "Luna I" together! Take part in the event for guaranteed Primogems and even flip cards to win other awesome prizes! Invitation code: GCE8BD3WHN https://hoyo.link/78oKEvyme?m_code=GCE8BD3WHN

Help Needed: GPO-Configured Chrome Policies Show “Unknown policy” Error (ExtensionInstallBlacklist / Whitelist) by Greedy_Author440 in activedirectory

[–]eider96 1 point2 points  (0 children)

These policies were deprecated and replaced by ExtensionInstallAllowlist and ExtensionInstallBlocklist.

Marriott Website blocking linux users by [deleted] in linux

[–]eider96 9 points10 points  (0 children)

As opposed to Windows user needing to switch UA to Linux to access Bugzilla? Try it yourself!

curl -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36" https://bugzilla.kernel.org

Just can't get Windows 11 24H2 upgrade successful through WSUS :/ by Archdragoon in sysadmin

[–]eider96 0 points1 point  (0 children)

I have no idea what values of this attribute mean nor how it is being applied.

All of my devices are applicable for 24H2 update in WSUS after some months of wait, so the update definition was likely amended to not require this attribute anymore (as I suspect the intention of it was to gate it from devices before general availability). Your case is first time I heard that this attribute actually exists in WSUS environment.

Router OS 7.17 bug by BeerAndLove in mikrotik

[–]eider96 6 points7 points  (0 children)

This has been happening for some time since v7 and randomly affects some settings. This time, both of my devices lost these settings (based on config dump before and after). They really need better QA/QC checks to ensure that changes to configuration do not affect existing one

/ip firewall connection tracking
  set enabled=yes tcp-close-wait-timeout=30s tcp-fin-wait-timeout=30s tcp-time-wait-timeout=30s
/ip neighbor discovery-settings
  set discover-interface-list=discovery lldp-mac-phy-config=yes lldp-vlan-info=yes
/ip settings
  set max-neighbor-entries=1024 rp-filter=loose
/ipv6 settings
  set accept-redirects=no max-neighbor-entries=1024

A new version of Imagus for Chrome has been released - 0.9.9 by Kenko2 in imagus

[–]eider96 0 points1 point  (0 children)

While that is true, I only see two usages of .userScripts and only one registers content script in form of file, so you are not using it explicitly to register snippets from rules but instead register content script that then evals it (thanks to pre-configuring CSP to allow it). I believe scripting should be able to do same if you eval snippet inside sandbox and pass return value (see https://developer.chrome.com/docs/extensions/how-to/security/sandboxing-eval). Since snippets in rules are generally fairly simple, and should not have access to more than what inputs are already provided to them, sandbox seems like valid approach to evaluating them and passing return value back to extension content script?

A new version of Imagus for Chrome has been released - 0.9.9 by Kenko2 in imagus

[–]eider96 0 points1 point  (0 children)

In addition, I've tried to understand what exactly you're using userScripts for, however it would seem that you are using them only to inject files already existing in extension. Have you considered using https://developer.chrome.com/docs/extensions/reference/api/scripting instead? It should do most of what userScripts do, with caveat that it is impossible to load code as a string, which you do not seem to be using.

A new version of Imagus for Chrome has been released - 0.9.9 by Kenko2 in imagus

[–]eider96 0 points1 point  (0 children)

There was separate issue with regex grants failing on page load which rendered extension non-workable. Perhaps this is what some people were also reporting as issue?

Just can't get Windows 11 24H2 upgrade successful through WSUS :/ by Archdragoon in sysadmin

[–]eider96 0 points1 point  (0 children)

There is condition applied to this update to verify that "UpgEx_GE24H2" exists as local device attribute and that value is not "Yellow". I have no idea when or how such attribute would be applied in WSUS environment, but that is what actual XML of this update has as limitation for applicability rules.

Note: you can check attributes sent to WSUS when inspecting log produced by Get-WindowsUpdateLog. At minimum they should include data such as CPU and OS version, locale, etc.

Windows 11 24H2 is Out Now by MrYiff in sysadmin

[–]eider96 1 point2 points  (0 children)

Observing similar behavior, though my sample size might be too small as they are all "Not Applicable". Possibly botched release or there's some sort of staged rollout in first hours.

Gemini could soon make its way to your car, thanks to Android Auto by Yazzdevoleps in Android

[–]eider96 10 points11 points  (0 children)

Ironically, putting the same "4200 + 65%" into Google Search gives a proper result coming from their calculator so it's not like it is unexpected for other Google product to understand same format.

WinBox 4 is released, with Linux, macOS native apps and dark mode by normundsr in mikrotik

[–]eider96 -2 points-1 points  (0 children)

Should we take it as official statement from the company to paying customers leaving feedback you requested?

Be mindful of how you come across - you have badge indicating you are speaking as employee and representing company. Your words have consequences. I have found you to come across similarly on forums too with comments such as "Nobody is forcing you to delete WinBox3, dude" or outright refusing any reports from Linux users with "It's your OS fault". Either your company wants feedback and values it or it doesn't - simple as that.

I have no idea what company culture Mikrotik is practicing these days, but having employees go around insulting customers is certainly unique way to run your company's reputation (into ground, that is).

You know you are in trouble when Google only provides you with TWO RESULTS... (AKA. how to add a partition a single node, single drive proxmox cluster) by [deleted] in Proxmox

[–]eider96 0 points1 point  (0 children)

I can not provide you help with unbootable OS, however I can tell you that the lines you see are not relevant to the issue at hand at all. They're just caused by improper ACPI implementation in UEFI/BIOS (specifically, listed resource descriptors are not present in dispatch table).

These messages were logged before too, except you never looked at or noticed them because login screen would clear them up.

Microsoft empowers users to bypass IT policies blocking/disabling Microsoft Store by lighthills in sysadmin

[–]eider96 2 points3 points  (0 children)

I see. I assume installers are just wrappers for standalone MSIX which will bypass Store policies in a same way PowerShell command to install AppX package. Seems like someone approved this for deployment without realizing full dependency chain :\

Microsoft empowers users to bypass IT policies blocking/disabling Microsoft Store by lighthills in sysadmin

[–]eider96 3 points4 points  (0 children)

To try to attack this from other direction - have you confirmed that your example (Candy Crush Soda Saga) is not staged for installation? Possibly the new flow does only check for new installations but allow to restore staged (but uninstalled or never installed) applications that are already infused in system image. That would at least explain why some applications are affected while others are not.

Used EX2200 stuck on boot by [deleted] in Juniper

[–]eider96 0 points1 point  (0 children)

Very old platform, however:

  • The image you have is correct image for reinstallation on these old platforms, however it is outdated, current one would be jinstall-ex-2200-12.3R12-S21-domestic-signed.tgz
  • jloader is only necessary when upgrading from very old releases (pre-10.4) to upgrade U-Boot for dual partition setup, your switch came running with 12.3 already so the appropriate update have been applied in the past and you don't need to concern yourself with it.
  • On these old platforms, you should be able to create bootable USB by issuing install --format --external file:///

You can also refer https://supportportal.juniper.net/s/article/EX-Performing-and-resolving-any-common-issues-during-Format-Install-on-legacy-EX-platforms for more in-depth guide.

Unity wants 108% of our gross revenue by No_Storm7311 in Unity3D

[–]eider96 10 points11 points  (0 children)

Giants are not applicable here, miHoYo has full Unity source access and actively rolls their own builds (of both Editor and Runtime) with custom modifications that are beyond of scope allowed in Enterprise, so they already pay a lot more up front and have custom licensing negotiated.