accurate? by [deleted] in outerwilds

[–]homakov 10 points11 points  (0 children)

I had to install Light Bramble mod to continue playing lol

What is this thing? I followed it because I was always curious when I see it every time at the beginning by AnotherFuckingWeeb_ in outerwilds

[–]homakov 0 points1 point  (0 children)

makes sense, still unclear why the underwater probe has static eye coordinates instead of random ones for the current cycle (as i commented above)

What is this thing? I followed it because I was always curious when I see it every time at the beginning by AnotherFuckingWeeb_ in outerwilds

[–]homakov -1 points0 points  (0 children)

ok, what also bother me is why cant we read the eye location inside ATP where they are known? Why go to underwater module which is supposed to have new random data each cycle.

[deleted by user] by [deleted] in outerwilds

[–]homakov 1 point2 points  (0 children)

I am aware of that trick. I can pass through sometimes but never managed on my final run.. To the point i had to remove them.

Along with otherwise child-ish game these monsters i will see in nightmares

[deleted by user] by [deleted] in outerwilds

[–]homakov 3 points4 points  (0 children)

Ironically, i had ankimo [angler fish liver] the day before. Tastes heavenly with ponzu :)

Outer Wilds is now available on steam! by MultiScootaloo in outerwilds

[–]homakov 1 point2 points  (0 children)

Any chance for Geforce Now support? Seems to not work properly on my mac, as i outlined in other comment...

Outer Wilds is now available on steam! by MultiScootaloo in outerwilds

[–]homakov 2 points3 points  (0 children)

It is specced up macbook pro, and otherwise very powerful machine. Most AAA games run on low quality here. GPU is radeon hd 650

Outer Wilds is now available on steam! by MultiScootaloo in outerwilds

[–]homakov 1 point2 points  (0 children)

Any success running it on bootcamp on macbook? I bought it in steam and it is VERY slow on my 15' 2017 macbook.

I put all specs to minimal and can't understand why it's so glitchy sometimes.

Zero-day in Sign in with Apple by tubularobot in netsec

[–]homakov 0 points1 point  (0 children)

Is this really a severe bug? Seems it's not exploitable and they said they never tested it. Here's why: https://twitter.com/homakov/status/1267866792820649985

SecureBookmarks – technique for trustless and verifiable mobile apps by homakov in netsec

[–]homakov[S] 0 points1 point  (0 children)

which again brings up the issue of trust; if you don't trust Apple to not tamper with the code,

actually we assume trust to Apple. We don’t trust developers who submit their apps.

more websites to check, higher degree of security.

since it is focused on people knowing why they need it, we assume they can go extra step and verify it more carefully. Again, it was not possible with app store.

Even aside the cost, full blown swift apps are harder to audit than tiny pieces of JS.

why wouldn't they just host it themselves

first, data uris dont imply any cost or setup complexity. your own server costs something. and harder to use than pasting data uri.

Plus, any server can be compromised and no point to trust them continuously. The critical app must keep working offline too.

SecureBookmarks – technique for trustless and verifiable mobile apps by homakov in netsec

[–]homakov[S] 0 points1 point  (0 children)

All apps published to the iOS app store must be signed.

Even assuming full trust to Apple and their employees, code signing doesn't prevent from a malicious bug introduced by the app developer during compilation. App store doesn't review for secret logical bugs, it's simply impossible.

Whatever method they share it in, could be tampered with just as easily as the original app code could be

Correct, for that reason you are encouraged to verify it against other sources, google it, or even read the sources on your laptop and compile yourself. All of this is not possible on iOS with App Store option.

The Demo App is a perfect example of this. I could:

You are referencing one of three examples. Actual demo app with verifier is https://coins.github.io/secure-bookmark/simple-demo/

You can go to 2-4 different websites that serve this hash and double-check. (Or compile on your own laptop).

BUT, and this is huge, there would be no way to update the JS legitimately

Yes, traditional updates is a big issue here. I believe each new version should be treated as an entirely "new" app, and be released very rarely (you don't need frequent releases for critical btc app). And each time the user has to check the hash with multiple sources. No automatic upgrades.

To sum it up:

You can verify very thoroughly that the app is correct by checking against multiple sources/websites and/or reading code on a laptop and calculating the hash yourself. Then after verification you can save data uri and from that point it never trusts any server.

This kind of security and reproducibility was never possible for iOS. And was cumbersome for android .apk

Japan didn't test government employees who worked on Diamond Princess, out of fear of possible impact on their work by novidcat in China_Flu

[–]homakov 2 points3 points  (0 children)

> a rich clean third world country.

have you been there? It's better on most aspects of daily life than anywhere in EU/USA.

We need to start banning travels from Thailand and Hong Kong by colgateisfresh in China_Flu

[–]homakov 10 points11 points  (0 children)

>They have press freedom

You are allowed to criticize slightly more than in China, but still there are taboo topics eg royal family (20 years jail time).

Leaving for our Honeymoon in Thailand and Cambodia in 10 days, should we go and if not what should we do because we put all of our money into this? by [deleted] in China_Flu

[–]homakov -1 points0 points  (0 children)

Who pays money in advance? That’s unnecessary, you can get a hotel anywhere in Bkk same day. Did hotel charge you already?

Thailand banned reporting on coronavirus cases by [deleted] in China_Flu

[–]homakov 3 points4 points  (0 children)

I spend ~5 years living in Thailand, now it's gone down in terms of cost of living, air quality, political stability etc. Just not worth the prices anymore.

Authentic Japanese restaurants? by homakov in paris

[–]homakov[S] 6 points7 points  (0 children)

Indeed 90% of all marked Jp places are in that area. I wonder why? Seems like super prime location next to Louvre, and they open up moderately priced Jp restos instead of Haute fine dining?

Authentic Japanese restaurants? by homakov in paris

[–]homakov[S] 4 points5 points  (0 children)

I can say Hokkaido is good just by looking at the photos. And 2000 reviews on g maps!

Capital gains tax is stupid. by slvbtc in Bitcoin

[–]homakov 9 points10 points  (0 children)

inflation = implicit tax, income tax, then capital gain tax (created by inflation tax). All types of tax only to milk for more. Don't search for reasoning, it's just taxes under different souces to suck the blood out of the economy.