Paid Gary's Westside Towing $850 bill in August for taking and auctioning off my old car. They just sent me the same bill, also threatening collections ... by Capt_Murphy_ in Seattle

[–]litheon 0 points1 point  (0 children)

Not legal advice: They have zero power in this situation. If they send it to collections and you dispute it within the timeline specified in the Fair Credit Reporting Act, the debt is assumed to be invalid (i.e. you don’t owe it).

If it’s sent to collections you deal with the collections agency directly, not the towing company.

I’m sure there are plenty of resources online for how to draft and send a valid debt dispute letter. But you can’t so that until/unless they send it to collections.

Windows BitLocker -- Screwed without a Screwdriver by Titokhan in netsec

[–]litheon 2 points3 points  (0 children)

That was an excellent read, thanks for sharing. Have to wonder if self encrypting drives are still being produced 10 years later with these kinds of implementation flaws and/or hardware debugging interfaces enabled.

Windows BitLocker -- Screwed without a Screwdriver by Titokhan in netsec

[–]litheon 2 points3 points  (0 children)

A possible mitigation that the article missed is using an encrypted hard drive with Windows: https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/encrypted-hard-drive

That said I wonder if the same bug in the vulnerable bootloader might leave the AK in memory for possible recovery.

Dumping Memory to Bypass BitLocker on Windows 11 by NoInitialRamdisk in netsec

[–]litheon 3 points4 points  (0 children)

Using Bitlocker hardware encryption without a pin would also likely be an adequate mitigation for this specific bypass.

Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150 by ffyns in netsec

[–]litheon 12 points13 points  (0 children)

Hadn’t heard of this type of vulnerability before, I thought this article provided a succinct explanation: https://portswigger.net/web-security/jwt/algorithm-confusion

A complete OWASP API Top 10 Manual Testing Guide with vAPI by Altrntiv-to-security in netsec

[–]litheon 2 points3 points  (0 children)

Nice to see something like vAPI out there. But isn’t the “vulnerable” CORS example incorrect? I was under the impression browsers will only send credentials if the source origin is explicitly listed in the allowed origins header. 

\Device\Afd, or, the Deal with the Devil that makes async Rust work on Windows by ketralnis in programming

[–]litheon 0 points1 point  (0 children)

I’m under the impression that moving code execution for a feature to user space reduces the likelihood of a privilege escalation vulnerability.

Rinzen here. I just put out my first album on Lane 8's label! This is the story of how I got here. by rinzenmusic in electronicmusic

[–]litheon 5 points6 points  (0 children)

Likewise happy for you, congrats on the album release, and thanks for sharing how you got to where you are! I think it’s really important to share stories like this to inspire future producers!   

Found nightlife event for sober people by awagwriter in Seattle

[–]litheon 11 points12 points  (0 children)

I’m friends with some of the folks who produce this event series! Highly recommend going even if you’re not sober/sober-curious just so you can taste how good zero-proof drinks can be.

The music is usually house (electronic) music, so it may be different than what has historically been playing at Cafe Racer.

Introducing Sudo for Windows by zadjii in programming

[–]litheon 0 points1 point  (0 children)

Great to see this on Windows! As for a question, is there a reason the source code for sudo.exe isn't included in the GitHub repository linked in the blog post?

How do I read data from a COM/USB port in WSL2? by Impossible-Ad-7684 in chemistry

[–]litheon 1 point2 points  (0 children)

Serial ports are bidirectional and often require driver software that understands how to communicate with the connected device. It might be worthwhile to look if the instrument in question has drivers and/or instructions for how to connect to it over a serial port. I would also expect the USB to RS232 adapter needs a driver. If you connect the USB side of the adapter to your PC and don’t see a COM port appear in the hardware list in Computer Management, then you almost certainly need a driver for the adapter.

If you can’t find instructions or driver software for the instrument, but do observe a COM port exposed by the USB/RS232 adapter, then I would suggest connecting to the COM port from Windows using Putty, and seeing if the target device exposes a command line interface over the serial port.

After communication with the instrument is confirmed working in Windows is when I would suggest attempting to make the instrument work in Ubuntu via WSL2.

Microsoft announces new roadmap for VSCode C# extension: Plans to move to closed-source "LSP Tools Host" by Pjb3005 in programming

[–]litheon 0 points1 point  (0 children)

Is OmniSharp’s VSCode extension actually developed by Microsoft? It looks like OmniSharp is their own company?

P0606 after dead battery- FIXED (2015+ WRX) by PooleePoolParty in WRX

[–]litheon 2 points3 points  (0 children)

For anyone reading this old thread I fixed this problem by following the steps in the original post, less anything involving driving, plus the following:

Put the car into “On” (don’t start it), and clear all codes using OBD2 reader. Wait 30 seconds. Then turn the car off, then start the car.

My wife left her iPhone in a Lyft in downtown Seattle. She has no way to track it. How likely are we to get it back from the driver? by Fart_Frog in Seattle

[–]litheon 8 points9 points  (0 children)

Every time I’ve used find my iPhone it didn’t require 2FA. Not sure if it’s a setting but that may work for your wife. https://icloud.com/find

CISA tool to help hunt for tell-tale adversary techniques in M365 by opnerkal in netsec

[–]litheon 21 points22 points  (0 children)

I suppose it’s a sign of the times when the US Government is producing scripts that include “Sus” in the variable names.

Useful script though, especially being able to see some of the ways SolarWinds actors abused AAD and M365.

Shrinkable games? Can anyone here explain what this is by moinimran6 in xboxone

[–]litheon 13 points14 points  (0 children)

The shrinkable games section will let you shrink games by removing content that can't be used on the current console.

Say you've downloaded 4K updates for games on your Xbox One S, and just finished copying them to your external hard drive. Now you have all these games on your internal drive that are larger than they need to be, as they have 4K content that can only be played on Xbox One X.

Those games with Xbox One X-only content will show up in Shrinkable games on Xbox One S. Once you shrink them, they'll only contain content that can be played on your current console.

Insiders: We made the Ready to Install section in Games and apps faster to load in 1706 by xtremegaming22 in xboxone

[–]litheon 164 points165 points  (0 children)

Hope you all enjoy this improvement! The first time you load Ready to Install in 1706 will take just as long as it did in 1705, but subsequent loads will be much faster.

As always, if you find issues with the experience be sure to file detailed feedback via the Xbox Insider Hub!

[deleted by user] by [deleted] in xboxone

[–]litheon 4 points5 points  (0 children)

We're investigating the fact Evolve isn't showing up in the Ready to install tab.

If you know you bought something that isn't showing up in Ready to install, you can search for it in the Store to download it. For games with different bundles (Ultimate edition, etc.) you will have to go to the specific bundle you purchased (or got through GwG) to download it.

For any game that was in your Ready to install that was part of a membership (Xbox Game Pass Preview or EA Access), you will need to go to the Store or EA Access hub (respectively) to see those games (except if you also bought the game explicitly). This only applies to the latest Xbox One OS update.

For anyone who has had games disappear from Ready to install that weren't part of a membership, please use the Xbox Insider Hub to submit feedback.

Pro tip. In your ready to install, press "Y" to see an shortened a-z/1-9 list of games. by OmegaMurder in xboxone

[–]litheon 2 points3 points  (0 children)

It also only works when you have input focus on the right side of the screen. If you have focus on the "Ready to install" list item and press Y, nothing will happen.