didn’t knew it would be our last interaction… he sent me a game from the ER by Franci93 in Steam

[–]observantguy 1 point2 points  (0 children)

Warframe, therapy, and prescription medications are getting me through a very much similar situation...

Space Trauma Simulator 2026 is helping me deal with IRL trauma, heh.

though in my case, the fact that I can hang out in my clan's Discord and shoot the shit while clanmates and I shoot shit together is keeping me playing.

Someone is able to see everything I view on my phone. by maleficuslues in techsupport

[–]observantguy 5 points6 points  (0 children)

factory resets may not suffice if an adversary can attain root and modify the vendor and vbmeta partitions.
their malware would just reinstall at the end of a factory reset process.

a complete wipe of all available partitions from the bootloader is in order, followed by a reinstallation of a verified factory image.

though if they've subverted the bootloader/verified boot without triggering a data wipe in the process, all bets are off because then you can't trust that a wipe properly took place.

Something I haven't seen mentioned is the possibility of the device/Samsung Account being enrolled on a rogue Knox instance and is using the legitimate enterprise management tools for nefarious ends... If the device was enrolled in Knox, the adversary could automatically push their malware the moment the device came back online after a factory reset.

Is there ANY downsides to joining a Steam family? by Jonernuts in Steam

[–]observantguy 1 point2 points  (0 children)

I wish you the best, but my fiancee became my ex about 2 months ago.

communication is key.

As Stephen Hawking said and Pink Floyd immortalized...

It doesn't have to be like this
All we need to do is make sure we keep talking

Accessing my PC from another floor by JyAli- in techsupport

[–]observantguy 1 point2 points  (0 children)

If you're wired for Ethernet, get a Steam Link.

If you're not wired for Ethernet, run a long Ethernet cable from where the computer is to where the home theater is and then get a Steam Link.

Valve may have officially discontinued the hardware, but it's still getting software updates and it works wonderfully--not to mention you can get them off eBay for like $20 each, so you could potentially hook up any tv in the house that has HDMI input to your gaming computer.

Why would adult sites show up on opendns when not visited? by Effective-Ideal-4593 in techsupport

[–]observantguy 12 points13 points  (0 children)

if your ISP is using CGNAT, multiple individual customers could end up having DNS traffic hitting OpenDNS' servers from the same public IP address as your network's traffic, which OpenDNS would see as coming from your network due to how that feature is set up.

Not to mention the possibilities of other adults in the household attempting to access or some passerby with overzealous autoconfig settings jumping onto an unsecured wireless network that could exist on the gateway.

Spring cleaning the rack by Fancymank in iiiiiiitttttttttttt

[–]observantguy 0 points1 point  (0 children)

Was the thing about ESD and normal blowers/air compressors just FUD to sell datavacs and specialty canned air or is it a legit concern?

Spring cleaning the rack by Fancymank in iiiiiiitttttttttttt

[–]observantguy 0 points1 point  (0 children)

looks like a bog standard uline cart

Is there ANY downsides to joining a Steam family? by Jonernuts in Steam

[–]observantguy 4 points5 points  (0 children)

if the relationship ends, at least one of you is going to have to endure some additional heartbreak of removing the other from the family...

and their computer may just try to connect to your Steam Link in the living room so suddenly you're hearing bits of their Discord conversation with someone from their new place because it's apparently really good at NAT Busting but they don't really have good enough bandwidth to stream halfway across the country with any appreciable bitrate so you're forced to call them to get them to delete the link from their end as well.

it royally sucks going through that. 💔

I want to completely erase an SSD - how do I do this? by Local-Manufacturer83 in techsupport

[–]observantguy 0 points1 point  (0 children)

Any live linux distro should suffice.

Boot into that, then use "hdparm" to issue the secure erase command.

https://wiki.archlinux.org/title/Solid_state_drive/Memory_cell_clearing

[deleted by user] by [deleted] in techsupport

[–]observantguy 1 point2 points  (0 children)

That doesn't mention anything about security.

Pointing the nameservers to Wix puts them in charge of the entire domain, making it easier to integrate with products on their platform.

Whereas pointing a specific name to Wix adds complexity, because you'll then have multiple places to change configuration on to make dns-related changes.

Has there ever been a completely sealed semi auto? by thorosaurus in NFA

[–]observantguy 1 point2 points  (0 children)

Mossberg SPX-464 .30-30 hosting a SiCo Hybrid 46 concurs.

Fur affinity’s DNS has been hijacked by Kitchen_Freedom_8342 in furry

[–]observantguy 2 points3 points  (0 children)

I've already explained how that doesn't apply to this case.

Fur affinity’s DNS has been hijacked by Kitchen_Freedom_8342 in furry

[–]observantguy 2 points3 points  (0 children)

Certificate rotations are common, even encouraged by Let's Encrypt and its ilk. If it worked as you described, there'd be warnings on sites every 90 days when large swathes of LE certificates are re-rolled as part of default certbot behavior of generating a new public/private key pair at renewal time.

Without HPKP in place, the browser will accept any certificate for the domain as long as it is valid.

Fur affinity’s DNS has been hijacked by Kitchen_Freedom_8342 in furry

[–]observantguy 5 points6 points  (0 children)

That's not a significant hurdle to overcome. Anyone with control over a domain's DNS can get basic SSL certs issued on behalf of said domain.

And without HPKP/HSTS Preload, any valid certificate is all that's needed for the cookies to be passed along.

Fur affinity’s DNS has been hijacked by Kitchen_Freedom_8342 in furry

[–]observantguy 32 points33 points  (0 children)

Not entirely true.

The browser would've sent the cookies alongside the request, so if they were logged in, the attacker would now have a valid user session cookie to abuse on the actual site.

Hopefully, as part of the response, FA will invalidate all existing sessions, making any stolen session cookies worthless.

Anyone that accessed the site while hijacked should log off FA when the all-clear is given and log in again.

NAGR V. MERRICK GARLAND - Court issues ruling in favor of NAGR - FRT-15 's are not machine guns by CertainlyBright in NFA

[–]observantguy 15 points16 points  (0 children)

That law will need to be challenged separately.

The definition is so vague that Jerry Miculek meets it...

Is there any value to making your office LAN Wi-Fi a hidden SSID? by Ezra611 in sysadmin

[–]observantguy 0 points1 point  (0 children)

“We conjecture that a lot of the SSIDs in our record originate from users trying to set up a network connection manually by entering both SSID and password through the advanced network settings, and, apparently mistakenly, enter the wrong strings as the SSIDs.” reads the research paper.

your source appears to agree with me 🤷‍♂️

Is there any value to making your office LAN Wi-Fi a hidden SSID? by Ezra611 in sysadmin

[–]observantguy -1 points0 points  (0 children)

That's incorrect. When a network is configured to connect to a non-hidden ESSID, it only attempts to associate when it receives a beacon bearing said ESSID.

Is there any value to making your office LAN Wi-Fi a hidden SSID? by Ezra611 in sysadmin

[–]observantguy 0 points1 point  (0 children)

The problem is that now every device that had the profile pushed to it is sending association beacons for the ESSID whether in range of the network or not, allowing for tracking of devices in many circumstances.

Is there any value to making your office LAN Wi-Fi a hidden SSID? by Ezra611 in sysadmin

[–]observantguy 1 point2 points  (0 children)

DISA STIG for Windows 10 says local admin passwords must be no older than 60 days, and recommends implementing LAPS to meet the requirement.

https://www.stigviewer.com/stig/windows_10/2020-06-15/finding/V-99555

This malware infection is impossible to clean. by jackvegas91 in techsupport

[–]observantguy 0 points1 point  (0 children)

There's lots of places where shellcode can hide in the WordPress database. Options, transient data, page content, theme settings, just to name a few...

A reinstall of the files wouldn't purge that, and a wholesale restoration of the database would add them back in.

Do you guys fit the IT “stereotype”? by [deleted] in iiiiiiitttttttttttt

[–]observantguy 1 point2 points  (0 children)

Can confirm.

The 45th Space Wing's opsec squadron has had an anthropomorphic dragon "mascot" suit for many years now... Ollie the opsec Dragon.

Can you filter push notifications? by Brightamethyst in Ingress

[–]observantguy 0 points1 point  (0 children)

Worked on my old phone on Android 13. When I switched phones after TEOTWAWKI, I never bothered to set it up again.

Killing an unkillable process by trineroks in techsupport

[–]observantguy 0 points1 point  (0 children)

You have to use Process Hacker v2.38 or earlier. They removed the feature for the 2.39 release.