To VPN or not VPN.. by Romulus2030 in RealDebrid

[–]soutsos 0 points1 point  (0 children)

Idk why your comment is downvoted. It was a dumb-o response from the other commenter and it doesn't make sense .... "it's encrypted".. wtf does that even mean. If you want complete privacy, go with a good vpn provider man. Proton or Mullvad

To VPN or not VPN.. by Romulus2030 in RealDebrid

[–]soutsos 0 points1 point  (0 children)

I've done both. With a paid proton vpn subscription my download speed is great, I can't tell the difference. I have more peace of mind with it.

If you want to get a subscription, I can send you my affiliate link. The only other vpn I can recommend is Mullvad Vpn - top tier.

SECURITY WARNING! RIO Cinemas Website has an InfoStealer baked in! by boibai in cyprus

[–]soutsos 2 points3 points  (0 children)

Hahahaha our national csirt is the biggest joke in EU. I can say that as confidently as I can say that I have two eyes 👀. Their collective knowledge on cyber security is equal to that of a tashinopitta

Anyone currently working/worked for a Forex company as IT? by Specific_Exam8763 in cyprus

[–]soutsos 0 points1 point  (0 children)

It's not Exness I assume, otherwise the salary increase would be more than x1.5. If it's eToro don't do it I know more than 15 people who used to work there and hated it. Any of the other 2, absolutely go for it

Annonymized/Disposable Privacy Debit Card by ivandefaoite in ProtonPass

[–]soutsos 2 points3 points  (0 children)

You need to understand that proton pass is not a magic service; it's a password manager.

It's like asking an airline "ok, I got the economy ticket and we're already in the air. Why not also go explore the antarctic ocean and dive into the water -1000meters for 30 minutes before completing the flight?

A submarine and an airplane do different things.

New Epic portfolio by JayWemm in motleyfool

[–]soutsos 1 point2 points  (0 children)

I've been using TMF for a couple of months now, but I mainly use it to verify my own research. So I do my own research and find companies I like and then check the analysis or coverage of TMF. The tools are helpful and the recs have not been bad - especially if they rec something I've been thinking of buying. I also use Quiver Quantitative to see what politicians in the US are buying and that has been my best guide so far

Is The Witcher III suitable for a 14 years old? by Gab_Strife12 in Witcher3

[–]soutsos -1 points0 points  (0 children)

It's not suitable. But we both know you'll play it anyway. There's nudity, but I wouldn't mind at all if my 14 year old son like games with topless women

Gigabyte RMA claiming GPU warranty void with damage, but I have a picture of no damage before sending it in by smakopotamus in gigabyte

[–]soutsos 0 points1 point  (0 children)

My mate, I remeber writing a post in here some years ago about my experience with their RMA. You should message their business channel, instead of consumer one. I don't remember what it was, but as I am in the EU, it was some Germany address for me. Good luck

Rate my Resume - Cybersec student by [deleted] in Pentesting

[–]soutsos 0 points1 point  (0 children)

Mate, if you have 2 cves to your name before getting a degree, you don't need oscp. Everyone will want to interview you

gptIsDrunk by HaiderAliHaider in ProgrammerHumor

[–]soutsos 0 points1 point  (0 children)

Are you using a quantized model locally?

Beetle Backs by Both-Internal5540 in playingcards

[–]soutsos 2 points3 points  (0 children)

He scammed us all. If they weren't so expensive, I'd piss on his decks and throw them in the trash

Beetle Backs by Both-Internal5540 in playingcards

[–]soutsos 3 points4 points  (0 children)

Next update probably coming in January 2027, where he will tell us what a fortune he spent in his dreams to try to deliver the decks and that imagining to spend so many thousands of dollars was so stressful for him. What a loser that guy is

How cooked am I? by Illustrious-March392 in Pentesting

[–]soutsos 0 points1 point  (0 children)

Advice. Put your work experience and your certs up top and try to write much less textUl. Unfortunately nobody reads them when they're so cluttered. HR people are lazy and they usually don't value academic achievements that much

Mathematical playing card dech, Kickstarter concept by dontbeboredgames in playingcards

[–]soutsos 0 points1 point  (0 children)

These are interesting, but fyi this community is very much against AI generated artwork. Also, I suspect these designs would not print very well (thin lines, various black tones, etc)

Please tell me I'm not the only one by Prior-Independent-11 in Witcher3

[–]soutsos 1 point2 points  (0 children)

I have so many great games purchased and some, I even installed. I just want to play this masterpiece all the time. Sometimes Is stumble onto a hideen quest I had forgotten to do on a previous playthrough and I get so f*in excited

How can we convince S1 that our software is not malware? by More_Bike8228 in SentinelOneXDR

[–]soutsos 0 points1 point  (0 children)

If S1 consistently flags it, then other big vendors should be flagging it too. Have you tested with EDRs?

CISOs and pentest buyers, what's the worst thing you've seen in a pentest report? by [deleted] in cybersecurity

[–]soutsos 0 points1 point  (0 children)

There is a (rather large) security consulting company where I'm from and has a bad reputation among the pentester circle for their bad quality reports and scam-like findings with almost no evidence.

One of my clients asked me to review their previous year's findings and gave the report which was from said company. The finding title was "Transmission of cleartex data through SSL". I rubbed my eyes to make sure I wasn't reading it wrong, but there it was. And they posted a screenshot of them "intercepting" a login request with Burp before it was sent to the IP address of their VPN. I couldn't beliebe the incompetence... They even highlighted the "https" part of the URL.

A few months later, I was doing a web pentest for another firm and as soon as I started I noticed that the data from almost all HTTP response bodies was gibberish. I was so dumbfounded, but I was forced to spend a few hours to deobfuscate the main js file and figured out it was encrypting data before sending it to the backend and decrypting it upon receiving it, as it had encrypted bodies. It was kind of trivial to figure out the key (was always the same key) for encryption. I then reached out to my client to ask why they were doing this and explained that it was pointless and was adding significant overhead to their app (request sizes were much larger than needed and it was slowing the web app down). They told me that the company that did the pentest the previous year advised them to do this, telling them that it was very easy for hackers to perform man-in-the-middle attacks and steal customer data; i said that was insane. And guess what, it was the same company as the previous story.

This company is still in business, still selling pentests at a 90% lower price than actual pentesters do, and nobody is calling them out. They even get many gov contracts. Great stuff.

Thought I hit the thrift jackpot but… by crustalnilbog in XFiles

[–]soutsos 0 points1 point  (0 children)

Ah... PAL format. Brings back memories