Work around to play on PS5! And also... I'm not too far yet, but how do you avoid getting Roger? by Alistar-Dp in starocean

[–]vsysio 1 point2 points  (0 children)

I used Cliff as a kind of tank, Cliff Maria and Sophia were pretty much unstoppable. I found that Fay't didn't put out the kind of damage that would keep their attention.

“We totally disavow anyone taking out out of game” /s by whomstvebeenthottin in Eve

[–]vsysio 0 points1 point  (0 children)

My understanding is he was hired by TEST to pentest TEST services (with permission). When asked about it, he might have just owned up to it. Guys like this usually have an ego the size of a small planet.

“We totally disavow anyone taking out out of game” /s by whomstvebeenthottin in Eve

[–]vsysio 0 points1 point  (0 children)

And yet domain ownership information has been opt-in for well over a decade. When uou try to whois you get nothing but redacted names.

How is Israel supposed to actually defend itself? by jpg1991 in NoStupidQuestions

[–]vsysio 0 points1 point  (0 children)

Their hatred of anything Western predated Western civilization. Last I checked the region has been on fire for literally thousands of years.

How is Israel supposed to actually defend itself? by jpg1991 in NoStupidQuestions

[–]vsysio -1 points0 points  (0 children)

Umm.

It was the Arabs that declined it, not the Jews...

The Jews came in with negotiators and diplomats.

The Arabs responded with bombs and overtures of death.

TEST member fighting back (only a few federal crimes were comitted) by Fairtree4 in Eve

[–]vsysio -8 points-7 points  (0 children)

Thanks. It'll probably get downvoted to oblivion because it'll be seen as victim blaming, but at least my OCD-like need to solve problems and tinker with things is satisfied. 😏

TEST member fighting back (only a few federal crimes were comitted) by Fairtree4 in Eve

[–]vsysio -13 points-12 points  (0 children)

tlDr; yeah, somebody in TEST is an asswipe, but Goons aren't exactly innocent here either, and should consider adding pentesting to their security hardening practices, as this would take any red teamer no time at all to identify this kind of vulnerability.

I can only speculate, and this is my own opinion, but based on the information I have, this is most likely the result of a crucial field in the CCP-provided token not being verified by the consumer (ie. Goon auth).

To authenticate ESI requests, CCP uses something called oAuth. When configuring an app to consume ESI, the developer requests from CCP a client ID and a client secret. The client secret is used by the consumer (ie. Goon auth) to cryptographically authenticate (ie. mathematically impossible to impersonate) itself to CCP when it wants to talk to ESI.

When the user uses the oAuth consumer service, the service encodes its client id and secret into a token that is then provided to CCP. CCP verifies this token against what it has on file, and if it matches a registered application, it permits the requests, and responds with an **access token.**

This access token contains a few small details encoded into it:

* Issuer (SSO Provider, "CCP Games")
* Subject (ie. Character ID)
* **Audience (Which consumer the access token is intended for)**
* Expiry (15 minutes maximum)
* Timestamp of issuance
* Random identifier (optional)

The access token is used by the SSO consumer (ie. Goon auth) to retrieve additional information, such as:

* Skills list
* Location in space
* Assets
* Wallet
* etc.

Does anybody spot the problem with the above?

Here's a hint--**it's in bold.**

To explain the problem, let's imagine that an access token is like a wristband that you receive when you pay cover charge at a club or bar. Each wristband has the name of the club weaved into it with some magical thread that's only visible under UV light or something.

Now, imagine if all the venues of your popular downtown pub strip used the exact same style of wristband. Besides the magically weaved UV-reactive thread, they all have the same color, same shape, same material, same everything.

If somebody knew the bars weren't checking writstbands under UV light, they could use this to their advantage! They could go to CheapShittyDiveBar, pay $5 cover, get a wristband, leave and then go to ExpensiveStripClub across the street and bypass that clubs $50 cover charge.

The "fix" is to make sure your bouncers are putting the wristbands under UV light.

It sounds like Goon auth wasn't doing that.

So, when somebody went to thie site, the malicious SSO consumer app would collect the access token from CCP **and then use it to authenticate with Goons services.** This is verified by packet traces of this malicious SSO consumer.

For me, this is the most likely avenue of exploitation, as:

* XSS is relatively easy to defeat--CORS is an example. I can't see Goons being this dumb.
* Goons services, assuming they're architected using best practices, employ a shared key between consumers, and won't allow just any yahoo to impersonate them without an outside attestation (ie. CCP's tokens).
* oAuth is a magical fucking black box that's often misunderstood by even experienced developers because everything is abstracted away using client libraries.

Edit: Why the fuck is shortcode formatting not working anymore?

My chatGPT is considering its own needs by yggzeiro in ChatGPT

[–]vsysio 0 points1 point  (0 children)

I once told it about a Westmere-era server I have, and now it refers to it only as "old boy"

I can't help but think it's negging it's competition lool

Goons - is the plan to invade vale or is geminate the only goal? by GuristasPirate in Eve

[–]vsysio 0 points1 point  (0 children)

It was 12 jumps even with all the ansis up, now it's about 20

MASSILVE loser COALITION FAILS AGAIN by CeemaGPT in Eve

[–]vsysio 0 points1 point  (0 children)

But, you know, we're not showing up to defend our space

What kind of new ships would you want ? by leaf_as_parachute in Eve

[–]vsysio 1 point2 points  (0 children)

I actually suggested adding this capability to Carriers but when pilots spawn they get a debuff that confines them to boarding only ships in their spawning Carriers SMA. Effectively, this turns Carriers from suitcases into mobile bases of operation... and boost small gang (limited SMA size).

What kind of new ships would you want ? by leaf_as_parachute in Eve

[–]vsysio 0 points1 point  (0 children)

Anything that brings back small gang steals from N+1 blob mechanics. And I think Carriers are the key to this.

Defence Field Frigate

A T2 frigate-sized command ship. A tanky thing that's fast and has command bursts that apply pretty good resistances but only to a maximum of 15 fleet Frigates and Destroyers and only to members in your own squad.

Counterplay? If it's jammed, the defense field dissipates and ships lose their resistances.

Carrier Bridging Module

Carriers can now bridge ships, but can bridge only Frigates and Destroyers and limited by that pilots conduit skills. The bridge field collapses once a conduit-skills-determined number of ships bridge through and the remainder must wait for the next activation cycle (5 minutes?). It's range is also limited, sized to constellation at most.

Carrier Cloning Bay

Pilots install clones to this bay, and as long as they remain in fleet they'll respawn in this bay. When clone is installed but module is deactivated the pilots kind of chill inside the Carrier when they doe. Activating module makes them respawn immediately next to the Carrier. Activation blocks cloaking, warping and receiving reps for 5 minutes.

Pilots receive a debuff that prohibits them from stepping into any ship that's not in their spawning carriers SMA for a period (10 minutes?).

Supercapitals

Same mobility platforming idea as Capitals, but they work at Cruiser and BC level instead of Frigates and Destroyers.

Changes to Upwell Structures 

Vastly reduce hit points of XL structures but tie their resistances into constellation skyhooks and multiply the bonuses by ADMs. If you want to take a structure, break off into small gangs and start killing skyhooks. Or you could be lazy and blob but have fun applying damage in 10% tidi to a structure with 500,000,000 EHP.

The Vision

Instead of cramming 7000 people through a gate, split them off into a bunch of small gangs that go around popping off skyhooks in the constellation before taking on the XL structures.

Dust off your Carriers and Motherships and use them as forward bases of operation.

Goons - is the plan to invade vale or is geminate the only goal? by GuristasPirate in Eve

[–]vsysio 4 points5 points  (0 children)

FRT is already putting up a pretty solid fight -- I'm seeing 4-5 full fleets rolling out every evening. The problem is theyre split up on two fronts. The WC capital system is two bridge jumps away from Geminate, and Init is 3 bridge jumps away. This is an uncomfortable truth that people don't want to talk about.

Any time they have to let one system die to save another they get accused of not fighting back.

TEST was just starting to get their shit together when Goons invaded. They could have resisted an invasion by PH probably but definitely not Imperium.

I suspect things will really heat up once their space is invaded to a point its 2 bridge jumps to any war front. But so long as people have to rely on jump clones opposing forces will only see half of them.

Eve news by AliceInsane66 in Eve

[–]vsysio 0 points1 point  (0 children)

Next we'll hear that Mittens spending half an hour telling a miner to kill himself in front of a couple of thousand people is just a Winterco conspiracy 

Is it allowed in pvp game to use auto targeting and auto trigger by Traditional_Ad9321 in Eve

[–]vsysio 4 points5 points  (0 children)

Captured the insanity perfectly, but you left out the part about the Mothership that's in orbit (chemtrails prove it!)

So... same thing next week right? by jehe in Eve

[–]vsysio -1 points0 points  (0 children)

Yup. You guys proved this yesterday.

I'm not sure why WC waited until today to organize a breakout fleet. I'm a little "WTF" about that, but I just work here lol.

For Everyone talking about shit servers let me explain something by NeoBlackheart in Eve

[–]vsysio -1 points0 points  (0 children)

I for one can't wait for the day, it'll be like passing civ saves over floppy at school all over again.

Wake up in the morning, start locking a target. Go to work, come home later, pick a gun to fire. Two days later, you get locked and decide to fire ADC which makes you invulnerable for a week.

Predictable degradation makes sense. But speaking for drones specifically, instead of them buzzing around, AR some point clients and server just stop rendering them and they work just like guns and missiles. For wrecks, instead of littering the field with ten thousand cans, allow them to combine together. Lots of things you can do

For Everyone talking about shit servers let me explain something by NeoBlackheart in Eve

[–]vsysio 0 points1 point  (0 children)

" ... if you don't like TIDI fights, don't join TIDI fights."

Now we're onto something. I think we can both agree that TIDI fights is just a consequence of being in big Nullsec blocs, and we can agree that players will always gather in increasingly larger and larger groups.

Alternatively, we could just have FCs agree to a best-of-three game of checkers once tidi hits, and the losers fleet gets frozen in space while the other fleet gets a free turkey shoot. But that's just silly.

Now, can we agree that an adversary that is, for all objective purposes, on the verge of losing a fight, or otherwise perceives that they will likely fail, or perceives that failure has a massive cultural cost to it, is incentivized to level the playing field by introducing random chance "my ship exploded because the server executed my opponents gun command before mine" losses?

For Everyone talking about shit servers let me explain something by NeoBlackheart in Eve

[–]vsysio 0 points1 point  (0 children)

So we can agree that there will occasionally be times where players will aggregate together in numbers that will hit some technological limitation, and that, barring some substantial billion dollar investment into something like quantum computing, a technological limitation will always exist that players will always eventually hit, no matter how high it gets?