Hacker Newsnew | past | comments | ask | show | jobs | submit | more Fokamul's commentslogin

-> bad OPSEC ;-)


BT standard wasn't even that bad, from security stand-point, the worst thing is implementation and maybe only SW implementation.

Televisions(eg.: LG) where you're unable to turn BT off. With that knowledge, you can buy cheap device which is normally used for development and analyzing of BT communication.

And with that device, you can spam any TV around you with fake BT connection requests, TV is basically unusable during this time and best thing, this cannot be blocked :D

(only way to turn BT off on LG TV is with you getting root and downloading homebrew app, which of course degrade the use of your TV remote, because it uses BT)


I dev my private fork of browser fingerprinting bypass and I can tell, this is like 1% of what commercial tracking companies use for fingerprinting.

Unless they tackle all the hidden things, all artifacts, canvas rendering and many more.

These companies will be actually happy after this change, because even users with ublock and other plugins, will think they're not tracked. Yeah, nope.

And it's not that hard to see how they fingerprint your browser, reverse any JS tracking script yourself and see.


Phone bombers are still a thing ;-)


In perfect world, Microsoft would help to create this tool.

Nope, they don't have time for this. Too much work om security through obscurity, making crap SW which eats RAM like hamburgers and disabling local accounts...


I think that’s a really unfair portrayal of Microsoft’s product management. They spend a lot of time— even more than on some of the things you listed — creating GUI frameworks to ignore, injecting creepy analytics for their war on privacy, obfuscating those analytics and stymieing users efforts to avoid them, and figuring out terrifying new definitions for the word experience.


Microsoft provides a tool called "Media Creation Tool" https://www.microsoft.com/en-ca/software-download/windows11

But of course it’s highly simplified and designed solely for installing Windows.


For Windows and FROM Windows.

I swear the most recommended way of creating a bootable Windows USB on Linux changes every year, and usually doesn't work. I keep an old Windows laptop just so I can create bootable Windows usbs, whenever needed.


Making custom Windows install media is insanely painful, even from Windows. I went through the process of creating non-interactive install media for Windows once, and was astonished at how awful it is compared to building custom Linux live media. (Not least of all because of the churn in the XML you have to maintain that basically represents clicking through all the installer menus.)


WAIK? I created a customized Windows install image as a 19 year old intern and presented it to the rest of the IT team...


It depends on what customizations you'd like to use.

I've also had a very hard time creating an automated install media for an appliance for windows iot... Worst was the (LLM generated?) powershell scripts in the documentation that didn't work at all.


Microsoft's tooling for customizing images amounts to several gigabytes to download and install just to get started.

The Windows approach is based on a mix of relatively limited offline modifications and automating clicks and keystrokes (AutoUnattend.xml, OOBE.xml) and recording or forgetting manual changes (Audit Mode, Sysprep). Both are insanely kludgey.

New development of the tooling always comes to dism.exe first rather than the DISM PowerShell module, so you may need to use DOS commands instead of the (very lovely) modern shell that Microsoft maintains.

Depending on what kind of stuff you're trying to install, you might need to do half a dozen reboots in the course of recording your manual changes.

Mounting/unmounting a WIM file can take more than a minute (wtf?) and if you're working on modifying one of the installer images from upstream, you need dozens of gigabytes of free disk space.

If you don't just want install media, but a bootable repair environment, everything is even worse. Hardware recognition is bad, boot is slow, and only some programs can actually run in a WinPE environment.

Have you ever customized bootable Linux media?

When I had to make some custom NixOS install media for an aarch64 VPS, it required only a few lines of code in the exact same environment as I use to customize running systems, and it's completely declarative, non-interactive, requires no special toolkit, doesn't require dozens of gigabytes of scratch space, never requires me to boot anything...

Teenage interns can also shovel manure, but that doesn't make it pleasant or painless!


For as long as Windows has supported UEFI, you've just been able to copy the files from the ISO directly to a UEFI partition.


Also, adding Copilot to everything.


>eats RAM like hamburgers and disabling local accounts...

Those are the kind of hamburgers that make people say "Where's the beef?"


ramburgers are quite healthy, they've been shown to improve memory


Stretching your hate for the company a bit too far, don't you think? I mean all the cool kids do it, but you can't blame them for not having done this.


It's likely in future, you won't need app store approval process. I hope that EU will nuke Apple with some huge fines.

And there will be corporate tax per each EU country, it's ridiculous corporates are raking huge money here and paying basically nothing on taxes, well only in Ireland and they're having party.

Anyway, asm is great if you are using iOS emulator and need to do something and since you have root there, well :) (not apple meme simulator)


You can already deploy apps on alternative stores inside of the EU. Apple has some bullshit fee but Epic has promised to cover that for AltStore.


More locked device, more difficult obfuscation -> more motivation for certain people to break it and share it with everybody.

There is no way, you can plug all holes, iPhone couldn't do it with their golden cage and they spend ridiculous amount of money so their phone cannot be rooted, but you still have rooted iphone.


Easy ownership test. Try flash custom firmware on your phone. ;-)

You can't? THEN YOU DON'T OWN YOUR PHONE.

Simple as that.


Hmm, meanwhile you have whole gaming platforms like Steam, where they basically make huge profit from gambling in games like Counter-strike and others. And hmm whose playing those games?


In defense of the parent comment, I don't know that he suggested that it wasn't effective, but it is a dark pattern that probably should be avoided if the gist of the effort is to truly be an educational game that you'd want to enthusiastically support.


But the makers of CS don't go around telling their game is targeted at kids.

And that's another topic, plus this is part of the gameplay, not just some cosmetic stuff.


Aren't most micro-transactions like those purely cosmetic?


Yes for Valve, but that hasn't stopped a secondary market transacting tens of thousands of dollars or more for them in some cases.

> https://dmarket.com/blog/most-expensive-csgo-skins

> https://tradeit.gg/csgo/store


They are in Valve's own games. But items drop at different rates, which creates artificial scarciry and items can also be traded for money.


It's cloud based, yep :D


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: