Skip to content

Reddit in talks to embrace Sam Altman’s iris-scanning Orb to verify users

Technology
154 121 4.0k
  • 33 Stimmen
    16 Beiträge
    27 Aufrufe
    alphane_moon@lemmy.worldA
    Call it word salad, mashed potatoes or Peruvian causa, makes no difference to me. The fact remains that libertarianism is an American oligarch polemical strategy aimed at enabling corruption and keeping local plebs in line (because Americans respond particularly well to certain keywords and copytext). Denying that doesn't give you much credibility! Just think for a second how it makes you look! I saw all I needed by clicking a random article on the Cato's frontpage. It's is clear that they are demagogues and malicious. And I am willing to bet if we look at their funding, it is all run by oligarch/criminal groups. I am not going to deny basic facts about life "follow the money" based on some half assed rehortic. We good?
  • 631 Stimmen
    49 Beiträge
    501 Aufrufe
    jabjoe@feddit.ukJ
    They should be being sued for doing anti repair tricks. The guys exposing the anti repair tricks are the heroes here.
  • 46 Stimmen
    4 Beiträge
    22 Aufrufe
    S
    It really is addictive to ask ChatGPT to answer questions that would annoy another human ... And probably it makes your brain more dependent on trusting an authority.
  • Steam Users Rally Behind Anti-Censorship Petition

    Technology technology
    244
    1k Stimmen
    244 Beiträge
    5k Aufrufe
    J
    It's also the US legal standard for obscenity laws, unfortunately.
  • Firefox is fine. The people running it are not

    Technology technology
    206
    1
    852 Stimmen
    206 Beiträge
    2k Aufrufe
    O
    Sounds like some deliberately obscure concentrations of power. The fear bit is really problematic though as scared people are not ideal decision makers.
  • 4 Stimmen
    6 Beiträge
    76 Aufrufe
    jimmydoreisalefty@lemmy.worldJ
    I wonder! They may be labeled as contractors or similar to a merc. Third-party contractors that don't have to follow the same 'rules' as government or military personnel. Edit: Word, merchs to merc, meaning mercenary
  • 1 Stimmen
    1 Beiträge
    18 Aufrufe
    Niemand hat geantwortet
  • 1 Stimmen
    8 Beiträge
    77 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.