j4k3

joined 2 years ago
[–] j4k3@lemmy.world 3 points 2 weeks ago

Use offline open weights.

[–] j4k3@lemmy.world 4 points 2 weeks ago

It is the tiny URL link that has a unique identifier. The normal website links are just the regular website address root for reddit.com. Tiny URL links stand out more to me because I use a DNS whitelist firewall and will never approve any of these forwarding connections.

[–] j4k3@lemmy.world 6 points 2 weeks ago (3 children)

Why the reddit tracking link?

[–] j4k3@lemmy.world 3 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

The easiest way I know of to check any machine is to put another router or machine in front of it with a white list firewall or way of logging DNS traffic. You just need to spot the address in the list.

DNS filtering usually only filters on incoming packets, but for bot stuff that should catch issues.

In general, most routers run everything from a serial flash chip on the board. These are usually 8, 16, or 32 megabytes. They have a simple bootloader like U-Boot. This is what loads the operating system. These devices have a UART serial port on the PCB. You can use a USB to serial UART adaptor to see what is happening in the device. With a proprietary OS, you are still likely to see the pre-init boot sequence that the bootloader prints to terminal. Most operating systems also print information to this interface, at least of the couple dozen junk devices I have been given and messed around with. I make a little mount for a USB to serial adaptor and add it to all of my routers when new, so I only need to plug in USB to get to the internal bootloader and tty terminal interface of OpenWRT. You will need to know the default baud rate of the device, although it is probably listed somewhere online or can be guessed as one of the common high values at or above 9600.

Getting into this further gets complicated. It is probably better to look for any CVE that is relevant to the device or software and work backwards. Look for any software updates that have obfuscated the risk for each CVE. If the issue was not fixed, that is where to look to see if someone has exploited the device. Ultimately, they need clock cycles from the CPU scheduler. So it must be a process or some way of executing code from unregistered memory.

This is getting to the edge of what I have messed around with and understand. There may be a way to get a memory map that includes unused pages, and compare that with a hex dump of the flash memory. This is outside of your scope of a proprietary OS, but hopefully frames the abstract scope of what is possible on this class of device when you have an open source stack. The main advantage of this kind of device and issue is that you can physically remove the flash chip and then see and manipulate every page and memory location. The device likely doesn't have microcode loaded into the CPU(s) that make it challenging to determine what is going on.

There is probably an easier way, but a hex dump of the current system can be hashed against the factory updated version to see if any differences are present. It is likely that any exploit will include a string with the address to connect to somewhere in flash memory. It could be obfuscated through encryption or a cypher, but a simple check for strings in the hex dump and a grep for "http" is a simple way to looks for issues.

The OpenWRT forum is a good general source. The people behind the bootloaders for these devices are also Linux kernel developers and on the OpenWRT forum.

 

I don't need useful translation. I need a way to randomize the words across different languages within the same sentence like a noise source where the basic grammatical structure is English but the words are many languages. I need to ensure the translated words are not in a list, then display the rest as a pull down menu or just code to swap the first option.

I was thinking about using the Wiktionary data dump, but if anyone knows a better option, I'd love to hear it.

 

We need a system like a RockChip processor based single board computer, paired with a trusted protection module, and all fediverse services prepackaged for minimal user input required to self host any fediverse services. All updates should be safely installed over the air via the TPM chip based encryption just like with Graphene OS. All of the necessary connections should be preconfigured to punch a hole for the port into the internet. The hardware should be completely locked down with an immutable base system and SE Linux fully configured. There shouldn't be any accommodations for obscure edge cases outside of the base configuration. It should not require any further payment or services.

A RockChip RK3588 is fully documented with a 3k3 page long full datasheet. As I understand it, this chip is open hardware, though it still has the ARM proprietary blob (TrustZone), similar to the x86_64 Intel Management Engine, and AMD Platform Security Processor. I have not heard of a similar system present in RISC-V processors, but I also have not seen RISC-V SBCs that are more than alpha prototype dev kits. Unlike other single board computers, the RK series has the documentation required for community based Linux kernel support. No one could pull kernel support that they are the only ones providing using a proprietary datasheet.

There are many RK3588 single board computers available for around $100 already. As a back of the napkin quality idea using baseless imaginary statistics, I bet we could get around 3-5% of regular users to purchase hardware within a year if it was within a $250 price point. This should be set up for one click image and video hosting, threadiverse, mastodon, file sharing, git, blogging, etc.

This is way outside of the scope of a project I am qualified to manage; I am no real developer, just a sloppy hacker type. I'd volunteer to do a hardware design, or at least the bulk of the tedium for someone more experienced with production stuff to review. I would not mind playing the glue between those that have more limited time. If LW has 6k plus active daily users, and 3-5% of these purchased the hardware, the rough margins are nowhere near a viable business. Still, something in the back of my head says the only thing actually impeding internet freedom with the fediverse is the challenge of self hosting, and this is like the issue that Android addressed with mobile hardware. If people could one-time purchase the hardware, and only pay for their regular internet connection, I think they would buy straightforward honest open hardware they fully own.

I don't know if it is possible, or if the fediverse projects would participate in some kind of automatically updated end point. This was just a fantasy shower thought that I have been mulling over all day. It addresses all of my personal hesitations and insecurities about self hosting, and is simple enough I can imagine my techno illiterate family giving it a try. It is the kind of project I would like to be a part of.

 

I stopped using piefed a week ago when I got a message some random quack banned my account in some community I had never engaged with but I could not figure out who did it or where it happened. Any lack of modlog accountability for mods and admin with full transparency are an absolute no-go for me.

Maybe I am just dumb and not seeing where to find these. I only use the web browser front end.

 

A master wood machinist, if ever there was such a thing.
https://www.youtube.com/watch?v=TyTE0OaB4oM

I made a Crytex such as the one from Da Vinci Code, out of wood. This time I used aluminum as well as a metal lathe to produce parts that would have otherwise been too fragile for a customer.
Ebenisterieeloise.com

One of my favorite rare-to-upload stuff - channels. She likes a type of classical music that resonates with me, and I like the way she composes the content, music, and voiceover, combined with clever approaches to problem solving and projects.

 

This is a 2012 Lazer Helium cycling helmet. They came with this silicone gel pad. I had one of these and loved it. Lazer does not make/sell these any more after they were bought out by Shimano-America.

These pads were odd in how they were packaged originally and had no form of branding, hinting that they may have been sourced from some other industry or application. Search engines are garbage when I try to find the abstract application keyword for wherever these originated from due to advertising disinformation obliterating anything remotely useful. I imagine these may come from something like surgeons to prevent sweat contamination or for very hot environments like mines or foundry work. Does anyone know of applications where they have seen a pad like this sold or used?

 

The info wore off the grip and I do not recall what it was. I think it was a German brand. These have been one of my favorite tools for a decade. The jaws are much more narrow than what is typical for side cutters and these handle like a surgeon's scalpel. Best of all, they can be sharpened many many times. Unfortunately, these are getting close to end of life from all of my sharpening and pivot pin wear. I want to get another set, but I have never been able to figure out the brand to find them again. They were given to me by a tech for a computerized Guru bicycle fit machine we had installed in one of our bike shops in 2012.

 

The magnet is around an order of magnitude more powerful on the coil side versus the back, so must be Eddie/Maxwell magic mathsticism of some wizard variety. Are these style drivers typically rare earth magnets? The sticking power feels like a rare earth magnet, but I don't know that factually is the case. Perhaps the flux is unintuitive when guided well.

Is the port shape intended to increase the Reynolds coefficient... (Is that even a valid question at this limited displacement volume? Like, I don't even know how, or if, this falls between laminar and turbulent regimes, or if such a system should be modeled more like a spring and damper or something like that.) Do you think the little square volume in the lower left is intentional or a byproduct? Does this port design have a niche name specific to the zigzag?

 

You can see the outside on the edge of the top speaker (bottom-right corner). The wood is thin, maybe 2mm, and glue applied likely by a machine, yet the slot length looks like it was intended for tuning frequency response. But why wood, and only for this one side of the one slot in an otherwise plastic housing?

 

It is more flexible in tight spaces without collapsing. The color and texture remind me of RTV gasket making silicone in automotive applications, but these (very old) tubes do not have any hint of the pungent oder of RTV gasket maker, or anything else for that matter.

I'm looking for a hose that is more flexible than typical rubber (like automotive) and PVC (gardening/aquariums) hose in a 1/4in or 6mm ID for ethylene glycol at pressures between 1 & 2 bar and at 30-100 C. I need to turn around a 50mm radius reliably with flexibility and without substantial (~15%+) constriction... If any experts are around – TIA

 

Don't be a vote connoisseur here please. Redefine how you think about voting and participating.

Do you miss your communities from elsewhere. Well guess what, you are that core community now. If you want it back, the only thing holding you back is you. Don't wait on someone else to start posting. You don't need to worry about the perfect polished quality of your content or if it has been done before elsewhere. The current bar is, umm, poorly defined. No one is judging you. Call it practice. EVERY time you see something interesting, get in the habit of posting it please. Maybe go out of your way to grab a reference or two and post them.

Along these lines, think of how unsure and uncomfortable this may seem to most of us former lurker connoisseurs. You can play hard and thick skinned all you want, but you know exactly what post or comment you posted elsewhere that got the most votes or interaction. Why? Because it matters to you. So upvote everything you can. It matters to someone else too. Don't upvote just for the value or interest you have in the content. Do it just to say "hey, thanks for making the effort to participate and make this place a few lines longer." Please rethink how you handle voting, at least for now, think of a down vote as FU for participating, no votes as I wish you weren't here. We are all likely accustomed to a lot more interaction and validation in our own little niches. This is really an underpinning value of social media, we are here to engage with people, so tell people who are new and unsure about a new and different place, "hey, thanks for participating." You may not know or really appreciate their interests, but you can help us grow a core that can evolve into your favorite niches as the community grows. You are the core community. We can all make it grow if we make it a place people want to be.