gnuhaut

joined 1 year ago
[–] [email protected] 4 points 4 days ago (1 children)

I edited my comment on your other reply and by my estimation, calculating every SHA256 of all MACs ever potentially issued takes less than 89 seconds on an RTX 3090.

I also think MACs are (or should be considered) personally identifiable information, since there is potentially a paper trail back to the person who bought it. Plus MACs are not secret information, it's broadcast on the LAN and for wireless modules over the air in the immediate vicinity (though some systems will randomize wireless MACs for privacy reasons). Privacy-unfriendly software has been known to collect MACs (even from other devices on the network and in the vicinity), so there are already databases connecting MAC addresses with other data.

[–] [email protected] 10 points 4 days ago* (last edited 4 days ago) (1 children)

You don't need this to count unique users. You could just assign a random number on install or whatever. Or even more simply, just run the thing once per month, should be accurate enough. Do they expect the software to just randomly spam duplicate reports? Don't write it that way.

Best case they don't care about collecting minimal data and don't understand that hashed MACs are easily reversible. So incompetent fools with no sensitivity to privacy.

Maybe this should be Manjaro's tagline: Not purposely malicious, just grossly negligent and ignorant.

[–] [email protected] 10 points 4 days ago (1 children)

Debian popcon is opt-in, first of all.

https://popcon.debian.org/FAQ

Q) What information is reported by popularity-contest ?

A) popularity-contest reports the system vendor [1], the system architecture you use, the version of popularity-contest you use and the list of packages installed on your system. For each package, popularity-contest looks at the most recently used (based on atime) files, and reports the filename, its last access time (atime) and last change time (ctime). However, some files are not considered, because they have unreliable atime. For privacy reasons, the times are truncated to multiple of twelve hours.

[1] i.e. the dpkg Vendor field, see dpkg-vendor(1).

So no fucking MAC addresses and machine-ids and harddrive serial numbers and stuff.

They only want package statistics, the point being to have statistics about the popularity of packages, mainly so they can be prioritized for the CD/DVD isos. You know, information that actually has a use, not hardware identifiers that can only be used for tracking purposes.

[–] [email protected] 10 points 4 days ago* (last edited 4 days ago)

That's not anonymous, that's pseudonymous.

What is the point of this? The machine-id already looks to be some unique random number, so you're calculating another unique random-looking number from that, might as well use the original number.

You can't glean any useful information from a unique random-looking number that would help with developing Manjaro. You can't calculate any statistics from that. The only use is tracking.

Edit: And as mentioned in my other comment, reversing the MAC SHA by brute force is trivial, so that one at least (and possibly the other hardware serial numbers they collect) shouldn't even be considered pseudonymous.

[–] [email protected] 15 points 4 days ago* (last edited 4 days ago) (3 children)

MAC addresses are 48 bit, and half of that is just the manufacturer. So 24 bits really, and those bits aren't random, I think manufacturers just assign these based on some scheme, like a serial number. Point is you could easily reverse the SHA by brute force.

You can't calculate any useful statistic from a hash so literally the only use this would have is some sort of tracking.


Edit: I just looked up some data and I found someone using hashcat on an RTX 3090, which looks like it can do almost 10000 million SHA256 hashes per second of salted passwords (which are longer than 48 bit MACs, so MACs should be faster). 2²⁴ is 16.8 million, so it'll take about 1.7 ms per vendor. I found a database with (all?) 53011 vendor ids:

>>> 2**24 * 53011 / 10000 / 1000 / 1000
88.93769973759998

Yup, 89 seconds. You can calculate the SHA256 of every single MAC ever potentially issued in 89 seconds on a bog-standard 3090.

[–] [email protected] 5 points 1 week ago

Ich dachte eher an Holz (und Flüssigkeit) auf Edelstahl, was sehr gut abschabt. Aber ja Teflon ist auch ein Problem bei Metallutensilien.

[–] [email protected] 9 points 1 week ago (3 children)

Ist aber wurst wenn sich's verfärbt? Scheint ja hygienisch trotzdem okay zu sein, weil Holz antibakteriell wirkt. Und Holzlöffel sind voll gut zum abschaben von Bodensatz beim ablöschen, das geht mit Plastik und Metall nicht gescheit. Je nach Situation kann aber Metall auch besser sein.

[–] [email protected] 4 points 1 week ago

Shoving everything into the task bar doesn't strike me as more orderly. Less so really.

[–] [email protected] 4 points 1 week ago (3 children)

I'm not a Gnome user but I stopped minimizing my windows years ago. Don't need that if you (a) don't have icons on your desktop and (b) move your windows over to another workspace when stuff gets crowded.

[–] [email protected] 12 points 2 weeks ago (1 children)

Yeah better discriminate based on nationality /s. But why stop at that? Poor people are too easily bribed can't have them. I hear the CIA recruits from top US universities, can't trust those college grads either. Anyone belonging to some homophobic church or religious group? Better not what if they're closeted gay and get blackmailed? Anyone in a monogamous relationship should be excluded for the same reason, if you think about it. *tips forehead*

[–] [email protected] 0 points 2 weeks ago

Racists and Xenophobes will try to stop global collaboration,

Yes! Go on...

real conflict that matters will always be the smart vs the lowiq.

Uff... That's some serious brainworms right there. How do you call your worldview? IQ Supremacy?

[–] [email protected] 2 points 2 weeks ago* (last edited 2 weeks ago)

Maybe he's trying to avoid conflict with US government, but he clearly is not trying to avoid conflict with that statement.

 

Am 25.03.2024 wurde unser Konto bei der Berliner Sparkasse mit sofortiger Wirkung gesperrt. In einem Schreiben teilt uns die Sparkasse mit, dass sie diesen Schritt vorsorglich unternommen hat und wir zur Aktualisierung unserer Kundendaten zahlreiche Vereinsunterlagen bis zum 05.04. einreichen sollen. Die Sparkasse ist als Körperschaft des öffentlichen Rechts an das öffentliche Recht gebunden und darf nicht willkürlich Konten sperren ohne es zu begründen, was sie nicht getan hat. Außergewöhnlich ist auch, dass zu den geforderten Unterlagen eine Liste unserer Mitglieder mit vollständigen Namen und Anschriften gehört.

 

On 25 March 2024, our account with the Berliner Sparkasse was frozen with immediate effect. In a letter, the Sparkasse informed us that it had taken this step as a precautionary measure and that we should submit numerous internal documents by 5 April to update our customer data. As a public corporation, the bank is bound by public law and may therefore not arbitrarily freeze accounts without providing an explanation, which it did not. It is also highly unusual that the required documents include a list of our members with their full names and addresses.

 

Angesichts der Angriffspläne auf Rafah muss die militärische und moralische Unterstützung Israels an konkrete Bedingungen geknüpft werden. Kritik allein reicht nicht.

Langsam kommt etwas Realität auch in den deutschen Medien an, was da Israel eigentlich so macht.

Kommentarspalte ist aber übel. Da wird Israel jegliche Verantwortung abgesprochen. Solange sich die Hamas nicht ergibt geht das Morden weiter, und die Hetzer halten das für absolut gerechtfertigt.

 

Palästinensische Quellen melden den Tod eines Mädchens, das mit seinen Verwandten auf der Flucht aus Gaza-Stadt unter Beschuss geraten war. In einem dramatischen Notruf hatte sie zuvor um Rettung gefleht.

 

Giftige PFAS reichern sich in der Umwelt an und belasten die Gesundheit. Nun sollen sie schrittweise verboten und ersetzt werden

 

In ihrem Koalitionsvertrag hatten sich SPD, Grüne und FDP darauf geeinigt, biometrische Erkennung im öffentlichen Raum europarechtlich auszuschließen.

Grüne warnen vor unregulierter KI

Dennoch plädierten inzwischen mehrere Grünen-Politiker dafür, der Verordnung auf EU-Ebene zuzustimmen. So sagte der Bundestagsabgeordnete Tobias Bacherle auf Anfrage von Golem.de: "Statt jetzt den AI Act auszubremsen und aufs Spiel zu setzen, muss die Bundesregierung ihrer Verantwortung nachkommen und sich klar für eine Verabschiedung des AI Act einsetzen. Nach jahrelangen Verhandlungen alles aufzuknöpfen, führt nicht zu einer besseren Verordnung. Es führt lediglich dazu, dass wir bei der dringend notwendigen Regulierung von KI sehr viel Zeit verlieren."

 

Curtailing aid to Ukraine will only prolong the war, Mr Zelensky argues. And it would create risks for the West in its own backyard. There is no way of predicting how the millions of Ukrainian refugees in European countries would react to their country being abandoned. Ukrainians have generally “behaved well” and are “very grateful” to those who sheltered them. They will not forget that generosity. But it would not be a “good story” for Europe if it were to “drive these people into a corner”.

 

Now, the words and figures "with the exception of articles 2-c, 4-c, 5-c, 12-c, 13-c, 14-c, 17-c, 21-c and 22-c" have been removed from the Regulation, i.e. everyone will be recognised as fit under the "controversial" articles:

  • 2-c – clinically treated tuberculosis;
  • 4-c – viral hepatitis with minor functional impairment;
  • 5-c – asymptomatic HIV carrier;
  • 12-c - slowly progressive and non-progressive with minor functional impairment and rare exacerbations of anaemia, blood clotting disorders, purpura, haemorrhagic conditions, other diseases of the blood and haematopoietic organs, and some disorders involving the immune mechanism;
  • 13-c - diseases of the endocrine system with minor functional disorders;
  • 14-c - mild, short-term, painful manifestations of mental disorders;
  • 17-c - neurotic, stress-related and somatoform disorders with moderate or short-term manifestations, with an asthenic state;
  • 21-c – slowly progressive diseases of the central nervous system with minor functional disorders;
  • 22-c – episodic and paroxysmal disorders, except for epilepsy, with minor impairment of organ and system functions.
view more: next ›