Jump to content

Spotty

Senior Moderator
  • Posts

    12,574
  • Joined

Posts posted by Spotty

  1. 21 minutes ago, wanderingfool2 said:

    Can someone who actually saw examples of this clarify, was Twitter modifying the href and/or the text? i.e. <a href="texta">textb</a> [is it texta, the href or textb that was modified]

    textb

    The text in tweets was modified but the URL was not. This meant if you posted a link to netflitwitter.com it would show the link as netflix.com but if you clicked the link it would go to netflitwitter.com

    For example: netflix.com

     

    Quote

    Security reporter Brian Krebs called the move "a gift to phishers" in an article yesterday. It was a phishing risk because scammers could register a domain name like "netflitwitter.com," which would appear as "netflix.com" in posts on X, but clicking the link would take a user to netflitwitter.com.

     

     

    The reason I suspect they didn't change the URL as well is because x.com currently just redirects to twitter.com anyway. There's no benefit to changing the URL to x.com since it would just redirect back to twitter.com. Twitter just wanted it to display in the app as x.com but actually direct to twitter.com

  2. 1 hour ago, darknessblade said:

    The problem with Single Letter URL's is also that if you have other sites that start with said letter you might accidentally visit one of those due to the auto-complete feature browsers have

    Why would that problem be unique to single letter URLs? If you type "x.com" in the URL bar it will take you to x.com. The only problem would be if you type "x" and then choose one of the suggested URLs - but if you end up somewhere you did not intend then that's the users fault for relying on the suggested URLs and selecting the wrong suggested URL. That's not a problem that is unique to single letter URLs though, or even typing just a single letter in to the browser bar and letting the browser do the rest of the work. If you type "linu" and then let it autocomplete (choose one of the suggested URLs) then you might end up at linustechtips.com, or you might end up at linusmediagroup.com, maybe linux.org, or possibly something completely different depending on your browsing history.

  3. Der8auer has also posted a video weighing in on the EK stuff.

     

     

    @FlyingPotato_is_taken Please update your post to comply with the Tech News Posting Guidelines. Posting a link to the source is not a quote. You need to include actual quotes from the source.

    • Your thread should also include quotes from the cited source(s). While you shouldn't just copy the entire article, your quote should give the reader a summary of the article in a way that gives the key details, but also leaves room for them to read the full article on the linked website. Please use quote tags to show that you have copied this content from another site.
  4. 12 minutes ago, gt710 said:

    click the one in the red box in the photo

    i fill out my first epic games email my fortnite name ect but when im ready to click done its going to send an email to hackers email

    It sends the email to the new email address you provide.

     

    Quote

    Please provide the new email address for your account. Your new email address will receive a code which you must enter on the next step. We will also use this email to reply to your request later.

     

  5. Can you describe what the actual performance issues are?

    Gaming? If so, what game(s)? What resolution and settings are you playing on? What fps are you receiving on the 4070? How does it compare to the 2070S?

     

    If you swap the card back to the 2070S does performance improve? 

     

    It can be a good idea to enable an on screen performance display or logging while checking this to help diagnose the issue. MSI afterburner has an OSD built in that will display things like CPU, GPU, memory usage, temperatures, etc. 

  6. 20 minutes ago, viejosabio said:

    Hey guys! First time in the forum... someone can comment about this link i found? 
    I was searching "Password manager LTT" to find some good recomendations in the forum or reddit but i found this:
    See imagen attached

    Just some garbage website writing fake articles putting popular key words on the page to trick people in to visiting the site.

  7. 1 minute ago, scottox said:

    I noticed that in the PSU package there's the cable that you can see in the photo. Should I attacht that instead directly from the PSU to the GPU?

    Yes. You only need to use the adapter cable that goes to 3 PCIe cables if your power supply does not have a 12VHPWR cable. Since your power supply has the 12VHPWR cable you can just use that instead of the adapter cable and PCIe cables.

  8. The 4k versions will typically have a higher bitrate and should provide better visual quality even when displayed on a lower resolution monitor.

     

    Here's an example of the most recent LTT video at 1080p and 4k displayed on the same screen with the same viewing window (2236x1118).

    There's some noticeable difference around the face and hair. The eyebrows, cheeks, nose, and hair look a little smudgey and less detailed on 1080p compared to 4k.

    Spoiler

    Click images to expand to full size.

     

    image.png

    image.png

     


    image.png

     

  9. Quote

    Per the linked story, social security numbers and dates of birth exist on most rows of the data in encrypted format, but two supplemental files expose these in plain text. Taken at face value, it looks like whoever snagged this data also obtained the private encryption key and simply decrypted the vast bulk (but not all of) the protected values.

    https://www.troyhunt.com/inside-the-massive-alleged-att-data-breach/

    Oof. At least they encrypted it, I guess?

     

    Also looks like - for the birth dates at least - the encrypted data wasn't salted. The dataset has birth dates in an encrypted state. It includes a separate file (rainbow table) for birthdays which just includes every possible birth date combination and its encrypted value. It's possible to compare the encrypted value from the dataset to the table of birth dates to get the true value.

    image.png

     

    I'm actually surprised that birth dates were encrypted at all.

     

    30 minutes ago, TVwazhere said:

    While the data is speculated to be from 2021, it is unknown how far back the data extends, so customers who switched form AT&T back in 2018 (Hi, hello, its me) could still be affected.

    2021 was when an attempt was made to sell data stolen from AT&T. Apparently this data has been confirmed by AT&T to be from 2019 and include data on current and former customers from 2019 and prior.

     

    If it was 2019 then the attacker would have generated every possible birth date combination since 1900 (1900 - 2019 = 119 years).

    I wonder if that is also the same for the SSNs, since that also includes a separate table for decrypting the values. If SSNs weren't salted and they had the encryption key they could have just generated a table of every possible social security number and their encrypted value.

  10. It's stated on the store page that the images are a digital mock up.

    Quote

    THIS ITEM IS LISTED AS PRE-SALE. ALL SHIRTS WILL BE PRINTED FOLLOWING PURCHASE.

    PLEASE NOTE, THIS ITEM WILL ONLY BE AVAILABLE UNTIL SATURDAY, APRIL 6, 2024.

    ALL ITEMS WILL BE SHIPPED TOGETHER - IF YOU ORDER MORE ITEMS THAN JUST THIS SHIRT, THEY WILL ALL SHIP ONCE YOUR SHIRT IS READY.

    ALL ORDERS SHOULD SHIP BY APRIL 26, 2024.

    Image shown is a digital reference mock-up - we always aim for 100% accuracy in our final prints, but please understand that digital mock-ups do not always provide a perfect reference for physical prints.

     

    For limited edition t-shirt prints they will do a digital mock up of the design and only print the t-shirts after all of the orders have been placed. Printing the shirts after selling them allows them to produce the limited edition shirts in smaller quantities, in a single production run, and with minimal excess inventory. It also allows for a faster turnaround from design -> sale which is usually essential for their limited edition runs to catch the demand while whatever topic is still relevant (in this case April Fools).

    They've done this for their previous limited edition shirts such as the Gone Phishin (LTT hack) shirt and more recently the Tax Write Off shirt. Digital mock ups allows them to quickly design a shirt and make it available for sale, sometimes within a day, whereas designing a shirt and sending it off to the printer and scheduling it in to be printed, printing samples, receiving the samples, and doing modelling shoots could take weeks to organise by which time they've missed the hype. There probably wouldn't be as much demand for an April Fools shirt sold in June.

     

    1 minute ago, helgehelge123 said:

    To be fair though, I would expect them got get samples of everything after the dual bottom-we didn't check the features misshap. And It's still different blends. Don't they have sample picture of each blend?

    I believe they're printing the shirts on their standard LTT shirt. If you've purchased any of LTT's shirts recently it should be the same blend. You could also view photos for other shirts, though I'm not sure how much information you could get about the blend from a photo.

  11. 1 minute ago, vincentv said:

    I have a concern regarding Vessi, though not directly related to the brand itself.

    Vessi isn't currently exporting to Europe. However, when I search for Vessi shoes in Germany or the Netherlands using Google, I come across websites like https://www.vessiinederland.com/ that seem to be copying the original Vessi website.

    These sites are offering unreasonable discounts on everything, and although I haven't ordered from them myself, I've found complaints about these sites online.

    Perhaps it could be highlighted on the WAN Show, especially when Vessi is sponsoring the show, that such websites exist, and European fans are unable to order Vessi shoes as things stand.

    These are scam websites. They have no affiliation to Vessi. Only purchase from vessi.com

     

    If they do not ship to your country reach out to the customer support on the official site https://vessi.com/pages/contact and ask if there are any authorised sellers. As far as I know they only sell within North America. They also have a list of authorised retailers (NA only): https://vessi.com/pages/retailers

    If Vessi does not sell in Europe then any website claiming to be Vessi selling in those regions is a scam.

     

    I have seen several complaints regarding scam websites impersonating Vessi. For whatever reason the Vessi brand seems like a popular target for scammers. Likely because they're a brand that is heavily promoted on social media and by influencers and likely also because they aren't available in all regions creating demand for the product in regions they do not ship to that the scammers can market to.
    Here's an older post on the forum from somebody who was scammed by one of these websites. Instead of receiving shoes they received a cheap hat. It's not the only case of scammers impersonating Vessi I've seen though.
    https://linustechtips.com/topic/1428939-lmg-sponsor-complaints/?do=findComment&comment=15996291

     

    There's only so much LMG (and Vessi) can do to stop scammers impersonating the brand, but like you suggested I think it would be worthwhile calling it out and mentioning to only buy from the official store.

  12. 1 hour ago, BlueChinchillaEatingDorito said:

    Part of me still wishes they did more than just the comic sans. Like change the banner, title, or favicon to an inside gag. 

    Recent budget cuts from LMG meant that we could no longer afford the license for the font pack we were previously using. Comic Sans is the best free alternative.

     

    Spoiler

    Since April Fools and Easter were so close together this year we decided to hide the April Fools gag as an Easter egg for people to find. I don't think anybody has found it yet.

     

  13. 2 minutes ago, Godlygamer23 said:

    So I did put my email into https://haveibeenpwned.com and found "demo.zeeroq.com" came up - date of occurrence is unknown, but this data breach apparently goes back to January 2024, per my screenshot, and as you mentioned, the data may have been stolen already and that was simply when it was detected.

    Yeah, it was re-leaked in the leak-lookup breach that occurred in January 2024.

    https://cybernews.com/security/billions-passwords-credentials-leaked-mother-of-all-breaches/

     

    The demo.zeeroq paste was detected July 2020. Leak-lookup entered it in to their database in August 2022. Leak-lookup was hacked in January 2024.

    The data leaked on zeeroq in July 2020 is a collection of data stolen from other breaches. Your data was originally stolen from an unknown website some time prior to July 2020.

    Credit Karma was unaware of the demo.zeeroq paste from July 2020 despite it being a known and documented paste which had been indexed by haveibeenpwned (unknown when) and leak-lookup (August 2022). Credit Karma is only seeing it for the first time from the January 2024 leak-lookup breach when the same data was exposed again.

×