Aurix

joined 2 years ago
[–] Aurix@lemmy.world 15 points 2 days ago (1 children)

tl;dr Add-on developer ansh sold out the extension to new owners. Commited updates 1.8.8 to the Mozilla repository, but nothing on GitHub containing the malware. The malware was a custom implementation of the mellowtel scraper mentioned in the arstechnica article. It had the opt-in functionality disabled and other "bugs" which caused excessive bandwidth usage. Please be aware there is no independent verification whether not more possible harm was caused than the mentioned mellowtel scraping.

By jiffyreader, the from the github link provided:

"Hey all,

Sorry for the delay in answering here. I was waiting for the dust to settle a little bit before clearing things up.

I tried to explain the timeline and sequence of actions in the last messages. Many of you want to know the reasons behind them.


I saw that developers were earning a lot from turning their products into proxies for scraping and were being paid by proxy providers like anyIP or brightdata. Usually they pay more for mobile proxies. So I decided to try a similar idea. I saw that Jiffy Reader had already tried with mellowtel but had stopped after a while. I thought I could monetize it by making a custom integration and bought the plugin. I tried the open source version of mellowtel but changed the code in order to make it native (refer to the Single Purpose policy issue above) and removed some of the limits in the library. In the process I introduced bugs and caused issues to a lot of you which triggered the malware report. The reason why these bugs were not immediately clear and I couldn’t solve them is because they showed up based on some specific requests/websites (google search or pdf download, etc.) and device conditions (pdf viewer open/scrolling a tab with videos) which I didn’t have a way to replicate and solve.

As I remarked before, the plugin didn’t steal any cookies/credit cards/password or personal data and you can check the network output logs or any VPN logs to confirm. You are still free to change passwords/auth sessions but JiffyReader didn’t collect or leak any of this personal information.

Ideally, I wanted to keep the product running/improving it and using this forked version for monetization without affecting users negatively. But in my eagerness to have the version accepted by the review team I changed the code to not display the opt-in and out page immediately and that removed a lot of user control. And I think I introduced some bugs (but from an arstechnica article that @concernedcitizen2 has also linked it looks like the original library had some issues on its own, so it could also be due to that).

For GDPR, I haven’t collected any data from this bandwidth sharing monetization (including IPs which I don’t store). The privacy policy on the website refers to google analytics, to the Crisp web chat and to any contact information the user might pass to us. The public pages that were scraped didn’t have to do anything with the websites a user might be visiting. The same goes for Meucci.js which just monitored xhr/ajax requests INSIDE the session-less frame, not outside, so again it didn’t revolve around any user data. You can look at the mellowtel library since I used a lot of that code

Sorry for the issues and concerns I’ve caused with these actions.

I will be committing all changes to this repo and removing all the flawed forked code. I will also send a new version for the same to FireFox, Edge and Chrome again. Going forward, I will always keep the open-source version in sync with the submitted version.

If anyone wants to reach out, you can do at jiffyreader007@gmail.com. I feel like it’s not good to keep this discussion on this repo and I’ve created a separate Discord in the meanwhile: https://discord.gg/cjwS8vmR3R

I’m really sorry for this and having removed a useful plugins that so many people used. Thanks for your understanding."

 

Just received the notificaiton Jiffy Reader was disabled for a TOS breach by Mozilla, but what actually happened? I couldn't find news on it.

[–] Aurix@lemmy.world 10 points 1 month ago

The Deep Fake Detector probably can't keep up anymore with the recent AI advances.

[–] Aurix@lemmy.world 2 points 1 month ago (1 children)

It is a definitional and logical conclusion that a concept cannot tolerate its anathema and inverse.

This is a pretty good rewording removing ambiguity.

As for my experience seeing this point brought up, its usually to silence a voice, and then this logical statement is equaled to the moral reasoning and justification in one, instead of reasoning inside that case how a "removal" would be required.

[–] Aurix@lemmy.world -4 points 1 month ago (2 children)

What if the other party in question is of the opinion they didn't break it, yet the other claims it has been. Who gets to decide it?

[–] Aurix@lemmy.world 3 points 1 month ago (2 children)

What does nuking a potato mean? Unfamiliar with the slang.

[–] Aurix@lemmy.world 1 points 1 month ago

As an individual you can't be expected to do that and there are many good reasons not to do it, as you could suffer from consequences. As part of a society, all of your actions do shape the social environment around you in small ways. But when the interests of you as an individual with those actions of society clash, you do bear the responsibility of what happens in that society. In my opinion this would apply even to those who have worked against unethical actions, because taken for a bigger scope at a nationwide level, it wouldn't be feasible to exclude those from reparations either way. Even if the "good" would get compensated with a lower tax, they will economically feel it either way, as the "bad" around them are still sanctioned. And then the ethical dilemma is what could be considered "good" or "bad" at all.

Now taken this generalized context back to marginalized groups, if everyone would be obligated to be an activist, it would punish those unable to cope with the additional stressors activism could entail. Then, the question is who is actually marginalized and who is not, the rich 1% is a minority, but definitely not in "need". There are people labeling themselves as things which they are not. (Some "leftist queer" folk are more rightwing in their deeds, than actual conservatives.) I also believe those who fight for the rights of those that person itself doesn't belong to, adds nuances, you can quite often see ideological shifts in people depending on their income. Which gives the question on whether a truly fair solution between groups is attainable, and probably an unsolvable optimization problem, so compromises must happen.

Every policy you go for, will eventually have some people discriminated against in some ways or even actively harm them. No matter what your stance on HRT and medical transition is, there will be some people who should not have done it in the first place, or should have to alleviate their gender dissonance. And whatever line you draw in the sand, there will be something wrong with it. Expecting everybody to strictly enforce some kind of policy by activism, is an ethical burden we can't place on an individual, but which we involunatarily bear by its consequence.

[–] Aurix@lemmy.world 1 points 2 months ago

This should be illegal. As a person who was once false flagged manually by network attribution. Of course the anti troll flagging network was itself socially destroyed by time and is frequently cause of scandals while nobody cares for me.

Add certain language patterns and political stances and you have an excellent oppressive tool.

The behavior the study is referring to, is actually result of reddit's algorithms and human psychology. Often the contrarian view of whatever the post is about will automatically float to the top, no matter the topic, opinionated, factual or debunking, nature.

[–] Aurix@lemmy.world 5 points 2 months ago (1 children)

Probably signing up with Bluesky, even if slightly off-topic. The lack of algorithms means the only way to swim up is to post everyday at prime time in the hope to catch some exposure. Because quality posts with high interactions with likes will not bubble up from the crowd.

[–] Aurix@lemmy.world 1 points 3 months ago

Stormblood has structural issues, but none of the fundamentally flawed writing at every single moment of Dawntrail. I hope 8.0 will make me forget this pain.

 
 

Edit: Official Riot confirmation the Asus Xonar audio driver is blocked due to a cheating exploit by user Baconspleet who received following statement by official support: "... the driver is indeed blocked by vanguard as it was reportedly being used as a way to cheat. In this case, I'm afraid the only option to have sound in the game is a hardware upgrade, though that is understandably, not ideal."

https://maxedtech.com/asus-xonar-unified-drivers/comment-page-230/#show-comments

As Valorant players with all kinds of Asus Xonar sound cards have noticed since the 9.x patch series, the support for these devices has been dropped and the game will no longer function acceptably. After roughly half a minute, the entire system, not just the game, loses its audio output. Reddit user /u/travishenrichs has contacted support and received following statement: "In order to protect the competitive integrity and security of our games, some pieces of hardware are not supported with VALORANT and will not function properly with the game. Having said that, this is something being looked into by our QA team, but I can't provide an ETA at this time."

Since this critical bug is known for half-year, is not fixed by 9.10, it is unlikely to be resolved anytime soon as the doubtful support response suggests. I hope software developers avoid situations such as these to avoid forced obsolescence of hardware devices, as these devices do function correctly on Windows 10 and 11.

 

Happened after the newest Valorant update.

 

I want to express my deepest gratitude to the support and development team for adding third party HRTF support and fixing the primary mouse key issue. They listen and care about their customers (but definitely not the wallets, 100€ skin bundle incoming).

15
submitted 2 years ago* (last edited 2 years ago) by Aurix@lemmy.world to c/games@sh.itjust.works
 

Metacritic changed not so long ago their posting format and adopted a microblogging like Twitter with 140 signs stance in that regard. Why was that done? I understand there are different demands between expressing the overall feel towards something in few sentences, but why is even a mid sized review, like many on Steam not welcome anymore? Even 200 words just become a wall of text and sometimes that is needed to express complex feelings.

 

After I found in Ghostblade a fun character for me I had some great time, but the online is so terrible without any ping indicators or blocking. The game design was criticized plenty, and I also don't see it replacing the big titles for me, perhaps for a local evening with friends it is quite good. Shame the online is so bad though for as an alternative game.

 

Gaming communities can be rough, but I can't think of another forum like Steam which is across so many games consistently incredibly toxic towards developers, even if their product is fine with only minor issues and no predatory monetization. They are my least favorite place of conversation.

What would you do to improve the culture around them?

 

Loved it. The visuals are great, the feel is really there, the Arcade mode was joyful and the Story fight was very epic. I touched Tekken as a series only briefly on PSP and it was not at all my cup of tea and later installments didn't interest me. But this one is a winner so far.

53
submitted 2 years ago* (last edited 2 years ago) by Aurix@lemmy.world to c/opensource@lemmy.ml
 

Updated.

I have used Microsoft Office for many years and wanted to see how LibreOffice has come along in the meantime and it does not do as well as I would have hoped for on Windows. There is no included updater tool as in Firefox, so my old version stopped working completely (frozen UI) and the ancient hassle to download .exe files. Not a great start.

The dark mode switch causes buttons to be in the wrong colour looking like a buggy mess until a restart, but even then some of the icons and application colours were not applied correctly until I manually changed them so.

The ribbon view in Calc has its setting burger button on the right and it opens on another screen next to it?

What completely breaks it for me is the broken window resize. The ribbon tab titles are not rescaled and become inconveniently small. I then discovered the the compact grouped view and it made a better initial impression on me. Then I snapped the the window to the left and the UI is just cut off. Manually resizing it horizontally just breaks everything even more until the UI is empty and the rest is moved into the arrow.

The old school UI view meanwhile works and resizes, but it might be the slowest and laggiest UI on resize with goofy stretching I have seen in quite some time.

Also I really think the default theming and the 6 presets are questionable in fashion, but this is the least of its problems.

Wondering what happened to the development of LibreOffice? There are definitive improvements and probably there are even better under the hood changes, but why would such a large project ship such a bad experience? Was the core of the UI never touched the past 15 years? I have to to use an alternative.

EDIT: Resize runs better after forcing Skia Software renderer. Should not have to do that with an up to date AMD driver. Skia/Vulkan was the culprit. Disabling Skia leads to flicker on resize, so even more rendering bugs.

 

I see a temperature map of the sea around Italy reaching above 30 C today. Obviously the sea water hasn't this cozy temperature deep beneath the surface yet, maybe in a few decades, so where is the measurement taken depth wise?

 

One of the reasons I liked to visit the reddit formula1 community is that it had a beautiful overview over the upcoming events and UTC times. Could we have something like that too?

Also I am wondering why the community has multiple threads active at the same time. As in, why the Race discussion thread doesn't start with the actual race or pre-race show?

view more: next ›