None

Generated by TLDR This:

Days after Russia launched a full-scale invasion of Ukraine in February, Western states, led by the U.S. and European Union, levied vast sanctions on the Russian economy, hoping to drive Moscow into an economic crisis that would prompt a military retreat.

One possible scenario is that Russian miners leverage the country’s plentiful energy reserves to mine bitcoin (BTC), then use unhosted wallets to move those bitcoins through a series of shady crypto transactions – likely involving chain-hopping, tumblers and peer-to-peer (P2P) marketplaces – to convert them into U.S. dollars to pay for goods.

Moscow has heavily promoted SPFS to key trade partners that are also Western allies, such as India, Israel and the United Arab Emirates.

In fact, in 2019, after a FinCEN staffer leaked 2,100 SARs, 400 journ*lists needed 16 months to examine them.

This brings us to the second reason, which is that the blockchain’s transaction data is free of errors and publicly accessible.

That his attempts to circumvent western sanctions have yet to incorporate crypto speaks volumes about its usefulness as a money laundering tool.

None
18

I have mass uploaded pirated comics to the internet archive and they were all approved to be in the main comics section as “public domain” :marseysipping::marseysipping::marseylaugh::marseypirate::marseyspiderman:

None

Orange Site

Generated using TLDR This:

So there’s a new popular AI image generation tool named Stable Diffusion.

Years later, a gag in the straight-to-Disney+ movie Chip N’ Dale: Rescue Rangers reintroduced this design as a gag, officially called Ugly Sonic.

a portrait of Sonic the Hedgehog , via DALL-E 2 Stable Diffusion does a tad better, capturing Sonic with a variety of styles and eras.

a ((((hyperrealistic portrait)))) of [] in the style of and the style of , trending on artstation , via Stable Diffusion Lastly, Stable Diffusion experts on /r/StableDiffusion have gotten prompt engineering down to a science, with massive prompts even longer than the ones above.

Although a given textual inversion concept may not work with future versions of Stable Diffusions or other diffusion models using the CLIP encoder, it’s a good demo of how well trained concepts can be used to get more specific outputs, even if the concept isn’t in the original dataset the model was trained upon.

There were a few AI-generated images of Ugly Sonic with his human teeth, but I opted not to include them because I have standards, believe it or not.

None

Generated by TLDR This:

When a TikTok user searches the social media app for information on top news stories, ranging from Covid-19 vaccines to school shootings, nearly 20% of the videos presented as search results contain misinformation, according to a research report published Wednesday.

For example, a search for the question "Was the 2020 election stolen?"

NewsGuard's report was released amid bipartisan concerns in Washington about the possibility that US user data could find its way to the Chinese government and be used to undermine US interests due to a national security law in that country that compels companies located there to cooperate with data requests.

TikTok does not operate in China, Pappas said, though it does have an office in China.

But this takes it so many levels further."

None
None

r/technews thread

r/smugcoin thread

r/ethereum thread

r/cryptocurrency thread

Generated by TLDR This:

Ethereum, the second largest cryptocurrency in the world, continued to plunge in price over the weekend following the network’s highly publicized technical change known as ‘the Merge’ last Thursday as well as comments from the head of the Securities and Exchange Commission that ether might need to be a treated as a security.

Ethereum is currently trading at roughly $1,290, down over 11% from 24 hours ago, while bitcoin, the most popular crypto in the world, is also down 8% to just $18,420.

Cardano is down 80% from a year ago while Solana is down 78% from a year earlier.

Either they’re extremely lucky or this entire thing is a Ponzi Scheme.

Everything is down not just on the day but over the past week too.

None

Thoughts? Discuss.

https://marsey.club/

None

Archive link

Generated by TLDR This:

The UK’s financial regulator has warned consumers against dealing with FTX, the cryptocurrency exchange run by billionaire Sam Bankman-Fried, in the latest clash between British authorities and offshore digital asset companies.

“This firm is not authorised by us and is targeting people in the UK,” the statement said.

FTX did not immediately respond to a request for comment.

Crypto exchange and wallet providers have to register with the FCA for anti-money laundering supervision if their digital asset activity is “carried on by way of business in the UK”, according to an FCA guide.

FTX’s European division this month announced that Cyprus’s financial regulator had granted it an investment firm licence, as the crypto firm pushes to expand across the continent.

None

:#marseyworried:


Generated by TLDR This:

A week ago, we received an email that every website owner dreads - a notification of a DMCA takedown request that has resulted in our website being removed from Google Search.

Editing a video in Kapwing We're a fully featured platform that allows creators to resize content, add text, edit video clips within a timeline, and much, much more - all within an online interface that doesn't require downloading or installing any software.

The paste a link feature on Kapwing A creator can paste a link to a piece of content that they own, and then start editing the video within our editor.

In addition, we maintain an email address - [email protected] - that anyone can reach out to if they believe that someone misused Kapwing’s cowtools and violated our terms of service, and we have a policy of taking down any content from our cloud servers if we receive information that it violates copyright.

Youtube Video Downloaders that are allowed to rank on Google The hardest part of this process is that we don't know exactly why we have been taken down, or what we can do to be restored.

In startups, progress is measured in days and weeks, not years, and for creators to be unable to find us through Google Search for the last week has been heartbreaking for our team, who have always worked hard to build a reliable and ethical product.

None

Imp tier post in the substack article.

Generated by TLDR This:

There’s a phrase that’s been living inside my head lately, a brain parasite, some burrowing larva covered in thorns and barbs of words.

People will cheerfully admit that the internet has destroyed their attention spans, but what it’s really done away with is your ability to think.

Until 2020, the average daily time spent on the app kept rising in line with its growing user base; since then the number of users has kept growing, but the thing is capturing less and less of their lives.

They’ll pretend that by spending all day on the computer they’re actually fighting fascism, or standing up for women’s s*x-based rights, as if the entire terrain of combat wasn’t provided by a nightmare head-chopping theocratic state.

Yes, the future is always capable of getting worse.

A sword is against its trends and fashions and against all the posturers in its midst, and they will become out of touch.

None

r/smugcoin thread

None

https://archived.moe/biz/catalog


:marseyvibing: The Democratic Party will collapse by 2030. :marseyvibing:

None

Generated by TLDR This:

Jefferies Equity Research Analyst Brent Thill assesses Adobe's deal to acquire Figma amid its third-quarter revenue beat, while looking at investor responses, the climate of the tech sector, and Amazon's NFL streaming deal.

Video Transcript [AUDIO LOGO] SEANA SMITH: Adobe shares taking a very hard hit.

There's been a couple of head-scratchers in the past, but nothing like this.

Were there any weaknesses that you think that Figma can really help strengthen Adobe with?

So this is a head-scratcher for a lot of our clients, and you're seeing it, as a result, on the stock price.

None

Yes there's the win98 theme (cool!), but why isn't there a 90's macintosh theme for rdrama? Hacker News has this very cool theme and we don't? :marseypathetic2:

Orange Site

Orange Site w/theme

GitHub

None

Orange Site

None

:marseythumbsup:

Generated by TLDR This:

Written by Nihal Krishan Early figures indicate that new open-source chips Google is working to produce in partnership with NIST could be “hundreds of times” cheaper for researchers and manufacturers, according to Will Grannis.

NIST research physicist Brian Hoskins, who also spoke with FedScoop, said that to his knowledge, the SkyWater-Google partnership at present is the only domestic provider of an open-source process design kit for manufacturing semiconductor wafers.

I think the important thing to realize is that members of the academic community have been asking for better access to the semiconductor supply chain for a while and we are listening to their needs and trying to respond to them,” Hoskins said.

“It would be very difficult to develop new memory technology if you can’t actually access, say an intermediate step where you maybe have the ability to prototype at the millions level, before moving on to a final product,” said Hoskins.

The gap between academic research and the commercialization of technology.

Grannis is the founder and leader of Google’s CTO Office and a seven-year veteran of the company.

None
21
JavaScript strikes again :marseydisgust:
None
Reported by:
  • 1 : I don't get out of bed for anything less than third circuit
None

Orange site :marseyill: : https://news.ycombinator.com/item?id=32886795

None

Generated by TLDR This:

The people of Louisiana’s East Carroll parish had been fighting for decent broadband for more than two years by the time their governor, John Bel Edwards, arrived in town in July to announce his plan to make their wishes come true.

But shortly after Edwards announced the grant to Conexon, Sparklight (formerly Cable One) mounted a protest to the state broadband authority.

A spokesperson for the Louisiana Division of Administration, which oversees the GUMBO grant program dedicated to helping underserved areas get broadband service, said the division will review Sparklight’s protest and Conexon’s response before making a decision.

Now, thanks to a massive amount of broadband funding set to flow into states under the Bipartisan Infrastructure Law, these fights could become even more frequent — and even more fierce. “

Waiting game But these eleventh-hour objections aren’t permitted in every state, and experts say states and the federal government could learn a lot from places that have instituted guardrails to discourage last-minute or frivolous protests.

The way it’s structured, we had to wait,” Chambers said. “

None

Generated by TLDR This:

China's GPU market is heating up with several domestic chipmakers either developing or offering their products in offices, and industrial applications & for mainstream client computing needs.

While there is some hope for Chinese GPUs in the general-purpose computing and HPC segment with the unveiling of the Birentech BR100 GPU, the client side sits years behind in performance with the best graphics cards only offering GTX 1050 or 1050 Ti level of horsepower.

They also have a second flagship GPU in R&D that will be mass-produced around 2024.

However, both of these GPUs are once again dedicated to AI.

That's where Muxi's next-generation gaming GPU comes in.

The GPU is going to feature all the essential graphics rendering techniques and will support modern APIs.

None

I have to find a strategy to fix this development team without managing them directly. Here is an overview:

  • this code generates more than 20 million dollars a year of revenue

  • it runs on PHP

  • it has been developed for 12 years directly on production with no source control ( hello index-new_2021-test-john_v2.php )

  • it doesn't use composer or any dependency management. It's all require_once.

  • it doesn't use any framework

  • the routing is managed exclusively as rewrites in NGInX ( the NGInX config is around 10,000 lines )

  • no code has ever been deleted. Things are just added . I gather the reason for that is because it was developed on production directly and deleting things is too risky.

  • the database structure is the same mess, no migrations, etc... When adding a column, because of the volume of data, they add a new table with a join.

  • JS and CSS is the same. Multiple versions of jQuery fighting each other depending on which page you are or even on the same page.

  • no MVC pattern of course, or whatever pattern. No templating library. It's PHP 2003 style.

  • In many places I see controllers like files making curl requests to its own rest API (via domain name, not localhost) doing oauth authorizations, etc... Just to get the menu items or list of products...

  • no caching ( but there is memcached but only used for sessions ...)

  • team is 3 people, quite junior. One backend, one front, one iOS/android. Resistance to change is huge.

  • productivity is abysmal which is understandable. The mess is just too huge to be able to build anything.

This business unit has a pretty aggressive roadmap as management and HQ has no real understanding of these blockers. And post COVID, budget is really tight.

I know a full rewrite is necessary, but how to balance it?

None

Orange site: https://news.ycombinator.com/item?id=32880558

Extended spellcheck features in Google Chrome and Microsoft Edge web browsers transmit form data, including personally identifiable information (PII) and in some cases, passwords, to Google and Microsoft respectively.

While this may be a known and intended feature of these web browsers, it does raise concerns about what happens to the data after transmission and how safe the practice might be, particularly when it comes to password fields.

Both Chrome and Edge ship with basic spellcheckers enabled. But, features like Chrome's Enhanced Spellcheck or Microsoft Editor when manually enabled by the user, exhibit this potential privacy risk.

Spell-jacking: That's your spellcheck sending PII to Big Tech

When using major web browsers like Chrome and Edge, your form data is transmitted to Google and Microsoft, respectively, should enhanced spellcheck features be enabled.

Depending on the website you visit, the form data may itself include PII—including but not limited to Social Security Numbers (SSNs)/Social Insurance Numbers (SINs), name, address, email, date of birth (DOB), contact information, bank and payment information, and so on.

Josh Summitt, co-founder & CTO of JavaScript security firm otto-js discovered this issue while testing his company's script behaviors detection.

In cases where Chrome Enhanced Spellcheck or Edge's Microsoft Editor (spellchecker) were enabled, "basically anything" entered in form fields of these browsers was transmitted to Google and Microsoft.

"Furthermore, if you click on 'show password,' the enhanced spellcheck even sends your password, essentially Spell-Jacking your data," explains otto-js in a blog post.

"Some of the largest websites in the world have exposure to sending Google and Microsoft sensitive user PII, including username, email, and passwords, when users are logging in or filling out forms. An even more significant concern for companies is the exposure this presents to the company's enterprise credentials to internal assets like databases and cloud infrastructure."

https://i.rdrama.net/images/1684135172360782.webp

Alibaba login form fields, with 'show password' enabled (otto-js)

https://i.rdrama.net/images/16841351729975235.webp

Chrome's enhanced spellchecker transmits password to Google (otto-js)

Users may often rely on the "show password" option on sites where copying-pasting passwords is not allowed, for example, or when they suspect they've mistyped it.

To demonstrate, otto-js shared the example of a user entering credentials on Alibaba' Cloud platform in the Chrome web browser—although any website can be used for this demonstration.

With enhanced spellcheck enabled, and assuming the user tapped "show password" feature, form fields including username and password are transmitted to Google at http://googleapis.com.

A video demonstration has also been shared by the company:

BleepingComputer also observed credentials being transmitted to Google in our tests using Chrome to visit major sites like:

  • CNN—both username and password when using 'show password'

  • http://Facebook.com—both username and password when using 'show password'

  • http://SSA.gov (Social Security Login)—username field only

  • Bank of America—username field only

  • Verizon—username field only

A simple HTML solution: 'spellcheck=false'

Although the transmission of form fields is happening securely over HTTPS, it may not be imminently clear as to what happens to user data once it reaches the third-party, in this example, Google's server.

"The Enhanced spell check feature requires an opt-in from the user," a Google spokesperson confirmed to BleepingComputer. Note, that this is in contrast to the basic spellchecker that is enabled in Chrome by default and does not transmit data to Google.

To review if Enhanced spell check is enabled in your Chrome browser, copy-paste the following link in your address bar. You can then choose to turn it on or off:

chrome://settings/?search=Enhanced+Spell+Check

https://i.rdrama.net/images/1684135173502743.webp

Enhanced spell check setting in Chrome needs to be opted-in (BleepingComputer)

As evident from the screenshot, the feature's description explicitly states that with Enhanced spell check enabled, "text that you type in the browser is sent to Google."

"The text typed by the user may be sensitive personal information and Google does not attach it to any user identity and only processes it on the server temporarily. To further ensure user privacy, we will be working to exclude passwords proactively from spell check," continued Google in its statement shared with us.

"We appreciate the collaboration with the security community, and we are always looking for ways to better protect user privacy and sensitive information."

As for Edge, Microsoft Editor Spelling & Grammar Checker is a browser addon that needs to be explicitly installed for this behavior to take place.

BleepingComputer reached out to Microsoft well in advance prior to publishing. We were told that the matter was being looked into but we are yet to hear back.

otto-js dubbed the attack vector "Spell-jacking" and expressed concern for users of cloud services like Office 365, Alibaba Cloud, Google Cloud - Secret Manager, Amazon AWS - Secrets Manager, and LastPass.

Reacting to otto-js' report, both AWS and LastPass mitigated the issue. In LastPass' case, the remedy was reached by adding a simple HTML attribute spellcheck="false" to the password field:

https://i.rdrama.net/images/16841351740933118.webp

LastPass "password" field now includes spellcheck=false HTML attribute (BleepingComputer)

The 'spellcheck' HTML attribute when left out from form text input fields is usually assumed by web browsers be true by default. An input field with 'spellcheck' explicitly set to false will not be processed through a web browser's spellchecker.

"Companies can mitigate the risk of sharing their customers' PII - by adding 'spellcheck=false' to all input fields, though this could create problems for users," explains otto-js referring to the fact, users will now no longer be able to run their entered text though spellchecker.

"Alternatively, you could add it to just the form fields with sensitive data. Companies can also remove the ability to 'show password.' That won't prevent spell-jacking, but it will prevent user passwords from being sent."

Ironically enough, we observed Twitter's login form, which comes with the "show password" option, has the password field's "spellcheck" HTML attribute explicitly set to true:

https://i.rdrama.net/images/16841351749178247.webp

Twitter password field has 'show password' and spellcheck set to true (BleepingComputer)

As an added safeguard, Chrome and Edge users can turn off Enhanced Spell Check (by following the aforementioned steps) or remove the Microsoft Editor add-on from Edge until both companies have revised extended spellcheckers to exclude processing of sensitive fields, like passwords.

https://www.bleepingcomputer.com/news/security/google-microsoft-can-get-your-passwords-via-web-browsers-spellcheck/

None
None
Link copied to clipboard
Action successful!
Error, please refresh the page and try again.