[02:12:26] <.ultraraptor> Chat look at this goofy guy [02:12:29] <.ultraraptor> https://cdn.discordapp.com/attachments/615786602454581249/1307528760165273660/Screenshot_20241116-184905.png?ex=673aa28d&is=6739510d&hm=88801ed3aa9997a80969a2fe9c9d5c8b2827c7f80c504ef321b1246ee646ca47& [02:29:57] You do you, bud. Just keep it above board here. [02:49:34] Canuckistan [02:49:44] Trudeaukistan [02:49:49] Trudeausalem [02:50:05] Canac.. whatever [03:08:21] it's not that deep bro a whole week timeout for denying the "existence" of a "Canada" is wild [03:11:11] <.ultraraptor, replying to clockworky> I know, right? [06:25:19] <.guardianx.> Canadia? [11:05:16] i should come up with more esoteric ways to review yaron extensions [11:05:17] copy the files to my ti nspire cas and check out the code using a text viewer from there, with a pen and paper to keep notes [11:40:21] I guess it depends on the server a bit [11:40:46] it would take quite a bit before that became a problem unless you jump into every halfway normal conversation about canada and spout that every time [12:11:57] every gamer from the US is like hitler unless proved otherwise lol [12:16:46] not surprising at all [12:17:17] I expect a non-answer from Valve [12:36:43] damn, you got me [12:37:02] i just joined the chat, how did we get to hitler? [12:37:23] there's a law about that [12:59:29] nvm [13:15:00] https://dialogo-americas.com/articles/chinas-dangerous-play-in-peru-part-ii/ [14:21:31] me whenever i see another trans person on miraheze channels: \o/ [14:38:45] [1/2] Who the fuck is this guy [14:38:45] [2/2] https://cdn.discordapp.com/attachments/615786602454581249/1307716562555502643/Screenshot_20241117_083556_Messages.jpg?ex=673b5174&is=6739fff4&hm=774fb6bf3f295713b1031c131d028a69705e1f76a87dc7429c16b482fa0777bd& [14:41:35] And why is flirting with me [14:41:48] But well, wrong number [14:45:38] say that you're a guy and flirt back [14:45:44] 50% chance he'll get disgusted [15:17:48] Ooo maybe can use this in my own bot [15:18:05] I think she’s offline rn though [16:45:19] "Mi morenita chula y corajuda" XD [17:53:54] I don't have credit :'( [19:32:24] Interesting, nice to see the EU’s petition system being put to good use [19:37:20] It still is only recommendation to the Commission (basically the EU government) but it certainly can't hurt [19:37:49] Well yea [19:37:57] The stop killing games one is the other one I know of [19:38:01] But that had serious issues [19:38:26] Ref the Thor video [19:41:01] [1/2] ..why [19:41:01] [2/2] https://cdn.discordapp.com/attachments/615786602454581249/1307792631014883408/IMG_5280.jpg?ex=673b984c&is=673a46cc&hm=f70df30afec8b91c691b1a9812cb39fcc54dfd249f62028959063dc9a8f6bb67& [19:41:08] In other news Arcane is #3 in shows [19:41:14] Criminally low [19:54:36] [1/2] I love MLP [19:54:37] [2/2] Though gen4 is outdated, they should suggest G5 [20:07:49] FiM my beloved [21:31:12] You know the talk you’re watching is old when they list Internet Explorer as one of the big three [22:03:45] there's not really a big three anyway anymore is there [22:04:29] you've got google, maybe safari, everything else is a shade of google which iirc still has negligible market share, somewhere on the hill there's firefox, somewhere out of sight on the horizon is anything else [22:04:30] Its just chrome [22:04:56] not sure what safari's share is in relation with google, pretty sure google still dominates [22:05:12] everything on apple is just safari anyway so feel free to add all that in together [22:05:29] even more flagrant than google on that [22:05:48] part of why I utterly discard apple in the competition, if they had their way they'd be much much worse [22:05:59] google at least bothers to pay firefox to exist [22:09:39] watching a DEFCON talk of someone rickrolling their entire school district for a senior prank [22:09:48] PEAK [22:10:47] [1/3] ”we tried to access the system that manages bells but the default passwords dont work :(“ [22:10:47] [2/3] >one day before the prank [22:10:48] [3/3] “Oh the example password from the manual worked [22:11:10] smh [22:12:47] BRO [22:12:51] So [22:12:58] still watching [22:13:08] the other schools in the district [22:13:16] used different passwords [22:13:22] couldnt get in [22:13:39] but the BACKUPs used the default password [22:13:48] and they had sql dumps [22:14:03] huge oof [22:14:19] shockingly they were hashed passwords [22:15:03] Buuuuuut the dump showed a secret ‘district’ backdoor account. And guess the password to the [22:15:41] perfectly secure randomly generated pass that would make bitwarden proud obviously [22:16:55] password [22:17:06] yeah that checks out [22:17:20] Also he pulled this the day before AP exams [22:17:46] I’ve seen a few DEFCON talks before. Easily my favorite [22:18:45] and now I'm listening to it [22:19:08] Found it lmao? [22:19:50] pretty easy to look up ye [22:21:19] SCHOOL DISTRICT AGREED GO NOT TO PURSURE DISCIPLINARY ACTION W [22:21:45] oh and among us thrown in for good measure [22:30:24] @raidarr if you like these kind of hyjinks id recommend watching defcon talks [22:30:35] ive seen some good ones i can recommend when i find then lok [22:30:54] And they just posted more recordings from DEFCON 32 today [22:39:31] the district account thing is wild [22:39:58] and not at all the district's fault at a glance [22:40:11] Beautiful [22:40:25] my school actually uses a different software for this [22:40:42] making me a bit curious to poke around it [22:40:43] I wouldn't recommend software with something like that which is so horribly insecure [22:40:59] It’s basically spyware yea [22:42:12] But no keylogger at least [22:42:24] we have Chromebooks, GoGuardian works in the browser [22:42:33] backdoor like that is whatever you want anyway [22:42:48] unfortunately in a chromebook, besdies the browser, there’s really not much else there [22:43:04] yeah I've never cared for those [22:43:09] this is what i do my remote miraheze work on too, so im quite eager to get my own laptop soon [22:43:14] only chromebooks I get willingly are so I can install something else over them [22:43:30] heartily recommend getting something you can actually own [22:43:34] my school has been locking them down mote [22:43:48] i know a guy who gets a ton of pc donations [22:44:09] also a close family friends and one of my main tech mentors figures growing up [22:44:20] he’s the one who gave me my desktop years ago [22:44:31] I may ask if he has some spare laptops [22:44:38] im gonna go for linux prob [22:45:19] naturally [22:45:32] ie crosh is disabled, only district accounts can login, there was a bit where they would actually block entire categories on youtube [22:45:32] ensure it's compatible though, that's a big mess on laptops [22:45:33] such as [22:45:36] comedy [22:45:40] smh [22:45:44] entertainment [22:45:45] music [22:45:52] SCIENCE AND TECHNOLOGY [22:45:54] wouldn't dare do anything personal on a device like that anyway, the very idea to me is inexcusable [22:45:58] YOU ARE A SCHOOL COMPUTER [22:46:12] I just dont own a laptp [22:46:15] got one where the wifi card specifically just does not cooperate with linux [22:46:22] yeah in your case it's not really avoidable [22:46:30] and Ivhave reasons i cant always use my phone for MH stuff [22:46:38] I guess in those shoes I'd bank a lot on phone unless the phone was the same problem [22:46:45] its why i set up my poor mans bastion to do dev worm [22:46:48] in which case idk, I'd become amish or something [22:46:59] no my school has no power over my phone [22:47:03] different issues [22:47:07] I'd be tempted to just send you a bloody laptop [22:47:09] or desktop [22:47:10] but way better [22:47:33] i have a desktop lol(although note to self investigate those random freeze and shutoffs) [22:47:36] wanted to send doug an all in one a while ago so he could run discord reliably at least [22:47:55] got three burner laptops I could probably just ship out and not miss [22:48:14] performance on two of them not guaranteed [22:48:56] oh yes, GoGuardian, my mortal enemy [22:49:04] you used it too? [22:49:08] I did [22:49:29] I found various ways to evade it which led to my almost suspension and the district going overboard for Chromebook security [22:49:57] I'd have probably been the same, got lucky and had a nice windows that was not even remotely locked down and I could bust up at will [22:50:13] Know of any vulns :patience: [22:50:17] pft [22:50:23] It can’t see inside apps [22:50:29] but of course this was with computer labs™️ and not individually assigned devices [22:50:32] so if you can download Chrome apps, you can bypass it [22:50:40] Years ago they didn’t disable admin mode so i know someone who installed roblox [22:50:41] it also doesn’t detect Android apps inside ARC [22:50:47] oh forgot mentioj [22:50:52] no vulns required, they did things like block the config mode one way and I'd just use the other config menu [22:50:53] you know extensions? [22:50:59] basic windows settings bared open [22:51:17] If you have developer tools still enabled, you can also force it to close itself [22:51:23] yeah they dont like that shit [22:51:27] please [22:51:34] i cant even use inspect element [22:51:38] the [22:51:40] ENTIRE [22:51:44] chrome webstore [22:51:49] Is nuked [22:51:52] minus like [22:51:52] I would absolutely hate devices like that [22:51:54] sounds like my district [22:52:05] very few specific ones [22:52:08] on the other hand I was trying to install an apk on a work phone the other day so ye [22:52:26] massive pikachu face when it said I wasn't allowed [22:52:30] im tempted to give you the hash of my school district acronym just to make sure we didn’t go to the same place [22:52:34] /j [22:53:28] [1/2] My favorite evasion tool of all was to turn on developer mode on Chrome, have it fail because it’s disabled by enterprise policy and have it powerwash itself. On my router, I’d block all GoGuardian domains and then I’d setup the Chromebook like normal. Since it’s registered to the district, it will auto provision. Once logged back in, since it cannot download the extension for GG s [22:53:28] [2/2] ervers, you basically don’t have GoGuardian installed until the next time it pings the server which is about every 12 hours [22:53:59] hoo boi [22:55:57] smart [22:56:02] i dont wanna powerwash [22:56:14] If you have everything on Drive, it doesn’t really matter [22:56:20] …although what would just. Blocking the domain do [22:56:25] 🧐 [22:56:37] Not like IT will notice [22:57:18] If the redirect logic is local then won’t do much [22:57:39] im wondering if i could trick the bypass thing [22:57:48] but i dont wanna get my ass handed to me [22:59:35] that's paused anything ambitious on my end both in school days and later [22:59:52] I don't feel like holding liability for hacking and praying for goodwill [23:00:12] You can’t [23:00:50] you mean go guardians actually had a single security audit unlike lanschool? [23:00:54] :CatGasp: [23:01:37] oh Wikipedia said that til 2015 GG could keylog AND use webcam [23:01:46] WHAT JUSTIFICATION DO YOU HAVE FOR THAT [23:01:56] good thing I wasn’t in that district back then [23:01:59] your security and compliance, obviously [23:02:27] school devices in general are a special ring of privacy hell [23:02:42] a sophisticated neighbor of parental spyware [23:02:50] god forbid you have both [23:02:57] Even the EFF made a post about them [23:03:02] no comment [23:03:15] EFF is one of the few recipients of my regular donations [23:03:35] not really in the budget but I make do for them [23:04:20] i may see bout doing the same in this special state where i have a job but also no bills to pay to live [23:05:04] would recommend saving it tbh [23:05:13] that state changes quickly [23:05:21] i open mastodon and the newest post is https://phpc.social/@Schrank/113498519914461913 [23:05:26] wait [23:05:27] no [23:05:33] https://mastodon.social/@eff/113500776215839966 [23:05:35] this [23:06:10] hm [23:06:28] im curious. What would happen if i send claire my school Chromebook and let her do her thing [23:06:42] everyone's in trouble then probably [23:06:49] probably GoGuardian would have to file a few CVEs [23:06:55] if you reach that point just have me send you a clunker [23:11:01] In case I can’t get one of my own, I’ll let ya know i guess haha [23:11:27] petition to rename yubikeys as yurikeys [23:11:39] good god [23:11:44] hi claire [23:11:54] https://cdn.discordapp.com/attachments/615786602454581249/1307845703195951244/358EEDDA-7971-4513-B3A6-12AA2C6917C3.png?ex=673bc9ba&is=673a783a&hm=6ad64b5cd9690149d599920d72f15d41b3209480c8cfff861160eb185a362e6f& [23:11:58] 🤦 😂 [23:12:06] hello :3 [23:12:09] to claires comment? [23:12:15] did you just connect [23:12:25] technically yes [23:12:25] Just some goofs being goofs in offtopic. 🤣 [23:12:34] Technically? [23:12:41] having a blast [23:12:41] actually i connected on Nov 17 22:46:10 2024 +0000 from my phone at first, but then i reconnected from lappy [23:12:48] Protesting the 1984 [23:12:57] did you see the above convo [23:13:03] only "[18/11/2024 10:11] In case I can’t get one of my own, I’ll let ya know i guess haha" [23:13:05] i had just mentioned you lol [23:13:12] what a coincidence xD [23:13:24] > im curious. What would happen if i send claire my school Chromebook and let her do her thing [23:13:25] oh no [23:13:30] and you’re special ability “Oh look a CVE” [23:14:14] my yurikeys suddenly reappeared after four days [23:14:31] no idea how the travel looked, and i don't think we'll ever know (but not like it was that important or anything) [23:14:42] mines in customs [23:14:48] and [23:14:51] well, okay [23:14:55] I live in the US [23:14:57] it actually says "Arrived awaiting clearance (Inbound)" [23:15:09] and my nearest airport is JKF [23:15:12] SOOOOOOOOO [23:15:20] i keep reading JKF as JFK [23:15:32] few years til i get it [23:15:33] Jesus Fucking Krist /j [23:15:36] oh great [23:15:46] that reminds me of when daniel stenberg got his U.S. visa after 800 or so days [23:15:48] Thats you brains autocorrect [23:15:56] and it’s actually right this time i misspelled [23:16:01] it is JFK [23:16:09] sorry, 937 days [23:16:11] https://daniel.haxx.se/blog/2020/11/09/a-us-visa-in-937-days/ [23:17:38] anyway you should read up the rest of this comv [23:17:42] convo* [23:17:45] oki [23:17:48] :smile_villager: [23:18:52] > Ooo maybe can use this in my own bot [23:18:54] wdym? [23:20:15] > 2024-11-17 22:45:52 SCIENCE AND TECHNOLOGY [23:20:16] > 2024-11-17 22:45:58 YOU ARE A SCHOOL COMPUTER [23:20:18] xD [23:20:32] ngl [23:20:47] i was about to suggest that you set up X11 or wayland on your phone and vnc from your chromebook, but i forgot that you use an iphone [23:20:57] lol [23:21:12] it was a forwarded message for the my bot one [23:21:15] relay dont support [23:21:16] oh [23:21:18] > I found various ways to evade it which led to my almost suspension and the district going overboard for Chromebook security [23:21:20] ugh [23:21:31] discord adding commands that can be run on images directly [23:22:31] > 2024-11-17 22:53:28 [1/2] My favorite evasion tool of all was to turn on developer mode on Chrome, have it fail because it’s disabled by enterprise policy and have it powerwash itself. On my router, I’d block all GoGuardian domains and then I’d setup the Chromebook like normal. Since it’s registered to the district, it will auto provision. Once logged back in, since it cannot download the [23:22:33] extension for GG s [23:22:34] > 2024-11-17 22:53:28 [2/2] ervers, you basically don’t have GoGuardian installed until the next time it pings the server which is about every 12 hours [23:22:36] holy shit that's genius [23:23:45] i wonder [23:23:52] how does goguardian integration work w/ chromebooks [23:25:03] its a browser extension [23:25:19] chrome polices enforce keeping it I believe [23:25:33] redirects when you go on a webpage it dont like [23:25:59] well now i wanna play around w/ it [23:26:02] from my experience it’s some combination of AI changing what it doesn’t like on a whim and pattern matching? Or maybe just the first [23:26:07] ugh [23:26:13] Github.com is GG blocked [23:26:25] (and chromepolicy blacklisted????) [23:26:39] chromepolicy? is that chrome://policy or smth [23:26:39] and some URLs containing GitHub are blocked too [23:26:49] let me check [23:26:55] (i dunno much about chrome, but firefox has about:policies, so i made a guess) [23:27:05] yes [23:27:11] policy [23:27:38] they even disabled the dino game [23:27:50] ew [23:27:52] EW [23:27:55] EWWW [23:28:09] yup… [23:28:20] i can try and export and send you the policies if youd like [23:28:29] identifying stuff removed ofc [23:28:40] ooh that sounds interesting [23:28:49] i love subverting arbitrary boundries [23:29:01] i wanna take a look at these myself [23:29:17] oh god [23:29:25] google has genAI in dev tools [23:29:29] of course [23:29:29] not even my school [23:29:48] its enabled in policy [23:29:54] even though dev tools aint [23:30:01] lol [23:30:08] well devtools disabled is actually false [23:30:22] but dev tools availability is set to 2 [23:30:56] Taunting me [23:31:03] what a tease [23:33:10] Btw claire do you have signal. Curious [23:33:15] no, not yet [23:33:27] i could get it if you want, but i very much prefer not to share my phone number [23:33:38] i believe usernames are available, but you still need to register with a ph # afaik [23:36:07] https://support.goguardian.com/s/article/Installing-GoGuardian-Extensions-for-All-Products-Super-User-1630089628266 [23:36:09] oh bloody hell [23:36:30] Oh totally fair [23:36:41] i don’t think they need phone number anymore [23:36:47] what now [23:36:59] they self-host the extension themselves [23:37:09] i was hoping i can do a code review of it [23:37:56] If it was twitter, the red button stores unspeakable stuff [23:38:49] hm [23:38:52] im wondering [23:38:58] can you extract the source code i wonder [23:39:07] but yeah, that's the problem: how? [23:39:31] I think the extension installs when i log into my school account on chrome on my own personal computer [23:39:32] :) [23:39:38] EHEHEHE [23:40:19] No idea if it’s obfuscated [23:40:34] that will certainly be a pain [23:40:37] i can deal with minified tho [23:40:45] if you can get me a guide on how to extract the source i can hand it to ya when i get on my PC [23:41:05] i desperately need to stop procrastinating i have a test tmr [23:41:23] https://stackoverflow.com/a/4999426 [23:41:26] heh, same [23:41:35] i have an exam in two hours [23:41:46] i studied yesterday though (for once!) [23:42:43] me when there's highly secure hardware for running grapheneos: :) [23:42:49] me when there's highly secure hardware for restricting users' freedom: >:( [23:44:45] https://grapheneos.social/@GrapheneOS/112826160880324005 [23:44:52] i read FFS here and i thought of facial feminisation surgery [23:44:53] ah yes [23:45:18] gay gay trans gay