●● IRC: #boycottnovell @ Techrights IRC Network: Wednesday, June 30, 2021 ●● ● Jun 30 [03:11] *DaemonFC has quit (Quit: Leaving) [03:17] *job (~job@bfjdrpzm6v77y.irc) has joined #boycottnovell ● Jun 30 [04:22] schestowitz
  • [04:22] schestowitz
    Having fun with CSS injection in a browser extension
    [04:22] -TechrightsBN/#boycottnovell-palant.info | Having fun with CSS injection in a browser extension | Almost Secure [04:22] schestowitz
    [04:22] schestowitz

    Normally, CSS injection vulnerabilities are fairly boring. With some luck, you can use them to assist a clickjacking attack. That is, unless the vulnerable party is a browser extension, and it lets you inject CSS code into high profile properties such as Googles. Ive now had some fun playing with this scenario, courtesy of G App Launcher browser extension.

    [04:22] schestowitz

    The vulnerability has been resolved in G App Launcher 23.6.1 on the same day as I reported it. Version 23.6.5 then added more changes to further reduce the attack surface. This was a top notch communication experience, many thanks to Carlos Jeurissen!

  • ● Jun 30 [05:10] *job has quit (connection closed) [05:15] *job (~job@bfjdrpzm6v77y.irc) has joined #boycottnovell [05:43] schestowitz I think we can write some search and replace scripts to help migrate the wiki to gemini, but should we? Dir and file creation, plus updates (and wiki changes) won't be easy to automate, so maintenance overhead in the long run. ● Jun 30 [07:24] Techrights-sec Do you mean mirror the wikin in Gemini? Read-only would not be too hard, [07:24] Techrights-sec but would tak some time. ● Jun 30 [10:05] *job has quit (connection closed) [10:20] *psydroid_ (~psydroid@cqggrmwgu7gji.irc) has joined #boycottnovell [10:23] *psydroid_ has quit (Ping timeout: 2m30s) [10:23] *job (~job@bfjdrpzm6v77y.irc) has joined #boycottnovell [10:27] *psydroid_ (~psydroid@cqggrmwgu7gji.irc) has joined #boycottnovell [10:40] *psydroid_ has quit (connection closed) [10:45] *psydroid_ (~psydroid@cqggrmwgu7gji.irc) has joined #boycottnovell ● Jun 30 [11:11] *psydruid has quit (connection closed) [11:12] *psydruid (~psydruid@jevhxkzmtrbww.irc) has joined #boycottnovell ● Jun 30 [12:23] *psydroid_ has quit (connection closed) [12:24] *psydruid (~psydruid@jevhxkzmtrbww.irc) has left #boycottnovell [12:24] *psydruid (~psydruid@jevhxkzmtrbww.irc) has joined #boycottnovell [12:24] *psydroid_ (~psydroid@cqggrmwgu7gji.irc) has joined #boycottnovell [12:37] *Disconnected (Connection reset by peer). [12:37] *Now talking on #boycottnovell [12:37] *Topic for #boycottnovell is: TechRights.org | Channel #boycottnovell for http://TechRights.org | Free Software Sentry watching and reporting maneuvers of those who oppose software freedom :: please also join channels #techrights and #boycottnovell-social [12:37] *Topic for #boycottnovell set by schestowitz!~roy@haii6za73zabc.irc at Tue Jun 1 20:22:10 2021 [12:37] *rianne__ (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [12:38] *libertybox (~schestowitz_log@22e8m8t4gqjin.irc) has joined #boycottnovell [12:38] *job (~job@bfjdrpzm6v77y.irc) has joined #boycottnovell [12:45] *Disconnected (Connection reset by peer). [12:46] *Now talking on #boycottnovell [12:46] *Topic for #boycottnovell is: TechRights.org | Channel #boycottnovell for http://TechRights.org | Free Software Sentry watching and reporting maneuvers of those who oppose software freedom :: please also join channels #techrights and #boycottnovell-social [12:46] *Topic for #boycottnovell set by schestowitz!~roy@haii6za73zabc.irc at Tue Jun 1 20:22:10 2021 [12:46] *rianne__ (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [12:46] *Techrights-sec (~quassel@22e8m8t4gqjin.irc) has joined #boycottnovell [12:46] *libertybox (~schestowitz_log@22e8m8t4gqjin.irc) has joined #boycottnovell [12:51] Techrights-sec One way would be to read the database directly and query for updates. [12:51] Techrights-sec Another would be to poll the Wiki's RSS feed with cron and then scrape the HTML [12:51] Techrights-sec I'm not sure how navigation within the mirrored wiki would work in Gemini. [12:51] Techrights-sec It seems hard to create / import the navigation. ● Jun 30 [13:12] Techrights-sec https://nitter.actionsack.com/yuhong2/status/1410188245678186498#m [13:12] -TechrightsBN/#boycottnovell-nitter.actionsack.com | Yuhong Bao (@yuhong2): "https://news.ycombinator.com/item?id=27686678 Part of the reason why I talked about Google so much is that even Techrights trusted it." | nitter [13:21] *job has quit (Ping timeout: 2m30s) [13:36] *Disconnected (Connection timed out). [13:43] *Now talking on #boycottnovell [13:43] *Topic for #boycottnovell is: TechRights.org | Channel #boycottnovell for http://TechRights.org | Free Software Sentry watching and reporting maneuvers of those who oppose software freedom :: please also join channels #techrights and #boycottnovell-social [13:43] *Topic for #boycottnovell set by schestowitz!~roy@haii6za73zabc.irc at Tue Jun 1 20:22:10 2021 [13:43] *rianne (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [13:43] *libertybox (~schestowitz_log@22e8m8t4gqjin.irc) has joined #boycottnovell [13:43] *acer-box (~acer-box@22e8m8t4gqjin.irc) has joined #boycottnovell [13:43] *psydroid_ (~psydroid@cqggrmwgu7gji.irc) has joined #boycottnovell [13:43] *blitzed (~blitzed@dtqwd9qmkxpqy.irc) has joined #boycottnovell [13:43] *spazzz (~spazz@urifce6zxwtdi.irc) has joined #boycottnovell [13:43] *bridge (~bridge@sp6mg7ktjfurg.irc) has joined #boycottnovell [13:43] *irc.techrights.org gives channel operator status to bridge [13:43] *Techrights-sec (~quassel@22e8m8t4gqjin.irc) has joined #boycottnovell [13:43] *liberty_box (~liberty@22e8m8t4gqjin.irc) has joined #boycottnovell [13:44] *MinceR` (~mincer@sgfzprzxvda2g.irc) has joined #boycottnovell [13:45] *psydruid (~psydruid@jevhxkzmtrbww.irc) has joined #boycottnovell [13:53] *Disconnected (Connection reset by peer). [13:53] *Now talking on #boycottnovell [13:53] *Topic for #boycottnovell is: TechRights.org | Channel #boycottnovell for http://TechRights.org | Free Software Sentry watching and reporting maneuvers of those who oppose software freedom :: please also join channels #techrights and #boycottnovell-social [13:53] *Topic for #boycottnovell set by schestowitz!~roy@haii6za73zabc.irc at Tue Jun 1 20:22:10 2021 [13:53] *blitzed (~blitzed@dtqwd9qmkxpqy.irc) has joined #boycottnovell [13:53] *rianne (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [13:54] *psydruid (~psydruid@jevhxkzmtrbww.irc) has joined #boycottnovell [13:54] *psydroid_ (~psydroid@cqggrmwgu7gji.irc) has joined #boycottnovell [13:54] *Techrights-sec (~quassel@22e8m8t4gqjin.irc) has joined #boycottnovell [13:56] *MinceR` (~mincer@sgfzprzxvda2g.irc) has joined #boycottnovell [13:58] *MinceR` is now known as MinceR ● Jun 30 [14:09] *job (~job@bfjdrpzm6v77y.irc) has joined #boycottnovell [14:32] *Disconnected (Connection timed out). [14:36] *Now talking on #boycottnovell [14:36] *Topic for #boycottnovell is: TechRights.org | Channel #boycottnovell for http://TechRights.org | Free Software Sentry watching and reporting maneuvers of those who oppose software freedom :: please also join channels #techrights and #boycottnovell-social [14:36] *Topic for #boycottnovell set by schestowitz!~roy@haii6za73zabc.irc at Tue Jun 1 20:22:10 2021 ● Jun 30 [15:11] Techrights-sec what are the five most popular wiki pages? I'm looking at the EPO wikipage [15:11] Techrights-sec but need more examples to ensure a more generic conversion. [15:12] schestowitz we're doing some work on routers at the moment, so the sites aren't in a state to be doing work on right now. most viewed pages would inclue front page, mono etc. [15:19] *job has quit (connection closed) [15:34] *bridge has quit (connection closed) [15:37] *bridge (~bridge@sp6mg7ktjfurg.irc) has joined #boycottnovell [15:37] *irc.techrights.org gives channel operator status to bridge ● Jun 30 [16:48] *qa2 has quit (Quit: ) ● Jun 30 [17:29] *DaemonFC (~daemonfc@hyvmz96nd5wc2.irc) has joined #boycottnovell [17:43] *liberty_box has quit (Ping timeout: 2m30s) [17:43] *rianne_ has quit (Ping timeout: 2m30s) ● Jun 30 [18:06] *rianne_ (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [18:06] *liberty_box (~liberty@22e8m8t4gqjin.irc) has joined #boycottnovell [18:13] *liberty_box has quit (Ping timeout: 2m30s) [18:13] *rianne_ has quit (Ping timeout: 2m30s) [18:22] *rianne_ (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [18:23] *liberty_box (~liberty@22e8m8t4gqjin.irc) has joined #boycottnovell [18:37] *DaemonFC has quit (Quit: Leaving) [18:45] *DaemonFC (~daemonfc@hcz4kwb5fv9w4.irc) has joined #boycottnovell [18:54] *psydroid_ has quit (connection closed) [18:55] *liberty_box has quit (Ping timeout: 2m30s) [18:55] *rianne_ has quit (Ping timeout: 2m30s) [18:57] *liberty_box (~liberty@22e8m8t4gqjin.irc) has joined #boycottnovell [18:57] *rianne_ (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [18:59] *DaemonFC has quit (Quit: Leaving) ● Jun 30 [19:12] *DaemonFC (~daemonfc@rs9rjg3ve4y6a.irc) has joined #boycottnovell [19:38] *DaemonFC has quit (Ping timeout: 2m30s) [19:43] *liberty_box has quit (Ping timeout: 2m30s) [19:44] *rianne_ has quit (Ping timeout: 2m30s) ● Jun 30 [20:12] *rianne_ (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [20:12] *liberty_box (~liberty@22e8m8t4gqjin.irc) has joined #boycottnovell [20:19] Techrights-sec https://nitter.actionsack.com/lonestarangle/status/1410282614729105413#m [20:19] -TechrightsBN/#boycottnovell-nitter.actionsack.com | Americana (@lonestarangle): "http://techrights.org/2020/07/02/ddg-privacy-abuser-in-disguise/" | nitter [20:22] *rianne_ has quit (Ping timeout: 2m30s) [20:22] *liberty_box has quit (Ping timeout: 2m30s) [20:36] *rianne_ (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [20:37] *liberty_box (~liberty@22e8m8t4gqjin.irc) has joined #boycottnovell ● Jun 30 [21:08] *liberty_box has quit (Ping timeout: 2m30s) [21:09] *rianne_ has quit (Ping timeout: 2m30s) [21:13] *rianne_ (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [21:17] *rianne_ has quit (Ping timeout: 2m30s) [21:23] *rianne_ (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [21:24] *liberty_box (~liberty@22e8m8t4gqjin.irc) has joined #boycottnovell [21:28] schestowitz >>> What is your impression? Do the videos work for you? Have you had any [21:28] schestowitz >>> experience with video over IPFS issues for your own videos? [21:28] schestowitz >> I know gemini:// is unsuitable for large file. [21:28] schestowitz >> [21:28] schestowitz >> Some people told me that Techrights videos ended up in IPFS, but I never [21:28] schestowitz >> tried streaming over IPFS and I suppose lag would be a colossal barrier. [21:28] schestowitz >> [21:28] schestowitz >> IPFS is probably not good as a protocol for videos. [21:28] schestowitz >> [21:28] schestowitz > The problem can be subdivided into different spaces: [21:28] schestowitz > [21:29] schestowitz > - the ipfs.io gateways [21:29] schestowitz > [21:29] schestowitz > - IPFS itself [21:29] schestowitz > [21:29] schestowitz > The problems may only exist when a user accesses content through [21:29] schestowitz > ipfs.io. I could simply run my own alternative to ipfs.io and include [21:29] schestowitz > that in my URLs. People with a local IPFS daemon could still access the [21:29] schestowitz > content if my gateway is down. [21:33] *liberty_box has quit (Ping timeout: 2m30s) [21:34] *liberty_box (~liberty@22e8m8t4gqjin.irc) has joined #boycottnovell ● Jun 30 [22:17] *rianne_ has quit (Ping timeout: 2m30s) [22:17] *liberty_box has quit (Ping timeout: 2m30s) [22:20] Techrights-sec https://nitter.actionsack.com/maetrojl/status/1410265721179758593#m [22:20] -TechrightsBN/#boycottnovell-nitter.actionsack.com | you go when u feel like it (@maetrojl): "@schestowitz" | nitter [22:24] *rianne_ (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [22:25] *liberty_box (~liberty@22e8m8t4gqjin.irc) has joined #boycottnovell ● Jun 30 [23:30] *rianne_ has quit (Ping timeout: 2m30s) [23:31] *liberty_box has quit (Ping timeout: 2m30s) [23:34] *rianne_ (~rianne@22e8m8t4gqjin.irc) has joined #boycottnovell [23:36] *liberty_box (~liberty@22e8m8t4gqjin.irc) has joined #boycottnovell