Secure communication using Tor and socat

July 3, 2023242 words2 mins read

If you didn’t know, people can send you messages using socat and the Tor network, all communication is encrypted by Tor, no DNS lookups are performed and it’s impossible to identify who is sending you the messages (or who is receiving them, for what matters).

You only need Tor and socat installed.

Read more ...

How are you feeling today?

July 2, 2023282 words2 mins readPart of Life and death series

How are you feeling today, friend? When was the last time somebody asked you this one simple question?

Are you feeling demotivated, because all the values that kept generations moving are all destroyed and dead now, family, friendship, love, ideology, religion, parenthood, life goals, any sort of belief, honesty, kindness, love, morality, everything is absolutely dead? Because nothing brings satisfaction the way it did before, there’s an abundance of everything one can dream of, but no one can feel the joy from consuming and owning things anymore?

I guess this could be the reason why many try hard to show off what they read, eat and wear, because the only way they can feel something is by reacting to a reaction. What else can we feel? There’s the scent of last times in the air, like something is about to happen. The society is no longer seen as a community of civilized people, but rather as a flock of egocentric, greedy, mercantile, selfish scumbags.

Read more ...

Encrypted LUKS volume inside a file

June 25, 2023408 words2 mins read

LUKS can be used to encrypt a volume that’s stored inside a single file.

Start by creating a 2GB file (1M * 2k) that will hold the LUKS volume and fill it with random bytes. If you’re wondering why the strange filename, Solaris.1971.1080p.BluRay.x264-[YTS.AM].mp4.part, that’s so it is “hidden” as a temporary Transmission torrent file, away from prying eyes (unless your threat model is the NSA). If you want to use a qBittorrent temporary extension, change .part to .!qB.

Also, don’t put the volume file inside a CONFIDENTIAL or VERY_IMPORTANT_STUFF or HIDDEN_LUKS_VOLUMES directory, keep it somewhere where you’d store your downloaded files (maybe even add a subtitle file next to it, just for fun). You can cleverly disguise the volume file (depending on its size) in Windows dlls, macOS resource files, etc.

There might be an image on this website, that contains a small encrypted LUKS volume sandwitched between the PNG chunks.

Read more ...

Firefox telemetry disabled, yet telemetry sent

June 24, 202381 words1 min read

So, Mozilla, Firefox telemetry upload is disabled, yet your shitty web browser is still trying to send telemetry data? I guess your CEO needs a bigger paycheck, right?

There is currently not a single instance of incoming.telemetry.mozilla.org inside my tweaked about:config configuration values, so I guess this is a build flag and cannot be disabled. I don’t want to waste my time browsing Firefox source code but … yeah. Well done, Mozilla.

Firefox telemetry disabled, yet telemetry sent

Mozilla Firefox version 114.0.2 (64-bit) running on macOS Ventura.

Read more ...

Captain Blackbeard Radio #17

June 21, 2023675 words4 mins read

#17: The Seven Who Stole CaptainBlackbeard’s Treasure

What do ye get when ye force a psychopath, a homicidal maniac, a terrorist, a seductress, a sociopath, a mafia hitman and a clown to work together to steal a trillion dollars in gold?

Facing several life sentences in a secret ultra max black prison where ye are beaten and tortured every day. A mysterious wealthy man appears in yer prison cell offering ye a way out. The catch, is ye have to face overwhelming odds, hundreds of Russia’s finest sons who wish to kill ye and being stranded on a deserted island, in the middle of nowhere, on what appears to be a suicide mission.

Read more ...

The essential Russian movies list

June 14, 2023960 words5 mins read

Few days ago I ran into a list of the essential Soviet Union (and by extension, Russian) movies to watch. I don’t think it’s an actual top, though the first 10 movies in the list are spot-on. No external links, research and download them on your favorite websites.

#1 THE MIRROR

Andrei Tarkovsky, Soviet Union, 1975
The Mirror
Read more ...

Riseup - from RiseupVPN to OpenVPN

June 9, 20231201 words6 mins read

Riseup’s top-notch FREE services are funded by donations from people like us, so make sure you help Riseup provide those services. Go birds!
This article was sparked by a 4chan discussion, I was under the impression that everybody (that was interested in this) knew that you can use Riseup’s VPN service without their RiseupVPN (Bitmask, developed by LEAP) client. Apparently, nobody knows that.

Due to Riseup’s changes to the VPN API structure (version bump from 1 to 3) the Python script below isn’t working anymore. The only way you can create OpenVPN profiles from RiseupVPN now is by using my conversion tool. Most of the information in this article is still valid, though.

Even though it’s open source, people might not want to install additional applications when you can just use a 5KB OpenVPN profile for that. Basically you just need a way to “trick” the Riseup server to give you the correct data (CA certificate, client certificate and private key) so an OpenVPN profile can be generated, and for that we’ll be using this excellent tool by nitrohorse. You can also use Postman or wget/curl to retrieve the certificates and private key.

Caveat: The generated OpenVPN profile must be re-created every 60 days, the RiseupVPN client does that transparently, but you can use cron, or whatever automation tool you fancy, to re-create the profile when needed.

Update: There is now a tool that does the same thing.

Read more ...

Rhysida ransomware group opsec

June 6, 2023292 words2 mins read

I was debating whether I should publish this, Allah knows I hate to give tips to the feds and Interpol, but I noticed someone on Twitter already figured it out, so why not. Here we go!

There is a new-ish (since May 2023) ransomware group called Rhysida and they leaked some stuff from various companies and the French territorial colectivity of Martinique (why Martinique). All good for now, except they made a simple mistake, they forgot to disable (or it’s enabled on purpose, hello honeypot) the Apache server status page. I can’t remember whether the status page is enabled or disabled by default (and I CBA to check the manual, I’m cranky today) because we pros are way past the goth Apache phase and we’re converting packets straight into Morse code now.

Read more ...

WWW - Website Writing Workflow

May 30, 20231730 words9 mins read

Over the years I’ve tried a bunch of writing apps, and in this article I’m going to talk a bit about my writing workflow. To begin with, I write in Markdown and I’ve been writing in Markdown for a few years now. Using a plain text format makes it easy to use pretty much any application, whether on macOS, Linux or Windows, an I prefer Markdown to writing HTML by hand, but I can write HTML if I need a feature not implemented in Markdown.

My preferred Markdown editor is iA Writer for longer, distraction-free writing and if I’m writing short notes like the notes section which is basically micro-blogging) I will probably use Sublime Text, since it’s always open on my computer(s), anyway.

Read more ...

A society of children

May 27, 2023600 words3 mins readPart of Life and death series

In an effort to make everyone focus on the one thing they do best, we created a society of children who are experts in things that interest them and clueless in most other things; as soon as the economy loses its ability to ensure all the human rights, infrastructure and conveniences these require, there will only be a minority of people who can clearly judge the value of certain things - those who didn’t have them for granted. An utopia where nobody has to struggle to feed or house themselves would completely forget the value of food and housing and would collapse on itself when supply runs low, as everyone would oppose spending resources on food and housing (it being a given) and would instead start a campaign to find who is to blame.

Calling the west the most corrupt system might sound ungrateful at first, but if you look deeper into it you’ll see that our so-called “freedom” is really nothing more than just a smokescreen. In most dictatorships you usually know what to expect.

Read more ...