chameleon

joined 5 months ago
[โ€“] chameleon@fedia.io 18 points 3 months ago

Eh, no. "I'm going to make things annoying for you until you give up" is literally something already happening, Titanfall and the like suffered from it hugely. "I'm going to steal your stuff and sell it" is a tale old as time, warez CDs used to be commonplace; it's generally avoided by giving people a way to buy your thing and giving people that bought the thing a way to access it. The situation where a third party profits off your game is more likely to happen if you don't release server binaries! For example, the WoW private/emulator server scene had a huge problem with people hoarding scripts, backend systems and bugfixes, which is one of the reasons hosted servers could get away with fairly extreme P2W.

And he seems to completely misunderstand what happens to IP when a studio shuts down. Whether it's bankruptcy or a planned closure, it will get sold off just like a laptop owned by the company would and the new owner of the rights can enforce on it if they think it's useful. Orphan works/"abandonware" can happen, just like they can to non-GaaS games and movies, but that's a horrible failing on part of the company.

[โ€“] chameleon@fedia.io 4 points 3 months ago (1 children)

There's been an exFAT driver in the kernel for a couple of years now (merged after Microsoft's patent pact added ExFAT), it works fine. Same driver gets used on Android for SD card support.

[โ€“] chameleon@fedia.io 4 points 3 months ago* (last edited 3 months ago)

Pretty much every form of these scams is some kind of advance fee fraud. Two more possible avenues:

  • "Upgrade to a business account". They send you an email purporting to be from the payment provider you used saying you need to upgrade to business to receive a payment that large, and the upgrade page is a fake website run by the scammer that asks for a "refundable deposit" or the like (with a little helping of credit card fraud and of course a business account will require all kinds of personal info useful for identity theft too).
  • "But I want it as an NFT" was popular for a bit, they want you to "pre-pay the minting fee but it's ok I'll add it to your payment" and then they disappear. But they want it on a website ran by them and the moment you put the crypto in they disappear. Not sure this scam is popular nowadays because NFT screams scam to just about everyone for a lot of different reasons. But "rich guy spends $5000 on dumbass NFT" was a legitimate genre of news for a little moment.

It's all preying on someone that thinks they got an easy paycheck for work that they've already done, on a populace of artists that could really use said paycheck to pay for food and are thus willing to overlook weirdness or principles. They also tend to pick on newer and younger artists that haven't quite figured out how to run a business yet, hoping that they haven't heard of scams specifically targeted to their sector.

[โ€“] chameleon@fedia.io 12 points 3 months ago

Releasing server binaries (nobody in the context of this petition is asking for source code) is one option. Single player mode is another. Everything you'd wanna know is on https://www.stopkillinggames.com/ . Exact wording of laws and the like comes in a later phase, as with every initiative ever it will be up to the lawmaking body to make that.

[โ€“] chameleon@fedia.io 2 points 3 months ago

Probably an anti-piracy thing. It's pretty common in the console hacking scene for only specific versions to be vulnerable, or only have exploits released for a specific set of versions. People can get around it by looking for games released with specific updates on the disc/cart but it's a pain.

[โ€“] chameleon@fedia.io 5 points 3 months ago (1 children)

Easiest way would be to use borg create --read-special --chunker-params fixed,4194304 '/home/user/sdcardbackup::{now}' /dev/sdX (which I copied from the examples in the documentation). I'm not sure if Vorta has a way to activate --read-special but I suspect not; you can most likely still use it to make the repo and manage archives inside of it though.

Backing up from a command/stdin might also be relevant as an alternative, since that lets you back up more or less anything.

[โ€“] chameleon@fedia.io 14 points 3 months ago (1 children)

Browsing through the PDF, I'm getting the vibe that their way of measuring "skill" is weird. They claim to use multiple methods of measuring, they list a few obvious ones that they've found to be bad, but they don't say which ones they are using because "we are constantly iterating on our performance metrics to optimize the player experience per game-mode".

Elo-like systems tend to adjust skill based on the chance of winning current match X win/loss, but they're not (just) doing that. I wonder if they have a few weird metrics that look good on paper/in the lab but don't feel good in play.

[โ€“] chameleon@fedia.io 9 points 3 months ago (1 children)

Elixir, or Gleam/pure Erlang/some other Erlang VM language. I think Erlang is extremely cool and I've enjoyed the little time I spent with Elixir. I also have absolutely no use case to make proper use of it.

[โ€“] chameleon@fedia.io 52 points 3 months ago

Requiring agreement to some unspecified ever-changing terms of service in order to use the product you just bought, especially when use of such products is required in the modern world. Google and Apple in particular are more or less able to trivially deny any non-technical person access to smartphones and many things associated with them like access to mobile banking. Microsoft is heading that way with Windows requiring MS accounts, too, though they're not completely there yet.

[โ€“] chameleon@fedia.io 17 points 3 months ago (1 children)

Eh. I've been on the receiving end of one of those inboxes and the spam is absolutely, utterly unbearable. Coming up with a better system than a publicly listed email address is on Google at this point, because there is no reasonable way to provide support when you need a spam filter tuned up to such a level that all legitimate mail also ends up in spam.

[โ€“] chameleon@fedia.io 3 points 3 months ago (1 children)

Personally, I do believe that rootless Docker/Podman have a strong enough security boundary for personal/individual self-hosting where you have decent trust in the software you're running. Linux privilege escalation and container escape exploits fetch decent amounts of money on the exploit market, and nobody's gonna waste them on some people running software ending in *arr when Zerodium will pay five figures for a local privilege escalation or container escape. If you're running a business or you might be targeted for whatever reason (journalist or whatever) then that doesn't apply.

If you want more security, there are container runtimes that do cooler security stuff under the hood, like Firecracker/Kata Containers implementing a managed VM, or Google's gVisor which very strongly intercepts kernel syscalls and essentially reimplements Linux in userspace. Those are used by AWS and Google Cloud respectively. You can integrate those into Docker, though not all networking/etc options are supported.

[โ€“] chameleon@fedia.io 4 points 4 months ago* (last edited 4 months ago)

That's because they had a lot of people "buying the dip". CS is in a very similar position to SolarWinds during their 2020 security slipup. The extent of managerial issues there should've been unforgivable but unfortunately they got away with it and are doing just fine nowadays.

view more: โ€น prev next โ€บ