https://drkt.eu/

This is an alt account, you may see it around. I am not ban-dodging intentionally, I promise!

This is the main
https://scribe.disroot.org/u/drkt

  • 0 Posts
  • 20 Comments
Joined 16 days ago
cake
Cake day: March 16th, 2025

help-circle
  • I wouldn’t even know where to begin, but I also don’t think that what I’m doing is anything special. These NVR IPs are hurling abuse at the whole internet. Anyone listening will have seen them, and anyone paying attention would’ve seen the pattern.

    The NVRs I get the most traffic from have been a known hacked IoT device for a decade and even has a github page explaining how to bypass their authentication and pull out arbitrary files like passwd.



  • I have plenty of spare bandwidth and babysitting-resources so my approach is largely to waste their time. If they poke my honeypot they get poked back and have to escape a tarpit specifically designed to waste their bandwidth above all. It costs me nothing because of my circumstances but I know it costs them because their connections are metered. I also know it works because they largely stop crawling my domains I employ this on. I am essentially making my domains appear hostile.

    It does mean that my residential IP ends up on various blocklists but I’m just at a point in my life where I don’t give an unwiped asshole about it. I can’t access your site? I’m not going to your site, then. Fuck you. I’m not even gonna email you about the false-positive.

    It is also fun to keep a log of which IPs have poked the honeypot have open ports, and to automate a process of siphoning information out of those ports. Finding a lot of hacked NVR’s recently I think are part of some IoT botnet to scrape the internet.






  • Man I’m not going to dive into it but this reads like a FUD piece and I know the article explicitly calls out people who dismiss evidence as FUD, but please read just the first point that ‘Tor is compromised’:

    the agency has worked on several methods that, if successful, would allow the NSA to uncloak anonymous traffic

    If succesful, implying that they haven’t been. I’d love to read the paper but I’m European and they block me from clicking it, citing GDPR issues :-)

    promised to reveal how a $3,000 piece of kit could unmask the IP addresses of Tor hidden services as well as their users.

    a much anticipated talk at the Black Hat hacking conference was abruptly canceled.

    The university cancelled the speech and cited no reasons but I can think of several legal ones even if the device didn’t work. No proof.

    the FBI is able to de-anonymize Tor users and discover their real IP address remains classified information. In a 2017 court case, the FBI refused to divulge how it was able to do this,

    I can fly. No, I don’t have to prove it.












  • drkt@lemmy.dbzer0.comtoPrivacy@lemmy.mlIs Tuta a good alternative to gmail?
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    3
    ·
    16 days ago

    no paid ads for third party products

    Haha you almost fucking got me, I actually wrote a whole thing about how those are ads but then I read your comment again and noticed that clever little write-off. Ads for their own products are still ads and I don’t want to fucking see it. Get that shit off my eyeballs, I paid for this product.

    The newsletter is an ad, it’s not news. They’re just advertising their products to you and you can’t unsubscribe and you can’t ignore it because they very deliberately have a special styling for the newsletters that makes it stand out from normal emails.

    I don’t know why you want to defend this company. I’m glad you’re okay with the level of shitty behavior they engage in; it’s definitely less than most email providers do- I’m just letting people know that Tuta aren’t angels. They’re a company, and they used to be better. Proton was exactly the same. It was a good service and then it became shitty.

    I would love to log back in and show you the 3 separate buttons on my UI that did nothing except link to a “Please pay us for this feature” page because I was a legacy premium user because I didn’t want all those new bullshit they made. I stress that it’s not a case of them implementing a button in the UI for all users and because I’m a legacy user I get it too even if I can’t use it- the buttons had special CSS to make them stand out. They were ads. Why couldn’t Tuta just leave me alone? I could still be paying them to this day if they had just not gone down that path. I just want an email that is an email and nothing more and doesn’t get in my way. Tuta had that, and then they took it away and asked for more money to put it back.

    I think the misunderstanding here is that I was a legacy premium user. I was paying less to get only the email+calendar because that’s what I signed up for, originally. When people sign up today, that’s not an option. People who are new to Tuta (relatively) haven’t seen this change happen and haven’t witnessed how obviously desperate Tuta was to get people off the legacy premium plan.

    Also my name is drkt_ but I’m sure you tried your best.