Daily Shaarli

All links of one day in a single page.

March 29, 2022

Syncthing — How Scanning Works — Kastelo Inc.
thumbnail

What is Syncthing doing when it says “Scanning”, and what’s the point of it?

To answer that we first need to talk about the index database.
The Index Database

Syncthing keeps a index database with information about each file, directory, and symlink it knows about. Each entry contains the name of the item, some metadata like size, timestamps, and permissions; internal information like a version vector and sequence number, and a list of the blocks making up the file. The index is keyed on folder ID, device ID, and file name.

Syncthing — How Syncing Works — Kastelo Inc.
thumbnail

files are divided in blocks - typically 128 KiB each, but possibly larger for larger files. Each device calculates the hash (cryptographic checksum) of all blocks making up a file and informs its peers about the file contents. When Syncthing gets an index update from a peer device, containing a new block list, it compares the new block list with the one it already has in the index. If there are differences that means the file contents have changed and we should synchronize the file.

Hunter Biden’s Laptops Are Now An Active National Security Threat

An urgent concern for the country is the continuing threat to our national security posed by a compromised President Biden. //

On Friday, The Daily Mail reported that emails recovered from Hunter Biden’s laptop show he helped an infectious disease research company pursue projects in Ukraine. Those emails confirm portions of charges Russia made the previous day that an investment group run by the now-president’s son had funded a company conducting research at biological laboratories in Ukraine. //

Russia’s ability to point to the Hunter Biden emails as confirmation of its claims of a biolab in Ukraine raises a serious question with huge national security implications: How did Russia know the day before The Daily Mail’s exclusive that the Hunter Biden’s investment fund, Rosemont Seneca, had invested in Metabiota and been involved in Metabiota’s operations in Ukraine?

The timing of events last week suggests Russia has access to the same emails as The Daily Mail or that Vladimir Putin’s agents might well have obtained access to Hunter Biden’s first laptop—the one the president’s son believed Russians had stolen in 2018. In either case, the Biden family corruption documented on the laptops has gone from a potential national security risk to a real one—and in the midst of a war launched by Russia on a country bordering North Atlantic Treaty Organization allies.

Together, the Biden family, the intelligence agencies, and the corrupt media—social and legacy—hold full responsibility for the danger Americans now face. Biden knew full well how compromised his family was, and that there were two laptops, not one, with evidence of the corruption floating about. Yet Biden lied to the American public, with an assist from the former high-level members of the intelligence community who signed the letter suggesting the laptop scandal represented Russian disinformation.

Then there is the FBI which, by December 2019, had access to the abandoned laptop and thereby also knew that Hunter believed Russians had stolen his laptop in summer 2018. To date, there has been no indication that the FBI provided Joe Biden a defensive briefing on the national security risk posed by those laptops. Or if FBI agents did brief Biden on the risks in a timely manner, that means he nonetheless lied to the American public and ran for president knowing the propaganda at Putin’s fingertips.

Behold, a password phishing site that can trick even savvy users – Ars Technica

While the method is convincing, it has a few weaknesses that should give savvy visitors a foolproof way to detect that something is amiss. Genuine OAuth or payment windows are in fact separate browser instances that are distinct from the primary page. That means a user can drag them anywhere, including over the address bar of the primary window.

BitB windows, by contrast, aren’t a separate browser instance at all. Instead, they’re illustratons rendered by custom HTML and CSS and contained in the primary window. That means the fake pages can’t be cover the address bar of the primary browser window.

Unfortunately, as mr.d0x pointed out, these checks might be difficult to teach “because now we move away from the ‘check the URL’” advice that’s standard. “You’re teaching users to do something they never do.”

All users should protect their accounts with two-factor authentication. One other thing more experienced users can do is right click on the popup page and choose "inspect." If the window is a BitB spawn, its URL will be hardcoded into the HTML.