daveyOsborn

joined 10 months ago
[–] daveyOsborn@infosec.pub 2 points 2 hours ago* (last edited 2 hours ago)

USB PD is also a shit show. You might want to read this:

https://goughlui.com/2025/12/01/tested-usb-c-barrel-connector-adapters-5-5mm-od-2-1-2-5mm-id/

Which shows those USB PD negotiations can get dicey. It chooses voltages thought to be close enough to what’s requested.

I’ve run into a nasty problem where a USB-C appliance needed 9v. Says in the manual something like “only use Kenwood power supplies on this device”. I thought, fuck that, USB PD is a standard for a reason. I’m not going to blow money on a proprietary OEM Kenwood USB-C PSU. Then found that many power supplies actually skip 9v. The USB PD standard makes some voltage steps optional, and some mandatory. IIRC, 9v was one of the required ones, yet it was easy to find USB-C power supplies that skipped 9v but offered 12v (or 15v, I forget). And yet 12v or 15v was one of the voltage steps that’s optional. And IIRC, the Kenwood OEM PSU /only/ did 9v, which is also not USB PD compliant, so the Kenwood PSU could not be used on other things.

So the USB PD strangely and arbitrarily makes some voltage steps optional, and manufacturers ignore the standard anyway.

I have an adapter that goes from barrel to USB-C. Recipe for disaster. Even if a 9v PSU uses that adapter and a USB-C appliance wants 9v, it will fry shit because any non-5v appliance expects to negotiate the voltage. I don’t recall how it leads to frying (I think b/c it tries to start at the 5v default before negotiating for 9v but instead it just gets hit with 9v), but the fact that there are USB-C-barrel adapters that just hardwire without the needed logic is scary.

[–] daveyOsborn@infosec.pub 1 points 3 hours ago* (last edited 2 hours ago)

So in the context of copious dumb users plugging in anything that fits the socket, the data PIN may¹ have prevented a lot of damage while at the same time enabled HP to rack in lots of money on replacement OEM proprietary PSUs. Indeed I have seen on many occasians clueless plebs at the street market selling 2nd-hand appliances and quickly trying barrels from a pile of tangled PSUs until one fits, then trying to include that with the device they are selling without looking at voltage or anything. It’s common and I’m sure lots of gear gets fried because the general population is just not smart enough.

I know how to match voltage, polarity, and current demands. And I got stung. Spent a lot of time disassembling a laptop, trying different RAM sticks, removing wifi cards and other components as I was baffled about what this fucking blicking LED means when it is not blinking in any way to convey an error code. Removed the CR2032 battery to reset the CMOS. Wondered if my slower than spec DDR3 RAM was causing this, so I went to the trouble of tracking down a RAM stick the precisely matched the specs. Still just got a steady non-stop blink, which the manual falsely states means it’s in sleep mode. So I was ready to conclude that the laptop was trapped in sleep mode and irreparably hosed. Perhaps I would have tossed a working laptop.

Whether it is a good design to protect from incorrect PSUs (despite that the obscure barrel connector is probably only 19.5v systems anyway), most certainly it’s a crappy design to not inform users. To fail to assign an error code. Sure, it vaguely says in the manual something like “use only approved HP power adapters” -- something /smart/ consumers do not take seriously because they know how to match PSUs to appliance and know that shit is always a branding hussle. The data pin should not be a secret that is concealed from both the user guide and the maintenance and service guide (which HP says is not for end users.. yet they still withhold the info from service people).

Perhaps good design as far as the PSU goes. But shitty to not document the situation and to not implement an error code.

¹ I stress /may have/ prevented damage because I have seen a lot of street market goods and only seen this obscure barrel tip on HP and Dell laptops, both of which are 19.5v.

 

cross-posted from: https://infosec.pub/post/51092505

I have a 3-pin Dell PSU spec’d as 19.5v 3.34A and DMM measures at 20v unloaded. The power reqs on the HP laptop are 19.5v 3.33A. AFAICT, that’s a match. Even the 3-pin barrel connector geometry matches. So what’s the problem?

The center pin is a “smart pin” aka “data pin”, as I came to learn. According to @over_clox@lemmy.world, this PIN basically passes brand info so HP can reject non-HP PSUs. But according to this article, the data pin is used to “regulate” the voltage -- which I take to mean it negotiates the voltage for transmission as USB-PD does. If it’s merely negotiating power reqs, then the Dell should work.

It’s possible both sources are correct.. perhaps HP has its own proprietary way of negotiating voltage and Dell has theirs.

Someone even claims that the data channel is used to communicate temp info so a PSU does not overheat. If that’s true, then perhaps it was a good design (noting that the USB-PD standard did not emerge yet).

But is it true about the communication? Considering there are hacks with a resistor or something to satisfy the data channel, it’s hard to believe that the communication is that sophisticated.

This page advises HP owners to always buy HP-branded PSUs. But it’s unclear if that’s just overly safe nonsense.

[–] daveyOsborn@infosec.pub 2 points 20 hours ago

AT&T is the worst of the worst. And I boycott them for countless reasons like snooping on their own customers voluntarily without a warrant. It’s really a hard-right corp. In any case, never tried them so I didn’t know they blocked egress 25.

One trick that works if truth-in-advertising laws are in force: ask the sales people before subscribing if the block port 25. They always say “no, we block nothing” (in my experience). So you subscribe and sign the contract. Then when you see they actually block 25, you have a false advertising situation and also a contract violation (if either verbal contracts are enforcable or if you can get it in writing that nothing is blocked). So you complain. In my experience, they give a gratis upgrade to an enterprise level of service that generally has a static IP and no blocks -- for the price of the residential plan you signed up for.

[–] daveyOsborn@infosec.pub 3 points 1 day ago* (last edited 1 day ago) (1 children)

I can’t speak for @ShutUpWesley@piefed.zip, but I boycott both Google and Microsoft. This means 95+% of prospective people, corps, and gov agencies I would exchange email with are not getting email from me. They are also not getting an email address out of me.

I have been done with email for nearly a decade now, mostly. So, to answer your question, I use fax and snail mail. Not joking. I feel liberated and don’t give a shit about postage or inconvenience. There is still that exceptional 5% or so who I will exchange email with, which does not have GAFAM in the loop.

(edit) should add that I give friends and family an XMPP address (of my own, but often I also give them an XMPP acct for themselves). Google bounced from XMPP a decade or so ago and AFAIK Microsoft has no XMPP service. So it’s mostly snail mail and fax for govs and corps. XMPP for people.

Any friends or family who resist XMPP are mostly stuffed. They can either proxy through a mutual friend or call me if they are local.

[–] daveyOsborn@infosec.pub 2 points 1 day ago

Maybe the way to fight GMail’s outsized power is to stop using GMail.

Stopping your own gmail use is trivially easy. It just scratches the surface. In order to not lick Google’s boots, you also need to stop sending email to gmail users. That means doing an MX lookup before emailing to see if their vanity email address is on a Gmail host. And of course this also means not sharing an email address with gmail users.

I do that, in fact. I also boycott Microsoft. In the end, this means I am not using email much at all.

[–] daveyOsborn@infosec.pub 1 points 1 day ago (2 children)

They claim its for spam prevention which is why most ISPs actually also block outgoing SMTP port 25.

European ISPs block egress port 25, not American ones, generally. Not sure about the rest of the world.

In Europe, one refuge is to send using the GSM networks, which tend not to block egress 25 for some reason.

[–] daveyOsborn@infosec.pub 1 points 1 day ago* (last edited 1 day ago)

Very happy to have learned about tildeverse.org. It gives a great refuge from a lot of the garbage. But I have to ask, if you are part of the tildeverse project why are you on lemmy.world, a centralised exclusive Cloudflare instance? I realise tildeverse does not have a lemmy node but there are many decent ones and LW is probably the most contrary to the tildeverse philosophies.

[–] daveyOsborn@infosec.pub 1 points 3 months ago (1 children)

Sorry for the late reply. But for the record I must say Tails does not do what I want because Tails gives clearnet access. The UI discourages it, but the possibility is there to open a browser on clearnet.

You may be right about Whonix.. I have yet to tinker with it.

[–] daveyOsborn@infosec.pub 1 points 6 months ago* (last edited 6 months ago)

I like where your head is at but this feels like an impossible stretch. If you have the technical knowledge to run Tails, you aren’t being blocked.

It’s perhaps more complex than you realise. There are several facets to this with a broad range of effects, which is not necessarily just a Tor-acceptance problem.

Tor-blocking sites do not have the decency to so much as state /why/ they have blocked you. They either send a generic “403 forbidden”, or they drop packets and it times out, or you get a broken CAPTCHA. In the latter two cases you can’t even be sure Tor is the issue. They do not treat visitors with dignity. So playing dumb when facing them is a good policy. E.g. “I could not pay my taxes on time because I get this screen:…” then go boomer on them and send a camera pic of a timed out connection. If they take some time to investigate and chase their tails a bit, that’s already a win to some extent, in some situations. We want to penalise them for not even having the decency of transparency.

It’d be like shutting off your water, locking the mechanical room, and suing your landlord

Hence why Qubes is not ideal. But if there is an OS that simply excludes clearnet, I might say (when pressed): “my friend gave me this laptop.. said it was safer than Windows”¹. But the conversation never goes that far.

The baby step micro-goal is just to get a bit of due transparency and dignity. Not “403 Forbidden” but rather “We’re sorry, we detect you are using Tor and we do not have the competency to secure against Tor users”, or “we need to track you, thus cannot accept traffic from Tor or VPNs”.

¹ Note that this scenario is becoming increasingly realistic. A local group of volunteers offers gratis advice and support for digital self-defense. Some people walk away with Tails and only a superficial idea of what they have.

 

cross-posted from: https://infosec.pub/post/41531898

I need this for political/activist purposes. When a public service blocks Tor, I want to be able to say that the public service marginalises/disservices ppl on some platforms.

My first thought was Qubes OS, because it can be setup as a Tor-only platform. The flaw of course is that users can configure it either way. So the public service would argue that it was the user’s choice to configure it to not use clearnet. If an OS were to operate purely on anonymous networks with no direct clearnet access, this would have some niche applications for activism.