Sekitar 20 hasil (1.63 detik)
Komunitas slrpnk.net

Stop using Opera Browser and Opera GX

As somebody whose wife just downloaded opera onto the family computer I am horrified. She’s been complaining that the internet is slow and has blamed it on protonvon, so has resorted to turning the vpn off when using the internet or discord. I remember after Twin Peaks season 3 came out, showtime was stating left and right how profitable the show was, and then accusations started flying that the show was so profitable because showtime was taking over the browser while people were watching and mining bitcoin in the background without telling people they were doing so. I trust Opera about a thousand times less just because I had never hears of them until a week or two ago.

Komunitas mastodon.uno

Il sito di Xubuntu è stato hackerato e fino a qualche ora fa cliccando sul download delle ISO veniva servito un archivio "Xubuntu-Safe-Download.zip” contenente un malware.

Il sito di Xubuntu è stato hackerato e fino a qualche ora fa cliccando sul download delle ISO veniva servito un archivio "Xubuntu-Safe-Download.zip” contenente un malware. Ora il download non è più disponibile, probabilmente stanno riprendendo controllo nel sito. Virustotal: https://www.virustotal.com/gui/file/0f59f553fcfac3cac07aa7986eac914be069a6dd407b2d9f761f11d3e865b4f6 @linux #linux #xubuntu

Komunitas lemmy.world

Linux is not ready

I mean, I was able to figure out how MS-DOS worked as a child just be flailing on the keyboard and reading the errors. It was “easy” because now I know it while Macintoshes may as well have been alien technology. A “mouse”?, moving windows?, you have to find programs and click on them instead of just typing? You’re just used to Windows annoyances and not used to Linux annoyances, that’s all. For example: Installing and updating a program on Windows is a horror show compared to using a package manager. It expects average users to find, download and run executable files from the Internet and conditions them to approve elevation for anything that asks. If Windows breaks, how do you troubleshoot it? Maybe Google knows, maybe rebooting fixes it, if not then possibly re-installing the entire OS. It’s so bad that if you work with Windows clients you probably already have an image of a Windows install because troubleshooting is so much of a pain it’s easier to just completely re-image the machine. Don’t even get me started on how often Microsoft changes the layout of administration tools and system menus or their tendency to change the name of various system components for no logical reason. I don’t think Linux is for everyone, but only because most everyone already has years of Windows experience and forgets all of the frustration and learning. If you used Linux for just as long as you’ve used Windows, then editing fstab would seem as trivial a task as pinning an item to the ~~start bar~~ taskbar, or ~~launching a program~~ starting an app from the ~~system tray~~ ~~notification area~~ system tray.

Komunitas lemmy.dbzer0.com

Do y'all still consider the machine you run pirated software/games on to still be "Secure"? [+ Other Piracy Related Questions]

When engaging in criminal activity, you have no “legal” recourse for malicious behavior, so you work on the web of trust instead. If you can’t trust the software, nor the publisher, nor the hash verified by however many seeders, then don’t download it in the first place. Me personally, considering I install indie porn games on the regular and never once gotten a virus that I know of, I think it’s worth it to trust others. Of course you could always go into paranoid zero trust mode but sometimes being a social being means trusting the criminal serving you free shit isn’t ratfucking your data

Komunitas lemmy.world

These Are The Most Useful Linux Apps I Discovered in 2024

| Software | Description | |-----------------------|-----------------------------------------------------------------------------| | LocalSend | Open-source AirDrop alternative for transferring files wirelessly via Wi-Fi. | | Obfuscate | Rust-based app for quick and intuitive redactions on sensitive photos. | | Floorp Browser | Privacy-focused browser forked from Firefox with customizable workspaces. | | Dosage | Medication management app with reminders and inventory tracking. | | AB Download Manager | Cross-platform downloader supporting batch downloads and browser integration. | | Cartridges | Game launcher supporting multiple platforms and sources like Steam and Lutris. | | Zen Browser | Firefox-based browser with innovative tab management and split-view mode. | | RustDesk | Secure, cross-platform remote desktop client with self-hosting capability. |

Komunitas beehaw.org

Is crate fnmatch-regex2 a scam?

https://crates.io/search?q=fnmatch https://crates.io/crates/fnmatch-regex at version v0.2.1, repository: https://gitlab.com/ppentchev/fnmatch-regex-rs https://crates.io/crates/fnmatch-regex2 at version v0.4.0, repository: https://gitlab.com/brmmm3/fnmatch-regex2-rs (DO NOT SIGN IN, UNTIL WE KNOW ITS SAFE) I was looking through some crates and noticed there is “fnmatch-regex2”, just below “fnmatch-regex”. The second one is newer; 4 months ago updated, compared to the original 12 months ago updated. And it has more recent downloads and a “higher version number”. My first thought was, this either adds new functionality, or the old one is abandoned maybe? Looking in readme and documentation, I could not find anything that describes the differences. Looking at the source code on Gitlab, the first crate just shows it normally to me, but the second wants me to log in. My alarm glocks go on. Even the changelog for both are identical at version 0.2.1 (the original crate 1) without any word about changes, but the crate repository shows it should be at version v0.4.0. I would like to know what you guys think about it. I can’t even audit the code right now, even if its the same Gitlab instance on gitlab.com. Should this be reported? Or am I just paranoid? EDIT: After asking in Discord, someone said I can view the source code in Docs.rs: https://docs.rs/crate/fnmatch-regex2/0.4.0/source/ . This is much better, but I am still cautious. I still don’t know what the actual changes are and would need to dive into the code and compare to find out. Which is not really something I expect to do from a trustful library.

Komunitas lemmy.ml

How many Lemmy users are non-technical background?

Not technical at all, I work in Learning & Development at a company. I am always reading the comments and try to learn, but sometimes I have really no clue what you guys are talking about haha! Yesterday someone was expleaning about adblocker and all the comments were like: “Yeah, who can live without it…” Well, me I guess? And I saw one that was highly recommended so I downloaded it, because why not try it out right? But apparently it’s not for your phone. Or I didn’t have the right app to support it on my phone. I was thinking about asking it in the comments of the thread, but like you said: I think a lot of people here have a tech background and although everyone is very nice, I think the explanation might go over my head. I don’t want to give people the feeling I get when I’m trying to explain to my mom over the phone how she can e-mail a file on her computer. It can be very frustrating ;)

Komunitas lemdro.id

The first time I see F-Droid mentioned in a public infosec TG channel on russian of all languages

Translation of the key fragment: ❗️To protect yourself, download apps only from trusted sources. RuStore is the official Russian app store, created with the support of VK and the Russian Ministry of Digital Development. Every RuStore app undergoes a security check to ensure it meets requirements before being published. Google Play, Galaxy Store, Huawei AppGallery, and F-Droid also conduct security checks. Of all these mentioned alternatives, the last one isn’t pre-installed and obviously has a smaller reach akin to fediverse, yet it’s there, so it’s a little win I guess. If that geeky obscure international FOSS appstore got cheered by national infosec persons who naturally enjoy localization, it says a lot. It’s a genuine praise from an unlikely place. I generally trust that channel, mostly for their simple guides you can send to your parents and kids about a recent scam scheme. Sometimes it reeks of propaganda, as you could’ve noticed with 90% of that quote being about the RuStore thing I personally can’t trust. But for ru-speaking fellas it’s probably worth bearing with it.

Komunitas lemmy.dbzer0.com

The first time I see F-Droid mentioned in a public infosec TG channel on russian of all languages

Translation of the key fragment: ❗️To protect yourself, download apps only from trusted sources. RuStore is the official Russian app store, created with the support of VK and the Russian Ministry of Digital Development. Every RuStore app undergoes a security check to ensure it meets requirements before being published. Google Play, Galaxy Store, Huawei AppGallery, and F-Droid also conduct security checks. Of all these mentioned alternatives, the last one isn’t pre-installed and obviously has a smaller reach akin to fediverse, yet it’s there, so it’s a little win I guess. If that geeky obscure international FOSS appstore got cheered by national infosec persons who naturally enjoy localization, it says a lot. It’s a genuine praise from an unlikely place. I generally trust that channel, mostly for their simple guides you can send to your parents and kids about a recent scam scheme. Sometimes it reeks of propaganda, as you could’ve noticed with 90% of that quote being about the RuStore thing I personally can’t trust. But for ru-speaking fellas it’s probably worth bearing with it.

Komunitas ibbit.at

The Shock of the Obvious: Australia’s University Oligarchs

Photograph Source: Kgbo – CC BY-SA 4.0 It’s always comforting to hear politicians reveal wisdoms and novel notions long known to those who vote for them. This tendency endears the dim rascals to you, showing an ignorance that remains, for the most part, unblemished. If we get democracy, as H. L. Mencken would put it, we are going to get it most deservingly hard. But that hardness will be veiled in fully fledged ignorance. The issue of how universities in Australia are governed is a case in point. A system corrupt, riven and sundered by rapacious bureaucratic arrangements, governed by a smug white collar criminal class that deserves abomination and execration, finally made it to Australia’s parliament for scrutiny. Politicians were made aware of a deep rot in higher education. They seemed shocked by the obvious. The interim report by the Senate Education and Employment Legislation Committee at least serves to point the finger at a particular administrative stratum that blights university education in the country. The words of the chair, Labor Senator Marielle Smith, should shock and disgust: “Universities are public institutions, established for the public good. Their governance arrangements, and the remuneration of their senior executives, should reflect that – yet we’ve heard that more than 300 university executives earn more than their state premiers.” Senator Smith would seem to have been born yesterday. The theme through the report follows the same beat of revelation. The committee finds itself transfixed by the idea of a “gap” or “gaps” between subsidised managers on the one hand, and the exploited students and work horse staff on the other. (The words appear no fewer than 23 times in the report.) “The gap between universities’ perceptions of their governance processes and the experiences described by university staff and students was striking.” Here, we have a glaring problem of terminology. The first stems from the plodding administrators who have appropriated the term and convinced those in Canberra that they are somehow part of an ancient lineage of teaching and learning. The university staff and students are, by definition, not the university. A true triumph of the marketer’s dark art. There is also “a gap between policy and practice” with regards “matters of transparency and the management of conflicts of interest across multiple universities.” Those submitting reports to the inquiry were particularly concerned “about the transparency of council decision-making and university finances (including the use of consultants), as well as the handling of freedom of information (FOI) requests by universities.” The submission by the University Chancellors Council, for its part, was coy. The committee noted “one allusion to problems in the sector”. The words of the UCC are hardly worth recounting, except to identify culpability. And the culpable always claim to be credible when found out: “Robust systems of governance, while an antidote to failure in process, are not infallible and UCC is committed to continuous improvement in governance systems.” No sycophantic hack could have said it better. The problems of the Australian tertiary system are profound. The committee received evidence from staff and students showing their near inconsequential role in the making of decisions of the university before the autocratic whims of University Councils. The corollary of such inconsequentiality lay in those 306 university executives with Himalayan salaries who have proliferated like fungi in moist climes. The committee specifically noted a submission by Dr. Lionel Page, who remarked that the number of senior management positions at Australian universities between 1997 and 2017 “increased by over 110 per cent, while middle management roles grew by 122 per cent.” The pool of support staff, however, dried up by 70 per cent over the same period. University vice-chancellors earn more money than Cabinet ministers, the Prime Minister and the Premiers of state. Ditto the fat clutch of acquisitive deputy executives with nebulous titles who have little to do with classrooms, teaching and research. To put it into context: political representatives can send people to their deaths, declare wars and emergencies and be voted out on relatively lower levels of remuneration; the supposed magistrates of education can, on a fatter package, enact dreadful policies with impunity and never fear a collective vote of the university body that might terminate their tenure. Things would not be quite so ghastly were some of the administrators capable. We know this not to be the case. These tertiary education plodders are a formidable example of the Peter Principle in grim action, one expounded in the book by that name in 1969: those in any organisational hierarchy rise to levels of “respective incompetence”. What we see in place is an oligarchy of oafs. How, then, does the report address this problem? The twelve recommendations include improvements to transparency and accountability (for instance, publishing the minutes of all council meetings and publicly disclosing the expenses for consultants, along with reasons for hiring them); greater involvement of staff and students in “meaningful consultation” before the making of important decisions; ensuring that governing bodies have a minimum proportion of elected representatives and those with “public administration and higher education expertise”; and giving the otherwise benign Tertiary Education Quality and Standards Agency (TEQSA) necessary powers to investigate breaches of the Higher Education Standards Framework and enforce compliance. The fourth recommendation by the committee urges the Australian government to work with the Remuneration Tribunal and states and territories to create a mechanism that will assess the appropriate salaries for vice-chancellors and senior executives. Unfortunately, the report still approves of university councils setting that remuneration within the devised classification. History shows that university councils, unless they are utterly reformed, cannot be trusted with such a task. In her response to the interim report, the unchallenging Alison Barnes of the National Tertiary Education Union, more comatose inducing than threatening to university managers, approved something her organisation could do more about. “We strongly welcome the committee’s recommendations to boost transparency, cap vice-chancellor salaries, reform university councils, and strengthen the regulatory TEQSA.” The report, now written, risks suffering the lonely fate of others. The vice-chancellors and senior executives will drag their feet and ensure that change will be glacially slow, preferably non-existent. In the absence of regulations with true bite and an anti-corruption body with specific expertise on the wily, venal nature of the modern university, ideas for reform will suffer withering neglect. The post The Shock of the Obvious: Australia’s University Oligarchs appeared first on CounterPunch.org. From CounterPunch.org via this RSS feed

Komunitas ibbit.at

Chop Wood, Carry Water 10/13

Download this and other protest sign idea GIFs here. Hi, all, and happy Monday. Also happy Indigenous People’s Day! I recognize that, as it’s a federal holiday, not everyone wants to do activism today. If you do, however, I’ve got you covered! There’s a ton going on, as usual. The great news is that the hostages have been released and a ceasefire formally begun. Thank God for it. Aid is also flowing into Gaza, which is a huge relief. What happens in the weeks to come is less clear, and I’m not especially sanguine for the long-term safety of the Palestinian people, but we’ll take it as it comes. It’s a wonderful thing to see hostages returning to their families and starving people fed. We’ll leave it there for today. On the domestic front, which is where this newsletter is, after all, focussed, things are both chaotic and strangely static. First, the chaos: The Trump administration fired a bunch of CDC employees on Friday, then said it was a mistake and reversed the firings on Saturday. They fired thousands of other people, too, including hundreds from a key department at the Board of Education (more on that below). J.D. Vance went on the Sunday shows and absolutely humiliated himself. Adelita Grijalva still hasn’t been sworn in. We still haven’t seen the Epstein files. And so much more, of course. On the static front, no progress has been made—as in NONE—on reopening the government, because House Republicans are still “boycotting” Congress. Remind me next time I have a day job that if I don’t feel like working I’ll just declare I’m boycotting and put my feet up. It’s insane. Cracks are, however, starting to show. Marjorie Taylor Greene went on another rant about not just high healthcare prices, but our dismal economic state in general, and at least some Republican Congressmembers are now calling for Mike Johnson to swear Grijalva in. We’ll see where all of that leads. There’s so much more, but we’re here to do work, not to recap every nutty thing happening in the news. I will only say that the resistance is flourishing and expanding everywhere. Portland had a huge “Emergency Naked Bike Ride” in the pouring rain to protest ICE and the National Guard yesterday; inflatable animal costumes have made their way to Chicago, and everywhere we are hearing stories (I found this one particularly inspiring) of besieged communities standing up for each other. We’re going to get through this, folks. Make sure you do something nice for yourself today! Let’s get to work. Call Your Senators (find yours here) 📲 and Your House Rep (find yours here) 📲 Hi, I’m a constituent calling from [zip]. My name is ______. First, I understand that the Trump administration conducted over 4,000 firings on Friday. Among them were the firings of almost everyone in the the office responsible for overseeing special education at the Department of Education. This is outrageous and very likely illegal. To decimate the office responsible for safeguarding the rights of infants, toddlers, children and youth with disabilities is unconscionable. I want these firings reversed and I want Congress to take its power back from this vicious, chaotic and inept Executive branch. Also, Republicans need to come back to work, sit down with Democrats, and pass a bill that permanently extends the ACA premium tax cuts, prevents any increases in our healthcare costs, and restores the power of the purse to Congress. Thanks. Extra Credit ✅ Let’s call Mike Johnson’s office. ‭(202) 225-4000‬ or ‭(318) 840-0309‬ or ‭(337) 423-4232‬ or ‭(318) 497-6610‬. Script: My name is _____ and I’m calling Rep. Johnson in his capacity as Speaker of the House. I am absolutely furious that he is refusing to bring the House back into session or negotiate with Democrats in any way, and I’m outraged that he hasn’t yet sworn in Adelita Grijalva. He needs to bring Republicans back from vacation, work out a deal to permanently extend the ACA premium tax cuts, swear in Ms. Grijalva, and end this Republican shutdown NOW. We’re tired of the lies, the deflection, and the Epstein coverups. Tell him to do his job. Thanks. Get Smart! 📚 Join BigTentUSA on Tuesday, October 14 at 7pm ET as they examine how media paywalls, profit models, and political timidity have left the public misinformed and disengaged—and what we can do to fix it. Donald Trump’s return to the White House has placed American businesses in the crosshairs of an escalating battle over democracy, speech, and public accountability. From the high-profile suspension and reinstatement of Jimmy Kimmel to the mounting backlash against companies perceived as caving to political pressure, the stakes for business leaders have never been higher. Daniella Ballou-Aares, Founder and CEO of Leadership Now Project, and Heidi Przybyla, Founder and President of Get Real News, will unpack the dynamics between political power, private media’s business interests, and civil society. They will also explore how media companies can—and should—rebuild the public’s trust, expand access, and create news that truly serves the people. Please use this link to register. Messaging! Messaging! Messaging! 📣 The awesome newsletter posted this excellent piece about what a protest sign should and shouldn’t convey. It has a long list of suggested messages—so helpful for those of us who never know what to write! These protests are, among other things, a massive messaging and recruitment opportunity. Let’s use it! Reframing AmericaThe Big List of Protest Signs for #NoKings 10/18We protest because we strenuously object to the illegal and unconstitutional actions of this administration, but we should try our best to frame our messaging in terms of what we are FOR instead of what we are against. It is more effective persuasion…Read more6 days ago · 2446 likes · 251 comments · Antonia Scatton Give 💰! We are halfway to our 25K goal in Virginia and y’all that money is needed SO BADLY! Abigail Spanberger has likely raised tons of money but statehouse candidates have a way harder time doing so, even though their races are so very important, too! Please give any amount if. you can, and please, please share this link with people who want to help but prefer giving money to taking action. Win Races! 🗳 Posting this one last time because this is SUCH an easy way to help! Help the fight for YES on Prop 50 with super-easy-to-do postcards that only require 3 words of handwriting (” Dear Sally” and your signature) and come with pre-printed address labels! Cards come in packs of 250, and can be completed by most people in less than 3 hours per pack. You provide postage of 78 cents per card. We will mail packs of cards anywhere in US. Contact me, Geri ([email protected]) if you can help! ➡️ Please note: Because these cards are jumbo size, they require a 1st class postage stamp—not a postcard stamp! ⬅️ Resistbot Letter (new to Resistbot? Go here! And then here.) 💻 [To: all 3 reps] [H/T ] [Text SIGN PVPIJA to 50409, or to @Resistbot on Apple Messages, Messenger, Instagram, or Telegram] (Note that for the most effective RESISTBOT it’s best to personalize this text. More about how to do this here. But if you’re short on time just send it as is using the above code.) I’m writing to urge you to oppose any move by the Trump regime to privatize or sell off federally held student loans. This plan would turn the futures of millions of Americans into a Wall Street investment product — and it comes at a time when the Consumer Financial Protection Bureau has been stripped of much of its power to protect borrowers. Selling federal student loans to private investors would wipe out vital protections like income-based repayment, forgiveness programs, and hardship relief. Once these loans are in private hands, collection practices will become profit-driven, not people-focused. Borrowers would be hounded for payments, interest rates could rise, and the same kind of predatory lending that caused the 2008 crash could return unchecked. It’s one thing to tighten budgets; it’s another to sell out Americans trying to better themselves through education. Strong nations invest in their citizens. We can promote responsibility without handing over our children’s debt to corporate speculators who care more about quarterly returns than the country’s future. Congress must act now to prohibit the sale or privatization of federal student loans, restore full consumer-protection oversight, and ensure that higher education remains a ladder up — not a trap. Protecting hard-working Americans from exploitation should never be a partisan issue. OK, you did it again! You’re helping to save democracy! You’re amazing. Talk soon. Jess Chop Wood, Carry Water is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber. Share Leave a comment From Chop Wood, Carry Water via this RSS feed

Komunitas ibbit.at

This Week in Security: ID Breaches, Code Smell, and Poetic Flows

Discord had a data breach back on September 20th, via an outsourced support contractor. It seems it was a Zendesk instance that was accessed for 58 hours through a compromised contractor user account. There have been numbers thrown around from groups claiming to be behind the breach, like 1.6 Terabytes of data downloaded, 5.5 million user affected, and 2.1 million photos of IDs. Discord has pushed back on those numbers, stating that it’s about 70,000 IDs that were leaked, with no comments on the other claims. To their credit, Discord has steadfastly refused to pay any ransom. There’s an interesting question here: why were Discord users’ government issued IDs on record with their accounts? The answer is fairly simple: legal compliance. Governments around the world are beginning to require age verification from users. This often takes the form of a scan of valid ID, or even taking a picture of the user while holding the ID. There are many arguments about whether this is a good or bad development for the web, but it looks like ID age verification is going to be around for a while, and it’ll make data breaches more serious. In similar news, Salesforce has announced that they won’t be paying any ransoms to the group behind the compromise of 39 different Salesforce customers. This campaign was performed by calling companies that use the Salesforce platform, and convincing the target to install a malicious app inside their Saleforce instance. Unity [RyotaK] from Flatt Security found an issue in the Unity game engine, where an intent could influence the command line arguments used to launch the Unity runtime. So what’s an intent? On Android, an Intent is an object sent between applications indicating an intention. It’s an intra-process messaging scheme. So the problem here is that when sending an intent to a Unity application on Android, a command line option can be included as an extra option. One of those command line options allows loading a local library by name. Since a malicious library load results in arbitrary code execution, this seems like a pretty big problem. At first it seems that this doesn’t gain an attacker much. Doesn’t a malicious app already need to be running on the device to send a malicious intent? The reality is that it’s often possible to manipulate an innocent app into sending intents, and the browser is no exception. The bigger problem is that a malicious library must first be loaded into a location from which the Unity app can execute. It’s a reasonably narrow window for practical exploitation, but was still scores an 8.4 severity. Unity has released fixes for versions all the way back to 2019.1. Code Smell: Perl? We have two stories from WatchTwr, packed full of the sardonic wit we have to expect from these write-ups. The first is about Dell’s UnityVSA, a Virtual Storage Appliance that recently received a whole slew of security fixes for CVEs. So WatchTowr researchers took a look at the patch set from those fixes, looking for code smell, and found… Perl? Turns out it wasn’t the presence of Perl that was considered bad code smell, though I’m sure some would argue that point. It was the $exec_cmd variable that wasn’t escaped, and Perl backticks were used to execute that string on the system. Was there a way to inject arbitrary bash commands into that string? Naturally, there is. And it’s a reasonably simple HTTP query to run a command. A security advisory and updated release was published by Dell at the end of July, fixing this issue. Poetic Flow of Vulnerabilities There’s an active exploitation campaign being waged against Oracle E-Business Suite instances, using a zero-day vulnerability. This exploit works over the network, without authentication, and allows Remote Code Execution (RCE). It appears that a threat group known as Graceful Spider, another great name, is behind the exploitation. The folks at WatchTowr got their hands on a Proof of Concept, and have reverse engineered it for our edification. It turns out it’s a chain of little weaknesses that add up to something significant. It starts with a Server-Side Request Forgery (SSRF), a weakness where a remote service can be manipulated into sending an additional HTTP request on to another URL. This is made more significant by the injection of a Carriage Return/Line Feed (CRLF) attack, that allows injecting additional HTTP headers. Another quirk of the PoC is that it uses HTTP keep-alive to send all of the malicious traffic down a single HTTP session. And the actual authentication bypass is painfully classic. A /help path doesn’t require authentication, and there is no path traversal protection. So the SSRF connection is launched using this /help/…/ pattern, bypassing authentication and landing at a vulnerable .jsp endpoint. That endpoint assembles a URL using the Host: header from the incoming connection, and fetches and parses it as an eXtensible Stylesheet Language (XSL) document. And XSL documents are unsafe to load from untrusted sources, because they can lead directly to code execution. It’s a wild ride, and a great example of how multiple small issues can stack up to be quite significant when put together. Bits and Bytes Caesar Creek Software did an audit on a personal medical device and found issues, but because fixes are still being reviewed by the FDA, we don’t get many details on what exactly this is. Reading between the lines, it sounds like a wearable glucose monitor. It’s based on the nRF52 platform, and the best bit of this research may be using power line fault injection to get Single Wire Debug access to the MCU. They also found what appears to be a remote leak of uninitialized memory, and a Bluetooth Low Energy Man in the Middle attack. Interesting stuff. And finally, [LaurieWired] has a great intro to the problem of trusting trust with a bit of bonus material on how to build and obfuscate quines while at it. How do you know your compiler binary doesn’t have malware in it? And how do you establish trust again? Enjoy! From Blog – Hackaday via this RSS feed

Komunitas lemmy.dbzer0.com

Premier Pro - ACCEPT TERMS POPUP - (NON-AGS-RELATED)

Hi everyone, I tried to patch Premier Pro but with no success, I’m only posting a post here because the confirmation email link from Stoat (previously Revolt) doesn’t work -> Error 404). And I therefore cannot follow the steps there per previous post on the topic. Here are the steps I did updated CC to latest version Turned off Windows 11 Defender downloaded GenP 3.6.9 (Binary), opened as Admin Patched CC Opened CC, downloaded Premier Closed CC File > Quit CC Opened GenP 3.6.9 as Admin, Searched > Patched > Unpacked > Searched, Patch (Logs bellow as Logs 1) Opened Premier Pro from the windows search bar, and the TOS message still pops up (weirdly it’s poping in French, but my system is US English (tho I can read French) Realized “Always Search for ACC” was left checked Searched and Patched again -> Logs 2 Agree to Condition message still pops up WinTrust Clicked Toggle WinTrust > Untrust -> Nothing happened Toggle Reg Key > Nothing happened Agree to Condition message still pops up Posting now after having restarted the PC. I will move on to the Hostfiles firewall tmr, as I’m out of time tonight. If you see any mistakes please let me know, I appreciate your help and patience ! Logs 1: Logs: Activity Log GenP Version: 3.6.9 - CGP Config Version: 3.6.9 - CGP Unpacking 1 file(s): Processing: C:\Program Files\Adobe\Adobe Premiere Pro 2025\RuntimeInstaller.dll Successfully unpacked: C:\Program Files\Adobe\Adobe Premiere Pro 2025\RuntimeInstaller.dll Unpack process completed. 1 file(s) successfully unpacked and can now be patched. 31 File(s) were found in 17 second(s) Checking File: dvaappsupport.dll - using Custom Patterns Searching for: TeamProjectEnabler: 488379???740A488379???7403B001C332C0C3 Searching for: TeamProjectEnabler2: 488D4B08FF15???004885C07408B0014883C4205BC332C04883C4 Replacing with: 488D4B08FF15FA1213004885C07408B0014883C4205BC3B0014883C4 C:\Program Files\Adobe\Adobe Premiere Pro 2025\dvaappsupport.dll File patched by GenP 3.6.9 - CGP + config 3.6.9 - CGP MD5 Checksum: 0x188C12DE04348520C0B8890922F17966 Checking File: Registration.dll - using Default Patterns Searching for: Banner: 72656C6174696F6E7368697050726F66696C65 Replacing with: 78656C6174696F6E7368697050726F66696C65 Searching for: Banner2: 000000000000000072656C6174696F6E Replacing with: 000000000000000078656C6174696F6E Searching for: CmpEax61: 8B??85C074??83F80674???83???007D Searching for: CmpEax62: 8B??85C074??83F80674???83???007D Searching for: CmpEax63: 8B???85C074??83F80674???83???007D Replacing with: C743200300000083F806740048837B5800EB Searching for: CmpEax64: 8B???85C074??83F80674???83???007D Searching for: Good1: C7???1045???45???33??48???FF15 Searching for: Profile1: 00007504488D4850 Searching for: Profile2: 00007504488D5050 Replacing with: 00007500488D5050 Searching for: ProfileExpired1: 85C075???75??B892010000E9 Searching for: ProfileExpired3: 85C075???75??B892010000E9 Searching for: ProfileExpired4: 488D4D??483B??0F???000048???4889??4885C9 Searching for: ProfileExpired5: 488B0B4889034885C974??BA04000000E8???B00148 Searching for: ProfileExpired6: E8???4885C974??BA04000000E8???4C8D5C Searching for: ProfileExpired7A: 75??8D4E18E8???4889442420488BD04885C00F84??050000 Searching for: ProfileExpired7B: 75??8D??18E8???488BD048894424384885C00F84??040000 Searching for: ProfileExpired7C: 75??B918000000E8???488945C0488BD04885C00F84??050000 Replacing with: 6690B918000000E8FEA21400488945C0488BD04885C0660F1F440000 Searching for: ProfileExpired7D: 75??8D4E18???488BD048???4885C00F84??050000 Searching for: ProfileExpired7E: 75??8D4F18E8???48894424200F57C00F1100C7 Searching for: ProfileExpired8A: 00C740??01000000???488908C740109201 Replacing with: 00C7400801000000C7400C01000000488908C740100000 Searching for: ProfileExpired8B: 00C740??01000000???01488908488D4810C7019201???0F84 Searching for: ProfileExpired8C: 75??8D4F18E8???0F57C00F110048???48890848???C70192010000 Searching for: ValidateLicense1: 83F80175??BA94010000 Searching for: ValidateLicense2: 83F8040F95C281C293010000 Replacing with: 83F8040F95C2BA0000000090 Searching for: ValidateLicense3: 83F8040F95C181C193010000 C:\Program Files\Adobe\Adobe Premiere Pro 2025\Registration.dll File patched by GenP 3.6.9 - CGP + config 3.6.9 - CGP MD5 Checksum: 0x912A9BE9254B7AFD69D2C8866095491D Checking File: RuntimeInstaller.dll - using Custom Patterns Searching for: Good1: C7???1045???45???33??48???FF15 Replacing with: C7442420010000004533C94533C033D2488D0D5FFD2100FF15 C:\Program Files\Adobe\Adobe Premiere Pro 2025\RuntimeInstaller.dll File patched by GenP 3.6.9 - CGP + config 3.6.9 - CGP MD5 Checksum: 0x46FA89E3093F4CB55E8E2C421F8D27A1 Checking File: SweetPeaSupport.dll - using Custom Patterns Searching for: HevcMpegEnabler3: FF50??0FB6 Replacing with: FFC0900FB6 Replacing with: FFC0900FB6 Replacing with: FFC0900FB6 Replacing with: FFC0900FB6 Replacing with: FFC0900FB6 Replacing with: FFC0900FB6 Replacing with: FFC0900FB6 Searching for: HevcMpegEnabler4: FF50???0FB6 C:\Program Files\Adobe\Adobe Premiere Pro 2025\SweetPeaSupport.dll File patched by GenP 3.6.9 - CGP + config 3.6.9 - CGP MD5 Checksum: 0x4245B6E3DE219AA94C5569DB74E719C4 Checking File: 4.js - using Custom Patterns Searching for: JS5: 52656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 C:\Program Files\Adobe\Adobe Premiere Pro 2025\UXP\plugins\com.adobe.ccx.start\js\4.js File patched by GenP 3.6.9 - CGP + config 3.6.9 - CGP MD5 Checksum: 0xD486FE8B5D93D8B4E93A5DD95CFEF73B Checking File: manifest.json - using Custom Patterns Searching for: Version1: 6363782E7374617274222C0A20202276657273696F6E223A2022??2E Replacing with: 6363782E7374617274222C0A20202276657273696F6E223A2231302E Searching for: Version2: 6363782E7374617274222C0A20202276657273696F6E223A2022???2E C:\Program Files\Adobe\Adobe Premiere Pro 2025\UXP\plugins\com.adobe.ccx.start\manifest.json File patched by GenP 3.6.9 - CGP + config 3.6.9 - CGP MD5 Checksum: 0x9C5E1829185A47A896349883EE409AC0 Logs 2 Activity Log GenP Version: 3.6.9 - CGP Config Version: 3.6.9 - CGP Unpacking 1 file(s): Processing: C:\Program Files\Adobe\Adobe Premiere Pro 2025\RuntimeInstaller.dll Successfully unpacked: C:\Program Files\Adobe\Adobe Premiere Pro 2025\RuntimeInstaller.dll Unpack process completed. 1 file(s) successfully unpacked and can now be patched. 31 File(s) were found in 17 second(s) Checking File: dvaappsupport.dll - using Custom Patterns Searching for: TeamProjectEnabler: 488379???740A488379???7403B001C332C0C3 Searching for: TeamProjectEnabler2: 488D4B08FF15???004885C07408B0014883C4205BC332C04883C4 Replacing with: 488D4B08FF15FA1213004885C07408B0014883C4205BC3B0014883C4 C:\Program Files\Adobe\Adobe Premiere Pro 2025\dvaappsupport.dll File patched by GenP 3.6.9 - CGP + config 3.6.9 - CGP MD5 Checksum: 0x188C12DE04348520C0B8890922F17966 Checking File: Registration.dll - using Default Patterns Searching for: Banner: 72656C6174696F6E7368697050726F66696C65 Replacing with: 78656C6174696F6E7368697050726F66696C65 Searching for: Banner2: 000000000000000072656C6174696F6E Replacing with: 000000000000000078656C6174696F6E Searching for: CmpEax61: 8B??85C074??83F80674???83???007D Searching for: CmpEax62: 8B??85C074??83F80674???83???007D Searching for: CmpEax63: 8B???85C074??83F80674???83???007D Replacing with: C743200300000083F806740048837B5800EB Searching for: CmpEax64: 8B???85C074??83F80674???83???007D Searching for: Good1: C7???1045???45???33??48???FF15 Searching for: Profile1: 00007504488D4850 Searching for: Profile2: 00007504488D5050 Replacing with: 00007500488D5050 Searching for: ProfileExpired1: 85C075???75??B892010000E9 Searching for: ProfileExpired3: 85C075???75??B892010000E9 Searching for: ProfileExpired4: 488D4D??483B??0F???000048???4889??4885C9 Searching for: ProfileExpired5: 488B0B4889034885C974??BA04000000E8???B00148 Searching for: ProfileExpired6: E8???4885C974??BA04000000E8???4C8D5C Searching for: ProfileExpired7A: 75??8D4E18E8???4889442420488BD04885C00F84??050000 Searching for: ProfileExpired7B: 75??8D??18E8???488BD048894424384885C00F84??040000 Searching for: ProfileExpired7C: 75??B918000000E8???488945C0488BD04885C00F84??050000 Replacing with: 6690B918000000E8FEA21400488945C0488BD04885C0660F1F440000 Searching for: ProfileExpired7D: 75??8D4E18???488BD048???4885C00F84??050000 Searching for: ProfileExpired7E: 75??8D4F18E8???48894424200F57C00F1100C7 Searching for: ProfileExpired8A: 00C740??01000000???488908C740109201 Replacing with: 00C7400801000000C7400C01000000488908C740100000 Searching for: ProfileExpired8B: 00C740??01000000???01488908488D4810C7019201???0F84 Searching for: ProfileExpired8C: 75??8D4F18E8???0F57C00F110048???48890848???C70192010000 Searching for: ValidateLicense1: 83F80175??BA94010000 Searching for: ValidateLicense2: 83F8040F95C281C293010000 Replacing with: 83F8040F95C2BA0000000090 Searching for: ValidateLicense3: 83F8040F95C181C193010000 C:\Program Files\Adobe\Adobe Premiere Pro 2025\Registration.dll File patched by GenP 3.6.9 - CGP + config 3.6.9 - CGP MD5 Checksum: 0x912A9BE9254B7AFD69D2C8866095491D Checking File: RuntimeInstaller.dll - using Custom Patterns Searching for: Good1: C7???1045???45???33??48???FF15 Replacing with: C7442420010000004533C94533C033D2488D0D5FFD2100FF15 C:\Program Files\Adobe\Adobe Premiere Pro 2025\RuntimeInstaller.dll File patched by GenP 3.6.9 - CGP + config 3.6.9 - CGP MD5 Checksum: 0x46FA89E3093F4CB55E8E2C421F8D27A1 Checking File: SweetPeaSupport.dll - using Custom Patterns Searching for: HevcMpegEnabler3: FF50??0FB6 Replacing with: FFC0900FB6 Replacing with: FFC0900FB6 Replacing with: FFC0900FB6 Replacing with: FFC0900FB6 Replacing with: FFC0900FB6 Replacing with: FFC0900FB6 Replacing with: FFC0900FB6 Searching for: HevcMpegEnabler4: FF50???0FB6 C:\Program Files\Adobe\Adobe Premiere Pro 2025\SweetPeaSupport.dll File patched by GenP 3.6.9 - CGP + config 3.6.9 - CGP MD5 Checksum: 0x4245B6E3DE219AA94C5569DB74E719C4 Checking File: 4.js - using Custom Patterns Searching for: JS5: 52656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 Replacing with: 58656C6174696F6E7368697050726F66696C65 C:\Program Files\Adobe\Adobe Premiere Pro 2025\UXP\plugins\com.adobe.ccx.start\js\4.js File patched by GenP 3.6.9 - CGP + config 3.6.9 - CGP MD5 Checksum: 0xD486FE8B5D93D8B4E93A5DD95CFEF73B Checking File: manifest.json - using Custom Patterns Searching for: Version1: 6363782E7374617274222C0A20202276657273696F6E223A2022??2E Replacing with: 6363782E7374617274222C0A20202276657273696F6E223A2231302E Searching for: Version2: 6363782E7374617274222C0A20202276657273696F6E223A2022???2E C:\Program Files\Adobe\Adobe Premiere Pro 2025\UXP\plugins\com.adobe.ccx.start\manifest.json File patched by GenP 3.6.9 - CGP + config 3.6.9 - CGP MD5 Checksum: 0x9C5E1829185A47A896349883EE409AC0 28 File(s) were found in 12 second(s) Checking File: dvaappsupport.dll - using Custom Patterns Searching for: TeamProjectEnabler: 488379???740A488379???7403B001C332C0C3 Searching for: TeamProjectEnabler2: 488D4B08FF15???004885C07408B0014883C4205BC332C04883C4 C:\Program Files\Adobe\Adobe Premiere Pro 2025\dvaappsupport.dll No patterns were found or file already patched. Checking File: Registration.dll - using Default Patterns Searching for: Banner: 72656C6174696F6E7368697050726F66696C65 Searching for: Banner2: 000000000000000072656C6174696F6E Searching for: CmpEax61: 8B??85C074??83F80674???83???007D Searching for: CmpEax62: 8B??85C074??83F80674???83???007D Searching for: CmpEax63: 8B???85C074??83F80674???83???007D Searching for: CmpEax64: 8B???85C074??83F80674???83???007D Searching for: Good1: C7???1045???45???33??48???FF15 Searching for: Profile1: 00007504488D4850 Searching for: Profile2: 00007504488D5050 Searching for: ProfileExpired1: 85C075???75??B892010000E9 Searching for: ProfileExpired3: 85C075???75??B892010000E9 Searching for: ProfileExpired4: 488D4D??483B??0F???000048???4889??4885C9 Searching for: ProfileExpired5: 488B0B4889034885C974??BA04000000E8???B00148 Searching for: ProfileExpired6: E8???4885C974??BA04000000E8???4C8D5C Searching for: ProfileExpired7A: 75??8D4E18E8???4889442420488BD04885C00F84??050000 Searching for: ProfileExpired7B: 75??8D??18E8???488BD048894424384885C00F84??040000 Searching for: ProfileExpired7C: 75??B918000000E8???488945C0488BD04885C00F84??050000 Searching for: ProfileExpired7D: 75??8D4E18???488BD048???4885C00F84??050000 Searching for: ProfileExpired7E: 75??8D4F18E8???48894424200F57C00F1100C7 Searching for: ProfileExpired8A: 00C740??01000000???488908C740109201 Searching for: ProfileExpired8B: 00C740??01000000???01488908488D4810C7019201???0F84 Searching for: ProfileExpired8C: 75??8D4F18E8???0F57C00F110048???48890848???C70192010000 Searching for: ValidateLicense1: 83F80175??BA94010000 Searching for: ValidateLicense2: 83F8040F95C281C293010000 Searching for: ValidateLicense3: 83F8040F95C181C193010000 C:\Program Files\Adobe\Adobe Premiere Pro 2025\Registration.dll No patterns were found or file already patched. Checking File: RuntimeInstaller.dll - using Custom Patterns Searching for: Good1: C7???1045???45???33??48???FF15 C:\Program Files\Adobe\Adobe Premiere Pro 2025\RuntimeInstaller.dll No patterns were found or file already patched. Checking File: SweetPeaSupport.dll - using Custom Patterns Searching for: HevcMpegEnabler3: FF50??0FB6 Searching for: HevcMpegEnabler4: FF50???0FB6 C:\Program Files\Adobe\Adobe Premiere Pro 2025\SweetPeaSupport.dll No patterns were found or file already patched. Checking File: 4.js - using Custom Patterns Searching for: JS5: 52656C6174696F6E7368697050726F66696C65 C:\Program Files\Adobe\Adobe Premiere Pro 2025\UXP\plugins\com.adobe.ccx.start\js\4.js No patterns were found or file already patched. Checking File: manifest.json - using Custom Patterns Searching for: Version1: 6363782E7374617274222C0A20202276657273696F6E223A2022??2E Searching for: Version2: 6363782E7374617274222C0A20202276657273696F6E223A2022???2E C:\Program Files\Adobe\Adobe Premiere Pro 2025\UXP\plugins\com.adobe.ccx.start\manifest.json No patterns were found or file already patched.

Komunitas hexbear.net

Umineko no Naku Koro ni — General Megathread for October 4th & 5th, 2025

Off the coast of Tokyo, along the Izu archipelago, lies a quaint island measuring ten kilometers across—Rokkenjima, private land, sole property of alcoholic curmudgeon Kinzo Ushiromiya. Kinzo has four children, who each in turn have children of their own. Every year, the branch families reconnect on Rokkenjima for a family meeting. Despite the forecasted typhoon, for all intents and purposes, it’s business as usual—save for a returning guest. Kinzo has his foot in the grave. If he had a choice, he’d scatter his fortune to the winds. He doesn’t care to pen a will. There’s just one person he has to see again while he still breathes—the one who haunts Rokkenjima, the Golden Witch, Beatrice. Battler, eighteen, has been estranged from the Ushiromiyas for six years, due to the circumstances surrounding his father Rudolf’s prompt remarriage after widowing. After the death of his maternal grandparents, Battler decides to bury the hatchet and attend the next family reunion. Unbeknownst to him, there may be unburied ones lying in wait. Does Beatrice ‘exist’? Did she grant Kinzo his fortune? What’s with the morbid riddle under her portrait in the hall? Are there really ten tons of gold somewhere on Rokkenjima? Why do the servants keep calling themselves ‘furniture’? Is Battler intelligent? Who needs the most therapy? Is there a correct way to read stories? Does true love only exist in the next world? Is magic real? ~~One could say… it’s a mystery…~~ On October 4th, 1986, Rokkenjima had a population of eighteen. But when the seagulls cried… Umineko no Naku Koro ni (lit. When the Seagulls Cry) is the second serialization under doujin circle 07th Expansion’s When They Cry banner—serialized visual novels penned by Ryukishi07. Besides Umineko, he is also known for Higurashi no Naku Koro ni, the prior entrant in the series, as well as his most recent work, Silent Hill f. Serialized after the conclusion of Higurashi, Umineko was written between and released in episodic chunks for each Comiket, from Comiket 72 (August 2007) to Comiket 79 (December 2010). As with Higurashi, Umineko is organized into two blocks of four episodes, respectively localized as Questions and Answers arcs. There are three generally agreed upon ways to best experience Umineko: The official Steam port: Questions Arc, Answers Arc Both entries are 40% off on steam until October 6th. Comes with the Original and MangaGamer sprite sets. With this version, it is recommended to also install 07th-Mod, which adds voice acting (Japanese), PS3 sprites/backgrounds as additional visual options, and general QoL. The fan port of the PS3 release: Umineko Project This has the PS3 sprites (only) and voice acting built in, as well as animations that are not present in 07th-Mod. ~~the password is 035646750436634546568555050~~ The manga adaptation, which you can find online at various Sites[^1] If you can stomach long VNs, I’d recommend the VN. If not, the manga is generally regarded to be the next best way to experience the story. My personal recommendation is to use Umineko Project ~~(since you can get it for free with just some setup)~~—though, if you want to read with the Original/MangaGamer sprites, MangaGamer CGs, and/or Original backgrounds, use the Steam release. ::: spoiler Spriteset comparison (open dropdown) ::: Links: 🐻 Link to all Hexbear comms 📀 Come listen to music and watch movies with your fellow Hexbears in Cy.tube 🔥 Read and talk about a current topics in the News Megathread ⚔ Come talk in the New Weekly PoC thread 🏳️‍⚧️ Talk with fellow Trans comrades in the New Weekly Trans thread 👊 New Weekly Improvement thread 🧡 Disabled comm megathread ☕ Parenting Chat 🐉 Anime & Manga discussion thread Reminders: 💚 You can join specific comms to see posts about all sorts of topics 💙 Hexbear’s algorithm prioritizes comments over upbears 💜 Sort by new 🐶 Join the unofficial Hexbear-adjacent Mastodon instance, toots.matapacos.dog Resources: Aid: 🌈 LGBTQ+ Resource Post 🍉 Resources for Palestine 🐌☕ Zapatista Coffee Theory: ❤️Foundations of Leninism ❤️Anarchism and Other Essays [^1]: not on mangadex, got DMCA’d in the recent sweep. The site I used for my reread was WeebCentral, though be wary and use an adblocker at the very least.

Komunitas mander.xyz

Control light without 3rd party app

Hi all. I recently bought a Philips hue smart plug to control a lamp. I quite quickly realized that it was more complex than I thought. Not only did I need to install the DIYHue add-on to simulate a Hue bridge, I also needed to download the Philips Hue app, or some 3rd party app called Hue essentials, to connect the smart plug (via the DIYHue bridge add-on?) to the home assistant? I don’t want to install any app from Philips. Also it didn’t work. Isnt there a way to simply control a bulb or plug from the home assistant, running on a Raspberry pi, without having to install any corporate bullshit? Sorry for the swearing. Im just frustrated that this all turned out to be so complex.

Komunitas lemmy.world

*Permanently Deleted*

The whole Project 2025 was online long before the election. Complete, for free for everyone to download and read. It’s all written down. I bet my ass that not one MAGA and very few humans read this. It starts bad and only gets worse down the road. It’s like good satire, because no one would be that stupid, that reckless, that inhumane, that sadistic or that shameless to really push through, what is described in Project 2025. I read it before the election and was sure, that that was the end of MAGA. I was so wrong, that i lost trust in common sense among humans. Turns out, that without law or rules, people really turn into animals.

Komunitas kbin.social

Gog-games is back.

Gog.com are selling DRM-free games, so there’s no copy protection, Internet activation, mandatory launcher, etc. It used to stand for “good old games”, but they also have new titles these days. Same parent company as The Witcher developers. There is a launcher, but it’s entirely optional - you can just pay prices that are generally comparable to Steam and download the installation files for a game, which require no Internet connection at all (apart from some edge cases, e.g. a very small number of multiplayer games). Gog-games meanwhile is a piracy site that redistributes these DRM-free installers to people who are not inclined to pay for the privilege. What makes them preferable to other sites is that you get the trustworthy installers from gog and do not have to fiddle with potentially malicious cracks yourself. They are also uploading to fast file hosts. One thing they are particularly useful for is preservation, games that are now delisted on gog.com and elsewhere, only available there if you have purchased them in the past. The rather decent licensed Back to the Future game from Telltale for example can’t be bought anywhere anymore (since the license for the movie franchise was only granted for a few years), but it’s still available in its most convenient shape on gog-games.