Shared posts

11 Oct 17:32

Peacemaker Featurette: John Cena Is The 'Douchey Captain America Who Would Shoot A Kid'

by Shania Russell

Amongst the countless degenerate delinquents introduced in "The Suicide Squad," one jerk managed to rise above them all as not only the douchiest, but the one guy to get his own spin-off series. That's right, Peacemaker (John Cena) is on his way back, each day bringing us a little closer to the release of his upcoming solo outing.

This month's HBO launch event already gave us our first look at "Peacemaker," showing off his very well-named sidekick, Eagle-y, who is in fact an eagle. And given how utterly ridiculous he is, Amanda Waller's (Viola Davis) lackeys spend their screen time mocking the antihero, which there's sure to be more of in the series ahead. But thanks to a new featurette, we get to jump back in time to "The Suicide Squad" set and hear what went into creating the maniacal killer.

Below, you can hear writer-director James Gunn speak about crafting Peacemaker's backstory and glean some insight into everything Cena brought to the table. Fair warning, there's a very alarming five seconds where Gunn exclaims that "Peacemaker is a lot of guys I grew up with." It's a deeply concerning comment that might send you spiraling down a dark rabbit-hole, wondering about the psychopaths walking among us as we speak — but no worries, because he then clarifies, "He's like a dudebro." And while it's only slightly less scary to think about the many dudebros walking the Earth, take comfort in the fact that John Cena's Peacemaker is singular. Hopefully.

Peacemaker Featurette

Peacemaker really hits the sweet spot of being absolutely repulsive and terribly magnetic. It might be the John Cena of it all, but it's not hard to see how this character earned his own solo adventure. Peacemaker has long been deemed a "douchey" Captain America, but Cena now adds an addendum to that description, calling the character, "a douchey Captain America who would shoot a kid." For all who have seen his "The Suicide Squad" journey, this will come as no surprise. Peacemaker joined the team and fought alongside his fellow squad members including leader Bloodsport (Idris Elba) and the very lovable Ratcatcher 2 (Daniela Melchior), but when push came to shove, Peacemaker wasn't exactly a team player.

The upcoming spin-off series will no doubt take the time to delve further into this lunatic's psyche, looking at the impact of his father's training and his mother's absence. Maybe he'll even find time to actually make friends this time around, and shed some of his social awkwardness... Okay, fine, that doesn't seem super likely, but at least he'll always have his Eagle-y.

The "Peacemaker" series wrapped filming earlier this year in July, with Gunn directing five of its eight episodes. Brad Anderson ("The Machinist"), Jody Hill ("Eastbound & Down") and Rosemary Rodriguez ("The Walking Dead") are confirmed to direct the other three. Expect to see Cena back in his patriotic toilet bowl costume, along with returning Waller lackeys John Economos (Steve Agee) and Emilia Harcourt (Jennifer Holland). Newcomers include Chukwudi Iwuji as Clemson Murn, Danielle Brooks as Leota Adebayo, Robert Patrick as Auggie Smith, and Freddie Stroma as Adrian Chase.

"Peacemaker" is set to premiere sometime in January 2022.

Read this next: Superman Movies Ranked From Worst To Best

The post Peacemaker Featurette: John Cena is the 'Douchey Captain America Who Would Shoot a Kid' appeared first on /Film.

11 Oct 17:30

Why The Last Duel Is Matt Damon And Ben Affleck's First Script Together Since Good Will Hunting

by Chris Evangelista

"Good Will Hunting" helped launch Matt Damon and Ben Affleck into stardom, and won them a Best Original Screenplay Oscar in the process. But despite that success, the two haven't written a screenplay together in 25 years. That finally changed with "The Last Duel," the new Ridley Scott film Damon and Affleck wrote with Nicole Holofcener. Based on a true story, "The Last Duel" is set in France in the 1300s. Damon plays Jean de Carrouges, a knight who enters into a duel with his one-time friend Jacques Le Gris (Adam Driver) after de Carrouges' wife Marguerite de Carrouges (Jodie Comer) accuses Le Gris of rape. 

This material is a far-cry from "Good Will Hunting," so why did "The Last Duel" finally get Damon and Affleck to take a crack at a screenplay together again? /Film attended a press conference for the upcoming film and learned the answer. 

"We Didn't Know What We Were Doing"

While Ben Affleck and Matt Damon have appeared together in movies since "Good Will Hunting," they haven't penned a script together since that Oscar-winning experience. Ridley Scott's "The Last Duel" changes that, although the historical epic might not seem like an obvious choice for the guys who wrote "Good Will Hunting." During a press conference for "The Last Duel," the pair was asked why this particular film got them to fire up the Final Draft software yet again. 

While Damon and Affleck didn't specify why they chose "The Last Duel" to be their screenwriting reunion, Damon did offer some insight into why they didn't write together for so long: they were afraid. Specifically, the experience of writing "Good Will Hunting," while successful in the end, still made them nervous to try out a new writing project. "I think we were just kind of afraid of writing," Damon began, adding: 

Because we were so inefficient. It was so time-consuming the first time we did it because we didn't know what we were doing. And it took us, literally, years. And we wrote thousands and thousands of pages that we, basically, scrunched into a 130-page screenplay. But I think by just doing movies for 25 years, just kind of by osmosis, we figured out structure. It turned out to be really efficient, the process. And also begging an incredible writer like Nicole [Holofcener] to come help us was also a really good idea, too."

"That's what gave us the confidence to do it," Affleck added. "We knew we couldn't rely on each other." 

"Definitely knew we couldn't rely on each other," Damon concurred. 

"We Grew Up Together"

"I've known [Ben Affleck] for 35 years, and we grew up together," Damon said previously. "We were both in love with the same thing — acting and filmmaking. I think we fed on each other's obsession during really formative, important years and that bonded us for life." Damon began writing what would become the "Good Will Hunting" screenplay during a playwriting class he was taking at Harvard University. Eventually, Damon asked Affleck to develop the script with him, and what they initially came up with was a thriller in which an intelligent young man is targeted by the government. 

Castle Rock Entertainment bought the script, at which point filmmaker and Castle Rock president Rob Reiner urged Damon and Affleck to cut out all the government thriller stuff and instead focus on the small-scale drama. Affleck and Damon wisely took Reiner up on this suggestion. They also stressed that they wanted to act in the film, although studio execs were hopeful that the future "Once Upon a Time in Hollywood" team of Brad Pitt and Leonardo DiCaprio would star. Of course, we all know that didn't happen, and the end result was a big hit that landed Affleck and Damon a Best Original Screenplay Oscar. 

"The Last Duel" is a much different movie than "Will Hunting." But the script, which takes a "Rashomon"-like approach to the different perspectives of its three lead characters, is clever and sharp, and I'm curious to see how a wide audience reacts. "The Last Duel" opens on October 15, 2021. 

Read this next: 14 Sequels That Truly Didn't Need To Happen

The post Why The Last Duel is Matt Damon and Ben Affleck's First Script Together Since Good Will Hunting appeared first on /Film.

11 Oct 17:27

Ex-minister Predicts 'Huge Battleground' Over UK's Plan To Set Internet Content Rules

by msmash
The former UK minster of state for what is now the digital and culture department, DCMS, has warned of the looming battle in parliament over the exact shape of incoming online safety legislation. From a report: In an interview with TechCrunch, Ed Vaizey -- a former Conservative Party MP, now Lord Vaizey of Didcot, who was head of the culture, comms and creative industries department, as it was then, between 2010 and 2016 -- predicted a huge tug-of-war to influence the scope of the Online Safety Bill, warning that parliamentarians everywhere will try to hang their own "hobby horse" on it. The risk of over regulation or creating a disproportionate burden for startups vs tech giants is also real, Vaizey suggested, setting out several areas that he said would require a cautious approach. "In theory it's just going to be the big platforms that will be regulated," he said of the scope of the Internet Safety Bill, which was published in draft form back in May -- and which critics are warning will be catastrophic for free speech. "Some platforms that should be regulated could potentially not be be regulated. But you're right that people are concerned that, in effect, there's a paradox -- that it could help the Facebooks of this world because the regulatory hurdles that get going might be too big. And if anyone is capable of being regulated it's Facebook, as opposed to a startup. So I think that's something we have to be very careful of. "Secondly, although I support the principle of legal but harmful content being regulated I have no doubt at all that that is going to be the big battle in parliament. The balance between legal but harmful free speech is going to be a huge battleground. And it will be interesting to see in what form it survives. And thirdly -- I think, paradoxically -- everyone is going to try and hang their own particular hobby horse on this piece of legislation."

Read more of this story at Slashdot.

11 Oct 12:30

Rebel FM Episode 515 - 10/08/2021

We're here and so is the Fall games season, as we go on at length about Metroid Dread, Far Cry 6, Battlefield 2042, Exhausted Man, Where is My Parking Spot, Peglin, Jett: The Far Shore, Medieval Dynasty, and a lot more! This week's music:  Marissa Nadler - Couldn't Have Done The Killing
11 Oct 12:28

What’s New in Windows Server 2022

by Alessandro Cardoso

Get the full lowdown on Windows Server 2022 and its implications for IT admins from expert Microsoft MVPs Andy Syrewicze and Paul Schnackenburg in this unmissable upcoming webinar from Altaro/Hornetsecurity on 13 October. They will explain the full new feature set, security enhancements, editions and license comparisons, where Hyper-V Server has gone, where Azure Stack HCI fits into this discussion, and more!

So, what does this mean for the future of system admins? How will your daily operations change due to the cloud-hosted strategy shift?

The presenters will also be answering all your burning Windows Server 2022 questions so come prepared and make the most out of this event to prepare your organization for the next generation of IT workloads!

Register Now

11 Oct 11:49

Far Cry 6 Review: A Very Familiar Power-Fantasy

by Nick McCaskey

Far Cry 6 is power-fantasy first-person shooting at its finest. A gorgeous, huge tropical island is given to you, with carefully crafted locations, missions, and secrets to find and dominate. Urging you forward are the typical Far Cry cast of earnest and zany characters, providing motivation for your mad quest of vengeance upon a flamboyant … Continue reading Far Cry 6 Review: A Very Familiar Power-Fantasy →

The post Far Cry 6 Review: A Very Familiar Power-Fantasy appeared first on DSOGaming.

11 Oct 11:42

CISA Releases Remote Access Guidance for Government Agencies

by Ionut Arghire

The United States Cybersecurity and Infrastructure Security Agency (CISA) last week announced the release a new guidance document: Trusted Internet Connections (TIC) 3.0 Remote User Use Case.

read more

11 Oct 11:39

ScummVM celebrates 20th birthday with The Longest Journey support

by Alice O'Connor

ScummVM celebrated its 20th birthday on Saturday, two decades of making old games easier to run on modern systems. The project started focused on LucasArts adventure games built in the SCUMM game engine and the first release only supported Monkey Island 2, and it has since grown to support over 300 games across other genres too. To celebrate that big birthday, a new update hit adding support for more game engines and many more games, including The Longest Journey, Grim Fandango, and Crusader: No Remorse.

Read more

10 Oct 23:59

Data Exfiltration, Revisited

by Unknown

I've posted on the topic of data exfiltration before (here, etc.) but often it's a good idea to revisit the topic. After all, it was almost two years ago that we saw the first instance of ransomware threat actors stating publicly that they'd exfiltrated data from systems, using this a secondary means of extortion. Since then, we've continued to see this tactic used, along with other tertiary means of extortion based on data exfiltration. We've also seen several instances where the threat actor ransom notes have stated that data was exfiltrated but the public "shaming" sites were noticeably empty.

As long as I've been involved in what was first referred to as "information security" (later referred to as "cyber security"), data exfiltration has been a concern to one degree or another, even in the absence of clearly-stated and documented analysis goals. With the advent of PCI forensic investigations (circa 2007-ish), "data exfiltration" became a formalized and documented analysis goal for every investigation, whether the merchant asked for it or not. After all, what value was the collected data if the credit card numbers were extracted from memory and left sitting on the server? Data exfiltration was/is a key component necessary for the crime, and as such, it was assumed often without being clearly identified.

One of the challenges of determining data exfiltration is visibility; systems and networks may simply not be instrumented in a manner that allows us to determine if data exfiltration occurred. By default, Windows systems do not have a great deal of data sources and artifacts that demonstrate data exfiltration in either a definitive or secondary manner. While some do exist, they very often are not clearly understood and investigated by those who then state, "...there was no evidence of data exfiltration observed..." in their findings.

Many years ago, I responded to an incident where an employee's home system had been compromised and a keystroke logger installed. The threat actor observed through the logs that the employee had remote access to their work infrastructure, and proceeded to use the same credentials to log into the corporate infrastructure. These were all Windows XP and 2003 systems, so artifacts (logs and other data sources) were limited in comparison to more modern versions of Windows, but we had enough indicators to determine that the threat actor had no idea where they were. The actor conducted searches that (when spelled correctly) were unlikely to prove fruitful...the corporate infrastructure was for a health care provider, and the actor was searching for terms such as "banking" and "password". All access was conducted through RDP, and as such, there were a good number of artifacts populated when the actor accessed files.

At that point, data exfiltration could have occurred through a number of means. The actor could have opened a file, and taken a picture or screen capture of their own desktop...they could have "exfiltrated" the data without actually "moving" it.

Jump forward a few years, and I was working on an APT investigation when EDR telemetry demonstrated that the threat actor had archived files...the telemetry included the password used in the command line. Further investigation led us to a system with a publicly-accessible IIS web server, albeit without any actual formal web sites being served. Web server logs illustrated that the threat actor downloaded zipped archives from that system successfully, and file system metadata indicated that the archive files were deleted once they'd been downloaded. We carved unallocated space and recovered a dozen accessible archives, which we were able to open using the password observed in EDR telemetry. 

In another instance, we observed that the threat actor had acquired credentials and was able to access OWA, both internally and externally. What we saw the threat actor do was access OWA from inside the infrastructure, create a draft email, attach the data to be exfiltrated to the email, and then access the email from outside of the infrastructure. At that point, they'd open the draft email, download the attachment, and delete the draft email. 

When I first began writing books, my publisher had an interesting method for transferring manuscript files. They sent me instructions for accessing their FTP site via Windows Explorer (as opposed to the command line), which left remnants on the system well beyond the lifetime of the book itself.

My point is that there are a number of ways to exfiltrate data from systems, and detecting data exfiltration can be extremely limited without necessary visibility. However, there are data sources on Windows systems that can provide definitive indications of data exfiltration (i.e., BITS upload jobs, web server logs, email, network connections/pcaps in memory dumps and hibernation files, etc.), as well as potential indications of data exfiltration (i.e., shellbags, SRUM, etc.). These data sources are relatively easy (almost trivial) to check, and in doing so, you'll have a comprehensive approach to addressing the issue.

10 Oct 23:56

Astronomers 'Stumped' Over Images Of Bizarre Double Galaxy

by noreply@blogger.com (Unknown)

It's not too often that astronomers are at a loss for words when making a space-related discovery, but the above image from NASA's Hubble telescope managed to do precisely that. Of all the tools at our disposal for exploring outer space, Hubble has repeatedly proven to be one of the best. The 31-year-old telescope has made countless discoveries over the years, whether it be answering questions about our own Solar System or investigating galaxies millions of light-years away.



In 2021 alone, Hubble has been up to a lot. It's captured a large 'eye' in the middle of a constellation, learned new information about Jupiter's Great Red Spot, and even identified a 'ghost' galaxy utterly devoid of dark matter. All of this has happened despite a scare earlier this year — one that caused Hubble to go offline for a month due to a nasty computer glitch.


NASA just shared one of Hubble's latest discoveries, and it may be one of the most head-scratching of the entire year. Looking at the photo above, all seems pretty normal at first. The picture shows a large cluster of galaxies deep in space, with Hubble focusing on two of them. The first one, labeled 'single image,' is a run-of-the-mill galaxy with a bright center and numerous stars surrounding it. Where things get interesting is with the galaxy labeled 'mirrored image.' Not only does it look like a galaxy mirroring itself, but it's also a copy of the 'single image' galaxy above it. In other words, there are three sightings of the same galaxy for no apparent reason. After first spotting the 'double' galaxy in 2013, astronomer Timothy Hamilton admitted he and his team "were really stumped."



If it sounds impossible for there to be three instances of the exact same galaxy, that's because it is. What's really happening here is something called 'gravitational lensing'  — a visual trick that occurs when a large amount of matter distorts light from other galaxies. Gravitational lensing is a fairly well-known thing today, but in 2013 when Hamilton discovered these perplexing galaxies, that wasn't the case.

In this particular situation, NASA explains the lensing as follows: "A precise alignment between a background galaxy and a foreground galaxy cluster produces twin magnified copies of the same image of the remote galaxy. This rare phenomenon occurs because the background galaxy straddles a ripple in the fabric of space." Another way to think about it is like wavy reflections present in a swimming pool. When the afternoon sun is shining bright on an outdoor pool, the light from the sun appears on the bottom of it with swirling, wavy reflections. As Richard Griffiths from the University of Hawaii explains, "The ripples on the surface act as partial lenses and focus sunlight into bright squiggly patterns on the bottom."

This is essentially what's happening in the image at the top of this article, albeit on a much larger scale. A ripple in space is taking light from the single image galaxy, magnifying and distorting it, and that's what's seen with the mirrored image galaxy. That's a great oversimplification of all the science and research that went into getting to this answer, but that's ultimately how the photo is explained. If anything, it's a great reminder of how much we still have to learn about space. In just 8 years, astronomers went from not understanding this photo to having a logical explanation for it. In the next 8, 16, or 32 years, who knows what other mysteries we'll also have answers to.


Source: NASA




10 Oct 23:51

Diablo II: Resurrected Review – Another Warcraft III: Reforged?

by Chris Wray

Blizzard is a studio with several classics under its belt. Many a PC gamer grew up on Blizzard titles like Warcraft, Diablo and Starcraft, and I'm one of them. Despite the toxic work environment, which means you're allegedly more likely to get abused than to be offered a cup of coffee, I can't help but deny the calibre of their titles. It's a shame the company is seemingly rotten to the core, guilty of inequality of harassment, facing several ongoing investigations and lawsuits—anyway, the game. Following Warcraft III: Reforged, Activision didn't trust Blizzard to develop Diablo II: Resurrected, handing it over to Vicarious Visions, leaving Blizzard in charge of the backend and Battle.Net integration.

Unsurprisingly, when the game first launched, the backend and connection to Battle.Net was utterly shambolic. Complaints rang around the internet about the inability to maintain a stable connection to the online mode of a 21-year-old game, remembering that connection issues weren't an issue for the original unless my memory has failed me. It's not unusual, most modern releases have server issues at the start, but it's not something you can forgive from the big developers and publishers. Indies don't have the financial clout to prepare thoroughly; these do.

Now, a few weeks ahead, the server issues have quietened down a little. It's not quite ideal yet. I've had a few times where I've timed out due to work or other matters, and Battle.Net has thrown a strop and will not let me reconnect unless I close the game. It may be a PlayStation 5 only issue, I don't know if the same thing happens on the PC, but it's something that's hit me twice now. Is it major? No, of course not. Is it irritating and a mistake from Blizzard? Yes, it is.

Enough of the backend issues; let's talk about something else. I can't help but praise Vicarious Visions in their development of Diablo II: Resurrected and the aim to keep this as close to the original as possible. Much like many things you see in the game, this is a relic, a fossil, a spirit of a bygone era, and it's proud of it. Diablo II is the Action-RPG that defined the genre and still does to a fair degree. While a few quality of life changes have happened, it's still the game we all loved.

We did love it, don't deny it. That or you're one of those young people who never got to play the original when it was released. If you are one of those people, this is me telling you to stop wearing your baseball cap backwards, stop listening to rubbish space music, and stop wearing your trousers halfway down your arse. Also, play this. While Diablo III was decent, this shows you what Diablo truly is, and it shows you on a level that you've rarely, if ever, seen before.

Diablo II: Resurrected is a game with masses of content, but it's also a game that makes you work for that content. Most ARPG's now will have a large amount of protection for you and your character. If you die, you may lose some of your hard-earned gold, or your equipment will take a significant durability hit. Sometimes both. You rarely find a game that will strip your character bare and send you packing back what is often a fair way back. The checkpoints in Diablo II: Resurrected make the Souls games' bonfires look friendly and abundant. That's how I like and remember it.

The original, and by extension this, is full of grind. I would argue that this is grind before we viewed grind as negatively as it is now. It was a level of grind that was rarely tedious thanks to a robust variety of skills and spells across a handful of characters that felt unique. It's almost pointless for me to run through every character and have multiple trees to go down, letting you choose your path. It's pointless for me to tell you that I have returned to the same sort of character I was playing almost two decades ago, a necromancer that loves to raise little skelly-buddies to molest all of the creatures and demons around.

With Diablo II: Resurrected, you'll find yourself fighting through five huge acts: The four from the original, and then Lords of Destruction acts as the fifth and final act. There can never be an argument that all acts are equal - some parts of the game are more interesting than others. If you look at it as an extended story, not separating Lords of Destruction expansion from the original, this is a fantastic package. It offers as much, if not more fun than most modern titles, with the great gameplay that came with the original, packed full of story, quests, and world-building.

That's when you come to the bosses and return to the grind. Quite often, you can feel like you're blasting through the game, then you find yourself hitting a brick wall. This is especially true when you move into the higher difficulty levels, and death sends you packing, your inventory left by your now-rotting carcass.

All this is talking about something you all likely already know. Diablo II is one of the best ARPG's ever; it wouldn't make sense to change the core components that made it this game. Knowing that, let's talk about what this version, what Diablo II: Resurrected, does different. The first significant quality of life improvement is, at least for me, a hot bar. I played it on the PS5, which I thought was blasphemy, but I have to admit it's been a good time. The original is an old game before hot bar sensibilities were a thing, so this implementing it makes perfect sense.

Other quality of life improvements include a shared stash space, meaning no more alt bank characters. You also pick up gold automatically, something that was always necessary for a game coming to consoles. I genuinely wish they had gone just a few steps further with quality of life changes. I had genuinely forgotten how minuscule the bag space was in the original. I remember now, and it's infuriating. Sure, you can use a return to town scroll, but I want more bag space. I also think this could have worked without breaking the balance of the game.

Looking at more changes, the core thing you'll notice is a considerable change in visuals. You can switch back to the old school view at will, something I enjoy doing to see how much can be done with such an archaic title. It's just great, much like it was in the Command & Conquer Remastered Collection, to be able to switch at will to the new and impressive visuals, and knowing that they're essentially a veneer over the original.

If there's any difficulty in playing Diablo II: Resurrected, it's that... well, every square inch of the game has been meticulously documented. If you want to know the perfect build for a class, the internet has you sorted about a million times over. You can always play this as though you don't know anything about the original, maybe you don't, or you've never heard of GameFAQ's. It's not something I can hold against the game, it's a legend. It's a true artefact and worth any place in the gaming hall of fame.

Would I recommend Diablo II: Resurrected? Yes. Do I think they're charging too much for it, particularly when you remember that EA (yes, EA) charged half the price for the Command & Conquer Remastered Collection? Also yes. Still, a high price for this extended remaster (not just a remaster, but not a remake) doesn't mean it isn't a great title.

Playstation 5 version reviewed. Copy provided by the publisher.

The post Diablo II: Resurrected Review – Another Warcraft III: Reforged? by Chris Wray appeared first on Wccftech.

10 Oct 23:45

GOG Removes Hitman From Their Store Due To Always Online DRM

by /u/INeverUseReddit
10 Oct 23:45

Doom.Eternal.The.Ancient.Gods-EMPRESS

by /u/OrdinaryPearson
10 Oct 16:09

Quake 1 gets a “major update” that takes aim at mod problems

by Chris J Capel
Quake 1 gets a “major update” that takes aim at mod problems

The first big patch for the Quake 1 enhanced edition has dropped, described by Bethesda as a "major update" that takes aim at issues such as controls, bot support in multiplayer, and numerous bug fixes. It also features numerous mod support improvements to get new and old Quake mods working with the new remaster.

The new enhanced edition of the first game in the Quake series was announced at QuakeCon in August and released the same day, along with two original expansions created by Wolfenstein: The New Order developer MachineGames and a PC version of Quake 64. It was great news - especially as it was released as a free patch for anyone who owned Quake on Steam.

However, despite being a remaster of a 25-year-old game, the enhanced edition didn't launch without issues. Players reported numerous issues, including control problems such as with gamepads, mods not being compatible with the new version, multiplayer not working correctly, choppy performance - especially on the new expansion, Dimension of the Machine.

RELATED LINKS: Best FPS games, Best old games, Best multiplayer games
10 Oct 16:08

Chrome Attempts to Resurrect RSS With a New-Tab Feature That 'Follows' Your Favorite Sites

by EditorDavid
It's kind of like an RSS feed — and kind of not. Google now lets you "follow" your favorite web sites with Android versions of Chrome, reports Gizmodo: The feature has a similar effect to following an account on Twitter or Instagram, except you get content updates through Chrome on the new tab page. The ability is widely available to anyone on Android running the latest version of Chrome 94 that was pushed out to the Play Store at the end of September. Google introduced the ability earlier this year through the experimental Canary version of Chrome on Android. A Google spokesperson said at the time that the company planned to return to surfacing content through RSS feeds so that it could populate the aforementioned Following section for its users. The ability shows up in the overflow menu on the stable version of Chrome for Android. But since it's still rolling out, you might need to enable it manually. In Chrome for Android, type in chrome://flags in the link bar to reveal the browser's hidden settings. Then, search for web feed and select the singular enabled option to turn it on.... Chrome's director of engineering Adrienne Porter Felt tweeted on Friday that iOS users should expect the feature sometime next year.

Read more of this story at Slashdot.

10 Oct 02:34

Lebanon's National Electricity Grid Collapses

by EditorDavid
"Lebanon's electricity network collapsed on Saturday," reports the Washington Post, "after the two most important power stations ran out of fuel, leaving private generators as the only source of power." The state-owned electricity company has been providing citizens with just a few hours of power a day for months, but the total collapse of the national grid will compound the misery of those who can't afford to run generators and had relied on those few hours. The outage marks the latest milestone in the unraveling of Lebanon, which is undergoing what the World Bank has described as one of the world's three biggest financial collapses of the past 150 years. The banking system was the first to implode in 2019, triggering a 90 percent slide in the value of the currency that has left the government unable to afford fuel, food and medicine imports while plunging millions of Lebanese into poverty. The electricity grid ground to a halt after the country's two main power stations, Deir Ammar and Zahrani, ran out of diesel fuel, leaving the nationwide network without the minimum amount of power required to sustain it, said Energy Minister Walid Fayyad. The government is working to secure emergency fuel supplies from other sources, including the army, to bridge the shortfall until a shipment of Iraqi oil due to arrive Saturday night can be offloaded and distributed into the network. At most, he said, the total outage can be expected to last only a couple of days, and he hoped to find a stopgap solution faster. But the collapse is a reminder of the dire state of Lebanon's electricity sector, which has been unable to provide 24-hour power for decades. In recent months, its capacity has been further eroded by the lack of money and by corruption, with smugglers diverting state purchases of fuel to sell at a profit in neighboring Syria. A recent deal struck with Iraq to supply 80,000 tons of fuel a month still falls short of the minimum amount required to ensure a stable grid and at most will be able to keep the power on for about four hours a day, Fayyad said.

Read more of this story at Slashdot.

10 Oct 02:34

Twenty years ago today...

by sev

Twenty years ago today, on Tue Oct 9 16:30:12 2001, Ludvig Strigeus pushed the initial revision of the ScummVM code, which was version 0.0.1 of the project. Time flew quickly and, fast-forward to the present day, we are proudly releasing ScummVM 2.5.0 “Twenty years ago today…”

The list of changes is tremendous.

First of all, this is the first release that supports 2.5D games (almost 3D), thanks to the merger with ResidualVM. With this release we announce support for Grim Fandango, The Longest Journey and Myst 3: Exile. This is why we jumped straight to 2.5 in our versioning. Please note that only desktop platforms currently support these games and other platforms may or may not gain the support later depending on their capabilities.

In addition to these 3 games and engines, we officially support 10 more new engines and subengines that add compatibility with the following games:

  • Little Big Adventure
  • Red Comrades 1: Save the Galaxy
  • Red Comrades 2: For the Great Justice
  • Transylvania
  • Crimson Crown
  • OO-Topos
  • Glulx interactive fiction games
  • Private Eye
  • AGS Games versions 2.5+
  • Nightlong: Union City Conspiracy
  • The Journeyman Project 2: Buried in Time
  • Crusader: No Remorse
  • L-ZONE
  • Spaceship Warlock

We love localized game releases and multiple platform versions, thus with this release, we enhanced the support for Lure of the Temptress Konami release, Blue Force Spanish, Ringworld Spanish, Amazon: Guardians of Eden Spanish, Mystery House French, Russian translations of Sierra AGI games, Elvira 1 Japanese PC-98, Bargon Attack Russian, Woodruff Russian, Eye of the Beholder Japanese Sega-CD, Legend of Kyrandia Hebrew, Legend of Kyrandia 2 Hebrew, Legend of Kyrandia 3 Simplified Chinese, Inherit the Earth PC-98 Japanese, Gabriel Knight 1 Macintosh, Xeen Russian to name but a few. Notably, Macintosh b/w versions of Loom and Indy 3 are now also supported.

Besides the new games and game versions, ScummVM 2.5.0 brings many notable improvements and new features. We have completed a major rework of the GUI: We now support Unicode characters everywhere. The GUI also adapts to high resolutions used in HiDPI screens. The Nintendo DS port has been significantly rewritten. We added GOG and Steam achievements to a large number of Wintermute games and enabled KeyMapper in more games. Thanks to the work of one of our GSoC students, we have now added an option for text-to-speech to the games Sfinx, Soltys and The Griffon Legend.

You may find all of this goodness available to a number of platforms on our downloads page, or let the autoupdater kick in on Macintosh and Windows.

We wish you great adventuring, happy puzzle-solving and exciting journeys to RPG worlds, and hope to see you around in the coming years.

And by the way, GOG.com is running a special promo tied to the release and our anniversary, where you can buy many ScummVM-supported games at a discount.

10 Oct 00:28

Why Kingpin Is The Perfect Villain For Hawkeye

by noreply@blogger.com (Unknown)

Excitement for Hawkeye is building steadily leading up to its November 2021 premiere, but the addition of Kingpin as the series’ villain would bring the MCU series to a whole new level. Kingpin was the primary villain of Netflix’s critically acclaimed Daredevil series, where he was played tremendously by Vincent D’Onofrio, but because that show hasn’t officially been made part of the MCU canon, the infamous villain has yet to formally appear in the franchise. Here’s why Hawkeye would be the perfect venue to bring Kingpin back.



Traditionally, Kingpin – real name Wilson Fisk – is portrayed as a gargantuan mob boss, who’s sheer physical strength is matched only by his tenacity and strategic prowess. As a New York resident primarily, he’s faced off against numerous Marvel superheroes over the years, with particular rivalries established against Spider-Man and Daredevil. As both a criminal mastermind and an underworld powerbroker, Kingpin has been central to numerous plots throughout the Marvel comics. In the Netflix Daredevil show, Kingpin is portrayed as both shockingly brutal and quietly intellectual – a version of the character that has earned high praise from both critics and audiences.


D’Onofrio has said repeatedly that he’d love to play Wilson Fisk in the MCU once more, and Hawkeye would be the perfect place for the villain to return. The show is set in New York City, and appears to at least partially be about gangsters wanting revenge on Clint for his time as Ronin, making it easy for Kingpin to be worked into the story. Plus, the show will bring the Marvel character Echo (Alaqua Cox) – Fisk’s adopted daughter in the comics – to the MCU, creating multiple ways in which Kingpin might feasibly enter the story of Hawkeye.

Unfortunately, the odds of Kingpin actually returning to the MCU in Hawkeye are small. There have been no real rumors of D’Onofrio returning for the series, nor has any casting news come out about a new star taking on the role. Plus, Black Widow set up Contessa Valentina Allegra de Fontaine and Yelena Belova as Hawkeye's major antagonistic forces, or at least as some of them. It could be that Disney is simply keeping the return of Kingpin under wraps, as he does seem perfectly suited to the story of the Hawkeye show, but there’s a good chance that viewers will have to wait a little longer before seeing the villain on screen again.



If Kingpin were to become Hawkeye’s secret villain, however, it would be a glorious return – especially if D’Onofrio were brought back to play the bad guy. Given that the story of Hawkeye will largely focus on Clint and Kate Bishop battling enemies of Ronin – the vigilante identity Hawkeye created after Avengers: Infinity War. Ronin took down a lot of gangsters, so it’s more than likely that he would have disrupted Kingpin’s own criminal operations pretty severely. Does that mean that Fisk will return? Not necessarily, but D’Onofrio’s Kingpin does somehow end up being the main villain of Hawkeye, it would be a great moment for MCU Phase 4.

10 Oct 00:21

10 New & Upcoming Horror Movies To Stream Before Halloween

by noreply@blogger.com (Unknown)

As Halloween fast approaches, several highly anticipated new horror movies are set to hit both the theatrical and VOD circuits between now and October 31st. Acclaimed genre filmmakers such as James Wan, Edgar Wright, David Gordon Green, Patrick Brice, Scott Cooper, and more have intriguing new horror tales to go with a solid mixture of international arthouse fare, broad Netflix originals, and everything in between.

 

From eerie haunted houses, creepy creature features, and anthological period pieces to unnerving psychological thrillers and time travel chillers, this Halloween has plenty of cinematic streaming treats in store.

Updated on October 9th, 2021 by Tanner Fox: As summer descends into autumn and windswept auburn leaves dance between carved jack-o-lanterns and tacky lawn decorations, horror becomes the hot topic among moviegoers. However, thanks to the various streaming services available, satisfactory scares abound and are no longer relegated to the theater.

With cerebral artistic pieces and reboots to dormant franchises alike set to hit Netflix, Paramount+, and Amazon Prime Video before October is out, there's never been a better time to get immersed in all things horror.

Debuting on Netflix on October 6, 2021 is There's Someone Inside Your House, a sadistic high-school slasher film from well-established horror director Patrick Brice (Creep, Room 104). Based on the novel of the same name by Stephanie Perkins, the film tracks a masked killer stalking the senior class of Osborne High only to be met with resistance by a marginalized group of outcasts.

What makes this story interesting is how the killer intends to expose the students' deep-dark secrets before ending their lives, making for a subversive, unpredictable, and genre-defying story that Brice often enjoys telling.

One of the more underrated horror anthology series of the past decade includes V/H/S, created by David Bruckner and Simon Barrett. Both men return for the upcoming 4th franchise entry, V/H/S/94, set to bow exclusively on Shudder on October 6. Set in 1994, the film concerns a police S.W.A.T. unit uncovering a cult conspiracy recorded on a grainy old videotape.


The main draw of the film, aside from the promising premise and well-established brand name, is the collection of daring directing talent at the helm. Chapters will be guided by Barrett (Seance), Chloe Okuno (Slut), Ryan Prows (Lowlife), Jennifer Reeder (Knives and Skin), and Timo Tjahanto, the latter of which directed the scariest franchise chapter to date in V/H/S/2's "Safe Haven."

Strange occurrences plague a Mexican-American family after they move to a quaint home in the California countryside, and an expectant mother must endure malignant horrors as her due date approaches. While it's sure to introduce a few ideas of its own, director Ryan Zargoza's Madres certainly seems to be taking a page or two from the Rosemary's Baby playbook.



Set to debut on Amazon Prime Video on October 8, Madres looks be a sinister thrill ride comparable to other classic haunted house horrors.

One of a set of Blumhouse productions set to terrorize horror fans this October, The Manor is an upcoming offering from director Axelle Carolyn, who is perhaps best known for directing episodes of American Horror Story and The Haunting of Bly Manor.

After an elderly woman moves into a nursing home, she is accosted by supernatural entities. Unable to prove that what she experiences is real, she must figure out a way to validate her sanity and escape before she meets a grizzly fate. The Manor is set to debut on Amazon Prime Video on October 8.

An Argentinian psychological thriller set to boggle the minds of horror fans, Fever Dream is an adaptation of the short story Rescue Distance. Seemingly something out of the mind of horror auteur Ari Aster, the movie tells the tale of a fragmented family when a mother and son duo become the epicenter of unnatural happenings.

This may be a dense and intentionally difficult work, but viewers who love to dissect and interpret films will absolutely adore Fever Dream. Set to debut on Netflix on October 13, it may not be destined for widespread appeal, but it will almost certainly find a fascinated film niche.

Germany's ominous Black Forest is the setting of Demigod, the new folk horror outing from writer/director Miles Doleac (The Dinner Party) due on October 15. The story concerns Robin (Rachel Nichols), a woman who returns to her birthplace at the sinister site following her grandfather's death in search of answers.


Aside from the foreboding forest setting, the film boasts an unsettling mixture of ancient head-hunting rituals and scary sacrificial customs with a personal story of a modern-day woman uncovering her cryptic past. With cult-favorite scream queen Rachel Nichols (P2, Inside) taking center stage, Demigod is worth bowing to when it opens this October.

In addition to penning V/H/S/94, David Bruckner's third directorial effort The Night House will open to the public on October 19. After proving his filmmaking skills in The Signal and The Ritual, Bruckner's latest looks to be a deeply disquieting tale of a widow (Rebecca Hall) uncovering her deceased husband's darkest secrets.



The deliberately-paced, slow-burn horror film is already drawing rave reviews for Hall's central turn, the brooding atmosphere of rural upstate New York, the tonal tension Bruckner is able to sustain, and the chillingly ambiguous finale.

A Netflix exclusive set to debut on October 20, Night Teeth follows a hapless chauffer as he's wrapped up in a blood-soaked supernatural thrill ride when the women he's driving are revealed to be vampires.

Though it doesn't appear to be an out-and-out horror movie, Night Teeth will certainly be able to satisfy those looking for the perfect Halloween thriller. Starring Sydney Sweeny and Megan Fox, it's sure to catch the attention of Netflix subscribers.

Another Netflix exclusive, Hypnotic sees a woman suffering from general anxiety receive treatment from an enigmatic therapist. Unfortunately, he uses the suggestive powers of his practice to coax her into unconsciously performing strange and terrible acts. Now, she must get to the bottom of this strange plot before it's too late.

Stylish and cerebral, Hypnotic promises to have viewers scratching their heads until the credits roll—and likely for some time after that. The film also looks to be a breath of fresh air when compared to many of the more traditional horror movies debuting this October.

Billed as a reboot of the popular found-footage series, Paranormal Activity: Next of Kin removes the series from its Southern California roots, placing the preternatural panic in the heart of Amish country.

A woman begins filming a documentary about her newly-discovered biological relatives only to uncover sinister tidings in the otherwise tranquil rural setting. Helmed by William Eubank, who is best known for 2020's Lovecraftian undertaking Underwater, Next of Kin is set to be a return to form for the relatively wayward franchise.

10 Oct 00:18

New modifications for Gran Turismos, NASCAR Dirt to Daytona, and more

TL;DR - if you are not interested in an overview of my newly released cheat codes, scroll down to the Download section for download links.


Hello! This post might be slightly chaotic, as it’s about a whole pack of random cheat codes I made over the past month. Bear with me and maybe you’ll spot a code that’s interesting to you.

Let’s proceed to the codes. I sorted them per platform, and then per game. Most PS2 codes released apply to multiply games, and this also has been outlined.

PlayStation

Simulation timescale in Arcade

Applies to: Gran Turismo (NTSC-U 1.1, PAL)

American and European versions of Gran Turismo have a weird difference to the original Japanese release – in those Arcade Mode is noticeably faster than the Simulation mode. I investigated it and found that in these versions, Arcade Mode runs at 125% speed, although naturally without speeding up the in-game timer. With this code, Arcade Mode is restored to 100% speed, just like in the Japanese version of GT1.

This clip from Submaniac93 illustrates the differences well, so I’ll just use that in place of a gameplay presentation:

True Endurance

Applies to: Gran Turismo 2

Gran Turismo 2 has a single timed Endurance race – Millenium In Rome 2 Hours Endurance. However, while limited to 2 hours, this race can also end after 99 laps, whichever comes first. With this cheat, this race becomes a true timed Endurance race: like in PS2 Gran Turismos, the lap counter now only shows finished laps and the race ends after 2 hours, regardless of how many laps were finished.


Begone “Lap 1/99”.

PlayStation 2

Deinterlace/Autoboot in 480p (updated)

Applies to: Gran Turismo 4 Prologue (NTSC-J), Gran Turismo 4 (PAL), Gran Turismo 4 Online (NTSC-U)

First, an update rather than a new cheat. Recently, I discovered that my current GT4 PAL deinterlace cheat was editing a variable in a wrong way, relying on luck rather than stability because of dynamic allocations. I now updated this cheat to modify code setting up the 480p video mode variable, rather than editing the variable itself.

I have also ported part of the cheat to GT4 Online, so now it’s not necessary to select Progressive (480p) on every game boot. While a cheat for GT4O already exists online, it has the same mistake (editing dynamically allocated data), so it was never reliable for me.

Additionally, I also ported my existing Gran Turismo 4 Prologue PAL deinterlace cheat to the NTSC-J version.

Adjustable units

Applies to: Gran Turismo 3, Gran Turismo Concept, Gran Turismo 4 Prologue, Gran Turismo 4 First Preview (partially)

We had to wait until Gran Turismo 4 to have a proper measurement units selection menu in the game. Before that units were locked to the specific game version, most notably locking NTSC-U versions of the games to use imperial units. While in Gran Turismo 1 and 2 units were fully hardcoded, turns out Gran Turismo 3 and later include code handling multiple speed, power, and torque units, although they are predetermined by the user’s choice of language.

With these codes, measurement units may be freely picked, just like in Gran Turismo 4. Whether it means using metric units in the NTSC-U versions, or imperial in PAL versions, the cheat code can be modified to force any selection of such. For Gran Turismo 4 First Preview, this code only allows for modifying power and torque units, as speed/distance units can already be changed in the game’s options menu.

Please remember to read the instructions included in the PNACH file and adjust the code to your preferences!

Adjusted triggers sensitivity

Applies to: Gran Turismo 3, Gran Turismo Concept, Gran Turismo 4 Prologue, Gran Turismo 4, Tourist Trophy, Gran Turismo 4 Online

Since Gran Turismo games have always offered full control remapping, it’s possible to utilize triggers on modern controllers for throttle/brake, much like most modern games do. However, unlike in newer Gran Turismos, doing this in the PS2 games results in a mediocre experience – analog sensitivity is tailored for analog buttons of the DualShock 2 controller, and therefore inputs are heavily scaled. In practice, this means that anything over ~half the trigger press is already registered as a 100% input, so precise throttle control is hard. With this code, I’ve removed this scaling as much as reasonably possible, so now 100% input registers from a near full press of the trigger, therefore making the experience closer to how the later Gran Turismo games handle it.

Remappable controls

Applies to: Gran Turismo 4 Prologue

OK, in the previous section I lied a little. Gran Turismo 4 Prologue, despite being a (somewhat) full release, does not feature control remapping. The game internally loads and saves mappings, but no menus exist, leaving the feature unused.

With this code, I “exposed” mappings to the PNACH file, so users may freely map controls however they wish. By default, the code ships with stock mappings, so make sure to modify the code to your needs.

Please remember to read the instructions included in the PNACH file and adjust the code to your preferences!


Believe me, this screen shows remapped controls, as I’m gently pressing throttle on the right trigger.

Shoulders control mapping

Applies to: NASCAR: Dirt to Daytona, Test Drive: Eve of Destruction

For the first time, modifications for a console game that is not Gran Turismo! 😁

NASCAR Heat 2002, the first PS2 game from Monster Games, shipped with 4 control schemes to choose from. One of those control schemes was called “Shoulders”, and mapped throttle/brake to R2/L2. This translates really well to modern gamepads, allowing the player to use triggers for precise throttle control (just like I mentioned above).

For unknown reasons, the next two games using the game engine, NASCAR: Dirt to Daytona and Test Drive: Eve of Destruction both removed this control scheme (Test Drive got something resembling it, with throttle/brake on R1/L1 and not R2/L2). What makes this decision even more puzzling is a fact that NASCAR DtD was also released on GameCube and Test Drive EoD was also released on Xbox, and both are consoles with pressure sensitive triggers in place of PS2’s shoulder buttons!

With this code, I restored a full “Shoulders” controls set for both games. NASCAR: Dirt to Daytona gets a full mapping copied from NASCAR Heat 2002, while Test Drive: Eve of Destruction gets a custom modification of one of the alternate mapping, swapping bumper buttons for triggers. Test Drive additionally also restores analog throttle/brake, a feature that was toggleable in NASCAR, while Test Drive removed the option and locked both to Digital. Leaving it this way would defeat the purpose of using triggers to accelerate/brake in the first place, so it’s now been restored too.

Camera controls on the right stick

Applies to: NASCAR: Dirt to Daytona

When investigating the game’s code for the shoulders mapping cheat, I noticed that NASCAR DtD (but not NASCAR Heat 2002 or Test Drive EoD) still updates button mappings for Look Left/Look Right actions, albeit it always updates them with an empty mapping. I looked into that more closely and found that these actions are fully functional but unused. With this cheat, I replace the stock functionality of the right analog stick (Throttle/Brake) with key bindings to look around.

Note: When “uninstalling” the cheat, please follow the instructions in the PNACH file! Removing it without first making the code unmap the newly added controls will leave camera controls permanently mapped in the savegame.

Extended valid birth date range

Applies to: NASCAR: Dirt to Daytona

The last cheat released today is a huge nitpick 😁 When creating a new driver profile in NASCAR DtD, the birth years of the player are limited to the 1925-1986 range. In 2021 that limit doesn’t really make sense anymore (I can’t set my driver’s birth date to my own!), so in this cheat, I lifted it enough to future proof it for a very long time – with valid dates now being in the 1900-2100 range.

Download

All listed cheats can be downloaded from Mods & Patches. Click here to head to the Consoles page, from where you can go to the specific games’ pages:

Download cheat codes

10 Oct 00:14

Hitman pulled from sale on GOG

by Graham Smith

GOG have pulled Hitman from sale. The bald assassin joined the DRM-free digital shop in September, but was met with damning reviews. That's because, while theoretically DRM-free, Hitman relies on online connectivity for a lot of its features to work. In pulling the game offline, GOG apologised, saying that they "shouldn't have released it in its current form."

Read more

10 Oct 00:14

The Quake remaster's bot support is better now

by Graham Smith

The enhanced edition of Quake, released in August to celebrate the game's 25th anniversary, just got a major update. It improves the game's bots, and adds bot support for a bunch more deathmatch maps, among other bug fixes.

Read more

09 Oct 18:14

Debian 11.1 Released With Initial Batch Of Fixes

Debian 11 "Bullseye" debuted back in August as the latest major release for this popular community Linux distribution. Today it's been succeeded by Debian 11.1...
09 Oct 18:13

Stay safe in the great outdoors with 6 deals on first aid and emergency kits

by Boing Boing's Shop

Got an itch to get outdoors and camp (or glamp, for those of us who are super creative)? We get that, and with the weather turning blistering cold before we know it, this is the sweet spot to get the last of your camping trips in (unless you love frostbite, in which case, camp with caution). — Read the rest

09 Oct 17:23

FSF Warns Windows 11 'Deprives Users of Freedom and Digital Autonomy'

by EditorDavid
"October 5 marks the official release of Windows 11, a new version of the operating system that doesn't do anything at all to counteract Windows' long history of depriving users of freedom and digital autonomy," writes Free Software Foundation campaigns manager Greg Farough. "While we might have been encouraged by Microsoft's vague, aspirational slogans about community and togetherness, Windows 11 takes important steps in the wrong direction when it comes to user freedom." Microsoft claims that "life's better together" in their advertising for this latest Windows version, but when it comes to technology, there is no surer way of keeping users divided and powerless than nonfree softwarechoosing to create an unjust power structure, in which a developer knowingly keeps users powerless and dependent by withholding information. Increasingly, this involves not only withholding the source code itself, but even basic information on how the software works: what it's really doing, what it's collecting, and how often it's snitching on users. "Snitching" may sound dramatic, but Windows 11 will now require a Microsoft account to be connected to every user account, granting them the ability to correlate user behavior with one's personal identity. Even those who think they have nothing to hide should be wary of sharing potentially all of their computing activity with any company, much less one with a track record of abuse like Microsoft... We expect Microsoft to use its tighter control on cryptography that happens in Windows as a way to impose more severe Digital Restrictions Management (DRM) onto media and applications, and as a way to ensure that no application can run in Windows without Microsoft's approval. In cases like these, it's no longer appropriate to call a machine running Windows a "personal" computer, as it obeys Microsoft more than it does its user. Indeed, it's bitterly ironic that Microsoft is calling the program that verifies a system's compatibility with Windows 11 a "PC Health Check." We counter that a healthy PC is one that respects its user's wishes, runs free software, and doesn't purposefully restrict them through treacherous computing. It would also never send the user's encryption keys back to its corporate overlords. Intrepid users will likely find a way around this requirement, yet it doesn't change the fact that the majority of Windows users will be forced into a treacherous computing scheme... Sometimes, Microsoft realizes that it can't be quite so overtly antisocial. We've commented many times before on the hypocrisy involved in saying that Microsoft "loves open source" and "loves Linux," two ways of mentioning free software without reference to freedom. At the same time, Microsoft employees do make contributions to free software, contributions which benefit many others. Yet they do not extend this philosophy to their operating system, and in the last few years, they've made an attempt to impair the ways free software makes "life better together" further by making critical functions of Microsoft GitHub rely on nonfree JavaScript and directing users toward Service as a Software Substitute (SaaSS) platforms. By attacking user freedom through Windows, and the free software community directly by means of nonfree JavaScript, Microsoft proves that it has no plans to loosen its grip on users. No program that you're forbidden to copy, modify, or share can truly bring people "together" in the way that Microsoft claims. Thankfully, and right outside the window, there's a true community of users you and your loved ones can join... Let's stop falling for the trap of chasing short-term, superficial improvements in proprietary software that may seem to make life better, and instead opt for free software, the only software that can support the best versions of ourselves. The post urges readers to sign (or renew!) their pledge not to use Windows and to help a friend install GNU/Linux, "sending Microsoft the strong message that software that subjugates its users has no place in Windows.... If you don't feel ready to take the plunge and switch entirely, you can use our resources like the Free Software Directory to find programs you can use as starting points for your free software journey." The post also has harsh words for TPM, warning that "when it's deployed by a proprietary software company, its relationship to the user isn't one based on trust, but based on treachery. When fully controlled by the user, TPM can be a useful way to strengthen encryption and user privacy, but when it's in the hands of Microsoft, we're not optimistic." And when it comes to Microsoft teams, "it seems that no Windows user can avoid it any longer.... we hope Teams' unpopularity and its newfound, unwanted place in Windows will encourage users to seek out conferencing programs that they themselves can control."

Read more of this story at Slashdot.

09 Oct 11:00

EDR Bypasses

by Unknown

During my time in the industry, I've been blessed to have opportunities to engage with a number of different EDR tools/frameworks at different levels. Mike Tanji offered me a look at Carbon Black before carbonblack.com existed, while it still used an on-prem database. I spent a very good deal of time working directly with Secureworks Red Cloak, and I've seen CrowdStrike Falcon and Digital Guardian's framework up close. I've seen the birth and growth of Sysmon, as well as MS's "internal" Process Tracking (which requires an additional Registry modification to record full command lines). I've also seen Nuix Adaptive Security up close (including seeing it used specifically for threat hunting), which rounds out my exposure. So, I haven't seen all tools by any stretch of the imagination, but more than one or two.

Vadim Khrykov shared a fascinating tweet thread regarding "EDR bypasses". In the thread, Vadim lists three types of bypasses:

1. Technical capabilities bypass - focusing on telemetry EDR doesn't collect
2. EDR configuration bypass - EDR config being "aggressive" and impacting system performance 
3. EDR detection logic bypass - EDR collects the telemetry but there is no specific detection to alert on the technique used

Vadim's thread got me to thinking about bypasses I've seen or experienced over the years....

1. Go GUI

Most EDR tools are really good about collecting information about new processes that are created, which makes them very valuable when the threat actor has only command line access to the system, or opts to use the command line. However, a significant blind spot for EDR tools is when GUI tools are used, because in order to access the needed functionality, the threat actor makes selections and pushes buttons, which are not registered by the EDR tools. This is a blind spot, in particular, for EDR tools that cannot 'see' API calls.

As such, this does not just apply to GUI tools; EXE and DLL files can either run external commands (which are picked up by EDR tools), or access the same functionality via API calls (which are not picked up by EDR tools).

This has the overall effect of targeting analysts who may not be looking to artifact constellations. That is to say that analysts should be validating tool impacts; if an action occurred, what are the impacts of that action on the eco-system (i.e., Registry modifications, Windows Event Log records, some combination thereof, etc.)? This way, we can see the effects of an action even in the absence of telemetry specifically of that action. For example, did a button push lead to a network connection, or modify firewall settings, or establish persistence via WMI? We may not know that the button was pushed, but we would still see the artifact constellations (even partial ones) of the impact of that button push.

Take Defender Control v1.6, for example. This is a simple GUI tool with a couple of buttons that allows the user to disable or enable Windows Defender. EDR telemetry will show you when the process is created, but without looking further for Registry modifications and Windows Event Log records, you won't know if the user opened it and then closed it, or actually used it to disable Windows Defender.

2. Situational awareness 

While I was with CrowdStrike, I did a lot of public presentations discussing the value of threat hunting. During these presentations I included a great deal of telemetry taken directly from the Falcon platform, in part demonstrating the situational awareness (or lack thereof) of the threat actor. We'd see some who didn't seem to be aware or care that we were watching, and we'd see some who were concerned that someone was watching (checking for the existence of Cb on the endpoint). We'd also see other threat actors who not only sought out which specific EDR platform was in use, but also began reaching out remotely to determine other systems on which that platform was not installed, and then moving laterally to those systems.

I know what you're thinking...what's the point of EDR if you don't have 100% coverage? And you're right to think that, but over the years, for a variety of reasons, more than a few organizations impacted by cyber attacks have had limited coverage via EDR monitoring. This may have to do with Vadim's reason #2, or it may have to do with basic reticence to install EDR capability (concerns about the possibility of Vadim's reason #2...).

3. Vadim's #2++

To extend Vadim's #2 a bit, some other things I've seen over the years is customers deploying EDR frameworks, albeit only on a very limited subset of systems. 

I've also seen where deploying EDR within an impact organization's environment has been inhibited by...well...the environment, or the staff. I've seen the AD admin refuse to allow EDR to be installed on _his_ systems because we (my team) might remove it at the end of the engagement and leave a backdoor. I've seen users in countries with very strict privacy laws refuse to allow EDR to be installed on _their_ systems. 

I've seen EDR installed and run in "learning" mode during an engagement, so that the EDR "learned" that the threat actor's actions were "good".

One of the biggest variants of this "bypass" is an EDR that is sending alerts to the console, but no one is watching. As odd as it may sound, this happens considerably more often than you'd think.

EDR is like any other tool...it's value depends heavily upon how it's used or employed. When you look closely at such tools, you begin to see their "blind spots", not just in the sense of things that are not monitored, but also how DFIR work significantly enhances the visibility into a compromise or incident.

09 Oct 11:00

Tips for DFIR Analysts, pt III

by Unknown
Learn to think critically. Don't take what someone says as gospel, just because they say it. Support findings with data, and clearly communicate the value or significance of something.

Be sure to validate your findings, and never rest your findings on a single artifact. Find an entry for a file in the AmCache? Great. But does that mean it was executed on the system? No, it does not...you need to validate execution with other artifacts in the constellation (EDR telemetry, host-based effects such as an application prefetch file, Registry modifications, etc.).

Have a thorough process, one that you can add to and extend. Why? Because things are always changing, and there's always something new. If you can automate your process, then so much the better...you're not loosing time and enabling crushing inefficiencies. So what do you need to look for? Well, the Windows Subsystem for Linux has been around for some time, and has even been updated (to WSL2). There are a number of versions of Linux you can install via WSL2, including Parrot OS. As one would expect, there's now malware targeting WSL2 (Lumen Black Lotus LabsTomsHardware, The Register).

Learn to communicate clearly and concisely. This includes both the written and spoken form. Consider using the written form to make the spoken form easier to communicate, by first writing out what you want to communicate.

Things are not always what they seem. Just because someone says something is a certain way doesn't make it the case. It's not that they're lying; more often than not, it's that they have a different perspective. Look at it this way...a user will have an issue, and you'll ask them to walk through what they did, to see if you can replicate the issue. You'll see data that indicates that they took a specific action, but they'll say, "I didn't do anything." What they mean is that they didn't do anything unusual or different from what they do on a daily basis.

There can often be different ways to achieve the same goal, different routes to the same ending. For example, Picus Security shared a number of different ways to delete shadow copies, which included resizing the VSC storage to be less than what was needed. From very cursory research, if a VSC does not fit into the available space, it gets deleted. This means that VSCs created will likely be deleted, breaking brittle detections looking for vssadmin.exe being used to directly delete the VSCs. Interestingly enough, I found this as a result of this tweet asking about a specific size (i.e., 401Mb).

Another example of different approaches to the same goal is using sc.exe vs reg.exe to control Windows services, etc. Different approaches may be predicated upon the threat actor's skill set, or it may be based on what the threat actor knows about the environment (i.e., situational awareness). Perhaps the route taken was due to the threat actor knowing the blind spots of the security monitoring tools, or of the analysts responding to any identified incidents.

There are also different ways to compromise a system...via email, the browser, any accessible services, even WSL2 (see above).

An issue within or challenge of DFIR has long been signal-to-noise ratio (SNR). In the early days of DFIR, circa Win2000/WinXP systems, the issue had to do with limited data...limited logging, limited tracking of user activity, etc. As a result, there are limited artifacts to tie to any particular activity, making validation (and to an extent, attribution) difficult, at best.

As DFIR has moved to the enterprise and analysts began engaging with EDR telemetry, we've also seen surges in host-based artifacts, not only between versions of Windows (XP, to Win7, to Win10) but also across builds within Windows 10...and now Windows 11 is coming out. With more people coming into DFIR, there's been a corresponding surge in the need to understand the nature of these artifacts, particularly within the context of other artifacts. This has all led to a perfect storm; increases in available data (more applications, more Windows Event Logs, more Registry entries, more data sources) and at the same time, a compounding need to correctly and accurately understand and interpret those artifacts. 

This situation can easily be addressed, but it requires a cultural change. What I mean is that a great deal of the parsing, enrichment and decoration of available data sources can be automated, but without DFIR analysts baking what they've discovered...new constellations or elements of constellations...back into the process, this entire effort becomes pointless beyond the initial creation. What allows automation such as this continue to add value over time is that it is developed, from the beginning to be expanded; for new data sources to be added, but also findings to be added.

Hunting isn't just for threat hunters. We most often think of "threat hunting" as using EDR telemetry to look for "badness", but DFIR analysts can do the same thing using an automated approach. Whether full images are acquired or triage data is collected across an enterprise, the data sources can be brought to a central location, parsed, enriched, decorated, and then presented to the analyst with known "badness" tagged for viewing and pivoting. From there, the analyst can delve into the analysis much sooner, with greater context, and develop new findings that are then baked back into the automated process.

Addendum, 9 Oct: Early in the above blog post, I stated, "Find an entry for a file in the AmCache? Great. But does that mean it was executed on the system? No, it does not...you need to validate execution with other artifacts in the constellation...". After I posted a link to this post on LinkedIn, a reader responded with, "...only it does."

However, this tweet states, "Amcache entries are created for executables that were never executed. Executables that were launched and then deleted aren't recorded. Also, Amcache entries aren't created for executables in non-standard locations (e.g., "C:\1\2\") _unless_ they were actually executed." 

Also, this paper states, on the second half of pg 24 of 66, "The appearance of a binary in the File key in AmCache.hve is not sufficient to prove binary execution but does prove the presence of the file on the system." Shortly after that, it does go on to say, "However, when a binary is referenced under the Orphan key, it means that it was actually executed." As such, when an analyst states that they found an entry "in" the AmCache.hve file, it is important to state clearly where it was found...specificity of language is critical. 

Finally, in recent instances I've engaged with analysts who've stated that an entry "in" the AmCache.hve file indicated program execution, and yet, no other artifacts in the constellation (Prefetch file, EDR telemetry, etc.) were found. 
08 Oct 23:39

The 10 Best Modern Animated Superhero Shows, Ranked By IMDb

by noreply@blogger.com (Unknown)

There's no question that there are more superhero movies and television shows available today than at any other point in history. While a lot of praise has gone to live-action projects like Loki and The Boys or movies like The Suicide Squad 2 and basically the entire Marvel Cinematic Universe, animated films and TV shows are just as good.

RELATED: 5 Best Animated Superhero Movies (& 5 Worst), According To IMDb

Some viewers may not take them seriously because they're cartoons but all someone has to do is look at 2018's Spider-Man: Into The Spider-Verse to see how great these can be. The same goes for television, with some modern animated superhero shows getting tons of praise.

10 M.O.D.O.K. (2021) - 6.3 - Stream On Hulu

Although he was the main antagonist of the Marvel's Avengers video game, it's pretty clear that M.O.D.O.K. is something of a goofy-looking character. A giant floating head in a chair doesn't seem very intimidating, and that's the idea that the Hulu series M.O.D.O.K. played on.

The show followed the titular villain as he attempted to juggle his empire and his family life. Praise was dished out to how the world was built, some of the relationships M.O.D.O.K. had, and the stop-motion animation style. The voice cast was also a hilarious highlight, led by Patton Oswalt, Melissa Fuermo, Aimee Garcia, and Ben Schwartz.

9 ULTRAMAN (2019-Present) - 6.9 - Stream On Netflix

Ultraman is a hero that has kind of been around for decades at this point and has been adopted plenty of times over. His suit has become rather iconic and the character has remained popular since the 1970s. He has been part of video games, movies, miniseries, television shows, and more. Ultraman could even end up in the Monsterverse alongside Godzilla and King Kong since he's the first tokusatsu hero in history

One of the most recent iterations of a project starring the character is Netflix's ULTRAMAN, which premiered back in 2019. The 13-episode run received widespread acclaim from those who gave the series a chance and season 2 is scheduled to arrive in early 2022.

8 Avengers Assemble (2012-2019) - 7.0 - Stream On Disney+

If there was ever a perfect time for a show to release about Marvel's greatest team, it was in 2012. The MCU was really taking off and The Avengers surpassed the elusive $1 billion mark at the box office. So, it makes sense that Avengers Assemble was a hit series featuring Captain America, Black Widow, and more.

Part of what made the show so well-received was how it continuously expanded the universe and the lore. Later seasons went on to adapt comic arcs like Secret Wars and also brought in the likes of Black Panther and Thanos. You'd be hard-pressed to find a bigger combination of Marvel characters on one screen.

7 Axe Cop (2012-2015) - 7.4 - Stream On VRV

Back in late 2009, Axe Cop debuted as a webcomic and the premise is basically right in the name. The series follows a police officer who opts to use an axe when he goes into a fight. The comic was adapted into a Fox TV series in 2013 before FXX took it over in 2015.

RELATED: 10 Most Powerful TV Superheroes Of All Time

Although it's not the most popular modern animated superhero series, it did get critical praise. One of the biggest reasons it was loved was the voice cast with Nick Offerman leading the way and guest appearances from Alison Brie, Stephanie Beatriz, Jemima Kirke, Giancarlo Esposito, and more.

6 Generator Rex (2010-2013) - 7.6 - Buy On Amazon

The 1999 comic M. Rex served as the inspiration for the 2010 TV series Generator Rex. Again, this is a series that stood out immediately for its voice cast, which featured J.K. Simmons, Daryl Sabara, and Fred Savage. One of the highlights was that this Cartoon Network series crossed over with other shows.

2011 saw an episode that also featured characters from Ben 10. Although the series wrapped up nearly a decade ago, it was brought back for a special titled Ben Gen 10 in 2021, proving that it still has some legs. The show was set in a future where humans were infected by bots and one young man had the special ability to control those bots.

5 What If...? (2021-Present) - 7.6 - Stream On Disney+

The MCU finally got in on the animated action with the What If...? series. The idea was that it took the characters audiences have fallen in love with over the past decade or so and put them into situations and stories from other universes. Fans got to see T'Challa as Star-Lord, a world where Hank Pym murdered the Avengers, and Ultron wielding the Infinity Stones.

The animation style was an instant hit, though a few of the episodes somewhat missed the mark. However, many fans agreed that things all came together near the end as the show created the Guardians of the Multiverse and saw an epic clash where the likes of Gamora, Thor, and Captain Carter teamed up to face a multiverse threat.

4 Kid Cosmic (2021-Present) - 7.9 - Stream On Netflix

Craig McCracken is one of the most notable names in animation as he created the likes of The Powerpuff Girls and Foster's Home for Imaginary Friends, while also having a history on 2 Stupid Dogs and Dexter's Laboratory. In 2021, he tried his hand at superheroes with Kid Cosmic.

RELATED: The 10 Best Episodes Of The Powerpuff Girls, According To IMDb

The premise is simple enough, following a kid who is given superpowers he must use to fight off evil but the series shines thanks to its supporting characters and the animation style that feels like a retro comic book. Though it only just premiered in early 2021, two seasons are already out and a third and final one is on the way.

3 The Avengers: Earth's Mightiest Heroes (2010-2012) - 8.3 - Stream On Disney+

A few years before Avengers Assemble became a series, the Marvel team was brought to the small screen in The Avengers: Earth's Mightiest Heroes. Initially, the show was centered around the original group of Iron Man, Thor, Hulk, Giant-Man, and The Wasp but other heroes were brought in later on.

Like the follow-up series, this dealt with Marvel characters that hadn't yet come to movies like Skrulls, the Guardians of the Galaxy, Doctor Doom, and more. Fans were pretty disappointed with the news that it had not been renewed for season 3 and would be replaced by Avengers Assemble, though that show worked out well enough.

2 Harley Quinn (2019-Present) - 8.5 - Stream On HBO Max

Although superhero cartoons mostly seem aimed at children, it's actually the ones geared towards adults that have performed the best from a critical standpoint. DC's Harley Quinn is just that kind of series, centering on the titular villain as she leaves The Joker and looks to form her own band of baddies.

The series has been praised for everything from the voice acting (Kaley Cuoco, Lake Bell, and Alan Tudyk lead the way) to the animation style but the real highlight is how iconic characters are presented in a different manner. That includes a maniacal Jim Gordon and the hilarious Kite Man. Plus, audiences adore the core romance between Harley and Poison Ivy.

1 Invincible (2021-Present) - 8.7 - Stream On Amazon Prime

Amazon Prime first made gritty superhero waves with The Boys but they took it to the next level with Invincible. The animation format allowed for the show to do things that wouldn't be possible without an absurd budget in live-action, including one particular finale scene involving a train crash and hundreds of dead bodies.

The show follows Mark, a teen who gains superpowers and becomes the titular superhero. As he bands with other heroes to fight villains, he also learns that his father, a beloved hero himself, is actually the most ruthless villain of them all. Things culminated in shocking manner to wrap up a debut season that people were talking about for months.

NEXT: 10 Invincible Characters & Their MCU Counterparts



from ScreenRant - Feed https://ift.tt/2WVkP7n https://ift.tt/3DfRFPQ
08 Oct 23:38

iPhone Apps No Better For Privacy Than Android, Oxford Study Finds

by BeauHD
An anonymous reader quotes a report from Tom's Guide: A new survey has reached a startling conclusion: iPhone apps tend to violate your privacy just as often as Android apps do. "Overall, we find that neither platform is clearly better than the other for privacy across the dimensions we studied," say the academic paper entitled "Are iPhones Really Better for Privacy?" and presented by researchers from the University of Oxford. "While it has been argued that the choice of smartphone architecture might protect user privacy, no clear winner between iOS and Android emerges from our analysis," the paper adds. "Data sharing for tracking purposes was common on both platforms." There's one big caveat regarding the new study: It was conducted before the introduction of iOS 14.5 in April 2021, which made opt-in to tracking and app privacy labels mandatory on iPhones. The researchers analyzed the code, permissions and network traffic of 12,000 randomly selected free apps from each platform that had been updated or released in 2018 or later. Each app was run on a real device, either a first-generation iPhone SE running iOS 14.2 or a Google Nexus 5 running Android 7 Nougat. They found that nearly all (89%) of the Android apps contained at least one tracking library, which was almost always Google Play Services. The numbers weren't much lower on iOS, where 79% of apps had at least one tracking library, most likely Apple's own SKADNetwork, which tracks which ads a user clicks on. However, 62% of iOS apps also ran Google's AdMob ad tracking library, followed by 54% of iOS apps (and 58% of Android apps) running Google Firebase. Facebook trackers were in 28% of Android apps and 26% of iOS ones. In fact, most apps on either platforms -- 90% of Android apps and more than 60% of iOS -- shared data with tracking companies owned by Google. Almost all tracking companies observed were based in the U.S. About 9.5% of iOS apps and 5% of Android ones used Chinese-based trackers; 7.5% of iOS apps and 2% of Android ones used Indian trackers. The team commended Apple for making it possible for iPhone users to block the temporary advertising IDs that flag your phone to advertisers, but the team also saw an ulterior motive on Apple's part. "Apple's crackdown on Ad ID use could be interpreted as an attempt to divert revenue from Google and other advertising providers, and motivate the use of alternative monetization models -- which are more lucrative for Apple," the Oxford research paper states. "Apple has arguably placed a larger emphasis on privacy, seeking to gain a competitive advantage by appealing to privacy-concerned consumers."

Read more of this story at Slashdot.

08 Oct 22:41

28-year-old nurse known as the 'Russian Rapunzel' hasn't cut her hair since she was 5, says it doesn't take much upkeep because she simply washes it twice a week and leaves it to 'dry naturally'. No word if she is related to Cousin Itt [Weird]