@solids
@solids
Ñøñë
关注的小组(6)
动态 帖子 40 评论 285 短评 4 收到的赞 421 送出的赞 706
  1. solids   在小组 国家局域网研究所 回复文章

    Conjure网桥已进入Alpha版Tor Browser, 附使用方法

    这个和Snowflake网桥有何区别?

  2. solids   在小组 国家局域网研究所 回答问题

    有没有代理互联网档案馆(web.archive.org)或者archive.ph的镜像网站?

  3. solids   在小组 国家局域网研究所 回复文章

    一种直连2047论坛(以及其他使用Cloudflare CDN的网站)的方法

    如果要顺带直连品葱,可以这么写: --host-resolver-rules="MAP 2047.one who.int, MAP pincong.rocks who.int" --origin-to-force-quic-on="who.int"

  4. solids   在小组 2047 回复文章

    一位网友由于在qq群公开发泄露数据库磁力链接被缓刑4年(图片转文字)

    笑死。


    顺便一提,这篇文章原来发在作者shuax的个人网站shuax.com上,后来他自己把文章删除了,只留下6个字delete。不过没关系,有存档可以看。

  5. solids   在小组 2047 回复文章

    致中国朋友的一封信 | A letter to our Chinese users.

    非常中国特色的信。

  6. solids   在小组 2047 回复文章

    中国的防火长城屏蔽了google.com及其所有的子域名

    原来 mtalk.google.com 这个域名是被连带封锁的。

  7. solids   在小组 2047 回复文章

    H萌娘走了(T ^ T)

  8. solids   在小组 站务 回答问题

    是否时政类的帖子有点过于多?缺乏技术贴

    可以多发点援交帖呢。

  9. solids   在小组 2047 回复文章

    H萌娘走了(T ^ T)

    结合一些情况我更觉得这是有组织的关闭网站,而不是被迫:

    1. hmoegirl.com的DNS A记录被主动移除,而不是服务器下线导致Cloudflare显示502。

    2. 管理员海豚的GitHub账号被主动删除,而不是进入静默状态。

    3. Android客户端的存储库被删除,该存储库原来在koharubiyori名下。如果是部分管理员被妥协,这名不相关的开发者不会受影响。

    站长张宇鹏(人在美国)过去做过自我审查的事,按照其风格这次主动关闭站点不是没有可能。

  10. solids   在小组 2047 回复文章

    H萌娘走了(T ^ T)

  11. solids   在小组 站务 回答问题

    问一个敏感的问题

    各位管理员滥权严重,把喜欢言论自由的人都赶跑了。(之前就见到过冲浪TV人士抱怨这一点)

  12. solids   在小组 2047 回复文章

    小米手机在联网后对vpn实行拦截安装

  13. solids   在小组 2047 回复文章

    有人用过 XMPP 协议通信么?

  14. solids   在小组 2047 回复文章

    “净协”要对本小站“进攻”了嘛?

    只有两位管理员?那我算什么。

  15. solids   在小组 2047 回复文章

    H萌娘走了(T ^ T)

  16. solids   在小组 2047 回复文章

    H萌娘走了(T ^ T)

    奇怪的是,管理员海豚的GitHub账号也被删除了。

    https://github.com/850710247liu

    鉴于海豚曾经在GitHub上推广反审查工具TCPioneer,我很担心其人身安全。

    另,如果你有Telegram账号的话可以去他们的群组 https://t.me/Hmoegirl 看看什么情况。

  17. solids   在小组 2047 回复文章

    好聪明的中国人,好优美的中国话

    数据泄露事件时时有,今年特别多。 前天出现新闻,昨天开始大量传播,无论在国内还是国外都产生了严重的舆论影响。 尤其是国外盯着中国政府黑点的无良无底线的媒体,都在疯狂的炒作。 所以各位读者切勿信谣传谣,听国家的安排,最终国家会有准确的调查结果,对于这次时间的炒作者、攻击者该抓的抓,改判的判。

    (笑死了,Google 搜索结果也要打码)

    https://archive.ph/Eui5P

  18. solids   在小组 2047 回复文章

    好聪明的中国人,好优美的中国话

  19. solids   在小组 站务 回复文章

    请求取回 @solids 账号。

    已登入。

  20. solids   在小组 2049BBS 回复文章

    Lisa大神能不能帮忙解释下这两个问题?

    @霏艺Faye #2290348 代码那部分只是定义Accesser如何修改发出的SNI。验证的部分是给OpenSSL处理。

    我刚才测试了 badssl.com 上的一些示例域名,测试之前将其SNI加入 config.json 以指示 Accesser 不去除 SNI。对于有问题的TLS证书处理不同。

    https://expired.badssl.com/ (过期)

    终止连接

    ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate has expired (_ssl.c:1129)
    

    https://wrong.host.badssl.com/ (host不匹配)

    没有终止连接

    https://self-signed.badssl.com/(自签)

    终止连接

    ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate (_ssl.c:1129)
    

    https://untrusted-root.badssl.com/ (CA不可信)

    终止连接

    ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate in certificate chain (_ssl.c:1129)
    

    后面的 revoked 和 punning-test 是有问题的,但是我的浏览器也没有警告,所以不再测试。


    由此可见GFW要完成MITM只能获取有效的其他网站的证书和私钥。并非自签就可以。

  21. solids   在小组 2047 回复文章

    国内首个职场反性骚扰的开源工具包

    感谢您的分享。

  22. solids   在小组 2047 回复文章

    【纽约书评】许章润新文:Xi’s China, the Handiwork of an Autocratic Roué(待翻译)

  23. solids   在小组 2047 回复文章

    沈逸和自媒体是如何从郑爽一路批斗到CloudFlare的

  24. solids   在小组 2047 回复文章

    推荐一个很好的媒体项目:AG⓪RA

    突然想到之前 Be4 做的网站和这个很像。

  25. solids   在小组 2047 回复文章

    精神发布会“河南抗洪抢险精神”

    学习众人划桨开大船的同舟共济精神。只有团结才能迸发出强大的战斗力。从抗日战争到解放战争的胜利,从九八年抗洪到零八年抗震,再到今年的河南暴雨洪灾,每一次与灾难抗战取得的胜利都是一首首用众志成城谱写的进行曲,军民团结、干群同心。团结的力量,小到二人同心,其利断金;也可大到人心齐,泰山移。

  26. solids   在小组 2047 回复文章

    精神发布会“河南抗洪抢险精神”

    洪水如猛兽,来势汹汹,扰乱了江河,侵占了家园,惊扰了美梦。然灾难的突袭,上演的不是各奔东西,而是党员干部、人民子弟兵、八方群众的迅速集结上阵,并用血肉之躯筑起一道道人肉堤坝,与洪水抗争,全力守护美好家园。这一切的背后,彰显了团结的力量、大爱的精神、钢铁般的意志、大无畏的勇气。和平年代,我们不提倡多难兴邦,但多难背后的精神却值得我们倡导与发扬。

  27. solids   在小组 2047 回复文章

    Xmader可能会被驱逐

    @Truth #149280

    I don't see any unacceptable things

    • 雇员 Daniel Ray 先生以人身安全威胁其删除仓库(并所有 fork)。
    • Muse Group 要求 Audacity 贡献者签所谓 Contributor License Agreement,条款 违反 GPL。

    The CLA also allows us to use the code in other products that may not be open source

    • 增加追踪器和分析, turn free software into proprietary spyware.

    https://github.com/audacity/audacity/discussions/1225

    还用说更多吗?

  28. solids   在小组 2047 回复文章

    Xmader可能会被驱逐

    全 文 背 诵

    https://archive.vn/d2NZm (原文已被 Daniel Ray 删除)

    I think he was just trying to be nice. He wouldn't have suggested an in-person chat or gone along with one if he knew you wouldn't be comfortable with it. Yes, some of the company's actions have been questionable, but their employees are still human and there is no need to hound them down for suggesting an in-person meetup. Please don't dehumanise these employees, they seem like nice reasonable people, especially making time to speak with a freelance journalist.

    Thanks for injecting a more human element to this discussion. There is actually quite a bit more to this story here than most people realize.

    I'll try to explain.

    Wenzheng Tang (@Xmader) is actually violating the law with both repositories related to MuseScore, one of them a rather severe violation.

    This repository violates 17 U.S. Code § 1201 - Circumvention of copyright protection systems.

    Another repository of his, musescore-dataset, has far more serious implications as it may be considered willful infringement with criminal intent (see: 17 U.S. Code § 506 - Criminal offenses). That repository is actually illegally distributing copyrighted works licensed to MuseScore by major music publishers. That such distribution is considered copyright infringement on a massive scale (hundreds of thousands of works) is unambiguous. This purpose does not meet the four necessary requirements for fair use claim according to Section 107 of the U.S. Copyright Act.

    Those factors are:

    • the purpose and character of the use, including whether such use is of a commercial nature or is for nonprofit educational purposes;
    • the nature of the copyrighted work;
    • the amount and substantiality of the portion used in relation to the copyrighted work as a whole; and
    • the effect of the use upon the potential market for or value of the copyrighted work.

    Further explanation of the four factors can be found in this article - The Fair Use Exception.


    To provide further context, it is important to understands that 100% of all rights to transcription or arrangement of a copyrighted work belong to the rights holder, regardless of who performed the transcription or arrangement. This is a point of great confusion for many. Further explanation of this topic can be found in the following article - No, You Don’t Own Your Arrangement of That Hit Song.


    So, if it is such a clear violation, it should be quite easy to get this taken down, right? Why hasn't this repo been taken down yet? Simply put, the actual process of requesting the take down and proving violation would have severe implication on Wenzheng Tang, so I have hesitated in the hopes he would simply choose to take it down himself.

    I'll explain why...

    Upon further investigation, it became clear that Wenzheng Tang is a Chinese national, but not resident in China. As a guest in his current country, his residency status is predicated on a number of conditions, one of which is not violating the law.

    If found in violation of laws, residency may be revoked and he may be deported to his home country.

    This becomes even further complicated given another repo of his - Fuck 学习强国, which is highly critical of the Chinese government. Were he deported to China, who knows how he may be received.

    While under normal circumstances, he could apply for asylum in order not to be deported, but this option is extremely limited when found in violation of the laws of the country you are a guest in.

    And though the laws cited above are in reference to US law and he is neither a resident or national of the US, this is simply the starting point as the initial distribution is through Github, which is a us company and the copyrights in question are US copyrights. There are treaties between countries that would allow this to then be extended to his country of residence in accordance with their own laws (I do not mention which country out of courtesy or any other details such as the basis of residency out of respect for personal privacy). So, both repositories remain up, for now, not because we are powerless to take it down... it is that the process of exercising this power could very literally ruin the actual life of another person.

    At the same time, the company is legally obligated to enforce violation of copyrighted works licensed to them. There will soon come a time where hesitation is no longer possible. But do keep in mind that enforcement may also come from any one of the rights holders of the hundreds of thousands of copyrighted works illegally distributed at any time. It is unlikely that any others will be as empathetic. As you can see, there is far more to this story than what may be assumed by the external observer.

    So, Wenzheng Tang (@Xmader), I'm writing this entire post here not as a representative of any company or entity, but just human-to-human to strongly encourage you to remove both repositories and move on with your life.

    The LibreScore project is fully within your right as MuseScore is GPL, and is even encouraged, but I would suggest you remove any reference to registered trademarks.

    What I have described in this post is not at all a threat, but an informed assessment of your own personal legal risk.

    You are young, clearly bright, but very naive. Do you really want to risk ruining your entire life so a kid can download your illegal bootleg of the "Pirates of the Caribbean" theme for oboe?


    alter: https://rentry.co/workedintheory

  29. solids   在小组 2047 回复文章

    好聪明的中国人,好优美的中国话

  30. solids   在小组 2047 回复文章

    好聪明的中国人,好优美的中国话

    这件事也给我们广大站长提个醒,千万要管好自己网站的内容,非法违规发现一定要及时处理,否则迟早会中招,特别是涉及政治的,一定要删!

    https://www.zhujib.com/pudncom.html

  31. solids   在小组 2047 回复文章

    净网协会差不多得了

    超级黑客

  32. solids   在小组 2047 回复文章

    净网协会差不多得了

    内容已隐藏
    内容已被作者本人或管理员隐藏。 如有疑问,请点击菜单按钮,查看管理日志以了解原因。
  33. solids   在小组 2047 回复文章

    净网协会差不多得了

    @刘慈欣 #146214 和学历无关,对GFW稍有了解的即使是小学生也能搞懂DNS污染。

  34. solids   在小组 2047 回复文章

    净网协会差不多得了

    引用 /t/13375

    今年5月是“反独清网2021”,品葱和CDT都在攻击列表中:https://archive.is/VK1Pu


    thphd 引用这张图的时候没看出有何问题。

    但是稍有常识的人都可以看出,净网协会的技术人员连DNS污染都搞不清楚。收到GFW回复的随机IP地址就以为找到源站IP了,实在让人笑掉大牙,,,

  35. solids   在小组 2047 回复文章

    00后小红帽“净网志愿者协会”与两广网警联合办案,通过社工手段找到“编程随想”真实身份

    这张图真是,哈哈哈哈哈笑死我了。

    差不多得了,这群脚本小子 DNS 污染都看不清楚。还能起底编程随想。

    GFW 污染IP一览:https://fars.ee/zGgf.json

  36. solids   在小组 2047 回复文章

    新的source聲稱編程隨想疑似被抓

    走家人10年甚至9年没搞清楚的东西给你5个月调查完了

    😅😅😅

  37. solids   在小组 2047 回复文章

    新的source聲稱編程隨想疑似被抓

  38. solids   在小组 2047 回复文章

    好聪明的中国人,好优美的中国话

    刚刚补了那么多图都没有了,如果有决定要发去外网的姐妹可以私戳我一下吗,也许你看了west人的评论就不会这么做了。

    我不希望弟弟热度上来之后被老秃驴们(you know who)利用,这样他们会收到更多的资金,再策划一些恶心的行动,某些媒体再抹黑我们一把。

    小朋友可以先去搜索一下(315-1)的算数结果,我对那几年发生在包括昆明和迪丽热巴家乡的事情真的印象深刻。 更何况,某些事件发生后,对当地人民的生活也会有很大的影响。

    我都写成这样了阿北不会还继续删我的帖子吧😢


    我知道很多姐妹初衷都是好的,立场也是好的,可是外面的舆论环境和导向真的不是你想的这样。我也曾经觉得摆事实讲道理就,可是我自己出“门”之后所遇到的人和看到的东西真的改变了我,我们的身份有些时候就是原罪。

    **真的不要发外网!**会被西方国家利用打压我国的!!!

    最好不要去外网宣传,不要被外国势力利用了,丁真的民族问题比较敏感,不希望i珍珠们被别有用心的坏人利用,对丁真不利,对国家不利

    https://www.douban.com/group/topic/201160626/

  39. solids   在小组 2047 回复文章

    推荐一个很好的媒体项目:AG⓪RA

    赫鲁晓夫的笑话挺有意思的,哈哈哈哈哈

  40. solids   在小组 2047 回答问题

    苹果日报创造香港的报业奇迹的原因是什么?为什么苹果日报会影响香港乃至中国的报纸生态?

    派克笔讨厌派克笔的原因是什么?为什么派克笔会影响派克笔乃至钢笔的行业生态?

  41. solids   在小组 2047 回复文章

    一些不太好的事情

    @NullPointer #143941 咨询服务用的是 https://www.msn.cn/zh-cn/

    所以在中国打开“msn资讯”会显示下架。

    没有吧

    第二条 在中华人民共和国境内提供互联网新闻信息服务,适用本规定。本规定所称新闻信息,包括有关政治、经济、军事、外交等社会公共事务的报道、评论,以及有关社会突发事件的报道、评论。

    http://www.cac.gov.cn/2017-05/02/c_1120902760.htm

    msn.cn 的垃圾资讯里哪有这些。

    顺便一提,右下的新闻资讯很容易关闭