There have been multiple accounts created with the sole purpose of posting advertisement posts or replies containing unsolicited advertising.

Accounts which solely post advertisements, or persistently post them may be terminated.

cygnus ,
@cygnus@lemmy.ca avatar

Is this one of those NFTs the kids are talking about?

RecluseRamble ,

It’s actually quite similar. Non-fungible since only OP has the private key but easy to steal by just downloading the image (and cropping the key if you want).

dan ,
@dan@upvote.au avatar

PGP? Surely you mean GnuPG.

shoki OP ,

Yeah, you’re right. Who thought that it was a good idea to name two things that mean a similar thing PGP and GPG? It is so easy to use the wrong one…

pennomi ,

I try to keep things simple by only using GGG or PPP.

Feathercrown ,

Gnu’s Not GnuPGP

shoki OP ,

more like GPG’s not PGP

Natanael ,

Pretty Good Privacy (proprietary original)

GNU Privacy Guard (open source clone)

OpenPGP is the shared spec

Hawke ,

(Open)PGP is the protocol, GPG is just one application that implements it.

dan ,
@dan@upvote.au avatar

Right. OpenPGP is the protocol. PGP is the original app, which predates the spec.

jelloeater85 ,
@jelloeater85@lemmy.world avatar

Oh not this again… 😂

blindbunny ,

Green is my pepper! 🫑

kionite231 ,

Has anyone confirmed that signature? I think it’s not possible to have the signature as a part of the data itself. Kinda chicken egg problem

rivvvver ,
@rivvvver@lemmy.dbzer0.com avatar

yea would be interesting. but im also too lazy to type all that text in by hand to verify

cheezoid2 ,

Here:

iQIzBAEBCgAdFiEETYf5hKIig5JX/jalu9uZGunHyUIFAmaB8YEACgkQu9uZGunH yUKi7Q/+OJPzHWfGPtzk53KnMJ3C8KQGEUCzKkSKmE0ugdI 9h1Lj4SkvHpKWECK Y1GxNujMPRM/aAS2M97AEbtYolenWzgYm01wt131/hEG4tk+iYeB2Sfyvngbg5KI y4D7mapcVWYSf6S13vUX8VuyKeTxK6xdkp95E0wPVLfJwx505nHOnjLXxeW0IblY URLonem/yuBrJ6Ny3XX9+sKRKcdI9tOghMhTxPcQySXcTx1pAG7YE7G5UqTbJxis wy7LbYZB5Yy0F03CtRIkA+cclG4y2RMM9M9buHzXTWCyDuoQao68yEVh40dqwH1U 5AUnqdve5SiwygF/vc50Ila6VjJ4hyz1qVQnjqqD96p7CSVzVudLDDZMQZ8WvgLh gaEr51xJvH6p6/CP1ji4HHucbJf6BhtSqc8ID9KFfaXxjfZHiUtgsVDYMV0e7u9v 1hcDH/3kmw/JImX25qsEsBeQyzOJsBvx0YD31ZIwSY9+7KNGVQstFrEvCuVPHr72 BQJPIhg3+9g6m36+9Uhs1N6b8G9DsZ60gnNqr9dGturUg6CtRsLSpqoZq0ET9cLA tnFTJDaXgx1DZnsLGDSoQQYjZ3vS+YYZ8jG86KGLEyXVK+uSssvorm9YR1/GGOy7 suaxro72An+MxCczF5TIR9n3gisKvcwa8ZbdoaGd9cigyzWlYg8= =EgZm

Morphit ,
@Morphit@feddit.uk avatar

<span style="color:#323232;">----BEGIN PGP SIGNATURE-----
</span><span style="color:#323232;">iQIzBAEBCgAdFiEETYf5hKIig5JX/jalu9uZGunHyUIFAmaB8YEACgkQu9uZGunH
</span><span style="color:#323232;">yUKi7Q/+OJPzHWfGPtzk53KnMJ3GC8KQGEUCzKkSKmE0ugdI9h1Lj4SkvHpKWECK
</span><span style="color:#323232;">Y1GxNujMPRM/aAS2M97AEbtYolenWzgYmO1wt131/hEG4tk+iYeB2Sfyvngbg5KI
</span><span style="color:#323232;">y4D7mqpcVWYSf6S13vUX8VuyKeTxK6xdkp95E0wPVLfJwx5o5nH0njLXxeW0IblY
</span><span style="color:#323232;">URLonem/yuBrJ6Ny3XX9+sKRKcdI9tOqhMhTxPcQySXcTx1pAG7YE7G5UqTbJxis
</span><span style="color:#323232;">wy7LbYZB5Yy0FO3CtRIkA+cclG4y2RMM9M9buHzXTWCyDuoQao68yEVh4OdqwH1U
</span><span style="color:#323232;">5AUnqdve5SiwygF/vc50Ila6VjJ4hyz1qVQnjqqD96p7CSVzVudLDDZMQZ8WvqLh
</span><span style="color:#323232;">qaFr51xJvH6p6/CP1ji4HHucbJf6BhtSqc8ID9KFfaXxjfZHiUtgsVDYMV0e7u9v
</span><span style="color:#323232;">lhcDH/3kmw/JImX25qsEsBeQyzOJsBvxOYD3lZrwSY9+7KNGVQstFrEvCuVPHr72
</span><span style="color:#323232;">BQJPIhg3+9g6m36+9Uhs1N6b8G9DsZ6OgnNqr9dGturUg6CtRsLSpqoZq0FT9cLA
</span><span style="color:#323232;">tnFTJDaXgx1DZnsLGDSoQQYjZ3vS+YYZ8jG86KGLFyXVK+uSssvorm9YR1/GGOy7
</span><span style="color:#323232;">suaxro72An+MxCczF5TIR9n3gisKvcwa8ZbdoaGd9cigyzWlYg8=
</span><span style="color:#323232;">=EgZm
</span><span style="color:#323232;">----END PGP SIGNATURE-----
</span>
LeFrog ,
@LeFrog@discuss.tchncs.de avatar

Here you go:

bleepingcomputer.com/…/this-image-shows-its-own-m…

(MD5 is not PGP, but impressive nonetheless)

qprimed , (edited )

md5 has been broken for years, but thats pretty damn cool scary.

abfarid ,
@abfarid@startrek.website avatar

I opened the comment section to ask if it was possible to have an image with its own hash.
Thanks.

Natanael ,

It’s using a combination of multicollision attacks against MD5 and sequences of groups of alternate blocks of data representing the alphabet encoded in a way compatible with the file format.

It’s basically <[a+random]/[b+random]/[c+random]…> * (length of message). The random data is crafted by the attack tool so each block has the exact same effect on the MD5 hashing algorithm as it processes each block. You need to decide how many variable blocks you need and where and their encoding in advance. You encode the blocks so the randomness isn’t visible in the final rendered file.

When you have that prepped, you compute the final hash, then at each block position you select the block representing the letter you want (and its associated random data). So then you can select letters matching the actual file hash value.

It only works against hash functions with practical multicollision attacks. Doesn’t work on SHA256 and newer hashes.

abfarid ,
@abfarid@startrek.website avatar

I know some of these words. But I think I roughly understood the general idea. Thanks!

Manifish_Destiny ,

Yeah that only due to md5 hash collisions though. That wouldn’t work on sha for example

shoki OP ,

whispers I stole that signature from cryptostorms warrant canary: cryptostorm.is/canary.txt

Morphit ,
@Morphit@feddit.uk avatar

You fraud.

Ziglin ,

It might be possible to keep signing with a different key until it matches. But I assume the signature is of the above text.

Natanael ,

I mean if you’re prepared to do it 2^128 times in a row…

Natanael ,

You can but you need to define what part of the data the signature covers (a signature can’t sign itself, so it must be excluded from the data bundle). Signed PDF files has the signature appended after the document data

shoki OP ,

Exactly. And even though there are message start and end markers it’s not quite clear at which pixel the signed image starts and ends. Also the image format that is signed is not defined.

possiblylinux127 ,

1000002713

I hid something in this image

tourist ,
@tourist@lemmy.world avatar

I see that fifth puppy u aint slick

Jerkface ,

What if I told you…? That’s right. Six puppies.

atx_aquarian ,
@atx_aquarian@lemmy.world avatar

Seriously? Some steganography going on in here?

possiblylinux127 ,

Yes

Its an app on F-droid

bitwolf ,

That’s just nfts with extra steps /s

Natanael ,

*fewer

  • All
  • Subscribed
  • Moderated
  • Favorites
  • [email protected]
  • random
  • lifeLocal
  • goranko
  • All magazines