Audiophile Torrent Site What.CD Fully Pwnable Thanks To Wrecked RNG (theregister.co.uk)
Reader mask.of.sanity writes: Users of popular audiophile torrent site What.CD can make themselves administrators to completely compromise the private music site and bypass its notorious download ratio limits thanks to the use of the mt_rand function for password resets, a researcher has found. From the report (edited and condensed):What.CD is the world's most popular high quality music private torrent site that requires its users to pass an interview testing their knowledge of audio matters before they are granted an account. Users must maintain a high upload to download ratio to continue to download from the site. [...] "I reported it a year ago, and they acknowledged it but said 'don't worry about it,'" said New-Zealand-based independent security researcher who goes by the alias ss23.
What's this "CD" thing you speak of?
News at 11.
This doesn't seem like particularly shocking news, nearly all torrent sites are poorly run.
They could easily solve this problem by purchasing and installing some solid gold Monster Brand ethernet cables between the server and the router.
I'm actually surprised they don't already do this, in order to provide the clearest audio for their torrents.
Yeah not much in real good audio there. Sorry but a CD rip to FLAC is a joke. call me when you have found that rare japan release on SACD and then ripped that to FLAC....
Also their questionnaire is mostly Pseudo Knowledge and not real knowledge. Buddy of mine is an audio engineer with 2 degrees and he did not pass their test because he answered what was correct answers and not their audiophile misknowledge answers.
Do not look at laser with remaining good eye.
While many private sites have unreasonable upload ratios, what.cd isn't one of them. They have a graduated scale based on how much you've downloaded, but even at the highest point it's only 0.6, which is pretty easy to maintain even without all the freeleech tokens they hand out at holidays and special events.
We are on a relatively tech-savvy site, right? Why is there a link explaining what an audiophile is (as if I couldn't have guessed from the context even if I didn't know), but there is no link explaining how the exploit actually works? (It's not mt_rand that's the problem, it's how you seed it) Why do I have to google after reading the summary? What's the point of having editors here at all?!
The audiophiles on the torrent site care about proper rips, not fucking audio cables. Take your worthless jabs elsewhere.
"Proper rips" means that the audio doesn't contain 50-ms gaps of zeroed-out data because the CD had a scratch.
captcha: channels
Your math is disregarding a few details:
Just to be complete: Already mentioned:
1) Highest enforced ratio is 0.6. I've been on sites that go to the full 1.0 so this is somewhat friendly.
2) They have periodic Free Leech times (thanks for being a member this weekend, sorry for the downtime, etc) and items (editors/admin picks, Bowie catalog when he died, etc) which allow you to build up some buffer in your ratio.
Not already mentioned:
1) The biggest way to improve your ratio on any site is to upload material not already on the tracker. Every bit of upstream on those is pure plus for your ratio and until the swarm gets big enough you will tend to be the source for a lot of the download traffic so you get BIG multipliers. (20-30x makes up for a lot of under-performing torrents.)
2) It is kind of a ponzi scheme that at some point the leaves will tend to have difficulty attaining a 1.0 ratio on any given torrent and given What's somewhat exclusive membership size it *can be very difficult to gain positive ratio. That being said, this is a ponzi where anyone in the network can be at the top or bottom for any given Torrent SO maybe you were a leaf on some obscure album you just had to have but you happened to jump on early and be a root for an extremely popular release so you got 5x on that one. You might have a lot of torrents that never quite reach 1.0 but your overall ratio can easily be above 1.0.
Torrents only work well when people stay on to seed instead of hit-and-run style. Rules like this keep the swarms healthy. Note: this is not the only rule for this.. many sites also have specific restrictions for time period which actually ease the ratio rules a bit. "Sorry you were a leaf on this torrent but we're going to make you stay seeding for at least 2 weeks to keep the torrent alive. you don't get the ratio but you at least tried" Stuff.
I read as:
Do we look like we're experts in pulseaudio?
If there were experts, we wouldn't have pulseaudio.
Yeah, you can hear the difference between a solid-state amp and a SET amp, because the SET amp will sound like crap in comparison, with distortion and noise that is significantly higher than with the solid state amp.
And good luck actually hearing a difference between 320kbps or V0 MP3 compared to lossless. Try an ABX test, I think you'll be surprised at the result.
Eat the rich.
They need to run their server on an analog computer and install a special "real analog modem" that stretches the sound out to fit in the 20-2000Hz range and sends it directly over the phone line as a pure analog signal. Their customers will need to buy analog computers and analog recording devices and of course one of those special "modems." Only then will their users get the best sound possible coming out of their $10,000 home audio system.
Yea, it will be more expensive and keeping it temperature- and humidity-stable will be a pain in the rear, but it will be worth it.
As least that's what my friend's second cousin's son-in-law ex-con school chum says. He should know, he sells the stuff.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
The thing about "warmer" sound from tubes... it's actually not completely unreasonable. People don't listen to perfectly-reproduced signals, they like to mess with the frequency response. People mess with tone control all the time, and even the crappiest car radios have bass and treble control. Tubes mess with the signal in all sorts of complex ways, especially toward the top when a transistor would start clipping. It is reasonable that some people would find this distortion to be pleasant. It also seems like a non-trivial problem to recreate this distortion digitally, though recording it and playing it back should be fairly straightforward. I wonder if there's a market for pre-warmed music? :)
W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.