HN user

LinuxBender

57,650 karma

I am not for everyone. To ignore me in uBlock Origin, add to "My filters":

   news.ycombinator.com##tr.athing.comtr:has(a.hnuser):has-text(/\bLinuxBender\b/)
For HN usage questions see https://github.com/minimaxir/hacker-news-undocumented for HN tips (not my repo)
    (\_/)
    (='.'=)
    (")_(")
Posts10,468
Comments7,767
View on HN
gizmodo.com 1y ago

Driverless Semi-Trucks Are Coming Soon to a Highway in Texas

LinuxBender
6pts4
nltimes.nl 1y ago

Dutch privacy regulator concerned over Meta's AI plans using Facebook, Instagram

LinuxBender
3pts0
www.theregister.com 1y ago

Ninite to win it: How to rebuild Windows without losing your mind

LinuxBender
5pts0
www.phoronix.com 1y ago

New Patches Get Linux Booting on the Snapdragon X1-Powered Dell Inspiron 14 Plus

LinuxBender
3pts0
ktla.com 1y ago

Nationwide burger chain to close more than 100 stores

LinuxBender
2pts1
www.securityweek.com 1y ago

Korean Telco Giant SK Telecom Hacked

LinuxBender
1pts0
www.securityweek.com 1y ago

5.5M Patients Affected by Data Breach at Yale New Haven Health

LinuxBender
3pts0
www.scworld.com 1y ago

Critical bugs in Siemens, Schneider Electric gear top CISA advisory

LinuxBender
1pts0
www.theregister.com 1y ago

Ransomware scum bilked victims out of a 'staggering' $16.6B last year, says FBI

LinuxBender
9pts0
www.scworld.com 1y ago

Hackers exploiting vulnerabilities at higher rates, reports Verizon

LinuxBender
2pts0
www.scworld.com 1y ago

Bulletproof hosting provider Proton66 steps-up malware campaigns

LinuxBender
3pts0
www.dailymail.co.uk 1y ago

Breakthrough as scientists pinpoint cause of colon cancer in young people

LinuxBender
2pts2
www.phoronix.com 1y ago

VMware Updates Linux Patches for Running VMware Workstation Atop KVM

LinuxBender
2pts0
www.securityweek.com 1y ago

Cyberattack Hits British Retailer Marks and Spencer

LinuxBender
2pts0
www.scworld.com 1y ago

Google fixes Cloud Composer privilege escalation vulnerability

LinuxBender
1pts0
www.scworld.com 1y ago

Financial malware on the rise as espionage attacks decline

LinuxBender
1pts0
www.phoronix.com 1y ago

Linux 6.15 Git Tanked Nginx HTTPS Web Server Performance

LinuxBender
6pts0
electrek.co 1y ago

CATL unveils new EV battery that charges as fast as pumping gas

LinuxBender
8pts5
www.securityweek.com 1y ago

Microsoft Purges Dormant Azure Tenants, Rotates Keys Prevent Repeat Nation-State

LinuxBender
4pts0
www.phoronix.com 1y ago

Kmemdump Proposed for the Linux Kernel to Help with Memory Dumping and Debugging

LinuxBender
5pts0
arstechnica.com 1y ago

Chrome on the chopping block as Google's search antitrust trial moves forward

LinuxBender
7pts0
github.com 1y ago

Yt-dlp: a feature-rich command-line audio/video downloader

LinuxBender
3pts1
www.scworld.com 1y ago

Bulletproof hosting provider Proton66 steps-up malware campaigns

LinuxBender
5pts0
www.theregister.com 1y ago

Oracle hopes talk of cloud data theft dies off. CISA just resurrected it

LinuxBender
8pts0
www.securityweek.com 1y ago

North Korean Cryptocurrency Thieves Caught Hijacking Zoom Remote Control Feature

LinuxBender
8pts0
cowboystatedaily.com 1y ago

As AI Threats Grow, Wyoming Gets a Certified Cyber Defense Training Center

LinuxBender
2pts0
www.scworld.com 1y ago

Alarms sound over attacks via Microsoft NTLM vulnerability

LinuxBender
3pts0
cowboystatedaily.com 1y ago

Group Wants Nearly 1,200 Grizzlies in California, but Could It Happen?

LinuxBender
4pts0
www.bleepingcomputer.com 1y ago

Cisco Webex bug lets hackers gain code execution via meeting links

LinuxBender
5pts0
www.scworld.com 1y ago

Legends International notifies customers, employees of data breach

LinuxBender
3pts0

A flash board is interesting. How many browsers still support shockwave by default? Somewhere I still have an archive of SWF's from the early 00's. Most in my collection are probably too offensive by todays standards.

I agree with the sentiment but it's tricky. Logically and technically it totally makes sense but it's expensive and companies look at cost, maintenance, accessibility. Above ground is easier to maintain, less legal hassles and easements among other things. Even when it made sense to bury everything that would affect the investors. There are some rough laws around impacting shareholders. Oh and people are greedy. I probably could have just said people are greedy.

What type of business is this for? While I am not a fan of it, I found most developers liked Slack. The general consensus I received when trying to switch to an internal chat system was "You can take slack from our cold dead hands". This was in a financial company with a lot of developers. Compliance were OK with Slack after we had them add a lot of features, audit capabilities and limits.

For non developers people seem to like Discord for the freedom, options, ability to chat with whomever. It's not great in terms of compliance in a public company but maybe your company is small and this is not an issue.

The natural transition from Skype would be Teams and should be free if you are a small group. It is also free if you buy O365 or whatever they are calling it now. I can't keep up with the name changes.

Without understanding your business model it is hard to suggest anything that fits into your regulatory and audit requirements. Beyond that it would also matter what you put in your SOC1/SOC2 documents and what policies and procedures they reference.

Is Linux under the control of the USA gov?

Probably not? I could think of ways to hide the controls but the most likely targets would be Linux forks and firmware that run in cell phones, cars, appliances, IoT's, etc... Those are more likely to be in the path of monitoring something interesting. Even in the case of cell phones, cars, etc, I would expect the control to be in firmware that one could tickle with JTAG over bluetooth, USB, WiFi, LoRa to take full control of the OS and bypass all security controls rendering encryption into a placebo or a CPU warmer. Why waste processing cycles on brute forcing when you can tell the application that the encryption key was successfully decrypted without ever even looking at the key.

I guess a simpler way to say that is, why control Linux when there are always so many proprietary things are in the path that only have a handful of people controlling them, especially when one could replace said people whereas replacing all the Linux developers would be hard. Firmware that provides a CPU ring -4 shell can bypass absolutely every security control anyone could imagine in microseconds.

Error: Server Error The server encountered a temporary error and could not complete your request. Please try again in 30 seconds.

I've only had one incident of someone trying to defraud me using my card in the last few decades and the card vendor instantly blocked it and texted me. I am obviously only one person but I have been careful where I use that card. If I suspect anything I just report it stolen and get another one. That only takes a few minutes at the bank. With exception to Amazon I only use it in places that everyone knows me and I know everyone. Most of the time I use cash, especially if buying anything the government may wish to track. I will never tie my fondle-slab to a financial institution. To many entities have access to it.

Netting spread across tall poles are about the only thing that is not outright illegal. HOA's and some towns will throw a fit about the netting. Using radio weapons outside of a war-zone will likely result in fines if it interferes with anything revenue generating and possibly even arrest.

Is this how people ended up burning witches?

Only if their scientific minds and governing bodies lied to and gaslit the population repeatedly until all that was left was to come up with their own albeit wrong answers. In this case I put the blame squarely on the NIH and WHO, both of which need some serious reformation.

Oh, and the witches hammer. [1] That book killed millions of women and girls. numbers are often debated

[1] https://en.wikipedia.org/wiki/Malleus_Maleficarum

Phones have displaced paper money and credit cards as the preferred way to pay for a bill at the end of a meal.

In Europe maybe? I've never seen anyone pay with their phone. Not in big cities and not in rural areas in the US. I will never do financial transactions with my government spy device. To each their own obviously.

As for when I am ready to pay, I go to the counter and give them cash or I might use a debit card if I am picking up everyone's tab. If they give me grief then I simply do not return to that establishment and they will get negative reviews.

What's to stop them from changing it, after a few months, when people are used to it?

Exactly. If the software is loaded then enabling the service is just a feature toggle. The only way someone would know it is enabling itself is if sites like HN start talking about it.

A couple of browsers can connect to Tor without installing anything extra so maybe as the internet is tightened down more browsers will add this ability. To your point though it is still slower and people despise latency so the faster sites will likely win out.

In terms of legality it is not clear to me that countries will enforce the laws of other countries even if they are allies. Global trade is changing and I suspect that could affect international enforcement as dependencies shift, maybe. Time will tell.

Some vendors allow fallback / secondary email addresses. There is a process for getting a domain back. I've never been through it but I hear it is painful and not guaranteed.

My process is to pull all emails off the server daily so that if I lose my email account or domain then instead of trying to switch back to my self hosted solution I just get a new domain, a new email provider and update them in each vendor if I still can. In some cases it will require getting on the phone with someone but I do not have much of a digital footprint. I have cut ties with most vendors that are not within a 5 minute drive. The exceptions being the IRS and Amazon, both of which I could live without and I have secondary contact info in the IRS system plus they like money so they will help me.

I did something like this ages ago and attracted some hackers that in turn attracted the FBI to my house. I suppose in hind-sight I should have made them sign legal documents and had them notarized but I still would have had to deal with the feds. It didn't end with that. They also pissed off all the locals and the local police offered to drive them far out of the county and just leave them somewhere but I ended up paying to put them up in a hotel and paid to store their stuff in a storage at the advice of my lawyer. I guess all I am suggesting is to be careful.

It may also be worth mentioning that when using CAA and also using something like LetsEncrypt one can specify which account is permitted to create and update certs and which method is approved DNS in this case. [1]

Example using DNS validation:

    0 iodef "mailto:domainowner@example.net"
    0 issue "letsencrypt.org; validationmethods=dns-01; accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/xxxxxxxxxx"
    0 issuewild "letsencrypt.org; validationmethods=dns-01; accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/xxxxxxxxxx"
Only useful for non-rogue CA's of course and maybe some day crt.sh will be less after-the-fact on all browsers and API clients.

[1] https://www.rfc-editor.org/rfc/rfc8657

2FA Is No Good 1 year ago

Also, that does not improve the security that much especially if the IP address is later reused for something else

Hard disagree. That's one person out of the billions that is your potential adversary and highly unlikely at that. It is highly improbably that person with either know they have your old IP or that they would be a risk. Even limiting login to a ASN# or large CIDR block is monumentally better than allowing the entire internet to brute force ones account.

As an example I have a few services that I do not really care about but I still limit logins to the CIDR of my ISP. That means most of my country and all of the other countries can bang away or pound sand all day and night for millions of years and they will get nowhere.