HN user

Puts

1,236 karma
Posts2
Comments277
View on HN

The thing is that according to the Universal Declaration of Human Rights privacy and the right to private communication is a basic human right. And GDPR was literally enacted to enforce this human right.

Now one basic principle of democracy is that supreme courts are superior to the people in power. Someone needs to watch the lawmakers so to say. Because it could actually be that the European commission enacts laws that are illegal. And Chat Control 2.0 could actually be illegal because it violates the Universal Declaration of Human Rights. However, somebody has to take them to The Court of Justice of the European Union to test it.

My experience after 20 years in the hosting industry is that customers in general have more downtime due to self-inflicted over-engineered replication, or split brain errors than actual hardware failures. One server is the simplest and most reliable setup, and if you have backup and automated provisioning you can just re-deploy your entire environment in less than the time it takes to debug a complex multi-server setup.

I'm not saying everybody should do this. There are of-course a lot of services that can't afford even a minute of downtime. But there is also a lot of companies that would benefit from a simpler setup.

You hear this over and over again that Europe is over-regulated and this is why tech-companies don't succeed here. I would say this is utter bullshit. If you look at the acquisitions made by the tech-giants it just that anything that is going to be successful is instantly bought up by these companies.

People probably don't know how little Google for example builds in-house with everything from Analytics to Gmail being of European origin.

https://en.wikipedia.org/wiki/List_of_mergers_and_acquisitio...

https://en.wikipedia.org/wiki/List_of_mergers_and_acquisitio...

https://en.wikipedia.org/wiki/List_of_mergers_and_acquisitio...

ToS;DR 1 year ago

GDPR partly covers this since it's stated that the user must get information about how personal data is used in a clear and easy readable form. But I guess, there's some wiggle room how to interpret that. The law actually suggest that the industry could come up with symbols – like on food packaging. Your website could have a bunch of standardized icons in the footer to inform you how data is used, but since we don't have that it seems like the industry didn't like that idea of transparency.

"for most commercial organizations"

Most commercial organizations are not "internet" companies. They can run their business on a single VPS. Even e-commerce sites with several million euro turnover can run their Magento instance on a single VPS. Or industries manufacturing things can still run their inventory software or ERP stuff on some cheap VPS.

These kinds of questions would fry my brain. I seriously wouldn't know how to respond to such stupid open-ended questions.

Can you share an instance where you had to learn new tools or technologies quickly?

If you work with technology it's your fucking job to learn new things every single day?

Can you tell me about a situation when you made a mistake?

You make fucking mistakes daily, but unless you are a retarded moron you just learn, adjust and move on?

Can you give me an example of when a major change forced you to re-plan an ongoing project?

Have this person ever worked on a project? Not a single project have ever gone according to plan EVER in the history of humanity!!! But you fucking deal with it because that's what you are getting paid to do!

I don't think anybody is against optimizing government agenesis and their spending. People question the motives behind it. This is clearly done with ideological intentions, because Elon and Trump thinks that the big government in itself is a problem – as all fascists do. When you remove all government agencies and replace them with corporate interest you get what Mussolini called Corporatism but what we now know as fascism:

https://en.wikipedia.org/wiki/Corporatism

The point with a syn flood is to try to saturate the OS limit for open sockets. From an attackers perspective the whole point of a syn flood is to do a DOS without needing much bandwidth.

My experience form 15 years working in the hosting industry is that volumetric attacks are extremely rare but customers that turn to Cloudflare as a solution are more often than not DDOS-ing them self because of bad configured systems, but their junior developers lack any networking troubleshooting skills.

Most (D)DOS attacks are just either UDP floods or SYN floods that iptables will handle without any problem. Sometimes what people think are DDOS is just their application DDOSing themself because they are doing recursive calls to some back-end micro-service.

If it was actually a traffic based DDOS someone still needs to pay for that bandwidth which would be too expansive for most companies anyway - even if it kept your site running.

But you can sell a lot of services to incompetent people.

I think the author forgot the most useful use case for globals, and that is variables that has to do with the context the program is running under such as command line arguments and environment variables (properly validated and if needed escaped).

What if we come to a point where even the investors don't care if you can finish a product at all? If the pitch is good enough and they think you can bring in more investors down the road, they will get back their money at a higher evaluation anyway. This would actually explain why so many startups fail – nobody cared for them to succeed anyway, because the initial investors got rich even without there being a product.

Politics did not belong here at a time when CEOs for tech companies cared about creating new tech. But if tech company CEOs buy of politicians and romanticises nazism and facism publicly then suddenly tech becomes political and then it belongs here.

Have you ever met any person who says bullying is a good thing? I have not, yet it appears in any group of people large enough. So obviously people rationalise it somehow. How do you think they rationalise it to themself then?

Bullying is always wrong according to everyone, but that person being bullied is always the exception. “If they could just act in another way we wouldn’t be “forced” to do this to him/her.”

Well I think there are a lot of people out there who define bullying as "when a random person in a group is selected to be harassed". And if you ask them what they think about it they would say "It's horrible and totally unacceptable".

But "disciplining" someone that is acting weird on the other hand is the right thing to do, that is not "bullying" to them. But for the person that becomes the subject of this it becomes, "you sit wrong", "you talk wrong", "you eat wrong", "your sense of humor is wrong" until it feels like you can't do anything right. Some people even think they can fix your "wrong" behavior by hitting you, and then it becomes physical bullying.

A lot of people wanna believe that bullying is like the fist scenario because that is easier than actually having to start accepting people the way they are - even if they are a little "weird".

Unpopular opinion, but most people who get bullied are a little "off", a little weird in some way that affects their likability. And this also affects the adults where even they judge the kid being bullied harder. For example if you are autistic and lack verbal skills, that's going to be seen as you lacking social skills. And obviously if someone got hit, who's most probable to have started it? Maybe the kid that "lacks social skills".

The thing is though that it takes so little to just avoid things like this. If the security guard actually did his/her work and checked on unknown person coming in to the building. If the company used a password manager to share WiFi passwords (or maybe even Enterprise WPA with certificates), and make sure unused public ethernet-ports are not patched. Then these two very simple things would have made this much harder.

I think the sad part is that they had probably had some security guy tell them this already but people where just making fun of him because people don't believe things they can not see - so it takes a "pretend to be SPYs charade" to make people actually care.

This scan is so limited that I wonder if it even could be directly damaging. If the average Joe who set up a CMS for his business runs this and thinks "Great I got a 90% score our site is secure".

The product affected here is litelarly called "CrowdStrike Falcon® Cloud Security". Meraki all tough they sell routers and switches markets their products as "cloud-based network platform". Jamf all tough their product is run on endpoint devices is marked as "Jamf Cloud MDM". I think its fair to say that cloud these days does not only mean storing data, or running servers in cloud but also if infrastructure is in any way MANAGED in cloud.

So to tie back to what i wrote earlier – none of these services has to have the management part in the cloud. They could just give you a piece of software to run on your own server. That would certainly distribute the risk since now it only takes someone hacking the vendor to go after all their customers, or in this case one faulty update brakes all users experience. And as far as I can see it seems we are willing to take those risks because we think it's nice having someone else manage the infrastructure (and that was my main point in the first comment).

Well, in all times usually there has been the option to run a local proxy/cache for your updates so that you can properly test them inside your own organization before rolling them out to all your clients (precisely to avoid this kind of shit show). But doing that requires an internal team running it and actually testing all updates. But modern organizations don't want an IT-department, they want to be "cloud first". So they rely on services that promise they can solve everything for them (until they don't).

Cloud is not just about where things are – it's also about the idea that you can outsource every single piece of responsibility to a intangible vendor somewhere on the other side of the globe – or "in the cloud".