HN user

brerlapn

97 karma

Government contractor, systems analyst, HN lurker.

[ my public key: https://keybase.io/brerlapn; my proof: https://keybase.io/brerlapn/sigs/0wbOSJOnEd63EMJyjGTgsWEY5FhlsgT_s2vAeIRz46c ]

Posts2
Comments84
View on HN

The Hiya app lets you block calls that start with a particular string. It looks like the app allows for blocking just an area code. The only downside is that numbers being blocked by Hiya will sometimes start to ring for like a quarter of a second before the blocking takes effect - still better than having them ring through. I have the area code and exchange for both of the numbers that ring to my phone automatically blocked in Hiya (so, first six numbers) and it makes a big difference. My LG G7 has a call blocking feature, as well, but trying to block only the initial string of numbers for the area code and exchange didn't work. I'd recommend Hiya.

https://play.google.com/store/apps/details?id=com.webascende...

You can go into your account settings under Personal Info and Privacy\Manage Your Google Activity and toggle your location history if you want to turn it off, but I've never had them update me via email. Given how much information is in that, I'd be surprised if they prompted anyone to go review it since most folks would likely feel like it's creepy to see a map of everywhere they went.

Replying to cbr/muro - those are emails about specific people that you have allowed to see your location data. The NC police are getting warrants for everyone in an area's location data. It doesn't matter if you've shared it - GPS, cell-tower data is passively collected by Google and then provided en masse to the police when subpoenaed. Nobody receives periodic emails from Google saying "you have your location services turned on [which we will nag the shit out of you about if you don't] and thus Google has a running log of everywhere you go [and if you happen to be in a jurisdiction that wipes it ass with the Fourth Amendment we'll also turn over all the data we've collected to the police]."

I've known a couple of folks who worked in gaming and it sounds pretty hellish.

I would second thrownaway954's comment about finding jobs that take advantage of your programming background, and especially in security. Being able to understand the deeper technical aspects of systems and to troubleshoot issues that you spot can be a real differentiator over people who have some technical knowledge but can't really do much drilling down past running security scans.

If you're not hostile to federal employment or have personal hobbies that could cause obstacles to such employment, there is a lot of handwringing about finding good cybersecurity people. That is going to be a kinder work week, too.

I'd say my higher level comment though is to echo that short stints of employment aren't dealbreakers, and don't get stuck thinking too negatively about your experience or your resume. Get a second and/or third opinion from other people who can give you an impartial impression of your resume and talk through how you address those experiences in interviews. I've been involved in the hiring process recently for several positions and especially for younger people I actually expect them to be moving from company to company pretty often, if for no other reason than it can be hard to make meaningful salary gains without doing so. If you don't hate the day-to-day activities of the work, don't give up on it - just put more research into finding better environments.

The US, Israelis, and Saudis, among plenty of others, have engaged in campaigns to influence foreign elections, no doubt. I think lumping them all in as information warfare campaigns with the most recent Russian activity is misleading, though - information warfare is more about seeking advantage and spreading disinformation. I doubt the Israelis are both lobbying for their interests with US policy as well as simultaneously running campaigns advocating for Palestinian or Iranian support. Likewise with the Saudis. America has no doubt influenced foreign elections- I've read an autobiography of a CIA case officer describing in detail such activity in the Philippines prior to Marcos' ascendence. Again, though, we were not also simultaneously running campaigns stoking advocacy for Philippine communist groups.

The Russian campaign here is as much about increasing chaos and discord in our civic sphere as it is about trying to push specific positions that favor Russia. Their goal appears less at getting our government to take specific pro-Russian stances as it is to weaken our society as a whole so that we are less able to act as foils to whatever Putin wants to do.

Russia has been doing information warfare very effectively since the Czars, and this seems like one more place where they've outmaneuvered us. I've found it frustrating how little discussion and coverage of Russian activity addresses that they weren't just pushing Trump as a candidate or pro-Trump agenda issues, they were pushing issues that they knew were polarizing Americans, simultaneously "Clinton is Satan's Candidate" and "Black Lives Matter" (setting aside the difference in the stridency between simply organizing a fake Black Lives Matter protest vs. the more paranoid baiting of right-wingers, which in itself would be an interesting conversation). The narrative continues to be "Putin tried to help Trump get elected" (which isn't completely false) rather than "Putin shrewdly exploited America's polarized political atmosphere of closed identity affiliations to weaken our core institutions".

A number of folks have asked if anyone knows more details on how a false alert could have been issued. I had some exposure to conversations about these alerts a few years ago, so a few thoughts. This isn't based on extensive experience, but provides a bit more background than you'll get from the news stories I've seen, and if you're burning with curiosity this should give you some jumping off points to research it further.

Although FEMA is actively developing more robust controls for their IPAWS system, the controls on user behavior and what functions can be triggered in the system have limited capabilities to enforce restrictions (one would be the requirement for a digital signature to accept a CAP message as valid). If you listen to the press conference [2] Hawaii says they will now be using a 'two person rule' which indicates that the most significant controls they have are manual/behavioral (not automated in the system by user roles or automated workflows based on state policies). Few information systems do much more than have a few coarsely-permissioned user roles, though, so it's not like FEMA or Hawaii has tried to cheap out on the functionality - it's just not a very common capability and emergency alerts isn't a mission where you want to be using 'interesting new tools' that aren't well tested.

There are several alerting systems - the Emergency Alert System (EAS), the Wireless Alert System (WEA), and Non-Weather Emergency Alerts (NWEM). States use FEMA's IPAWS system for sending alerts, which [1] this one seems to have been sent through (localities don't necessarily participate in IPAWS, which is voluntary, but the Hawaii EMA was the one that sent this). Some questions I would have about this would be: - IPAWS messages must have a digital signature to be accepted by the system, however based the Hawaii EMA press conference and articles which say 'an employee made an error' I would guess that the digital signature is not used in a way that is actually tied to the official authorized to declare the alert but to is accessible to their whole emergency Operations Group. - Are they sending test messages with that signature? With a 'two-person rule', it sounds from the press conference that it isn't enforced by the machine (not like having two keys which both have to be turned to send the message) but by the first person stepping away from the machine and letting the other person push the "are you sure you want to send this?" button. That doesn't seem much better, but changing the system to do that gets away from the basic CAP architecture and isn't likely to happen soon.

The FCC is currently working on a proceeding regarding updating WEA to allow more geographic targeting of alerts, the way the other alerts can be targeted at specific locales. The current system dates back to 2011 or 2012, and is pretty coarsely-targeted, which is probably why you're getting Amber Alerts on your phone for a town that is 6 hours away just because it's in your state. You can find it at Proceeding Numbers 15-91 and 15-94 [3].

[1] You can see the message here, which archives messages sent via IPAWS: http://ipawsnonweather.alertblogger.com/?p=18764 [2] http://dod.hawaii.gov/hiema/press-conference-missile-alarm-l... [3] https://www.fcc.gov/fcc-announces-comment-dates-rulemaking-s...

This gives some more technical details on IPAWS and the Common Access Protocol that these messages use: https://www.fema.gov/pdf/emergency/ipaws/ipaws_cap_mg.pdf

I bought a license for this after having a series of problems with the Google Drive app, which was quite buggy and unreliable on syncing. Problems went away as soon as I switched to InSync, and it has been rocksolid for over a year and a half. It's definitely worth the cost of the license.

If you're using Linux for work, be careful with AMD - I had no end of trouble with the video drivers. Everytime the kernel updated the screen would only be black with the drivers installed. I had to go through an elaborate process of uninstalling the drivers, booting in safe mode so the video settings wouldn't also black out, run updates, and then make several attempts to get the drivers back in. Happened for both Debian and Red Hat distro variants, and I never found a fix despite a lot of forum research. I'll never try an AMD with Linux again.

Lawyers in most jurisdictions are required to take Continuing Legal Education courses, but my experience was they were of limited use and the ongoing practice of law kept me far more current about legal trends than the courses did. They seemed more geared toward keeping the lowest common denominator from dropping into the realm of malpractice than teaching you anything that would be 'cutting edge'.

I agree in that I go to Whole Foods or a similar store over mass market choices like Walmart, but even at Whole Foods you're not necessarily getting the best form of supplement in those generics. Differences between bio-availability or effectiveness can be very notable between citrates, acetates, chelates, glycinates, picolinates, etc. I've personally found some good functional medicine sources of information (I've found Chris Kresser and Chris Masterjohn informative, balanced, and non-doctrinaire) that pass the smell test, but find somewhere you trust that breaks that information down a bit more so that you're getting the best form of supplements. The best forms in my experience are typically not is the generics or multivitamins.

Fastmail is quite reliable, and they support CalDAV and CardDAV. Their android email client is fast but doesn't work offline--fortunately they support IMAP Push and work very well with whatever 3rd party email client you prefer. I haven't moved my personal domain over there yet, but I've been using a paid tier for several emails with them for over 10 years and have been very happy. I haven't tried the exported ical format programmatically, but some of their devs are active on HN and if you shoot their help desk a question about it I expect they'll get back to you promptly.

It wouldn't take a particularly imaginative plaintiff's attorney to come up with a strong argument that Airbnb itself is culpable for enabling discriminatory behavior. AirBnB would have deep pockets, which makes them a juicy plaintiff's lawyer target, and they'd likely end up settling to include a bunch of protections for minorities in their business practices with the people who own the rental units.

"Peter Schiff said back in January that the US would have a big recession this year. If we don’t have a recession this year, people will forget Schiff’s false prediction, as well as false predictions of major crises in the US in 2015 and 2013, and recall his correct prediction of the 2008 recession. (Insert broken clock analogy here.) Whenever I hear that someone has accurately predicted a recession, my evaluation of that person declines."

http://www.themoneyillusion.com/?p=31615

uMatrix looks heavy duty but effective. I'd never heard of it before--it looks like it could replace my user-string randomizer extension as well as Noscript and uBlock, which makes it worth a strong look. I've already found some tutorials that make it look a little less intimidating. An upvote didn't seem like enough of a thank you for posting.

ScriptSafe for Chrome. DisConnect or Ghostery maybe? Not quite the same, but they do break web pages just as well as NoScript. :)

I'm hoping someone else posts some reasonably user-friendly alternatives. Adblockers can be manageable for technically less-savvy users, but I'd never have considered putting NoScript or even Disconnect on my parents' computers for fear of how often I'd get help desk calls from them.

This is correct--I've had conflicts and a second kdbx file is created with conflicted copy and the date of the conflict in the filename.

It's a small pain to go through and figure out which item is out of sync, but doable.

Read this back to back with grugq's post today, although standing on its own the level of vitriol Farr describes over the LT would give me pause:

http://grugq.tumblr.com/post/145440005263

"Why Misogynists Make Great Informants: How Gender Violence on the Left Enables State Violence in Radical Movements"

Never met Farr, but it's always sad to hear stories where positive contributors are ground down by this sort of unacceptable behavior.

[dead] 10 years ago

Like we don't have enough trouble with people clicking links in phishing emails, why in the name of all that's holy would we want to train users to click on any 'interesting' link in a marketing cold-caller's email signature?

You're definitely welcome. My folks have been through this recently, as well. Smart practices like using a password manager to segregate all accounts with different passwords can help to protect ourselves from poor security practices by other parties, like banks or vendors, and making sure they never link a bank account directly to a pay vendor rather than a credit or debit card (looking at you, Venmo). The main thing for the folks you're working with (aside from dipping that hard drive in bleach) is to protect access to their existing asset accounts and then keep a fraud alert on their credit. I think leaving those avenues of attack open is where the identity theft horror stories come from (or just basic overtrustfulness from people like the women in the BCC article below), so closing those off is a good idea even if you don't know there has specifically been a breach.

On a side note, the amusing part about having my identity stolen is that identity management at the enterprise level is what I do professionally, so I am well aware of the flaws in identity management that make id theft exploitable and now have a really good story to drag out when someone gives me pushback. Also, when the IRS guy was apologizing to me about all the inconvenience, I stopped him and said "don't apologize, I think this is hilarious. I have his refund check, he'll never get it, and I know he's trying to find out what happened because every time he pretends to be me and files an inquiry with you guys, the IRS response letter gets sent to my address since that's what's on the return. I'm probably the only person in America who laughs maniacally when I see a letter from the IRS in my mailbox."

For those who are so inclined, I found the approach the guy in this article took to be pretty intriguing, and have a to-do project of figuring out how to do this in a virtual machine:

http://www.computerworld.com/article/3030216/windows-pcs/fed...

Vonklaus - the link you posted with the details is coming up with errors in viewing for me, FYI.

Technically, you've clearly got an understanding of the fix, so I won't waste a lot of time on that. I wanted to speak to the rest though, as I've had personal experience with identity theft in the past few years. Really, anyone should just operate from the assumption that their SSN is compromised. Too many places have used them and too many places either don't even realize when they've been hacked or hide that fact when it's discovered. Her son should do the stuff written below whether they actually got his info from that folder or not. (Also, they did freeze the payment they made to the scammers, right?)

First off, do check if your local police have a place to file a report online. My local police dept. has a website where you can report identity theft and immediately get a report number and printout. If someone uses their information to file a fraudulent tax return, they'll need that report as part of their package to substantiate the issue to the IRS. If you want to do IC3, too, that's fine--but get the traditional police report (and don't wait until some problem comes up as a result of the breach). It is a good idea to build a narrative with corroborating evidence--the IRS was apologetic to me, but having a evidence of a reported incident and efforts to follow up is a nice preventive to potential pushback at a later date from a private entity that wasn't careful.

I'd also recommend filing a tax return early, as soon as they receive their W2. Fraudsters try to get their fake returns in before the legitimate one, because the IRS will issue their refund without questions unless you've already filed.

Getting access changed for all of their accounts is a first step, but I would recommend also getting 2-factor set up for any account it's available for. 2-factor makes any future breaches that much easier to mitigate. Additionally, they should check any account settings for additional recovery emails or in email accounts settings for any forwarding addresses added to the account. All the remediations in the world don't help much if they can still trigger a change in a few months by getting the password reset sent to fuckingscammers@dickheads.com. This should additionally include making sure that anyone they have an account with has a fraud notice and ID check that doesn't rely on information in their credit report. For instance, my security question answer to "What is your mother's maiden name?" is to the effect of "a(DH?BMBNOrcumb#72tT". Use a password manager to keep those straight (I just keep them in the Notes field and cut and paste as necessary).

The son should have a fraud freeze with the credit agencies, so that they can't use the experian report to create new accounts, and he should make sure he's changed his passwords (if there was a folder of his on the computer with his job search files, it is also likely he's used it for browsing and there could have been passwords saved somewhere). I'm not sure what his concern is professionally, but he could contact his company's information security office about potential safeguards.

I've had no other identity theft issues from my information being out there aside from the fraudulent tax return, which makes sense. The IRS cut the douches a check for $8582, which, had they not fat-fingered the 16-digit prepaid Visa card number they tried to have it deposited onto, would have been a much more lucrative payoff than trying to run a couple of fraudulent credit card charges that Visa would quickly flag. Once you've triaged actual account access, keeping the credit agencies locked down is really the main thing to keep an eye on, since that would flag any attempt to use the information further. They should be reasonably vigilant, but my experience has not been that this was an apocalyptic meltdown of my financial identity and taking reasonable precautions while hardening their accounts should give them some peace of mind. I've heard mixed reports of Lifelock's effectiveness, but if they're anxious types Lifelock won't hurt them--it just might not be more than a placebo against worry.

I've got an AMD laptop with AMD graphics and have to install the Catalyst software to get responsiveness from Ubuntu graphics. If I don't completely uninstall and purge Catalyst before allowing system updates, then reboot using a custom boot command, then shut down and reboot (with the custom command again), and then reinstall Catalyst, I end up with a machine that boots to a black screen and is essentially useless until I wipe the drive and reinstall from scratch. With 15.10 I thought this had changed with a new set of non-Catalyst drivers, but the problem reappeared.

I hadn't expected this, as my previous two Dells with Intel or Nvidia graphics hadn't caused any problems since years ago when wireless issues got sorted out. Linux has made a lot of progress with hardware compatibility, but if you find one of the weird issues it can be damn near intractable and user forums are a maze to sort through.

Not the OP, but on my Android device I have an easier time of calendaring since basically any app I choose will show all of the calendars I want (personal, my work calendar, my manager's calendar, my team's calendar) in the same space. For desktop, I did have Sunrise's desktop app until I noticed I wasn't getting a proper sync of some (apparently random) appointments from desktop to cloud/mobile, and even more so because I accepted an appointment via Sunrise and it changed my email alias in the response from my actual address to Sunrise's generic "invitation@email.sunrise.am" so that people then started emailing me at the generic email rather than my actual address.

Most of my calendars are Google Apps. Outlook was my backup for the work calendar using the Google Apps Outlook Sync app (although I've noticed a few sync failures there, too), and just adding additional calendars to Outlook without having all of my email there too looks like it requires some kind of arcane magick. Thunderbird+Lightning got rotated out of the mix quickly due to a lot of issues syncing and getting multiple calendars into it.

Probably because everyone we're communicating with is mixing between Google Apps/webview calendar and Outlook or Office 365, I also find that I regularly can't see an appointment that is emailed to me in my email client as it shows up as an .ics file attachment instead.

So featurewise:

- Most important for me: Easy addition of multiple calendars, where I can just select which calendar a new appt should be added, as easily as I can in my Android clients- I hate using web clients for calendaring, and they never really show multiple calendars well. NOTE: I mean that the calendar has a direct sync to each of the calendars online, not having one main account to which I have to share all of my other calendars. I want one place where I can go to view and create appointments and then have them also show up in their respective accounts. - Supports open standards like CalDAV/CardDAV as well as syncs to Google or Office 365 (I can select a provider like Fastmail that uses CalDAV for my personal calendar, but I'm stuck with Google or O365 for work) - Desktop client, multiple views (agenda, today, week, month) - drag-and-drop of items into the calendar to create a new appointment - "Send to calendar" from an email as an option - Categorization/tagging on an appointment would be nice - Outlook allows this but Google doesn't seem to allow tagging appointments like you can email

A bit of a data dump, but a desktop client that handles multiple calendars well is surprisingly difficult to find in Windows. I happily pay for a number of otherwise free services (Pandora, Evernote, Pocket, Lastpass, etc.), but there really isn't even a pay option.

This is even more true for social benefit companies. When I attended Netsquared in 2008 it was immediately apparent that the products with the most promise for developing countries were mobile products--for many in developing countries mobile is the internet. One of the exhibitors had built an SMS service that farmers could text for commodity prices to determine when they would go to market and prevent being undercut by middlemen. I'm sure that sort of ingenuity will only be amplified with even low-end smartphone access.