HN user

devillius

36 karma

Healthcare Infrastructure

Posts2
Comments37
View on HN

The recommendation is to assign a /56 to end users from an ISP. That would give you plenty of subnets to work with.

/56 == 256 /64s Each /64 == 18,446,744,073,709,551,616 addresses

Web Browser: Firefox, Chromium, Chrome

Email Client: Thunderbird

Terminal: gnome-terminal

IDE: Atom, VS Code

File manager: Nautilus

Basic Text Editor: gedit

IRC/Messaging Client: None

PDF Reader: None

Office Suite: Libreoffice, Openoffice

Calendar: None

Video Player: VLC

Music Player: None

Photo Viewer: None

Screen recording: Recordmydesktop (Kali recorder)

As part of my current role, I setup and managed a unified logging infrastructure as part of a SIEM install. We're talking ingesting logs in the order of TBs a day (Lots). Here are my observations:

1. Syslog type logs are great when the volume is low, but field extraction can be a pain (unless you're a Regex savant)

2. Structured logs are nice to deal with. Fairly easy to read and a dream to parse. Make sure you have a good ETL process in place to process these logs so they are searchable. 3. If you have a lot of logs, they are only as good at the usability of the search on that corpus of text.

I use Splunk to ingest the logs and once the extractions are in place, it is a dream to search. Other options like ELK are available and work pretty well too.

Show the devs the advantages of having structured logs indexed and ready to search. No more: SSH > cat | grep | tail | less | more

Real-time functionality and the ability to alert on certain conditions is an added bonus.

Most password managers like LastPass let you designate someone else who can retrieve your account.

Master Passwords /Keys / Encrypted USBs in sealed envelopes stored together with your will all seem like probable options.

I personally have a Master password and a USB with my private encryption keys stored securely and Google Inactive Account manager to send instructions if I don't access my account for a month.

Good luck and I would be curious to hear what you end up doing.

I think the title is a little misleading. The report states that the findings are from 2006-2014 and that is when the rapid militarization of police forces with DHS funds was widely reported.

I fear that HN attributes all these to the current political atmosphere and how the foundation laid by the previous administration.

GPS Hacking, Part 1 10 years ago

The FCC rules for Amateur radio which is defined in Part 97 clearly states that an amateur may not disrupt radio location services. The frequency for the GPS Signals, high UHF is not close to any privileges available, amateur operators included. In short, don't do this unless you're testing / putting out very low power. Better yet, get an RF enclosure.

Here is a graphic of the spectrum available in the US: https://www.ntia.doc.gov/files/ntia/publications/2003-alloch...