This guy's OpSec was pretty bad. I'm not entirely surprised, but I am surprised it took this long for it to bite him.
HN user
digitalchaos
It's definitely a very focused search. There will almost certainly be more coverage over the coming days/weeks. It is reported that a full list of names and companies linked will be released in early May. http://www.irishtimes.com/business/what-are-the-panama-paper...
No. The government is the moving party. If the moving party drops it, the court drops it.
unless the digital data represents weapons? http://www.wired.com/2015/05/3-d-printed-gun-lawsuit-starts-...
I'd be all over this if they supported yubikey's U2F. I love 1pass, but it always makes me uneasy using Dropbox (or anything similar) for syncing.
Surprisingly, the passwords are probably the only thing safe. Looks like they were hashed with bcrypt.
> Astoria also opens multiple avenues for future work such as integrating realtime hijack and interception detection systems (to fully counter RAPTOR [18] attacks)
This is really interesting. I'm curious how that would work.
I'm pretty sure this is the answer to what Google wanted dropped (Edge Service): http://www.telecomsense.com/2015/03/the-fcc-avoided-a-bigger...
Isn't this the same thing as IRATEMONK that was revealed a year or so ago in the NSA ANT catalog? https://www.schneier.com/blog/archives/2014/01/iratemonk_nsa...
I wish my company did this when I had a kid. They gave me 2 weeks paid leave. Then I took 6 weeks semi-paid leave from the state. aaaaaand when I returned I was notified that since I "missed" a few weeks of on-call rotation during my leave that I was basically on-call for every day for the next month to "make up" for it. That was pretty awesome considering the production environment would break at least once every day between midnight and 6am. It made taking care of an 8 week old who needed feeding every few hours at night even easier.
Unless all they do is capture the flow of every handshake in a huge database. Then they can use that for targeted decryption or other forms of prioritized targeting. The NSA program is called Longhaul. Watch the talk Appelbaum gave at CCC very recently.
This is just the exceptional delays. People have given up reporting the "normal" delays we are now seeing every day due to overcrowding of the trains. The overcrowding slows down the onboarding/offboarding of trains by a lot.
Another crowdsourced caltrain twitter account is https://twitter.com/caltrain You can see some of the more granular delays there. All these crowdsourced status accounts should be proof that caltrain SHOULD publish the raw data for us to use.
That's understandable and probably a good reason for startssl to build an automated revoke tool, for the sake of keeping their name healthy. However, I would be way more concerned about a company unwilling to pay a trivial amount of money to revoke a cert that was compromises due to their own choice in how they used it. The best CA in the world won't fix bad security incident handling of another company.
Sure, most of the complaining was due to the entitlement, but I'd be interested in a list of all the companies that complained about this and/or failed to pay for a revoke.
If you read startssl'a justification on the free cert, you'll see that they charge in relation to the time they need to spend. A low level 1 year cert involves no human time. They don't have fully automated systems for revokes/reissues, so it's pretty lame for people to complain about them charging for it.
So the ITR report dropped back to normal right around the time that google claims to be returning to normal due to their load balancing infrastructure failing. https://groups.google.com/forum/?fromgroups=#!topic/google-a...
This article doesn't even touch the horrible nature of Clipper. Here is a summary of some of the worst that I have experienced:
1 - Intentionally inconvenient autoloading of a monthly pass.- They will automatically charge your CC for this but it doesn't load onto your card unless you have tagged on AND off in the specified zones. The even more annoying part is that during the beta period you could just double tag (acts like a refund) at a single station and your monthly would show up.
2- Effectively bricking their own card and making $250 worth of mistaken charges.- This is by far the worst I have ever heard about in terms of Clipper fail. I had a two-zone monthly pass autoload setup. I changed it two a one-zone. The next period they charged me for BOTH passes. I asked them for a refund and apparently this PERMANENTLY blocks your card from ever obtaining the pass type that you were refunded for. I discovered this when I changed the autoload back to a two-zone monthly.... and they CHARGED my credit card the $126 but never gave me the pass. Clipper insisted that they never charged me and wanted me to "prove it." It took me somewhere around 5 hours of phone time to get refunds and I still had to buy a brand new clipper card. The mistakes were 100% clipper's fault and it permanently broke my card. I am still waiting for that refund... should have just had my credit card block the charges!
You clearly have a large pool of hardware. Your numbers mean nothing without knowing the hardware that DIDN'T fail.
To give a more useful metric, for the last 4 years I have maintained a company have about 150 machines. 50% are Macbook Pros. 50% are Lenovos. I saw, on average, 5-6 Lenovos have some sort of hardware failure per year. The Macbook Pros would see 1-2 hardware failures per year. The Macbook Pros were also giving about 6-12 months of extra life before needing to be replaced. The external packaging of the Lenovos would produce MUCH more wear year over year than the aluminum Macbook Pro.
A big reason is that it's much easier to do from a legal perspective. Letting go of low performing people in a layoff is way easier than going through all the hoops of giving them warnings, putting them on probation, etc.
Also, a slow trickle of firings is just horrible for everyone. You have no idea if you are next, etc. A big layoff followed by a company meeting of "hey, we did a layoff because of X. There will be no additional layoffs as long as we hit our current goals."
It is always funny reading the hysterics of public perception when you are on the inside, isn't it? You are spot on though. These types of layoffs are the norm in gaming. I can't think of a single game shop that doesn't do semi frequent operational cuts (aka "trimming the fat") for the last 10-15 years. I don't know why this is always a shock to the community.
I propose that many of the "assholes" and "tear it all down" types are anti-authoritarians who fell through the cracks in the authoritarian system. They have all the anger, anxiety, and hate for the authority that surrounds them but they never found a way to obtain the higher knowledge about what is really going on. Maybe the "smart ones" just have a higher capacity to modify their world to fit them, maybe they had a better environment, or maybe they weren't as anti-authoritarian.
Handing your search data off to other people still opens up potential privacy problems. There was a FF plugin that would run random web traffic in the background based on various RSS feeds you pointed at it. I forget the name but I am sure you could easily modify that to do google searches. This would obfuscate your real data just as well without handing it off to other people.
Don't like the machine? Pile more shit on it!
The lack of a decent magnetosphere on mars is probably the biggest issue we have to tackle if we are going to send people there. It would require some pretty significant infrastructure on mars to shield us and all of our life resources. We would never really live ON mars. We would live inside of containers that happen to be somewhere on/in mars.
http://science.nasa.gov/science-news/science-at-nasa/2001/as...
http://en.wikipedia.org/wiki/Terraforming_of_Mars#Magnetic_f...
For all you guys targeting startups, do you have a recommended location for finding them? There are plenty of amazing startups around that I have never heard of. I feel like I just don't have the time to keep up or am unaware of some magic resource that some of you must have.
I am mostly curious about companies specific to the bay area but a larger scope would certainly be welcome.