HN user

fictioncircle

335 karma
Posts5
Comments199
View on HN
The Stack Clash 9 years ago

I can understand it may be the right approach from a day-to-day IT management perspective, but I'm not so sure it's the most viable path towards better security long-term.

Yeah, this is why I had the caveat:

At least imho, given my time constraints/budget.

The "best" long term path is to have larger security budgets that allow for the objective you and the other folks who dislike my response want. The problem, frankly, is we just aren't there yet.

For instance, our budget for maintaining security is ~5% of the IT budget. A large portion of that goes to perimeter defense appliances (firewalls, barracuda antispam/antivirus filters, etc.) as well as making sure ublock, anti-malware, etc are installed on every machine. The other major chunk ends up in securing WAN-facing services that can be exploited remotely. The last major chunk is user training to get them to stop doing things like pay bills for services we never purchased, clicking on strange links, running strange attachments, etc.

After that, we have no resources to do more than run apt-get update && apt-get upgrade -y for protecting the attack surface once an account is breached. We've got a few things we had to re-compile ourselves manually and break with that process so we moved them out of the package manager for the OS. Our actual applications we build internally also likely have exploitable vulnerabilities if attacked from a local account. Those items never have the budget to be maintained and we certainly wouldn't survive someone taking over a local shell account.

I suspect given this is (roughly) the situation every place I've worked at, its simply too common to be an issue.

ProtonVPN 9 years ago

No VPN can reliably anonymize you against government agents so I think the con is a non-issue. VPNs are only really useful when the local network is hostile and/or you want some degree of privacy from the sites you visit.

Anyone with sigint capability is going to figure out who you are with a VPN. (i.e. Government agents)

Bancor Is Flawed 9 years ago

Now, now. I assure you once the permitting issue is resolved I'll deliver your bridge.

I just need another $10,000 :p

Buy parts and run your own firewall/dns setup to drop anything odd.

Its honestly the only way to be "sure" if worry about a manufacturer doing that sort of thing. It won't be perfect but the odds of someone targeting you for hardware spyware is prettttttttty low. And most manufacturers of comp enthusiast parts know its suicide to do it mass-market like that.

The Stack Clash 9 years ago

Isn't that just saying "I don't believe in multiuser systems and/or their security models"...? If so, what specifically do you have against them?

[Core Services] + SSH is generally something you can harden effectively against attacks.

[2903429034902323094230 binaries] is something you generally struggle to maintain security patches/etc on.

The simple fact is, there is just too much attack surface on a vanilla Linux box once you have an account that you can reliably do EVERYTHING you need to do to secure it 24/7/365.

At least imho, given my time constraints/budget.

True, in theory, though in practice, i know plenty of capable people but almost none of them bothers to read the openssh source (or even a subset, like recent changes) before updating or recompiling.

Then they aren't paranoid but normal folks, eh?

For purposes of security paranoia, if you can perform a security audit on open source code it is just as good as any other code you've written.

Idk about other people but I find anything I don't find security holes in myself "as good" as anything I've written. I've got the same set of assumptions/blinders/competence either way.

And, transmitting an URL usually has no use beyond accessing it. They are doing what the user expects, it's just lacking some communication and power-user tools to override the default behavior.

Let us just say there are certain things that can cause legal complications merely accessing it and not reporting it is technically still a crime.

And this is why we need online anonymity, to be perfectly honest.

Its too dangerous to be honest under you real name and has been for years.

Its alot like Roko's basilisk that way. Once you know the capability exists, you have to destroy it or help it. There isn't really any middle ground.

To be fair, doing so would require a bunch of cache invalidations and they've always barely had enough money to limp on to the next investor. It would also likely be abused.

Its quite possible many features simply would raise their costs by .X% and therefore were impossible for that reason.

Cloud Firewalls 9 years ago

I use the San Jose facility for my Linodes. I haven't had a problem since the rolling power outages years ago where Hurricane Electric's backup power failed to kick in.

It terms of a hostile 3rd party and not an automated system? 5 times.

Snoopy relatives of women I have dated a couple times, a couple times by PIs paid to track me down, and a stalker once.

So...yeah. It's a real problem and none of these people had a legitimate cause to do so. Even beyond FB, etc. I don't post my face online because of shit like that.

Other people have stopped posting pics of me as well, a couple people have been called based on my name being tagged to things on social media.

I know it's probably out of your hands but if you could AGPL the codebase, pitch decks, etc. It would be wonderful to help ppl learn, if nothing else.

Totally agree with you. Twitter should be publishing whatever the user wants to convey (unless its violating any local laws). They shouldnt be deciding whats right or wrong based on their personal opinion.

Stop blocking spam, advertising, and government propaganda then.

Absolutist arguments like this have an obvious problem in that certain classes of speech are a problem.

I despise this quote so much, and I'm far from a Trump supporter. If you need to censor speech in order for your side to win, maybe you have bigger issues than Trump's twitter account.

Stop blocking spam, advertising, legalize government use of propaganda domestically, etc.

No?

Then clearly your position has an obvious flaw in that you have to censor certain classes of speech. All of those happen on Twitter.

Mueller was asked to stay on as head of the FBI by President Obama, and served in the post all the way to 2013.

I'm aware. You seem to believe it means something more than Obama didn't have any major scandals to worry about that involved the FBI.

If you're going to accuse him of partisanship, by all means post some citations.

He is a registered Republican that backed the vast majority of their programs that were later found unconstitutional. He only ever pushed back when it involved Bush trying to get a guy in a hospital bed to sign an order overturning one small portion of it.

There isn't any way to "prove" someone is a partisan to people's satisfaction if the man's career doesn't speak for itself already.

The housing bubble was sophisticated investors thinking they swindled unsophisticated investors to some degree.

Private student loans operate similarly and have similar risks. Similarly, you can't _sell_ an education except with a job so if there is even the slightest panic a bunch of people can't pay their loans and the holder of the note can't sell the underlying "education".

Will these results be accepted, or are we off for another round of whatever the last 6+ months of daily outrage can be called?

Mueller is a partisan who offered to fall on his sword to provide Bush Jr political cover during a scandal.

They needed to appoint someone genuinely neutral instead of someone like that. Lol.

Its Mueller, not Comey, who is a staunch Republican who was appointed by Bush. And then offered to fall on his sword for Bush during various domestic wiretapping scandals.

Personally, I wouldn't trust anyone that partisan to investigate Republicans. Honestly, I fully expect him to come back with a handful of middlemen + Flynn and nothing touches any elected Republicans. Not because its true, but because its his marching orders.