HN user

gapanalysis

401 karma
Posts159
Comments43
View on HN
www.ren-isac.net 13y ago

Prevent your institution from being an unwitting partner in DDoS attacks

gapanalysis
1pts0
www.wired.com 13y ago

Biometric Database of All Adult Americans Hidden in Immigration Reform

gapanalysis
20pts4
securityskeptic.typepad.com 13y ago

Are Party Affiliation and Educational Social Impact Related?

gapanalysis
1pts0
blog.icann.org 13y ago

How to report a DDoS Attack

gapanalysis
1pts0
securityskeptic.typepad.com 13y ago

Mac Users: Prevent Presentation Hijacking, Disable or Pair Your Remote Control

gapanalysis
1pts0
securosis.com 13y ago

How to use the 2013 Verizon Data Breach Investigations Report

gapanalysis
2pts0
securityskeptic.typepad.com 13y ago

Measure twice, cut once: sound advice for infosec, too

gapanalysis
1pts0
securityskeptic.typepad.com 13y ago

Protecting the world from Your network

gapanalysis
1pts0
securityskeptic.typepad.com 13y ago

Ad Industry Attacks Against Mozilla Reveal Poor Choice of Campaign Role Models

gapanalysis
2pts0
securityskeptic.typepad.com 13y ago

A visual aid for raising social engineering awareness

gapanalysis
1pts0
securityskeptic.typepad.com 13y ago

Securing the Kids: because Kids are Human OSs too

gapanalysis
2pts0
securityskeptic.typepad.com 13y ago

The New Face of IP Scanning

gapanalysis
1pts0
securityskeptic.typepad.com 13y ago

Research and victim phishing reports tell same sad story

gapanalysis
3pts0
securityskeptic.typepad.com 13y ago

Book Review: Internet Down - A Modern American Western

gapanalysis
2pts0
www.riskbasedsecurity.com 13y ago

2012 sets new record for data breaches

gapanalysis
1pts0
usa.chinadaily.com.cn 13y ago

China is victim, threatened by overseas hackers

gapanalysis
2pts1
securityskeptic.typepad.com 13y ago

Domain Internet Groper: Using dig to access DNS zone data

gapanalysis
2pts0
securityskeptic.typepad.com 13y ago

Domain Seizures Act II: Minimizing Collateral Harm

gapanalysis
1pts0
securityskeptic.typepad.com 13y ago

Book Review: On Internet Freedom

gapanalysis
1pts0
securityskeptic.typepad.com 13y ago

Use these WordPress plugins to help secure your site

gapanalysis
1pts0
securityskeptic.typepad.com 13y ago

How to protect your Wordpress site from hackers

gapanalysis
1pts0
securityskeptic.typepad.com 13y ago

Elements of an effective logging plan

gapanalysis
1pts0
www.circleid.com 13y ago

DNS ROI: 5 reasons slow website speed kills

gapanalysis
1pts0
365.rsaconference.com 13y ago

Web Application Defender's Cookbook (review)

gapanalysis
1pts1
www.circleid.com 13y ago

DNS Firewalls in action: RPZ versus SPAM

gapanalysis
1pts0
securityskeptic.typepad.com 13y ago

50 Years of Doctor Who (Infographic)

gapanalysis
19pts2
securityskeptic.typepad.com 13y ago

The (Sad) State of Application Security

gapanalysis
2pts0
securityskeptic.typepad.com 13y ago

12 Days of Phishmas (A Christmas Carol)

gapanalysis
1pts0
www.thechampioncommunity.com 13y ago

Research & Victim Phishing Reports Tell Same Sad Story

gapanalysis
1pts0
securityskeptic.typepad.com 13y ago

Dorkbot: Malware That Spams Contacts, Steals Personal Data

gapanalysis
1pts0

I don't believe this kind of reaction can be solely attributed to socialism. It's endemic among "entitlement" oriented individuals. But the real failure here has little to do with what is fair. The thinking here is badly flawed at many levels.

That's explained in the 1st line of the post:

"If you are fond of double-clicking the Title bar of a window to minimize"

If you are not fond of double-clicking the title bar, then you probably weren't looking for the UI change from Lion to Mountain Lion.

>the legislators arguing for SOPA and PIPA don't care too >much about our complaints about potential legal abuse and >curtailing of the rights of American citizens and companies.

I can't decide if this is sad, deplorable, or scary.

Seriously? Cloud operators are so desperate to attract customers they are playing the "green" card? Clouds are data centers. They heavily virtualize but no one else can? Show me you can secure my data, restore it quickly for me, migrate it to another operator quickly, track where my data are at rest and stop telling me nonsense.

All you have to do is read the description of trending to see how people will try to game Twitter:

"Twitter's Trending Topics algorithm identifies topics that are immediately popular, rather than topics that have been popular for a while or on a daily basis, to help people discover the "most breaking" news stories from across the world."

If you want to up your followers, toss a profanity in every tweet. It's that simple.

Favorites here are:

"Advanced Persistent Threat -> Alarming people thoroughly"

"There is nothing that would make the anti-virus companies happier than mobile malware to bring their performance degrading, signature-based shakedown business to a smart phone near you."

"Twitter is the worlds largest manifestation of Skinners operant conditioning chamber with compulsive tweeting behavior driven by semi-random retweets & responses."

and :-)

"The biggest risk from the cloud is moisture"

I don't know what else a company can say than we choose to comply with court orders rather than face the consequence of not complying. The comment about bypassing censorship doesn't seem to have any value other than to placate users of the service.

I'm a marginal Linux script writer at best but I appreciate the point regarding composability. Still, I have to wonder whether composability is as relevant today as 30 years ago, not because it isn't a desirable attribute for programmers but because the thousands of developers that are churning out limited feature, limited purpose apps don't seem to miss it. Happy to learn if I'm missing something here.

Wow, can the founding chairman of ICANN be so out of touch with international markets that she doesn't mention the value of internationalized domain names? Perhaps anything you can't read in your native language doesn't have value to some, but this article only considers one aspect of new TLDs.

Dramaticus,

I emailed the author. He contacted SURBL. They say that bit.ly is now using the SURBL black list but that they don't prevent shortening of black listed URLs; instead, they show the warning that you saw. He's changed his post.

[dead] 15 years ago

Google certainly changed the way we use the web/Internet. Apple brought more innovation to the the way we interact with computing devices. Both leveraged technology that existed prior to their existence, much as the Romans created from and improved on Greek and Egyptian technologies. We benefit from both, I really don't care to argue which was "best".

I'm not sure that the article really tries to say that a certification is a magical elixir. I think he's saying that they are sold as being magical. I also think he's intentionally calling attention to qualities and criteria that are not easily measured. But that's my read.

Good points. I think setting expectations is critically important. I see a lot of oversell in certification programs (this certification proves you are elite) and too much blind acceptance of the oversell. These are serious problems.

I don't mean to be simple but the best incentives for using a product are (a) it does what it promises to do and well, (b) the cost and benefits are commensurate, (c) it is more elegant or efficient or <name your quality metric> than its competition?

I don't need games or rewards or incentives to buy products that meet these criteria.

In some respects, it's overdue. The US is has the most debt in the world. The debt-to-GDP ratio is 100%. Spending exceeds income. Would you loan the US money?

Until the Dems and Reps stop trying to win elections and start governing, things will not improve.

We need to spend less and collect more taxes.

We also need to stop imagining that there's a 2-4 year fix. This is not an economic crisis. Several decades of poor leadership producing fiscally irresponsible legislation put us here. It's going to take 5-10 years to correct. Lots of Americans will have to learn to live with less.

We've long speculated that incidents are under-reported. Social and other media are catalysts for transparency. They may also force organizations to be responsible or accountable. I agree this is a good thing. We may not be able to find a good way to capture real numbers, but I suspect that we have a more accurate picture than we did 10 years ago.

RE: benefits to livelihood. My security consulting didn't suffer while organizations chose not to disclose. The only difference between then and now was a clause in the contract regarding disclosure :-O

I wonder how this will come to market and how privacy will be protected. I know purchasing a test chip is not the same as confirming HIV positive but it is a data point, just as pregnancy tests are. If it's OTC do you have to consider how easy it is to track?

FTA: "[W]e’ve been told that 12,000 e-mails, 12,000 website views, 4 streaming movies and 5 hours of streaming music will start to put you close to that upper range of usage," wrote 9to5Mac.

Won't the email/web figures be mostly irrelevant in comparison to the movie/music data consumption? I wonder how much of the data capping is reaction to Netflix/Hulu consumption. I understand this is a big issue at college campuses and some businesses?

Agree. Investors are quicker to jump on any reasons to take profits and run more than they have in better economic times. I don't think 24,000+ tweets or even 10x that number are influencing markets, especially given the nature of the boycott.

I enjoy hearing different perspectives and I appreciate when errors or misconceptions are corrected during threads. I don't like the nastiness. The relative anonymity of the Internet is a disinhibitor: some people feel less vulnerable and more empowered here. Others feel that this is a domain where they can tilt the bully-victim playing field in their favor and get a bit of 'payback' (unfortunately, it's rarely directed at the folks who bullied the folks posting on HN).

Being able to be critical in a positive/constructive way is a difficult skill to master. Of course, this begs whether someone wants to actually critique or bully. If you're here to bully, ignore my post (or bully me). If you actually care about respecting others and having others respect you. (A colleague and former editor/moderator of an online media forum shared these with me).

1) First, ask yourself whether the comment is worthy of a response, or if you are just entering an argument. If the latter, think whether arguing with this person in this forum is really the way you want to spend your time. (Think, too, if you'd engage in this conversation in real life) 2) If you want to participate, type what you intend to say. Study it carefully. Did you 'add value? Did contribute an intelligent remark? Did you attack someone in a personal/offensive way? Would you be offended if someone commented in this manner on your post? 3) Read, revise, re-read, and revise again until you've convinced you've expressed yourself in the clearest and least offensive manner.

If you can use humor, be assertive, and enhance the thread by sharing what you know or feel, is there really any need to reach for more (or less)?

With every advancement in sophistication and especially with a pre-Boot, network accessible environment like EUFI's, we add an attack surface. UEFI has to be trusted and secure. I found a Black Hat article by Heasman (Google "Hacking the Extensible Firmware Interface") that does a nice job of explaining UEFI and what the "worry points" will be.

I've had so many issues with Adobe on Windows and Apple platforms over the years that I'm not at all surprised at how this played out. I've long abandoned Reader in favor of the FoxIT version for Windows and Apple's Preview. Adobe seems incapable of implementing a competent quality control program.

How To Manage Geeks 15 years ago

+1

Labeling and classifying folks with common educational backgrounds and career "orientation" is a common error when managing people. Technically oriented people can be marginal programmers but excellent team/project leaders or managers. Marginalizing staff - thinking they can't manage people - because they have a technology affinity, however, is a common bias. Good managers don't buy into stereotypes.

Not a sock puppet, sorry to disappoint. Should I say more? I think "do no harm" applies when you claim to be an activist. I can't justify an attack as a protest or retaliation against governments, corporations who act contrary to the public interest, fundamentalists, or individual sock puppets when you harm others by disclosing personal information, disrupting business, etc. The fact that you want to "out" someone or some organization and you can't find a legal way to do it doesn't justify doing whatever you decide is the best course of action. And if you do decide to break the law in protest, perhaps you might consider manning up and identifying yourself like Ghandi or King.

I honestly didn't use venues of this kind. I was fortunate to have some folks contact me. There are publishers who look for authors for book chapters. I found these to be too much work for too little compensation. I don't know if ifreelance.com or similar sites (search "freelance tech writer") are reliable but you have some time to research perhaps?