HN user

grumpyinfosec

20 karma
Posts0
Comments21
View on HN
No posts found.

i don't really get the point of this? Its a ITX motherboard with a moible chip. I could buy a itx board and a desktop chip for less. Or get a miniPC with the same chip for even less.

They are trying to disrupt building a PC, which was already modular and easy to upgrade, with a 1000+$ motherboard with soldered RAM?

realistically blocking low cost personal VPNs / proxies is pretty easy. Any new servers they stand up are gonna get picked up by commercial threat intel services with an hour and then just blocked. Especially if the CDNs are working with the government.

You could roll your own but wireguard/openvpn going to random hosting provider is gonna achieve the same thing if they are playing hardball.

i always think about e911 calling for enterprise VoIP software phones. In order to make sure the calls go the right 911 local call center it is required to have the user enter the address they are using the computer at. It's the law and the fines for routing to the 911 center of last resort aren't cheap. And thats just the tip of iceberg if required employer surveillance just to follow the damn law.

https://www.fcc.gov/sites/default/files/voip_and_911_service...

ya it does seem like a good opportunity for US and Asian companies to get public sector research without even having to pay taxes for it. Europe really needs to build out the theory > applied science > product development > actually adding some value pipeline to make this have some impact longer term.

This makes alot of business sense, most orgs know better than to homebrew their mail env on (lets be honest here) "basement hosting LLC". So that leaves the people that are spamming/phishing as the core SMTP customer here.

We lost the personal self hosting fight long ago. I used to do it, but now i pay protonmail to do it for me and even that is losing its luster since proton technology IP blocks are pretty radioactive at this point. Some day will have join the outlook or gmail gang which makes me sad; but setting here in my chair staring at my orgs email firewalls and seeing 80+% inbound volume being auto-blocked as spam, bulk or phishing it make me wonder if anything of value was lost.

Its possible to restrict DIY building of pretty much anything if your end goal was to stop people from doing something outside of their basement with it. I can't build my own open source coal fired power plant and except to sell power without the EPA coming to kill me. Same would be if i used a open source AI that violated some new consumer protection / anti fraud law if i choose to use it over the public internet / build it into a product. Hell you could probably go after the devs for being accessory if you really wanted to.

The license really does nothing to protect your project from regulation its just that the government doesn't care about open source yet.

sounds about right, but I'd up #1 from "basic computer knowledge" to "sysadmin level enterprise system experience" if you want to truly be an expert. Success in cybersecurity on the blueteam side to me is more being a really good sysadmin that is paid to only think about security. I've seen people that just jumped into the field with just their fancy cybersecurity degree and by god they can tell me exactly what part of MITRE this control handles (in painful detail) but when rubber meets the road they don't really know how domain controllers work. It sometimes doesn't inspire confidence and since we need main IT to listen to us as security "experts" that really can be a issue if they think we can do anything practical. (they don't let us touch their toys) Im a computer janitor and i know it, just a fancy one with security written on my door.

or you could enable ios lockdown mode in one click if you feel like going full "im a targeted individual". I'm more talking appsec here. Even from the personal non-enterprise security angle android has the sideloaded boyfriend stalkerware issue and the flavor of the week banking Trojan PDF readers on google play issue. Apple just seems to stay out the news on the app store security front.

i wouldn't put much stake a zerodium numbers as the benchmark of platform security. People who sell these kind of gray market mobile zero days for big bucks aren't going public about it. Mostly because the only buyers that aren't the OEM are nation states, maybe the top end of criminal land and of course the NSO group. Plus android's at least 10x the market when you start talking IOT and point sale etc.

I don't even let my users have browser extensions without them going through the formal review process. Managing the proliferation of PWAs (potentially unwanted apps) is one of the most unsolvable issues in security. iOS is the gold standard for secure mobile computing due to inability to support alot of these risky use causes.

But like stealing from people just because you don't like them doesn't really change the moral calculus. I'd imagine most people that steal anything don't like the victim very much. Do what you want (or what you can get away with) but the "moral" thing would be abstain from consuming the products entirely or buy them according the terms of the seller.

GRC non-sense like this is really the cornerstone of cybersecurity. It seems like dumb boxchecking but these domains are the tools that we use to define, measure and most importantly sell security to management / main IT / users. The technical side is more sexy but then you discover that wack-a-moling the hot sploit of the week didn't really build your posture beyond the low hanging fruit.

i'm not sure many people would deny themselves the self-actualization / biological urge of becoming a parent for something as nebulous as sticking it to the man. People certainly didn't stop having children when we all where subsistence farmers or worked in glided aged era sweatshops to save them from the burden of being alive under the boot of capitalism.

Depends on the person. Alot of people don't really care about the macro. They go to work to add value, seek the admiration of their peers, not get fired (etc) and then go home and do something else. Living your entire life without really worrying about geopolitical bullshit that you have no agency over may very well be the optimal strategy. We have people for that.

seems pretty comparable to the other colder parts of the country. (besides the east coast) The warmer parts of the US i'd imagine are less sensitive to residential gas prices.

Thats kind of high. I only pay $0.78 a therm here in Wisconsin. 1 therm is around 30kwh so im paying like 2.5c a kwh vs 17c for electricity. So unless I can get a CoP of 700% from a air source heatpump im literally lighting money on fire. That really is the main issue, as much as I care about emissions I don't care enough to spend money on a heat pump to then spend more money on utilities. And the calculus gets worse and worse when your poorer.

Ya it does seem kind of silly. If it doesn't have caffeine or alcohol might as well just drink water or something diet. Your not getting much for your consumption of (usually) refined sugar or high GI carbs. Maybe in a social setting to pretend, but mocktails have existed for years?