HN user

ianmf

99 karma

A security engineer. https://ianm.tech

Posts1
Comments46
View on HN

I owned several versions of Little Snitch too. It started to be annoying when you had to approve each request, especially when running command-line scripts. Then I moved to run in silent-approval mode. At that point, there was no reason to have LS any longer, so I uninstalled it. Haven't used it in years now. But not to discredit LS, it is an amazing software when you need it.

These devices are funded by government/school systems. When you receive them, you have to sign a TOS or User agreement, where highly likely contains a verbage similar to "This device is subject to monitoring". This is the magic statement; it notifies you that they could be watching, and you are aware and agree to the search.

The consent banner is typically mandatory on all government IT systems. Here is the one for the DOD: https://dso.dla.mil/

IIRC from my military time, the first generations of the patriot missiles (PAC-1, PAC-2) were designed to explode when in vicinity of the target. The PAC-3 missile was the first to introduce kinetic damage before the payload would explode.

It depends on how you define top-tier hackers. State sponsored attackers (hackers with ties to governments, regime, etc.) have a lot more capital at their disposal. Sometimes they work inside government funded facilities. They could use matrix, signal, forums, IRC, for chat. Browsing usually comes to preference but a hardend version of firefox is preferred. OS, whatever they want. Usually you would attack from a custom distro or a kali box. These hackers are well funded.

Lone hackers, they would probably use Tor, Signal, Tails, Kali, to remain anonymous online but have the tools necessary. The most important thing for them to stay anonymous is to have jumpboxes. You would use stolen credit cards or gift card to rent a VM from a host like Linode or Digital Ocean, and use that system to proxy the attacks. You can add any number of jumpbox to make it harder to track the origin of the attack.

I have not received an email from Google about the changes. It lead me to think that it is for accounts that have more than 1 active user. I have a G Suite Legacy with 1 account only. The change make sense to block companies from abusing the free legacy version. However, Google should allow users to downgrade to 1 account or migrate the data to gmail accounts.

I don't miss the physical media. I am happy purchasing digital content. It makes management and organization very easy. What I do miss is owning the content. If you purchased a Music CD or a Movie DVD, it was yours. You could watch it any time and nobody could take it away. Now, if your iTunes account gets disabled, you lose all your purchased content.

If the attacker opens the document on a computer connected to the internet, it will.

IIRC, the way it works: the document contains external resources with a unique identifier attached to the campaign, which the document viewer will attempt to connect and fetch. When the document viewer makes the request to retrieve the online resource, it will trigger the alert, collect IP, GEO information, and whatever other data it can collect.

You can use this over the internet, or host internally for internal networks without access to public internet.

I was once looking for a solution to some technical problem, clicked on a promising web result, and found myself at my blog. I had posted a solution several years earlier but had forgotten about it.

That is funny.

Once I recognized that I have been researching the same topics I have researched before, it motivated me to change my blog from a "Hack the Box" showcase blog, to adding my technical journal on topics that were hard to find online and sharing my experience with certifications.

I have been thinking of adding more personal entries, but I don't want to make the blog a social media.

I don't have anything interesting to say

I don't agree with this part.

I use my blog to keep a journal on technical issues that were hard to fix, or was hard to find web sources about the subject. One of my top post is about using PFSense router with Verizon FIOS. It usually receives 2-3 unique visitors a day. It is simple and not interesting, but it helps a few people, so I keep it online.

https://ianmf.com

I got hired via LinkedIn, but it wasn't necessary to have an account to get the job. The position I got hired for had a job announcement on the corporate website. LinkedIn was just another source of job listings. LinkedIN was a great tool for discovering positions, whereas without LinkedIn, I would have missed them.

There is the usual job opportunity spams, which for IT Security is not bad. I have received several initial introduction from recruiters from respected companies.

What I like about LinkedIn is that I can find out instantly if I know someone who already works at the company I am interested in applying. Being able to ask someone about the company's culture can help you make the decision if you want to accept employment or skip to the next one.

When Google Chrome came out, it was fast, reliable, secure, and it was not Internet Explorer. Chrome was what everyone needed back then. The competition was Firefox, which performance was getting slower (before Quantum). The problem was that Google shifted priorities for Chrome (or played the long game) to better support Google/Alphabet's interest.

As long as it is work related, it is not unethical to educate yourself in something new. For example, a new tech stack, similar discipline, or business administration. Employers and employees benefit when the employee keeps learning and bring more diversity and experiences to work.

I am tired of dealing with cellphone services providers. I treat them as such, a service company. I buy my phones from directly from apple, never from ATT. I simply pay my monthly bill and when I upgrade, I hustle to have the "activation fee" waived. I have 6 lines under my plan, they usually give in. Maybe I should start looking into Business account like someone else mentioned here.

Fios had the most service outages than the other five ISPs I have used. However, their customer service has always been very good and getting a hold of a human customer representative is very easy. Currently I have Comcast and their customer service is horrendous.

Not a programmer, but I divide my day in something like: First hour: Morning greetings, follow up from previous workday, getting my area organized for whatever I have for the day, check HN and news. Next 3-4 hours before lunch: Tackle the most difficult problem or whatever task I really don't want to do but must. The goal is to have the task initial steps completed (planning/thinking) so I can work on it throughout the week. Next 3 hours: Continue working on the tedious task above or whatever work needs to be completed. Last 1-3 hours: Finishing up tasks that can be completed before day's end.

For personal projects, I dedicate as much time as needed as long as it doesn't hinder my family or fitness time.

I have been using Google Voice since around 2014. I can make and receive calls and SMS for no cost to me. Bringing into consideration the recent changes to Google products regarding monetizing them, I expect some changes to Google Voice to come in the near future.

I also have a grandfathered GSuite Basic, which I am wary that Google might cripple it or force me to pay for it.

Are they using to Spy on their users or to keep the 'image' that Apple devices are more secure than the rest? I think the binary execution protection can do more good than harm. Sometimes shit happens like it did on Big Sur release. I just hope they change feature to not bring down the system to nearly unusable when ocsp.apple.com doesn't respond.

For me, it depends on what the note is for. I store all my personal notes in Apple Notes. When I am at work and I need to store personal notes, I use my Google Keep that I will move to Apple Notes when I get home (Apple iCloud is blocked at work but not google ¯\_(ツ)_/¯ ). At work, I store all my notes in OneNote. OneNote is by far the best note taking tool I have ever used. I wish the Mac version was better. On my Kali box, I use Cherrynotes. I only use it for HackTheBox. If Microsoft would have a good linux and Mac version, I would use it instead of the others.