Usually through service accounts. Those are single factor.
HN user
itscrush
Monetize first is their strategy given this included statement:
Our future plans include letting you save a secure backup archive to the location of your choosing
Looks like AdGuard allows for same, thanks for mentioning dnsmasq support! I overlooked it on setup.
Certainly doable, grapheneOS has it https://grapheneos.org/features#duress.
Wrong. Their profile clearly states high school teacher. Why assume?
Wiz is closer to the CNAPP field instead of the software composition analysis tools you mention, Snyk would fit here for SCA.
Sysdig, Palo Alto's Prisma Cloud, or a few others compete with Wiz's CNAPP offering. Wiz also strays into some SCA and SCA-alike tooling for containers, code or XDR with their CDR/XDR products log ingest and agents available for response/quarantine.
Wiz uses various API's via read access in your accounts/orgs/subscriptions to assess risk of configuration.
They also snapshot your disks, cloning them to Wiz accounts to provide secrets scanning / vuln scanning / etc against your infra.
These resulting risks / findings are scored and provided in their SAAS Wiz console via dashboards / APIs / integrations with remediation guidance.
Yes folks do and I can't understand it either. Have asked / talked through their rationale but frankly humans are irrational is my clear takeaway. I experience it mostly when folks are prompting search in family settings. These usually overlap with the no-earbuds watch-videos crowd while others are reading / napping, etc.
Certainly not the UK, they're spearheading much of the privacy problem.
Bitwarden for usability. Vaultwarden if you can and prefer to self host. Being on the internet you'll have to trust someone at some point. Can reduce risk by combining strong 2FA (not SMS/Email) alongside backing up your vault.
Ensure all your passwords get reset at some point after vaulting, long randomly generated from Bitwarden extension/app is easy enough. Ensure you enable strong 2FA at each service you have an account at too.
https://bitwarden.com/help/setup-two-step-login/ https://bitwarden.com/resources/guide-how-to-create-and-stor...
I am using CloudFlare for my DNS.
Based on this it sounds like you exposed your resource and advertised it for others. Reverse dns, get IP, scan IP.
Probably simpler, you exposed resource on IPV4 publicly, if it exists, it'll be scanned. There's probably 100s of companies scanning entire 0.0.0.0/0 space at all times.
Why isn't your name in your profile here or why aren't you easily identified if that's the case? You're not all that identifiable here.
1. Is github the best place to report bugs / issues for Waterfox?
2. When (not in your lifetime obviously) Waterfox is broken, what canaries do you have deployed that we can archive now, like Mozilla's tell here?
3. What keeps waterfox afloat? Where/how do you accept funds?
4. How do I find a sync alternative or provide my own? Such that, I'm not reliant on Mozilla sync/backend? ... If none exists, how much would it cost for you to embed one? Would you accept a serious bounty for it assuming the focus is self hosted / no Waterfox backend services?
Veracrypt works just fine on M$ Windows 11 for FDE.
Same play as the meat industry leveraging "data analytics" to fix and sort at https://www.agristats.com/.
[1]https://www.justice.gov/archives/opa/pr/four-states-join-jus...
[2]https://farmaction.us/2023/10/12/food-price-fixing-is-still-...
The security community used to maintain one that was fairly active pre-covid.
Is the best counter here to acquire a brand tld to operate themselves (setting aside all the linkrot it generates)? They've certainly got the resources when you compare against other brand tlds that this could have been an option.
The tld it's dependent on doesn't fall within these parameters. They also don't own and operate the .cc TLD do they?
I think librewolf gets you most of the way there. Just add a sponsorblock extension and check a few extra lists on its built in ubo.
Does the reliance on Firefox ESL or based on Gecko rule this one out?
Namecheap's been out a while, I'd drop them from your list too. Porkbun's in for now.
It was released as freeware back when by EA originally, which is what openRA relies on. Later the source was released under GPL[1] during the CNC remastered collection from EA.
[1]https://github.com/electronicarts/CnC_Remastered_Collection/...
No, start with modifying the Colorado River Compact and other underlying agreements to allow more upstream retention than is currently allotted.
Turns out VPN source IP is given a different redirect
Thanks, FF fork here with ubo, most lists, and medium settings enabled ... somehow this is not the case for me. I'm not being served a page with any overlays / modals, just this redirect to login page.
I know exactly what you're referring to those "content hovers". Like the substack highlight, sign up overlays on immediate visit, or upsells in shopping cart flows.
Thanks for the response, somehow this is not the case for me. Like past times, I always hit the walled garden unless it's Facebook's actual Blog pages.
The provided link of https://m.facebook.com/story.php?story_fbid=1015993413146151... redirects me to https://www.facebook.com/login/?next=https%3A%2F%2Fwww.faceb... which is a hard auth page. No modals, no pop-overs, no X / bypass on the redirected page.
I tried the archive.is for content a work around on the share link, also didn't work.
Are you sure? Your link also lands me at an auth required splash page.
Yea good assumption, SQLMap for instance, defaults --dump to .csv with sqlite as an option if you're just looking for a simpler test point. Plenty of other tooling options out there too. Tooling providing your encoding during dump will overcome the ',' concern though, no?
[]https://highon.coffee/blog/sqlmap-cheat-sheet/#sqlmap-dump-d...
Free labor that you're handing away. Saw your edits, sounds like you've got start carving boundaries in stone and letting colleagues know it's their loss and fault for not eyeing timezones / after hours.
Abusive. Are you giving away your time for free too during these rotations? Bonus, overtime, equal time off?
Load Balancing && WAF or CDN enablement usually suggests at least a decrypt step or two in the HTTP(s) chain. WAF for layer7 payload inspection, or the default wildcard cert'ing your Cloudflare site for instance.
There's also significant aggregation of traffic at handfuls of service providers amongst service categories, all generally HTTP(s) type services too ... Mail, CDN, Video, Voice, Chat, Social, etc. Each of these are still likely to employ Load Balancing & WAF.
Most WAF/Load Balancing providers have documentation about when/where to perform decrypt in your architecture.
How many Cloudflare sites are just using the Cloudflare wildcard cert?
From there, plenty of 3 letter agency space to start whiteboarding how they might continue to evolve their attack chain.