Yep I use it quite a bit as well as Buffer's AI assistant to help me rewrite texts, or at least give me interesting synonyms. It's probably the only venue where I can say "maybe AI will help people instead of ruining their jobs"
HN user
luch
email : b93b3de72036584e405440479a77b4b7@outlook.com
there is a shit-ton of hacker cons outside of the US, the most famous one being the CCC (Chaos Computer Club Convention) in Leizpieg/Hamburg, Germany just before new year's eve.
You mention Dmitry Sklyarov but more recently Marcus Hutchins (MalwareTech) has been also arrested by the FBI following its appearance at Blackhat or Defcon
I don't think so, the adoption rate has done nothing accelerating since WWII. Once EV will be mainstream enough the switch will probably be quite brutal.
I don't think it is economically viable to maintain two sets of power distribution (electricity and petrol) at the same time so countries will probably "push out" traditionnal petrol stations once they think EV distribution is okay enough
Honestly what's the difference whether it's POTUS or Congress blocking the bill ? The writing on the wall is here: if Russia invades Poland, NATO article 5 or not the US will not go into full blown war with Russia.
And honestly it was the European's fault to believe in this pipe dream.
Obviously no what I mean that is ok if your superior and his boss are invited in your team's slack channel even if they only lurks, and you don't create a "shadow channel" with your teammates to talk on the project without being read by your hierarchy.
Same thing with corporate internet, you accept to use the corp proxy DNS and firewall (which all logs infos) to browse the internet instead of using a separate GSM endpoint to circumvent the company's surveillance.
That's not what I wanted to say. With remote teams, you need to establish a way to organize the work using written communications which are either mail/slack/sharepoint/whatever and within this framework management needs to have a "view" into what the team is doing.
It means for example being systematically in cc for mail exchanged and being in every teams discord channel. The new social contract when working remotely is "you (the manager) can't look over my shoulder to see if I'm working correctly so I (the employee) need to show proofs of communication instead".
I've seen too many juniors working remotely that just don't communicate on their day-to-day work, and completely blindside their manager/coworkers which understandably freaks out.
a videoconfering system that is reliable and easy to use is essential to remote management. You need to have as little friction as possible to propose a 1-1 or a 15 min roundtable to quickly brainstorm something orally.
Then you need remote "telemetry", meaning access either to chat messages, email, tickets, etc. and a way to process it at scale (without reading everything) in order to defuse sticky situations based on partial infos or misunderstandings. Such tools can be panopticon-y so you need to explicitly specify which convos "spaces" are private and which are subject to management interference.
most pentesters worth their salt would never do mass exploitation of vulnerable systems, there is little upside doing that and you never know what side effects you will trigger.
This project is fine for the author's self-improvement on how SSH is implemented, but personally I advise against using it in a production environment.
I agree with you on that, but the USA (and probably China) is the nation state least likely to skimp on iOS persistence when targeting Russian AV analysts :D
no way in hell the NSA forcibly tries to reinfect targets over and over, that's not their modus operandi. Instead they would have spend money to find a persistence on the infected device.
The fact that the attacker has almost a full-chain but no persistence screams to me "second fiddle", probably a nation state that have access to 0-days brokers but no in-house engineering.
Enabling lawful interceptions would only dry half the swamp, the other half being clandestine intelligence operations on foreign targets.
No way any reputable OS vendor would agree to enable, for example, Dutch intelligence services spying on Russian citizens living in the UK.
You jest but an eco-militant French association was dissolved last month for various reasons but among them :
- "le fait de ne pas communiquer les codes de déverrouillage de l'appareil ou de ne pas répondre aux forces de l'ordre en cas d'interpellation ; " // to not unlock your phone when police ask for it during an arrest
- "le fait de laisser son téléphone mobile allumé à son domicile ou de le mettre en « mode avion » en arrivant sur les lieux de la manifestation pour éviter le bornage, " // leaving your phone at home and go protesting in order to prevent from being geotagged
The chronological feed is coming soon
Not it won't. Facebook removed the chronological feed 10 years ago, they won't reintroduce it in Threads.
"Curated" feeds is how they get announcers to pay for visibility since the user has no control over what it is displayed at a given time
An example a real life reconstruction of a partially redacted SSH private key : https://blog.cryptohack.org/twitter-secrets
They have to choice to elect representatives that will legiferate on it, such as the EU with Apple regarding USB-C or app store sideloading.
Totally, DRM technologies aims to control the distribution, the consumer side is almost irrelevant here.
the DRM industry gets away with it since consumers don't care about openness or libre, they just want to watch videos in hi definition.
Wonderfully put. A relation of subordination is a relation of domination : as a team leader OP has agency over his/her team members' agenda, raises, roles, etc.
You can be chummy all you want with the people you are hiring for, but the relation will never be as equals and you have to be cognizant of that.
Yep a lot of debate even here focus only on tariffs and benefits splits where the principal issue is that fruits and vegetables have a seasonality and as a civilisation we should be more cognizant of that.
yep this problem has been solved on Android and iOS where the only place to install software is the App Store.
Windows did try to incite devs to use the windows store but it did not catch on. Restraining third-party installation only from the Store is a good way to remove adwares and co.
Honestly Microsoft did shat the bed with their app store, it has no right to be as difficult to use (both as user and developer) as it is.
Nope, most western European countries have extensive labor laws & social safety net and still struggles to find tradesmen. More often than not, they have to rely on immigration (portugal, poland, turkey, african nations, etc.)
They even joke about having to learn portuguese if you want to work in construction due to the massive number of portuguese tradesmen across Europe
Honestly it's a bit of both in this situation : they are good RF protocols that are secure enough (e.g. Calypso has not been broken yet) but they are not used by vendors since the insecure version is "good enough". Now that Flipper Zero exists, they have to adapt.
However, there is an ongoing discussion about offensive security tools such as Flipper Zero, IMSI-catchers, phishing frameworks, meterpreter lookalikes, etc. and their consequences on the overall security landscape. It used to be that tools were just tools, but now legislators and the general public ask for more responsibility from tools vendors. For example publishing a complete n-day exploit for a major vulnerability (windows/Linux RCE, O365 RCE, etc.) is becoming more and more frown upon since it primarily enables attackers.
you assume that Nintendo knows what they're doing, which is pretty bold if I may say.
that's probably the best advice. Instead of denying the proxy, just make it shitty to use for the end-user.
Yep, people seem to believe that Youtube is still a platform for crowdsourced videos, by the people for the people.
Youtube is since ~2016 primarly a platform for music clips, a sorta MTV for millenials and GenZ. They absolutely do not give a fuck anymore for content creator and hobbyists.
The faster people will understand that, the less they will be enraged about ContentID/DMCA
I do not need to explain to you what CVE means, but still the "C" is for Coordinated : CVE used to be that identifier where downstream actors could keep track of in order to keep their systems up to date.
Since Google and P0 are so worried about the safety of theirs users's ecosystem, they should issue CVEs for internally found bugs in Chrome so that CEF, Electron, and every chrome-like projects maintainers can verify if they have backported the correct fix. They even complained about downstreamers leaving a patch gap for attackers recently :)
Unfortunately, nowadays CVEs are a commodity (perhaps a currency in the future ?) where the less you have the more "secure" your system is, which is utter bullshit.
This may be unpopular to some here, but it is dangerous to let one man run a substantial part of the company's operations. There is a reason why the notion of "bus factor" exists and if you are senior enough, it is expected of you to mentor new recruits that ultimately will take your job.
That being said, they way he has been treated is absolutely infuriating and probably illegal in numerous countries which are not the USA.
because firewalls filter at the IP/port level, not at DNS level
Cool project, but AV are gonna flag the shit out of it.
ssf and other tunneling techno are already abused by a lot of threat actors ...
yes GDPR care about internal data like logs, because companies get breached all the time and data get leaked.
Since GDPR, PII (Personal Identifiable Information) data has become radioactive, the less you touch it easier your life is.
Microsoft is not the developer here, it has been outsourced to a game studio : https://www.asobostudio.com/games/microsoft-flight-simulator
But the remark still stand, and I hope OP has been correctly credited for it.