HN user

mSparks

79 karma
Posts3
Comments347
View on HN

Taking a devils advocate position for a moment.

I wonder if deminishing "net neutrality" will be "yet another nail" in the copyright industries coffin.

The closest analogy I can think of to a historic non neutral network is AOL. And we (should) all know how that worked out.

Dont think there is any doubt Russian (and Chinese) hackers completely own most US infrastructure. Only need visit a few Russian hacking forums to see that. It "was easy" because the NSA put so much effort into making systems insecure. (Have the US government replaced those Juniper routers yet?)

The only "doubt" is whether or not they are working for their state or just condoned by their state.

Plus a big chunk of playing to public opinion because it's heresy to imply let alone state as fact that Russian or Chinese offensive comp sci is better than US defensive comp sci. Even though, in your hearts, you all know it to be true.

such studies inevitably biased to find failures tho.

successes rarely get written up. so finding details on them is much harder.

also depends what you mean by fail.

if fail means "ran over budget and hit loads of unexpected problems" then yeah, most probably do "fail".

if fail means "shut down prematurly and abandoned without hope" then afaik, your only really talking about stuff by google and microsoft. most other software houses would fail with their software. and plenty are still arond from the 90s.

intel. ibm. apple... not so much real fail, for example.

My other post is flagged and downvoted by well, yeah, I'll keep it civil despite them.

But the point was, The russian hacker forums are orders of magnitude better than anything offered in English, and virtually every single one has made no secret (other than you need to read Russian) that they were working hard all year to get Trump "elected". From spreading rumours, distributing any dirt they could elicit, to boots on the ground playing with the voting machines. There was even talk of cash incentives from George Soros and Peter Thiel.

WaPo and NYT undoubtably have journalists that both read Russian and Frequent such forums. But it will be a while before they get the courage to go public with just how much US infrastructure is now completely pwned by the Ruskies. RNC and DNC only made headlines because some of the haul got sent to wikileaks aka FVEY.

My personal opinion is "America" deserves it for all the effort they put into making systems insecure.

that bit hes bolded isnt key is it?

the singluarity isnt "ai making new ai"

the singularity is ai solving problems that we cant - "greater than human intelligence."

which has basically already arrived. albeit bounded such that we still have ultimate control over what problems we direct ai to solve.

guess that depends on your definition of globalism.

the economist is pro imf/world bank.

that is less pro globalisation and more pro * poorer nations for the Western profit incentive.

which isnt quite an equivalence.

i often run into google web sites that render and behave terribly in android chrome (usually floating windows with the close hidden or extending outside the screen).

most web problems are now bugs either by the site developer or in a specific browser.

thats a long way from ie6 problems where either you needed a unique site configuration for every browser or supported ie6 only.

and for those to young to remember.

Rewson, SAFE, Waihopai, INFOSEC, ASPIC, MI6, Information Security, SAI, Information Warfare, IW, IS, Privacy, Information Terrorism, Terrorism Defensive Information, Defense Information Warfare, Offensive Information, Offensive Information Warfare, The Artful Dodger, NAIA, SAPM, ASU, ASTS, National Information Infrastructure, InfoSec, SAO, Reno, Compsec, JICS, Computer Terrorism, Firewalls, Secure Internet Connections, RSP, ISS, JDF, Ermes, Passwords, NAAP, DefCon V, RSO, Hackers, Encryption, ASWS, CUN, CISU, CUSI, M.A.R.E., MARE, UFO, IFO, Pacini, Angela, Espionage, USDOJ, NSA, CIA, S/Key, SSL, FBI, Secert Service, USSS, Defcon, Military, White House, Undercover, NCCS, Mayfly, PGP, SALDV, PEM, resta, RSA, Perl-RSA, MSNBC, bet, AOL, AOL TOS, CIS, CBOT, AIMSX, STARLAN, 3B2, BITNET, SAMU, COSMOS, DATTA, Furbys, E911, FCIC, HTCIA, IACIS, UT/RUS, JANET, ram, JICC, ReMOB, LEETAC,

etc etc.

In the good old days they just called them defectors.

Rather than whistleblowers that didn't blow any whistles. Political Correctness gone mad i tell ya.

As for "shared it with everyone on the planet." - really, where exactly can i download the 1.5 million highly classified US documents he has shared with the FSB?

There are three known potentially problematic areas and they are well documented. apple stuff, wifi cards, laptops and their custom sleep code.

aside from apple stuff (who have made it quite clear they believe their users want a totally walled garden and are not interested in compatabilty with the rest of the world), the other two are now rare afaik.

so if it happens to you regularily, then yeah, very likely it is nothing more than your distro sucks.

Its not exactly clear though, as far as I can tell "commercial features" just means JRocket Mission Control (which is a very cool bit of kit.... debugging production systems remotely with negligable performance hit, seriously you know you should be paying for that)

But yeah, the OP is a perfect example of a strawman.

Not just windows though afaik, JRocket MC is integral to the oracle JVM.

Their own fault they got slaughtered tho. I lost count of the number of times I watched a Lib Dem politician on TV defending idiotic Conservative policies.

They were all so blinded by actually being asked on TV most never seemed to think it would be a problem that they were being asked to defend things completely opposite to their views.

Why the beep they didn't say "Your policy, you defend it" I'll probably never know.

On Topic: I was worried this would be a "we're leaving the EU so we don't care" thing. But turns out they already lost in the UK courts and it was the government trying to use the EU to overrule the British legal system. Which is the first good thing I've heard the British legal has done in ages.

apple go to a lot of effort to make only their software work on their hardware, and vice versa, the days of the linux crowd caring enough to test it have long since passed.

whats the point in having a gui installed on a machine that by definition has no keyboard mouse or moniter (Aka a server)

they arent 3 "package managers". yum is a package manager, rpm is a package installer and dnf is a proposed replacement for yum. fyi https://en.m.wikipedia.org/wiki/Unix_philosophy

nearly all linux commands can be completed with around 4 key presses. e.g. aptTAB should give you apt-get

more depressing because fedora is the "canary" for new hardware rather than an everyday in use desktop let alone server.

so the fact it struggled on what seems like ancient hardware is hardly a surprise.

wonder what his reaction will be when he finds he has to go through the whole ordeal again after they end of life his installation in 6 months.

New XPS 15 Laptop 10 years ago

yet the link i posted is ubuntu users asking how to make it do exactly that, because by default something added no password to their sudo configuration.

which is also my experience.

having plenty of experience getting red hat fedora and centos set up just the way i like, i decided very quickly even getting ubuntu "safe" was more learning curve than reward.

New XPS 15 Laptop 10 years ago

most you can get to on a normal unlocked linux machine in normal use is the see browsing history.

you cant even copy files to a usb stick because mounting it requires a password.

that is very different to making the machine yours via remote access.

and very very different than letting browser plugins create user accounts that can be accessed remotely (that have root access by default). then theres the fact that selinux seems to be a right state on ubuntu

plus what everybody else said. basically put there are several nicer and more secure distributions of linux i would choose before ubuntu.

New XPS 15 Laptop 10 years ago

i barely trust my own programs to have access to the root account, why should any old script be able to access the entire machine in 6 letters?

"you should never run anything as root" yet on ubuntu everything as good as runs as root by default.

even windows ussually has a seperate password to create user accounts, but with ubuntu make the mistake of leaving your machine unlocked and unattended and any little script kiddy can own your machine in fractions of a second. worse even than windows, because they get remote access by default.

I understand why they did it. but if they are making those kind of changes I dont have the energy to track down what other things they "broke" to favor some (what i consider to be) misguided idea of useability over security.

you know, stuff like this

http://askubuntu.com/questions/153933/no-password-prompt-at-...

New XPS 15 Laptop 10 years ago

for a start, by default accounts can access the root account by simply running sudo -i

->Nobody is secure against their home country government, which has the power to both: -- Mount black bag attacks on your premises. -- Snoop the networks of internet service providers.

Indeed, not even our governments are safe from the government. like when they forced backdoors in juniper routers, then used juniper routers in government facilities. resulting in widespread compromise of most if not all government facilities and the loss of billions of dollars r&d advantage.

At least they put tons of effort into securing the voting system and didnt let a russian stooge get declared leader of the free world tho. so there is still some hope.

for us tho. encrypted at rest, and intrusion detection generally good practice.

nsa shill:everyone should use curve25519 hacker news:downvote to hell anyone who disagrees

that off my chest.

"protocol level" is the order of the bits. for example the octets in the tcp protocol.

"rearranging the payload" in this case is moving around those octets. and while of course it would work, is a bit simplistic. (so yeah, yek not far off)

the "Best" solution imho is to chain more than one cipher together. "like truecrypt does". for example, if you are using a pre shared key, use that key to encrypt the dhe with a symmetric cipher and a nonce. or some other non trivial obfuscation.

but the point is valid, even simple obfuscation requires human intervention, which breaks mass surveillance en mass.