HN user

mdmglr

700 karma
Posts9
Comments386
View on HN

The bogus CVE problem has caused delays in my projects because the CIO wants our COTS scanner tool reports to have 0 CVE's or a detailed explanation on why it is not an issue.

Also I'm having difficulty communicating: CVSS is not a measure of risk, and that many of the ReDoS vulns are very much dependent on the context.

I’m wondering if eventually airspace will be carved out for commercial drone operations. And if in the future the FAA will attempt to stop enthusiast drone operations via costly regulations in the name of safety for commercial drone ops. As it’s very easy for someone with a DJI drone from to fly beyond LOS.

Also a Walmart in my area has blocked off part of its parking lot to launch 6 delivery drones. I’m going to miss the days of quiet skies.

I think this is disingenuous. Example: configuring a linux firewall properly is not on the same competency level of changing your oil.

This script doesn’t harden sshd to the level I’d call safe. Disabling root login is minimum. I’d have port change, timeouts, fail2ban, otp via Pam all configured. Only allow specific IP ranges and users to ssh. I’d use ansible to properly configure instead of this script.

In the case of httpd. Id run it in docker or chroot. Again fail2ban, otp, I’d probably put it on a different port have it proxied via Cloudflare and have httpd only allow Cloudflare ips.

All this that are difficult to learn.

Source: I run my families infrastructure. Which spans multiple servers, routers, switches across 7 houses in 3 countries. I also change my own oil.

I don’t understand the tech independence claim? The script is replacing a unified service like Google or Apple iCloud with a lot of other services. Vultr and mailgun for example.

There is something to be said about the larger centralized services. I’d be hesitant to put any sensitive files on my own server. The larger firms have security departments ready to respond to CVE’s and 0days.

This will not be popular but you don’t need ECC or Xeons.

You can find great deals on powerful PCs from eBay sellers who are IT recyclers.

I’ve found the SFF/Mini PC’s to be great.

You also have to decide what you want to do. And if you want the headache.

For example it’s easy to start doing home automation, dns server, NAS. When things break or updates break things and nothing is working and you have to pull it all apart again was to much for me.

I agree. Many applications log for the hello of it and log unnecessary information.

We have concepts of debug, info, warn and error… but I think we need apps to be developed with the concept of log concern.

For example take sshd. For infosec they are interested in IP of failed attempts, operations might want to know connection failures, etc.

I would like to see a change in public policy on this. If you’re going to operate a car that costs 40k to get repaired on a small accident on public roads perhaps the operator should have to foot most of the bill. I believe the state of Michigan has this implemented.

There are already processes in place to make code developed from tax payer funded R&D available to American companies with a licensing agreement. To protect my anonymity I cannot elaborate more.

Well as coding is going away. Perhaps just show them how to login to ChatGPT and how to engineer a prompt to code. Oh an how to write requirements documents and manage an Outlook calendar. :)

In more seriousness, from personal experience, I’ve found is that when talking with younger children things need to be highly visual and interactive to keep attention.

The changing font idea is good.

An extension of that might be showing Scratch in real time and making changes or perhaps an Arduino and some LEDs.

Desktop Setup 3 years ago

Back in 2015 I tried to build my desktop. Rofi, Conky, polybar, i3, etc. I spent more time customizing things than getting work done.

The only figure I found in the article is Elon “was responsible for more than 2,000 tonnes of carbon dioxide emissions.”

Is there a compilation of emissions comparing across private jet owners, commercial aviation and perhaps other industries? It seems like only in the last few years there has been this microscopic focus on private jets. I would like to know if this is just an easy target or if this is a real issue.

I don’t understand why you’re mentioning your perception and opinion that people in Korea have 0 concerns about theft. And thus it somehow absolves Hyundai.

I suspect this was a money saving decision on Hyundai and Kia.

Immobilizers were standard on 96% of other manufacturers' models, the institute said. But they were standard on only 26% of Hyundai and Kia models. https://www.cbsnews.com/news/hyundai-kia-engine-immobilizer-...

It amazing to me people line up paying over MSRP for some of these cars. Some mechanic friends of mine have said that Hyundais are some of the worse cars. Full engine replacement with less that 30k miles.