yawnnnn...
wake me when the clickbate is over.
HN user
yawnnnn...
wake me when the clickbate is over.
I think the author is attempting to make the very valid point that not all good programmers can be expected to be giving freely of their non-work day time.
In short -- life happens but then the jobs dry up and good talent is over looked or lost.
And, yes, it does happen to women more than men.
the ultimate unanswered question
Answer: 42.
and, of course, DMARC -- so rejection policies can be set.
PGP FTW!
Now if only STEED would be implemented... http://g10code.com/docs/steed-usable-e2ee.pdf
But, unfortunately, even mail from a properly configured mail server on properly protected domain will still end up in gmail users' spam boxes by default. Domain and server rep systems are a bear to work with.
The encryption is really quite good. It's actually very rare to have a problem with the crypto. Compromise of the trust network is much more common and is really the problem with today's crypto systems... read a bit about superfish for a good news worthy example of abuse of trust.
When reading the https gov doc -- it's very important to remember that the government runs its own CA.
Freedom is an old idea. But somehow it never seems outdated. So, put down the iPhone and pick up the GNU Manifesto and enjoy software freedom -- as good as it is gnu
I strongly disagree.
The latest round of standardized testing, Common Core, is quite good. However, some schools and teachers and administrators will always act like:
TSA jackboots
This doesn't mean that the testing or the test material is a bad idea.
On my Firefox browser [31.5, Debian], the rotated image worked fine.
I agree. If you have more than one child, one parent's salary will go directly and entirely to pay for child care. It's also likely that one parent will need to work fewer hours and be available to drop off / pick up / emergency pick up the kids at day care -- which means at least one parent will need to be partially not working or at least not advancing in his/her career.
However, raising kids is very difficult and emotionally draining. Personally, I feel parental involvement is much more important than whatever might have been called a middle class lifestyle.
Yes.
I agree... almost.
You are dismissing the reality that some people are actually smarter than others. There are some people who really do have a real vision of a 'best' solution. However, it is true that collaboration is the requirement for a working relationship and thus a product out of that working relationship... But, the collaborative effort and resultant end product is always, by necessity, a non-ideal solution for at least a portion of the end-users. Keeping this in mind, it can be understood that "the best product doesn't win" -- rather, the most popular and most agreed upon solution or product is what wins.
In summary -- I agree that negativity and/or aggressiveness in pursuit of a solution leads to a unworkable /collaborative/ environment... But I disagree that the collaborative environment produces the best product or solution to a problem [programming or general]
Warning! I am not one of the smart ones. I tend to sit in a corner and doodle like the article writer. Perhaps, if the collaborative environment was less collaborative and more constructive, I would participate more... see Office Space for better answer.
Wide usage of DNSSEC is needed to trust DNS records. DNSSEC would also fully allow PGP keys to be stored in DNS...
See STEED...
http://g10code.com/docs/steed-usable-e2ee.pdf
But, yes! DNS is the correct and appropriate location for items like the OP posted... built-in widely used distributed 'trust'.
like PhotoStation, CloudStation, WebDAV,
There are secure ways to run things and insecure ways to run things. It's very possible to setup a postfix or exim smtp server as an insecure open relay running on port 25. It's also possible to have either running securely on port 25... And an open port is meaningless by itself. It's the security options applied by the system and application running a service on the port that matter.
The examples you give are just applications that run over http or https... https requires an SSL cert from a trusted CA, and http is a very bad idea for anything that you log into, or that has free access to your home network from the Internet.
I imagine most users skip this step... http://docs.qnap.com/nas/4.0/en/security.htm?zoom_highlights...
Note, the SSL certificate instructions... You can upload a secure certificate issued by a trusted provider. After uploading a secure certificate, users can connect to the administration interface of the NAS by SSL connection and there will not be any alert or error message.
...
The error message referred to here is the web browser message indicating that the SSL certificate doesn't match a trusted CA, and therefore your "secure" NAS connection might be Man-In-The-Middle attacked... And if you don't upload an SSL cert - and connect via http externally - it means that the most amateur of "bad guys" already has your 30 character username and your 45 digit/character/special character password...
Forget the password... Those are broken.
Use keys and only keys instead...
http://www.chainsawonatireswing.com/2012/01/15/ssh-into-your...
I'm not sure what you mean...
Are you comparing the Synology GNU/Linux distro to Debian or some generic [non-Debian] distro to Debian?
If you are comparing Synology to Debian, then the "trusted" source argument is entirely flawed. The source, meaning both source code and source of software, of software running on Synology hardware is not Synology. Synology only makes the GUI client that runs on your machine that locally interfaces to the NAS box.
As to the Debian 2006 SSL problem... stuff happens... Apple had some silly security problems too, much more recently than 2006. And Android is so full of holes, it's a wonder the platform works at all...
However, when the generalized public buys a NAS product -- the vendor should indicate the potential security problems regarding "cloud" connections in big bold letters on the box and in the manual and have a large red warning that pops up in the user interface. My guess is most users wouldn't care, but it actually is extremely risky to connect these devices to the wild wild west open Internet.
8760 hours = 1 year
So...
a 1 Watt device running 24x7 = 8.760 kWh
billed at about $0.40/kWh [includes both generation and delivery and normal for NE USA - ain't deregulation great?!] ~ $3.50 per year.
In order to get to $1.00, total cost per kWh must be about $0.114 ...
http://www.wegotserved.com/2014/07/30/synology-patches-nas-s...
However, there's really no reason to expose samba shares to the Internet. There are much better and more secure methods. As to the unfortunate victim, there's most likely no way anyone will be able to retrieve what has been locked by the remote attacker - except the remote attacker.
Synology DSM is a GNU/Linux distro. It runs the exact same stuff as any other distro, including the kernel and all services and the filesystem. The only differences between building your own NAS with a good server distro like Debian 'stable' and running a "commercial" Synology box are:
1. The client interface to the NAS.
2. The 'cloud' services.
Only #1 is actually a deliverable with the Synology NAS. And #2 presents a terribly broken privacy policy...
For myself, I'd much rather be running something that I know is updating from an authenticated and keyyed repo than something which is attempting to make the user believe that somehow the "commercial" NAS is magically different than running a regular GNU/Linux distro...
I think the snail mail to email analogy is flawed... snail mail has an envelope, plain text email does not. However, a postcard does not generally have an envelope...
So here are some better analogies:
snail mail letter == encrypted email
snail mail postcard == plain text email
publicly posted diary == plain text gmail
GPG works fine. It's difficult to get people to use encryption regardless of the implementation... I used to work for an organization that required, by written policy, all email to be encrypted. Everyone had an S/MIME cert with a short pin... the number of encrypted emails I received over a 7 year period was precisely - without exaggeration - '2.' People do not care about encrypted email, and don't want to bother with even the slightest inconvenience. This is by far the largest problem with encryption, much more so than any 'it's too difficult to use' excuse.
I believe they were told to hand over the SSL private key. I'm not sure everyone using the Lavabit service was a criminal... So, my thought is that probable cause for handing over the master key to the hotel should be a bit more than probable cause to hand over the room key...
End users need to and can take control over their own email privacy. GPG. Ten minutes to download, install, and generate a key pair is all you need to secure your email. Perhaps the willingness to do so will increase when the government successfully argues that non-encrypted mail posted through an email server is the same as posting your thoughts on a public peg board...
If you want full compatibility, you can pay a small yearly [extortion] fee to the Verisign gatekeepers... but I prefer not to...
No offense meant - but why tie yourself to a huge multinational corporate entity that sells your privacy to whomever, whenever, and forever - so that you, the user, can have email or know where the next coffee shop might be... The cost of using Google's services is not nothing. And while some here may be aware of that, and accept that - the generalized user is not fully aware - even if told...
There are several reasons not to use Google's services, but there are even more reasons not to sign up a minor for Google's services. It's useful to look at the issue from Google's point of view... Google's terms of services are meant to be taken seriously - they track you, and tell you they track you. If a parent signs up a child for these services, the parent is giving Google the right to track that child - if the services are tied to a mobile platform - the parent is giving Google the right to track the location of that child --- and Google has every right to assume that the child is not a child, but an adult, as that's in the terms of services --- thus, a parent signing a minor child up for Google services is giving away the child's anonymity and privacy, for pretty much forever --- that's a pretty big decision, and I would want my children to make that decision for themselves after trying to understand the long-term consequences.
I agree, if the email account is going to be used for long term purposes. However, an email account for someone at the high school level should be fine. Presumably, the kid is going to go to a college somewhere - and will use the college account until such time as the kid graduates and moves on into the 'real' world -- whatever that means. I'm just trying to say that a gmail account for a kid isn't a necessary burden that needs rescuing at even the meager upfront cost of $0.50... plus the massive cost in lost privacy - which is an ongoing fee into the indeterminable future...
I know lots of people don't know how to setup an email server. But gmail, as an email account, is worth less than $10/month. And, in fact, your ISP probably includes several email accounts with your internet service. If your child needs an email account, just assign him one...
If you have Verizon, here's how... [8 extra] http://www.verizon.com/Support/Residential/Internet/HighSpee...
If you have Comcast, here's how... [5 extra] http://customer.comcast.com/help-and-support/internet/adding...
If you have Cablevision, here's how... [4 extra] http://optimum.custhelp.com/app/answers/detail/a_id/1673/~/c...
So, in point of fact, gmail - as a 'free' email service - is actually a huge additional COST, considering the payment in privacy. And this is why I do not use it myself...
I would strongly advise that you complete the full Phd program if you possess the aptitude to do so... If you really want to work in industry as a physicist, a Phd will serve you very well. It's good to remember that completion of the Phd or MS shows stamina more than it shows knowledge - and employers look for the proof of stamina during resume review. So not completing the program shows lack of follow through. If you do not plan on completing the program, I would strongly advise you to get 'going' on something else that shows you have the stamina and work ethic that employers look for in new hire employees or contractors.
As a side note, I have a BSEE. Although, I did things a bit backward. I started a family first, and then discovered that a salary without a degree is much lower than with one regardless of the skills you may possess. It was a huge struggle to complete the degree later in life, even though it really wasn't much later... and completing a MS program was out of the question - even though I certainly possess the ability.
I think you are wrong on the control and privacy issue. It would seem to me to be more a lack of understanding on what control and privacy mean for the average user. Most Internet users are like most car owners. They have no idea about the inner workings, nor do they care. They don't generally assume that having a seat belt is more safe than not having one. And they generally trust that the manufacturer has their [the user's] individual best interests in mind when developing, building, and selling the car. -- Likewise, most internet users firmly believe that if it was "good" for me it would be already "built-in" to the system. This inherent trust in what is presented is the problem, rather than consumers not wanting control and privacy.
Perhaps the copies of data are geographically placed to minimize distance to within 20ms. Just a thought - I have no actual data to support that assumption.
My idea was a thought project, and I was not aware of RFC 6698. Thanks for the reading material, it sounds similar to my thought process...
However, my personal reasons to discard the current CA system is to enable secure communications from multiple subdomains without the need to pay a $500 rental fee for a wildcard identity+cert --- As well as enable secure passwordless access to A/MX records without fear of compromise.
The government is going to be able to break any system that's put out there. At the very least, a government can disrupt IP traffic in and out of a node. There is always going to be an open addressing scheme, unless the network is an encrypted peer-to-peer network with every node attempting to decrypt every packet... I seem to remember reading about a block chain peer-to-peer data network being developed. However, my guess is that overhead bandwidth limitations will be a problem for large networks.
In order to create a fake record, you would need to replace the PGP ID on the registrar's record. In order to that, you'd need to intercept and decrypt a PGP encrypted email. In order to do that you need to be in possession of the private key and have the passphrase. An attacker could steal the private key from the domain owner's computer [not the server] and install a keylogger to get the passphrase ... or an attacker could produce a private key from a public key... good luck with that one...
The system I've laid out would be significantly more secure and less spoof-able than the current system. Further, DNSSEC becomes entirely unnecessary...
Also, it is entirely possible to create a registrar which would store all user record data in an encrypted store which could also be encrypted using a domain owner provided public key... if this were added to the architecture, no government entity could modify anything regarding a domain - except replacement of the entire record.
Of course, since the entire system current and any possible future Internet relies upon computers and networks that are explicitly not under the control of the content provider - any government can at any time break the system... This is always going to be true of any and every system of wide networks.
EDIT: Computer A and B need a third entity C to validate A to B and B to A. True... However, this does not need to be a computer -- it could very well be a cryptographically generated unique ID... In my example "C" is the PGP ID. However, it could be any cryptographic item that is tied to the domain record and only modifiable using the private key that generated the unique cryptographic item... for example, it could be a bit coin address.