This is bad advice. You should use a PIN on your TPM and not a password protecting the drive header.
HN user
mlosapio
Sort of. The better analogy would be spinning up compute localized to the s3 object; which would be pretty interesting.
This feature they did release deserves little fanfare.
Yes.
Is the dm-crypt decryption key stored on the NitroKey with a pin/passphrase to access the key to mount the decrypted the disk?
iOS Walkie Talkie has been down since Wednesday
This is a fantastic piece! I’ve been advocating for “complexity points” for years now. MBSA (make boring sexy again!)
Awesome feature that will likely unlock a bunch of services or service providers like Iceberg, Snort and Suricata to be able to capture and inspect traffic inside the cloud.
Thank you to the project maintainers; while RedHat does release the source code anyone who’s actually compiled from source knows that it’s never push-button easy
Volunteer Firefighter and SRE here.
ICS is crucial in any and all of our incidents and should be the model on how any disaster is handled
Thank you Caroll Spinney for helping teach generations how to be compassionate, patient and respectful of your neighbors. You brought to life custumes and characters that will forever define Americana
This needs more upvotes
Those were the days....
I’m available for basic security consultancy.
- MFA for initial logins - captcha for repeated attempts - IP based heuristics to detect fraud
I feel like these places invest very little in securing their platform.
I have to hope that the URLs for the objects stored in the cloud (s3) are at least time-bound and signed.
OpenBSM is awesome except you’re forced to invent your own way of log gathering - which becomes more painful when you’re mobile or offline and then you’ve got to keep state on what’s been transmitted to the mothership.
Would be nice for some insight into Dropbox’s solution here...
Wonder if services like Let’s Encrypt were affected. I imagine a scenario where a small hijack of DNS could allow for properly signed certificates for domains that are not owned. If I operated a CA service, I would carefully examine the requests received during this time frame. Maybe someone can audit the Transparency Logs during this period for anomalous activity.
Wonder if services like Let’s Encrypt were affected. I imagine a scenario where a small hijack of DNS could allow for properly signed certificates for domains that are not owned. If I operated a CA service, I would carefully examine the requests received during this time frame. Maybe someone can audit the Transparency Logs during this period for anomalous activity.
I feel like containers (at-times) are the artifact organizational disfunction, the inability for teams to collaborate and a lack of engineering quality.
What’s sad is that I believe this to be true for the overhwelming majority.
Diaspora raised a slew of money back in 2010 but flopped.... it’s almost as though we knew this would happen....
https://techcrunch.com/2010/05/12/diaspora-open-facebook-pro...
I didn’t read past the first paragraph before I formed the opinion that running all your VMs on a file system like this is a terrible idea.
If you can’t afford an enterprise SAN (I’m not even talking a NAS, I mean a real fiberchannel-based block-store) for your virtual environment (and I get it - many cannot) then just do yourself a favor and run on local disk.
The reduction in moving parts will dividends. I promise.
SuperNAP is in that area. Only one of the largest colo’s in the country....no big deal
Billboards track cars using the RF of the TPMS sensors on your cars and then make inference about who the driver statistically would be ....
What’s the tl/dr on this?
Because that’s exactly what I want to do - give my home encryption keys to amazon.
This is terrifying
If you encrypt your iCloud backups isn't the whole concern moot anyway?
FreeIPA
Rolling your own crypto - how about "don't"