HN user

pheleven

28 karma
Posts0
Comments21
View on HN
No posts found.

Yes, it's definitely a economic decision. They're going to run this type of software on their own fleet and want it on everything connecting to the network. If you're willing to run it on your own device that saves them the hardware cost.

That said, a lot of users _want_ to use their own devices (maybe they have better equipment, maybe it's less locked down, maybe they don't want duplicates). It's not sane for the business to allow a device that is more likely to be compromised and/or have poor security hygiene on the network.

I'm a fan of privacy but... At least on my team, we're definitely not spying on you, we're making sure you have a password, encryption, antivirus, and updates installed before you can connect to resources. It's shocking how many people don't have authentication enabled and run as root, if they have a choice, on their home system. That said - we could flip switches and do a lot more spying if it was mandated :/

Some of my local restaurants are doing this - effectively becoming concierge grocers who will break down bulk quantities for their customers. Call an order in and pick it up in ~24 hours. They have and can get almost anything the grocery stores are out of including TP (in jumbo commercial rolls), flour, eggs, meats, etc.

This actually isn't all that strange a failure mode. We have several large ZFS arrays in service and replace 1-2 failed disks every month. About 90% of the time the first warning you get is exactly this - a message from the CAM controller saying it failed a read in the syslog. ZFS nor SMART often notice these until they get pretty bad/frequent. By the time they're bad enough for other software to notice, your pool is performing pretty poorly.

We deal with this by watching for these errors, printing to a log specifically for Icinga to watch for and alert on, and preemptively replace the disks. It would be nice if the other software (ZFS, SMART) would notice these in time to not become severe.

Sure. First and foremost, do you have permission from your customers who you're researching and reporting on here? If you do, great, ignore me. If not you'd be breaching (my) trust if I was one of them. The data is not yours and it may be possible to infer who these datapoints belong to if so desired. If one could do that, they may be able to gain competitive advantage or otherwise exploit knowledge of infrastructure (social engineering for example).

There is a big difference, IMO, in someone like backblaze releasing statistics. They own all of the hardware and they choose to release the data themselves. You (on the surface) appear to be harvesting data from your customers, digging through it, and presenting it. You also point out very specific cases, rather than aggregate pseudonymous data.

You are collecting sensitive data from your customers environments. This doesn't inspire confidence that you treat it as such.

Not to support his fairly trashy post in particular, but I believe his comment has utility.

As an infrastructure person this post was concerning; this company is collecting a lot of data and has a lot of access, which I wouldn't trust. I also would not be thrilled if I was a paying customer having these details shared (even without attribution, as in the article), further reducing trust. I appreciate these kind of real-world detail posts, but it's not appropriate if it's not your infrastructure.

GDPR: Don't Panic 8 years ago

I would argue there are several sections in the GDPR that appear to allow for a 3rd party to request data on behalf of the data subject. For example:

A20(2): In exercising his or her right to data portability pursuant to paragraph 1, the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible.

A12(3): ... Where the data subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.

Even in the case it didn't work out to directly query, as another has suggested, just making it easy to fill out as many forms as possible in an automated fashion has value. Use their email to send from.

Also, how does the data subject or gdpr.me know that your company hasn't hoovered up some PII of the data subject?

I've read it several times and unless more clarity comes down on questions like this I'm quite afraid of abuse. I've read 8% of UK citizens intend to (ab)use GDPR for spiteful reasons.

EDIT:

Ok - I believe this absolutely supports my point, straight from the horse's mouth... This is from WP29-2017-4-data-portability-guidance:

"Data subjects should be enabled to make use of a personal data store, personal information management system (PIMS) or other kinds of trusted third-parties, to hold and store the personal data and grant permission to data controllers to access and process the personal data as required."

This is immediately after saying businesses should create API's to allow data portability and GDPR requests.

GDPR: Don't Panic 8 years ago

Honestly, it's not my call to raise prices or not, but it doesn't seem like they intend to hide it, should it happen.

GDPR: Don't Panic 8 years ago

I was thinking a solid new business plan is to register gdpr.me (or whatever) and offer a service. $40, fill out a form, and I will send a GDPR request to every company in the world on your behalf. The data coming back is then offered back to you with the ability to create further requests (deletion for example) selectively or in full.

This seem explicitly allowed for in the law.

If this is the sort of enforcement we can expect, this could suck: https://ico.org.uk/action-weve-taken/enforcement/sse-energy-... (there are several others, this one is just interesting because it's a very simple mistake with very minimal PII)

Also, my understanding is Germany allows for whistle-blowers to take a cut of fines. Language in the GDPR calls for over-estimating damages for loss of PII when compensating individuals as well.

Generally, I appreciate the GDPR. That said, it's a huge burden trying to go through many dozens of workflows, technical or otherwise, where (typically minimal) PII is recorded, catalog them, limit (and purge) intake of data to bare minimums, create documentation supporting said workflows to be able to provide the SA's, create a plan for being able to search ALL those workflows/databases/spreadsheets/apps that have PII to supply that data upon request, and then be able to delete all cases of such data upon request.

Turns out that's actually a mountain of work. It will probably force us to significantly improve workflows and combine data repositories moving forward but it's a large burden up front. Likely many hundreds, if not thousands, of hours for our fairly small enterprise.

I got a pair of odriod's based on price/performance to act as NTP servers and have since removed them from service.

They both had the same MAC address on the NIC, which was not impressive and more importantly have about a .5% (consistent) outbound Ethernet error rate. Not ideal for a service utilizing UDP.

I now use Pi's, which work flawlessly.

It was many years ago now but I was living in an apartment complex that sold a shared connection on a wireless backhaul to a regional ISP - the ISP handled everything from building wiring to billing.

My friends and I were in college and taking lots of IS/CS classes. I had a personal apache server running to test a variety of things. I never once gave anyone a link to it - it was 100% for personal amusement and learning.

I had a 500k SWF video on it (which was creative commons) a few splash pages and whatnot, and that was it. The ISP was actively scanning their network for "servers" and came across mine. They played the SWF video from their office over the wireless backhaul. The video had ONE play (I kept the logs and attempted to give them to the ISP). I served ~505k, total. They turned off our internet connection and sent us a letter and bill of "overuse and abuse". They claimed we had uploaded 50mbps and were hosting illegal content and not abiding by our contract which said "no servers".

While the main moral of the story is that ISP has complete morons running it (I uploaded 500k for a few miliseconds topping out at 50mbps in their eyes; funny thing was it was a 5mbps wireless backhaul), but this isn't a small ISP (Surewest) and they were actively scanning my connection for open ports, and then manually looking through content that they found on open ports (they admitted that!).

My sister (several years ago) was flying United solo (minor, 17, first solo flight) from CA to ME, connecting in LGA. Her flight came in late and she missed the connecting flight (late at night). There were no United employees on staff (at all!) in LGA at that hour. My mom spent several hours trying to get someone at United to help her out and they couldn't get ahold of their "on call" staff member to assist her. They ended up telling her to "sleep on a bench" and wait till the staff came in some 4-5 hours later in the morning and someone could get her set up with a new connecting flight. They eventually offered a $150 coupon for her "next" flight, which will never happen.