Selling, no. Buying, definitely. And names don't influence my decisions. A rose by any other name...
HN user
thraway2016
procurement, management, finance, and others you need to appeal to
They don't need to appeal to any of these suits. Just the technical decision-makers, whose express job it is to choose solutions on their technical merits, not their spurious emotional reactions.
My point was that the job of a technology decision-maker is to make decisions on the actual technical merits of various options, the costs and tradeoffs thereof.
If you are in that role, and you permit the name of a vendor to trump the actual merits of the vendor's product, you should never have been trusted with decision-making authority in the first place, and any competitors who don't harbor your particular emotional hangups will get the better of you, and you won't be long for your position anyway.
Cockroach Labs is not selling to the end-consumer. They're selling to people whose job it is to behave like Vulcans. In this particular market, it doesn't matter what the name is.
If you make technology stack decisions based on your feelings rather than what the product actually does, then you shouldn't be employed as a decision-maker.
I see it as technical people on HN who appreciate the metaphor, versus marketing/business people who can only think of "image".
It's to expected with the massive infestation of HN by suits and khakis in the last few years.
Another, and better, alternative to slack: IRC.
Why exactly is HackerOne drawing a distinction with this software producer?
The truth is: because a H1 rep went on Risky Business and did not deliver a very good performance.
Patrick, who is absolutely okay with H1 having FiveEye clients like the US DoD, has a very serious problem with them also servicing an obscure spyware application provider. Because, I suppose, being murder-droned by a panopticon hegemony is much better than getting yelled at by an angry spouse?
While I applaud this move, I suspect H1 will continue servicing government and law enforcement clients of all kinds.
A consistently applied policy would see ties with ALL surveillance entities severed.
The unfounded hostility that the mere existence of Soylent brings out of otherwise level-headed people is always a great source of amusement.
As larger proportions of the infosec community get hired or contracted by law enforcement, intelligence, and other government agencies, you'll find that the respect for liberty that the hacker manifesto espoused is increasingly hard to find.
The prescient Upton Sinclair: “It is difficult to get a man to understand something, when his salary depends on his not understanding it.”
i2p, freenet, or forgoing websites altogether.
for asynchronous messaging, agl had something really promising with pond, but for "reasons" decided to abandon it, and nobody bothered to continue its development.
Is there any reason KVM/IP is not a viable solution for remote management?
Remote access to DMA capability is just batshit insanity.
IME is likely not a case of Intel "not taking security seriously". It's almost certainly a case of doing what FiveEyes demanded of them.
This is an unpopular position, but approaches like BrickerBot are likely to be effective.
Thanks for your response. I'm peripherally interested in application security, so I've followed SwiftOnSecurity, the grugq, HN's very own tqbf, 0x00string, xntrik, matt blaze, etc. I also listen to Risky Business, LiquidMatrix, cyberwire, etc.
My impression based on following "thought leaders" and listening to the most highly-regarded podcasts is that the community is, in fact, exactly as I described. (even the recent appointment of IC shill Jeff Man as a regular on Paul's Security Weekly has dramatically shifted his show in that direction.)
If you don't mind, can you recommend other people to follow/listen to that might balance out the impression I have received? Thanks.
It's not just Schneier. Seems that nearly everybody in infosec is convinced of Russia's complicity in everything from the DNC leaks, to Vault7, to ShadowBrokers, and now allegedly the Macron campaign.
Listening to the RiskyBusiness podcast, for instance, it's incredibly obvious that the community is fully in the tank for the Russian attribution hypothesis, and habitually carries the water for FiveEyes IC.
Meanwhile, we mere plebs have very little evidence to judge the community's beliefs by, other than blind faith in, say, CrowdStrike.
If the infosec community would like to actually state their case to the plebs, I would love to hear it. But all I've ever been able to find is "the phishing email is a little similar to something produced by APT28, and there was an IP once used by FancyBear like 5 years ago, so it's 99.9999% certainly Russia".
And nobody seems to care enough about those outside the community to even try to state the case.
Can you elaborate on what constitutes "broken" ?
Primary reason would be finally being rid of the Intel ME. For the truly paranoid.
DNS by PiHole and uBlock Origin combine to do a damn fine job of preventing the behavior you describe.
Conventional legal mechanisms against your home server cabinet can be handled via full disk encryption and a reed switch on your cabinet door connected to your power strip.
The article you linked only has a single citation for the Russian attribution, which is a Snowden quote: “circumstantial evidence and conventional wisdom indicates Russian responsibility”
Is there any evidence other than Snowden's speculation?
I use Tahoe-LAFS for all of my distributed FS stuff, and I really do love it. One minor downside is that the introducer server is a SPOF, but they can be backed up/spun up and distributed introducers are on the roadmap for the next year.
The point is that simply clicking a dodgy link can, in some cases, own you. No credential acquisition required.
Crafted-content UAF vulns are still occasionally being found in browsers.
To say nothing of unpatched/non-updated browsers.
Why not normal username+password authentication?
Sign up ... "ok" ...with Slack ... "no"
irssi is a significantly better interface than any slack application.
Probably the same reason that "slack == irc" and anti-systemd comments get heavily downvoted. Younger generations want badly to believe that they've invented something completely novel and unique.
This absolutely is usenet + crypto.
There already is an "Office Killer", called LibreOffice. Does absolutely everything any small business or home user could ever need.
Agreed. A combination of cryptsetup luksOpen foobar && mount foobar && vim foobar/passwords.txt has always worked fine.
I suspect it has to do with the modernist fetish of convenience. Not having all your data synchronized to all devices at all times is apparently a fate worse than death.