I would just send those domains through mailgun with a transport map in postfix, it probably wouldn't even break the free tier.
If you use mailgun or similar you have to setup dkim keys for them and add them to your spf.
HN user
[ my public key: https://keybase.io/tuzakey; my proof: https://keybase.io/tuzakey/sigs/VtEtRG1b8u6IDfXvgD8zfv-m1hDygG_Wf1qIY2P17QU ]
I would just send those domains through mailgun with a transport map in postfix, it probably wouldn't even break the free tier.
If you use mailgun or similar you have to setup dkim keys for them and add them to your spf.
I imagine an agent would make a lot of the first time setup from scratch easier, but the fastest reliable way to get up and running is mail-in-a-box or mailcow. Before those were available I built a flurdy style Postfix+Courier+Amavisd+MySQL setup and have been evolving it ever since. Now I'm on Postfix+Dovecot+rspamd+MySQL but I don't think that's for everyone or even the best way to start.
The science of not getting flagged is easy when you're not sending large volumes of untrusted mail; it only gets complicated if you start hosting mail for "customers" or let your system forward mail unfiltered into gmail/yahoo.
Here's my hit list of universal things to configure:
* Start with an IP with good or neutral reputation, non-residential, its nearly impossible to fix an IP that has been burned by a spammer. (Network)
* Valid reverse dns for your IP matching your mailhost forward dns (DNS)
* Valid SPF record; -all (DNS)
* Valid DKIM; with sufficiently sized key (DNS+Config)
* Valid DMARC; start with p=none to test and move to p=reject once you're configured (DNS)
* ARC if you or your users will ever possibly forward mail (Config)
* Don't get your messages flagged as spam anywhere ever, filter outbound mail even if its just you. All it takes is one piece of malware and a saved password and you'll have to get a new IP. (Config)
* Don't configure services behind your mail server with example domains that you don't control ~ I get so much mis-configured test mail from people who think its cute to use my domain as an example in their practice lab. It all gets reported as spam or bounces and then their smart host bounce rate goes up. (Config)
* Test for open relay; only relay for authenticated users. (Config)
* Use strong authentication, preferably with certificates or MFA. (Config)
* Secure everything; IMAP/SMTP/POP are old AF make sure you're requiring STARTTLS and setup MTA-STS to prevent downgrade attacks and enforce encryption in transit. Use a real certificate from Lets Encrypt don't self-sign. (DNS+http+Config)
* fail2ban your auth, you're going to get so much driveby password spraying and credential stuffing; I fail2ban block entire subnets at a time with iptables actions. I also have a bunch of "poison pill" rules for weird stuff I see in my logs eg block anyone who tries to auth with the NTLM hash for 'password'. (Config)
* Don't bother with BIMI at home, you can't get a blue check mark without deep pockets and a trademark (vmc) and most platforms only show logos that have a matching vmc. (DNS+https+config)
* DMARC reporting and TLS-RPT reporting are a pain to manage but are helpful troubleshooting deliverability be prepared to read some XML reports or setup a stack to parse them as they arrive (DNS + Config + https)
* setup the SMTP Submission port (587), so many networks block port 25 outbound and its the right way for clients to connect. (Config)
* configure BACKUPS, don't skip this step, encrypted restic backups to s3 or backblaze b2 is cheap and easy. (config)
* track your configs in git, don't commit secrets. (config)
* configure a free blacklist monitor on mxtoolbox for your domain(s) (config)
If you do those things you'll be in a pretty good spot, you could probably paste that list/this post into your agent and vibe up solid mailserver.
For me keeping the spam and phishing out is a bigger hassle than deliverability issues. rspamd does a pretty good job of keeping it manageable.
I do all of those things and with all of that setup the only place I ever run into issues with with users on AT&T's residential broadband mail servers. AT&T appears to block you if you're not known to them and they have a short memory. If you don't have regular correspondence with AT&T users they will block you after a bit. I'm a fairly low volume sender so I end up blocked every other time I try to send to AT&T by no fault of my own. I've talked most of those friends off of AT&Ts free email and on to ProtonMail at this point.
You can't do it reliably without a static IP in a non residential subnet that lets you set reverse dns. If you have a static residential IP and they don't filter inbound SMTP you can make it work with a smarthost/relay like mailgun. Its not the insurmountable obstacle everyone makes it out to be, but its not going to be free unless you already have an IP that meets the criteria.
If you don't have a static IP you need will want to think about a MX relay service too ~ although mail is surprisingly tolerant of offline MX hosts if you can wait a little bit for your mail.
Find a SAR team in your area, they usually have a recruiting page. SAR is not a casual volunteer commitment they tend to train a lot. The process here (alameda county ~ bay area) is take orientation class, apply, pass fitness/skills test/oral interview/background check, attend meetings and basic training, then train more while waiting for a call out. They want 6+hrs/mo to stay active. This will be different for every jurisdiction so ymmv.
"Wipes it every few weeks" probably means he has his data on a flash drive or external hard drive that he plugs in everytime. Of course it's probably far simpler than that~insider threat at the bank committing Wells Fargo style upsell fraud or simply password reuse.
This is typically used for agricultural/off-road fuel which is not priced with road taxes and as a result much cheaper. Off road fuel is dyed red in the US. If you get caught running dyed diesel on road you will be fined. Thus the switch on the dash, when you leave the highway to drive on your farm you flip over to dyed fuel to save $$.
Going back to games;.... That might be a model for new typed of education going forward.
I think this is how 42 school works. I've known a couple people who started the program there but none who completed it. However 42 is afaik not accredited and WGU(where the OP attended) is. 42 probably lands more in the coding bootcamp end of education the spectrum.
Sonic has their own fiber in some parts of SF/Santa Rosa and you would know if you were on it, all Sonic DSL products are essentially resold AT&T uverse.
Right!? That's the first thing I looked for in the project page. I'm really surprised it isn't using ebpf, but netfilter and a kernel module let them run back on 2.4 (but why?) I'm waiting for a bpf based solution to pop up as I think it will be superior in performance, ability, and maintainability.
I buy film from Film Photography Project, B&H, Adorama, and FreeStyle Photo. Most of the brick and mortar camera stores that still exist sell some film. For development I do black and white at home and send color out to thedarkroom.com because I don't shoot enough color to make the chemistry cost effective. I print black and white in my bathroom darkroom.
I'm still able to find 35mm, 120 and 4x5 film easily. I have a 127 camera that is a bit harder to find film for.
From 2013: http://www.coding2learn.org/blog/2013/07/29/kids-cant-use-co...
It's not just teens.
I'm an extra and a VE. I take a radio with me on all of my back country camping trips and have a solar+battery repeater set up in my 4x4. I've ended up many places where neither radio could get out to anyone simplex and no repeaters were in range. Amateur radio works great when you have a communications plan and know you'll be in range (like when you're working with a group) but for small groups/solo back country and new areas I'll be picking up either a PLB or an inreach for this season. Others mentioned HF, I don't think you can expect to be able to string a wire dipole up and transit if you break your ankle or something ~ assuming the solar conditions allow you to get out anyway.
Also I meet lots of people who have taken the test and bought the $30 radio but don't know how to use it. Practice, practice, practice. I look at group camping trips as an opportunity to practice wilderness protocol and usually come back with a bunch of notes on what worked/didn't.
I bought a pair of the Sony wh1000mx3 and let my coworkers try them out, as we have a noisy open floor plan. Everyone who tried them bought a set in spite of the price tag.
My only complaint is that they don't support multiple device connections. I can wear these cans all day without discomfort too.
In my experience with banks that did this it was to allow a mapping to 10digit keypads for bank by phone access. I haven't tried it recently, and they allow complex passwords now. When I noticed this several years ago I was able to log into my bank account via the website with the 10digit equivalent password. At least your bank balance is insured...
This reminds be of the classic Microsoft Bedlam DL3 story: https://blogs.technet.microsoft.com/exchange/2004/04/08/me-t...
I had a bunch of Crucial SSDs die a few years back, they'd work for an hour then disappear from the bus. Reboot and they'd work again for an hour. It turned out Crucial had a small counter tracking uptime by the hour, it would increment the counter to an overflow and crash. This failure could just have easily occur on a spinning hdd.
I just tried to turn it on for my USPS PO Box, it doesn't work. They require you to verify your identity via an online option that just reports that it didn't work or in-person verification. To verify in person you need a us government issued ID (passport, military, but not state gov) and if the address there doesn't match you need a secondary document (mortgage, bill, etc.) The only things I receive at my PO are amateur radio documents and domain registration scams. There are less stringent identification requirements to buy a handgun in California (State ID + supporting document)
That said, I'd really like it to work because it would save me trips down to the post-office only to collect junk mail and the previous PO box tenants non-forwarded correspondence.
It may be much worse than you think. Another large brokerage company I know of has similar password requirements. They also have a phone banking system, to use it you have to touch tone in your password. On a whim I tried entering the keypad version of my password on the website and surprise! it worked. Luckily for me there is zero customer liability for fraud on their retirement accounts.
I have an Asus ux31a zenbook prime (i5/4g/256g), running Ubuntu 13.10 currently, everything works fine except for the ambient light sensor. I had to have the keyboard fixed under warranty about 4 months in, otherwise it has been great. You can pick up a refurbished model in your price range.
The radiolab episode about colors talks about tetrachromats and some other very interesting stuff, worth a listen: http://www.radiolab.org/story/211119-colors/
The Chumby was cool 4 years ago... When the Chumby services started getting flaky as their business died I replaced mine with an Android tablet in a sound dock. The Android tablet is more reliable, has more apps, and doesn't turn into a worthless brick when the internet goes down. I still have the Chumby in a box somewhere, maybe now that services are back up I can sell it and recover some of my cost.
Thats where fail2ban is useful, pick a number of failed auth attempts on any service you care to integrate, lets say 8 PAM failures, and trigger a rule that inserts an iptables rule to drop/reject the attackers IP for 5minutes. That will time out the ssh scan for all but the most patient scanners. If you shared the fail2ban database across hosts you could inject null routes for the offender into your router or block them at your firewall.
Its kinda silly to move the port, a targeted attack is going to start with an portscan of you box, the attacker is going to say "oh what’s this here on port 2222?" and promptly discover that its ssh listening on a high port. Port knocking would make that discovery less likely I suppose but its still all treating a symptom of a bigger problem.
So why not solve the problem with something a little more proactive like turning off password auth and go for sshkeys only. Maybe toss in something like fail2ban if you want to interrupt kiddies scanning your boxen.
That said high port ssh can be nice if you're frequently on restrictive networks and getting out on port 22 is impossible.
edit(spelling)
You might want to draft a bylaw the codify the no one living there permanently part. Any plans to post your LLC operating agreement + bylaws publicly and/or in source control?
agreed, you can set up fancy jails for people scanning other services too, someone who probes SMTP/POP/IMAP doesn't need to hit SIP and SSH. Depending on the scenario you could choose to say block an entire netblock from hitting ssh after a single offensive IP probes a few services. Even a 10min jail time will cause most attackers to give up and move along to their next victim (unless you're being targeted.)