I think there's a Ben Franklin quote that applies here. "Those who would give up essential liberty, to purchase a little temporary safety, deserve neither liberty nor safety."
Or that Security Monitoring is well established field that has actually given a lot of results in preventing various attacks.
If the average corporation hates/mistrusts their employees enough to add a single point of failure to their entire business and let a 3rd party have full access to their systems, then well, they reap what they sow.
This is companies trying desperately to deliver value to their customer at a profit while also maintaining SOC 2, GDPR, PCI, HIPAA, etc. compliance.
If you're not a cybersecurity company, a company like CrowdStrike saying: 'hey, pay us a monthly fee and we'll ensure you're 100% compliant _and_ protected' sounds like a dream come true. Until today, it probably was! Hell, even after today, when the dust settles, still probably worth it.
There's a highly problematic underlying dynamic where 364 days out of the year, when you talk about the dangers of centralized control and proprietary software, you get flat out ignored as being overly paranoid and even weird (don't you know that "normal" people have zero ability or agency when it comes to anything involving computers?!). Then something like this happens and we get a day or two to say "I told you so". After which the managerial class goes right back to pushing ever-more centralized control. Gotta check off those bullet point action items.
Sincerely,
PreCheck Premium with Clear Plus Extra customer
I go through the regular TSA line out of solidarity and protest. Fuck the security theater.
And fwiw, I don't think the strong argument against precheck has to do with social class... it's not terribly expensive, and anyone can do it. It's just a further invasion of privacy.
I only fly once every couple years, but I really hated emptying my pockets into those bins. The last time I went through, the agent suggested I put everything in my computer bag. That worked a lot better.
It can. It doesn't happen to you because you're white, blonde, and can pass through a scanner without triggering it.
I wonder if they also have the capability to brick all our Windows machines like this.
Wow, I didn't know that, but you're right. It even works in Brave, which I wouldn't have expected:
% openssl x509 -text -noout -in news.ycombinator.com.pem
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
6f:9e:b3:95:05:50:6e:4d:03:d6:0b:a9:81:8c:2f:c3
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, ST=California, O=Zscaler Inc., OU=Zscaler Inc., CN=Zscaler Intermediate Root CA (zscalertwo.net) (t)
Validity
Not Before: Jul 13 03:45:27 2024 GMT
Not After : Jul 27 03:45:27 2024 GMT
Subject: C=US, ST=California, L=Mountain View, O=Y Combinator Management, LLC., CN=news.ycombinator.com
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
It seems to hijack the browser somehow, though, because that doesn't happen from the command line: % openssl s_client -host news.ycombinator.com -port 443
CONNECTED(00000005)
depth=2 C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert Global Root G2
verify return:1
depth=1 C = US, O = DigiCert Inc, CN = DigiCert Global G2 TLS RSA SHA256 2020 CA1
verify return:1
depth=0 C = US, ST = California, L = Mountain View, O = "Y Combinator Management, LLC.", CN = news.ycombinator.com
verify return:1
write W BLOCK
---
Certificate chain
0 s:/C=US/ST=California/L=Mountain View/O=Y Combinator Management, LLC./CN=news.ycombinator.com
i:/C=US/O=DigiCert Inc/CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1
1 s:/C=US/O=DigiCert Inc/CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1
i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Global Root G2They willingly relinquish their right to privacy in service of protection against a potential threat, or the appearance of one.
So yeah, screw 'em. But let's be specific about it.
Like the kind of autonomy that let's them uninstall Crowdstrike. Because how can you be responsible for a system which at any time could start running different code.
above comment is very naive.
If you stick to small privately held companies you might be able to avoid ending management but that's it.. any big brand you can think of is going to be running this or something similar on their machines -- because they're required to