1,587 karma · joined July 7, 2017
Anyway it would surprise me if the TV companies even had bare minimum acceptable security, because even the net security guys are struggling.
The cover of one of their issues is really something to behold: https://www.newyorker.com/books/page-turner/the-very-unnervi...
Anyway I switched to Caddy [2] even though I deeply love Apache and it has an amazing history behind it.
Now the issue is a company is using temps to hold down the market rate for salary. Less about tax avoidance, and more about wage suppression. Of course it’s also a valid argument to say the Supreme Court decision at the time made it more likely for companies to choose this route.
Human being play a huge role in climate change, but I don’t want to also write off the absolute enormous shifts than can occur naturally. We need to take those just as seriously for our own security.
One thing I would like to add (and perhaps the author mentioned but I did not see). Secure your cellular accounts such as Sprint, T-Mobile, Verizon with 2FA, good password, etc. This also includes the maximum length VM password, although usually that is only between 7 digits to 10 digits sadly.
Allows myself to get higher wage and the business I’m applying too to not feel disrespected.
Almost like a lost art, it was impossible to find serious tutorials other than Michael W. Lucas’s book of a couple of years ago or the O’Reilly book from 2006.
Very much appreciated. Thank you for documentation on these very important systems that many of us sysadmins who came into the field later in life missed (other than when we connect to our cloud servers). Soon, even the cloud part I mentioned will be gone mostly to because of ‘kubectl’, as Kelsey Hightower has said.
One thing though. There seems to be some internet shyness ppl have in getting the ball rolling on these kinds of mentoring projects. Would try to plan to deal with that fear of either party reaching out.
I’m for quite strict tax enforcement but that should be changed.
Also of course private companies need to start stepping up and providing the often only small sums of money needed to fix these projects via bug bounties and fees to the maintainers.
A couple of things about Linux security that really hinder ppl / I don’t think are promoted enough:
- People forget to secure VIM. Even if you’ve secured everything, very easy to use the built in mini-shell in VIM to move to the actual shell.
- Look at / focus on your SSH key fingerprints. These things matter. I didn’t pay attention to these things nearly as much as I should have the first two years of my career, but it’s so easy to just intercept your request, grab your private key, and then just pass you on to your regular server without you even knowing.
- Please please secure your web servers. The default configuration can be very difficult to argue is secure, e.g. the fact that every web server reveals out of the box the exact semver of the Apache/Nginx or the lack of automatic HTTPS redirection that would be useful for 90% of modern deployments. Check out Caddy which helps with some of this.
That being said, AWS does allow you to put your name servers somewhere else, say GCP, and then do DNSSEC there.
Really the main security concern with AWS is no browser in the terminal. This feature, which both GCP and Azure have, really eliminates the ssh-key litter.
Couldn’t see any text or email in your profile page.
Unfortunately this is harder than it should be. The media is right, there is a huge need for talent here, but there is 0 pipeline to take/train that talent.
Right now it’s just sysadmins, software devs, and B-Sides hackers who seem to fall into all the teams I’ve been a part of (mainly network defense and infrastructure hardening).
Texas is deploying a pretty innovative program next year that will teach cybersecurity for the last two years of high school and then award the student an Associates Degree. From there the plan is to deploy them a giant SOCs of various companies that need lots of eyes to monitor the logs/false positives. This will be 1 or 2 years of real world experience before letting them go on their own in the career marketplace.
A few days after Kent State a group of construction workers head into a protest against Vietnam and pretty viciously attack a crowd of 1000 college students. There is plenty of blame to go around for this event (like any occurrence of mob action) and many sociological trends that led to this, but historians tend to mark this event as the “beginning of the end” for Union influence in the US.
Regarding how death rates are calculated, there are controversies in the field regarding how to best calculate from both a math and even a philosophical standpoint.
This article, which talks about the famous paper from 2015 that first noted the dramatic rise in suicide, covers the controversy well. Some of the best statisticians and researchers in med stats, who all are competent and mean well, simply cannot agree if the death rate has gone up or down [1].
[1] https://www.thecut.com/2015/11/gender-controversy-over-white...
Regarding disclosure, although this sounds like a lame position, I would wait for the courts to decide. There are a lot of cases winding their way through the Circuit Courts in the US that will give us a framework for disclosing and when to do it regardless of The actions of any Federal agency.
If they don’t agree to fix the bug, by all means “name and shame”. Document all your interactions with them though.
Also if it’s medical data remember HIPAA has a breach notice that applies in all 50 states so there is that.
Also also, after the bug has been fixed there is nothing to stop you from writing a blog post and letting the “media” pick it up naturally as part of the news cycle.
NOTE: I have CISSP and CASP so I think that means something
For instance, people raised inside of a generation tend to have a similar cluster of personality traits to some degree. These traits propel certain innovations forward , leave other things lagging, and cause a reaction formation in the next generation who tend to value opposite traits. These new traits then alter which innovations are pushed forward, which are left behind, etc.
There are additional cycles I’m not covering here, but together they form a sort of “super cycle” with great periods of unrest as well as innovation occurring when the lines converge periodically.
Recently did this on the topic of “cancer”. All recent books published in the last 15 years by Big 5 Publishers.
Every single book had intense criticism for the NIH. It seems they do a lot of good, but their singular focus on only funding “hypothesis based research” has driven and then kept extremely promising ideas on the sidelines for 25 years.
Very sad to read at times, and made me really appreciate how scientific progress comes in amazing bursts that are short lived but that everyone depends on for decades to come.
EDIT: Kind of astonished by the downvotes. This book goes into more detail: https://www.amazon.com/dp/0374135606/
Also something else I forgot to add is how the death rate from cancer really hasn’t budged in 20 years by being generously massaged via something known as “average death rate”. Adjustments are made to have the US population conform to a model, against which the amount of deaths per year are calculated. While intended to smooth variance YoY, this model helps to a great extent the system currently operating.
About halfway between Dallas and Austin is Ft. Hood, the Army’s largest base. After WWII, so only a few years after it had been set up in the first place, the Army dynamited a series of caves in the very sparse western section of the base to carve out a massive underground structure for nuclear weapons.
The Army doesn’t use / maintain nuclear weapons anymore, but the bunker has been repurposed into a basically one-of-a-kind underground training environment. Units from all over the world train there. Pretty cool stuff.
https://www.chron.com/news/houston-texas/texas/article/Littl...
It is a huge difference from the “learning to program/programming” communities. Those groups can also foster their own feelings of self-lack, but not on the scale of cyber.
>”Mar 5, 2013 · “In the tech world it was such a bummer to say you worked for Yahoo,” said a former senior employee”
http://mobile.nytimes.com/2013/03/06/technology/yahoos-in-of...
I understand though taking issue with The NY Times as a source though, they do have their issues, with the recent Jill Abramson plagiarism case being a good example.
Now it’s McKinsey.
Yahoo source: http://mobile.nytimes.com/2013/03/06/technology/yahoos-in-of...
I’ve heard once you get in power you’ll be surrounded by 1). Ppl who are just like you because we as humans prefer that and 2). Ppl who flatter you very convincingly because we as humans also prefer that.
This can be a very dangerous situation to be in. You think everything is alright while outside the world flails and rages.
Who in the world is advising Mark Zuckerberg?