1,198 karma · joined September 9, 2019
- Used an APT for hire but I don’t believe they did succeed , still it is quite insane. I was lucky enough to catch a targeted rootkit but issue was quickly remediated. I’ll eventually find a consultant to analyse the Win 11 rootkit. They were definitely not script kiddies.
- Some black hat SEO and shills for hire, but that is expected.
I’m really surprised by hired journalist / APT aspect. Something I never imagined would happen, but apparently it does happen.
There is no way I’ll start another startup unless I receive backing from a huge VC company.
Current economic paradigm is more similar to centralised/controlled economies of USSR. Thus if you want to succeed, you will need friends with connections to central banks.
C - Redis
Honestly, an immutable OS would be more ideal but it isn’t very realistic. If you are adventurous, it would also be possible to setup a system where host image gets rebuild every night and persistent data gets pulled from a git repo.
I also recommend manually reading/checking the the BIOS EEPROM and re-installing the OS from scratch at least every 6 months. This should mostly eliminate most of the advanced threats.
You can setup an ansible script to re-install everything so it can automated.
There are ways to convert symbol names on the crash report server, so the claim that you can get better crash report with debug symbols is not correct.
Why you shouldn’t release debug symbols:
* It helps patent/copyright trolls litigate you easier.
* Makes it easier to reverse engineer your binaries, which will help malicious actors and competitors.
* You might lose some trade secrets.
If you are a startup owner, please ensure to never release commercial/close-source binaries with debug symbols. You can thank me later.
Some of these videos especially with small animals like hamsters have millions of views, so I guess there is a monetary incentive for them to keep such videos.
I would say that at least Flatpak is on the right direction.
It might be hard to implement it in a week but a hastily put AWS & stripe solution might work.
If you do ever implement it, do mention it on HN, I would definitely buy couple of slots.
We are vastly overestimating the cognitive capacities of humans, we should in fact have higher respect for other intelligent species living with us.
Main problem is that current ruling class is mostly comprised of psychopaths and what they actually mean is that “We will own everything, you will own nothing, and you will be happy or else!”
I think “You will own nothing, and be happy” can be utopic but we will first need to eliminate genes that cause psychopathy first.
You can then intercept everything through the ISP gateway. It would be theoretically possible to fragment the entire internet this way via coordinating with the ISPs.
I think lesson to be learned here is that centralized systems such as the internet, due to CAs (including Cloudflare) and ISPs, are unsuitable for private communications.
It is so sad that so many people won't experience late 1980s and early 1990s era of the internet, which was devoid of extensive surveillance and censorship.
Hopefully, humanity will somehow figure out a superior, decentralized communications platform to ensure privacy. However, the current internet offers no such guarantees.
My recommendation at this stage is to assume that government and supranational organizations control the entirety of the internet and act accordingly as if internet had no privacy.
I do wonder if this is the case for many people. It seems verifier is a bit unpredictable and makes eBPF programming quite painful.
So, you need to do a manual BIOS update to fix it.
Always self-sign the secure boot keys, do not use any third-party keys.
Unfortunately, this complicates the kernel & boot loader upgrade process as one shouldn’t keep private keys in the same machine.
I wonder if somebody built an automated process for this, or there is still a human element to it.
Also, automated vulnerability finding is very much real and already used today. This isn't something that has just become viable via LLMs, but I guess LLMs can enhance it:
At least LLMs will democratize the astroturfing.
Traffic correlation: All the large state actors are well capable of recording every single IP transaction between devices. You can create detailed correlation maps from these transactions. Considering that this wouldn't cost much for state actors to implement, one has to assume such traffic correlation systems currently exists.
Node compromise: It costs less than 5 dollars a month to create a TOR node. There are currently ~8000 TOR nodes/relays in existence. That is 40k USD per month (at most). Do you really believe state actors can't afford 40k USD per month to compromise the vast majority of TOR nodes? Even a single millionaire can compromise the vast majority of TOR nodes.
Another problem is that TOR is an outdated privacy tech. considering modern state actor capabilities. Mixer networks + network jitter is necessary to protect privacy at this stage, yet no such project exists yet.
TOR is not a good option for privacy. Currently only valid option for privacy is external Wi-Fi jacking and ensuring you don't send any private info like CPUID.
Or alternatively, you can hack routers/computers and put your own TOR nodes in them, then you can only use these known nodes.
Also, apt itself is supposed to be protected by distro’s key, but did any distro ever wrote how master keys are securely stored? Is there any other reasonable way to know that apt and entire Linux supply chain hasn’t been compromised already?