3,011 karma · joined March 13, 2008
1. Was this GIF-fetching endpoint likely exposed publicly by most customers' SolarWinds deployments?
2. Public or not, was there any auth in front of this endpoint when deployed?
My presumption is that some (most?) customers deployed the SolarWinds admin console publicly (with its own auth in front) and that this particular GIF-fetcher endpoint, being deemed trivial, was not protected by the console's auth scheme. Thus, those who knew about the trojan just had to scan the known IP ranges of SolarWinds customers until they found the exposed admin console, and then remote code execution was easy from there.
If this endpoint was protected by the same auth scheme as the admin console, then this trojan becomes more of a privilege escalation attack. Its existence would increase the value of obtaining the creds of a SolrWinds user, but (presuming SSO integration) those creds would get the attackers lots of other access given the sorts of IT people who use SolarWinds.
If the endpoint was not fronted by any auth scheme but the admin console was not exposed externally, then the benefit would be that attackers who gained access to a SolarWinds customer's employee-facing network (what's the name for the network segments accessible to anyone who plugs in a laptop in a cubicle?) could "ride" this trojan to gain access to a more privileged part of the network.
I'm not an infosec guy. Do these arguments make sense?
I own a Fujitsu Scansnap s1500. It's out of support, and the existing drivers are incompatible with Catalina. I now must pay a 3rd party $100 for drivers or fiddle around with a Linux scanner server or similar. Never again will I pay $400 for a Fujitsu scanner, that's for sure.
http://openjdk.java.net/projects/code-tools/jmh/
It takes care of details like JVM warm-ups. ensuring sufficient invocations for JIT compilation to have occurred, etc.
I like how the author says that sprawl isn't the problem, the problem is that new developments are large scale, single-purpose, and with no room for improvement or addition.
The graph/map showing how downtown and poorer areas bring in more tax is what did it though. Even just thinking about ploughing in the winter makes it pretty clear that winding suburbian roadscapes are costing the city a lot more than we pay them. That's without mentioning schools, fire halls, garbage collection, etc.
I guess one of the more difficult issues is convincing North Americans that they don't need a private single-family house, large yard, 2+ cars, etc.
The article doesn't mention one seemingly huge benefit of JIT compilation: profile-guided optimization:
http://www.slideshare.net/ZeroTurnaround/vladimir-ivanovjvmj...
Perhaps the baby has been thrown out with the bathwater?
Little is mentioned about how ART compares to the JVM. For example, does ART perform escape analysis? Not all object allocations are equally bad. The Sun JVM can figure out which objects may be allocated on TLABs (Thread Local Allocation Buffers) - an optimization which reduces the burden placed on the garbage collector because TLAB-resident objects may be deallocated as the stack is popped. [Please fact-check me as I'm merely a long-time Java developer vs. an expert on JVM internals]
I suppose the relevance of my entire comment hinges on the presumption that anyone reading HN only uses hotel PCs for printing stuff. Valid?
So, what's left? Collusion between buyer and space provider -- in all likelihood, they are one in the same, or identities have been stolen. For example, I list my condo on AirBnB for $100/night. Someone books it for the weekend, and then doesn't show up. AirBnB owes me $200 -- after all, I gave up other options to profit from its use. An honest buyer pays up. But, maybe the buyer is dishonest -- he used a stolen credit card, etc. In this case, AirBnB eats the loss and pays me as the space provider. Now, wouldn't it be convenient if I was also the buyer? Cash from stolen credit cards, funneled through AirBnB (much akin to the way online poker sites were used to transfer stolen money via bad heads-up play). This would work until AirBnB noticed that my listing seems to have a suspicious propensity to attract fraudulent buyers. Then, they'll shut me down. So, I'll pop-up elsewhere. After all, no need to actually have a space because no one I accept will ever show up!
I bet the usage patterns of the party/parties involved in this fraud are drastically different than those of legitimate market participants. Someone with a fraudulent listing could out himself by rejecting a bunch of legitimate AirBnB buyers, and this behavior would stand-out as it's the opposite of the behavior expected of an honest seller. So, he must protect against this risk by making his listing unappealing (high price, bad photos/description, unpopular location, etc.). The behavior of users browsing AirBnB when viewing this property could identify its relative undesirability (few clicks, etc.), and price outliers could be identified by comparing similar offerings by date/location/type. The click stream of the "buyer" likely is most revealing. Someone selecting an unappealing property without doing much comparison shopping likely isn't a legit buyer.
What other stuff might predict fraud? Vague descriptions might indicate a fraudulent listing. Most space providers love to tell buyers what's special about their offering. Could some scoring of a listing's prose prove a strong predictor? I've never listed with AirBnB. What do they do to verify listings? As a buyer, they verified my identity. Could this serve multiple purposes? Certainly, I'd feel better listing my guest room if I know that AirBnB will know the identity of the guy who rented the room and then stabbed me at 3AM. But, in addition, does identifying market participants in strong ways help keep fraudsters from repeating their crimes by setting up multiple accounts? Obviously, newer market participants are more risky than established ones, especially those who have interacted with known legit, long-time users. The social graph comes to the rescue here. Even astroturfing ought to show up as a small, disconnected graph unless legit users' identities are stolen.
Of course, this comment is all just conjecture. Obviously, AirBnB can't tell the public about specific fraud methods or how they identify suspicious activity. However, I like the concreteness of considering actual fraud scenarios, so I decided to put forth some ideas for discussion.
My understanding of container shipping is that customers make SLA choices much akin to us Americans choosing between UPS Ground/2nd Day Air/Next Day, etc. UPS uses these varied SLAs to smooth out its use of fleet capacity and for price discrimination. Shippers operate transshipment ports as part of distribution networks much like the hub & spoke designs of the major airlines. These ports have a bunch of shipping containers sitting around awaiting capacity.
Consider the needs of companies that must transport low-value, high weight/bulk cargo. These companies likely already choose the "UPS Ground" equivalent for container shipping. Due to low product value, inventory costs are low (in transit goods are inventory), so it's probably less expensive to have buffers of goods in the supply chain than it is to pay for tight shipping SLAs. Why should these companies care if the variance they experience in shipping duration is due to capacity constraints of manned-ships or that it took an extra two weeks to fix the ship upon which their cargo was in transit?
I have a condo in Chicago and was delighted to learn that a company was offering our building last mile connectivity via microwave along with SLAs for not only bandwidth but latency as well (to which point I don't recall)! Sadly, the condo board didn't seem so enthralled. Unlike the suburbs, city folk have more options apparently.
With all this said, I'd much rather see advances in bionic attachment techniques. If I could have a metal rod extending from the distal end of my tibia through skin, being without a foot would be much less annoying, and my physical abilities would improve significantly. I could just clamp on a prosthetic in the form of a carbon fiber spring -- the same sort I have now. Presuming the rod required little maintenance, I would require far fewer trips to the prosthetist for construction of new sockets as the shape of my residual limb (the politically correct term for "stump") changes over time. No risk of skin issues preventing me from using my prosthetic leg. No risk of catching my prosthetic foot on something while walking and pulling it off my body. Current socket-based attachment techniques create what effectively is an extra joint with very limited range of motion. Oddly, this is useful for subtle manipulation of a gas pedal (I'm missing my right foot), but it is mechanically inefficient, reduces my perception of stability, and keeps me from feeling like the prosthetic foot is "mine". Because of this extra joint, heavy shoes feel really heavy. Lots of effort has gone into making prosthetic feet light -- a much less valuable attribute if direct body attachment was possible. Reducing the value of making prosthetics lightweight would allow for all sorts of innovation.
My understanding of the current state of affairs is that, while it's quite easy to stick a metal rod into the distal end of a bone, it's quite difficult to allow it to protrude through skin without risking infection. My general take when reading yet another article about some amazing $100K prosthetic device is similar to my thoughts when hearing fuel cell folks talking up the technology in the early 2000's -- They all showed up at tech events talking about how fuel cells were going to change the world, how their own novel technology was going to make them more efficient, lighter, whatever. My question to them was always, "When am I going to be able to replace my laptop battery with a fuel cell so I can take a cross-country flight without worrying about my battery running low?" They always gave some vague answer and then went on talking about the improvements they were making to a technology which was not at all available to me. It's 2013, and I haven't yet owned a fuel cell. However, I'm writing this on a Mac with much better battery life than was available a decade ago even though the fundamental technology used in its battery is unchanged.
In a nutshell, I want a service lifecycle container which allows me to write small, lightweight, modular services which depend on each other. The container should provide for cross-cutting concerns like monitoring, management, configuration, logging, auditability (I have concrete definitions for these things -- they're not just abstract biz-speak to me). HTTP should be an out-of-the-box, optional module. A service which exposes another service via a RESTful interface and depends upon the HTTP service should be another. For my application, services which listen to multicast data streams are just as important interfaces to the world as JSON-over-HTTP-via-REST. I want to write the HelloWorld method body and be able to do stuff like: expose it via a RESTful interface, invoke it every N seconds, inject an interface exposing the HelloWorld contract into other services, etc. When I want to know how my HelloWorld service is performing, there's a pre-built web interface which provides New Relic-esque views. I'd like to capture audit trails of the transactional flows through my services from an origination point (HTTP call, scheduled job, etc.) so I can translate failures, poor performance, usage rates, etc. into meaningful information (I wrote a poor man's version of this myself, and it's been quite useful).
Does anything like this exist? I sure can't find it. Modern JBoss (now Wildfly) might actually be closer to my requirements than I think. Perhaps I should look at the work they're doing on Version 8.
So, according to the link, some guy in China invented one. My dad worked for years in Akron rubber factories, often in front of a steam-powered press of some sort. Temperature was controlled through large exhaust fans -- a practice largely adequate when the outdoor temperature was cool but barely tolerable in August. I recall Summer days when he would instruct my mom before he left home that the window air conditioner in my parents' bedroom should be cranked up to full power in anticipation of his arrival home from work. [We didn't have central air at the time] After eight hours in a 100+ degree Fahrenheit work environment, he wanted little more than to lie down in a cold room.
I was thinking just a couple of weeks ago about this and how a refrigerated suit would have made him much more comfortable (and likely a more efficient worker). Even if an employer does not care about the happiness of its employees, it does care about productivity and the wage required to attract and retain workers. Why are refrigerated suits not more common? I recall reading about ice pack vests worn by people in sports team mascot suits. However, I don't see the guys working on the side of the road wearing anything similar.
Could an inexpensive, reliable suit be "powered" primarily by dry ice? I presume the energy density of a block of dry ice to be at least a order of magnitude greater than a modern battery pack. I'm imagining some sort of small water pump which would cool off the water by allowing it to flow around the dry ice and then circulate it around a person's body. It doesn't seem unreasonable for a road crew to carry along a cooler of dry ice for suit refills.
I have presumed that Musk's choice of how to present the HyperLoop to the world was motivated by the goal of drumming up popular support for the project in California. In effect, he likely wants the citizens to tell their government, "Go out and buy Elon's product." Governments are accustomed to citizens saying, "X is a problem and something must be done." vs. "We want Problem X solved via Means Y." So, one incentive which kicks in is risk aversion. No elected official wants the failure of something new to be pinned upon him. Also, better ways of doing things often are worse for politicians. How much bribery, favoritism, etc. is encompassed in the process of fixing the same road over and over again every few years? Politicians might dislike the reduction in power and control which would come along with a road which would last 50 years.
Imagine if companies with innovative technologies marketed them directly to citizens. "We sell a road system which will last for 50 years. Tell your local government you want Surface XYZ." Such marketing would be akin to the marketing of prescription drugs to consumers as a indirect way of influencing physician prescribing habits.
The warehouse is huge. It's (somewhat ironically) in an old auto plant in a Cleveland near-ring suburb. They (as of a few years ago) list items both on their own website and on eBay/others. I recall being told that their business model is to make an offer to a company closing a plant for all equipment -- simple liquidation.
When I was there, some guys from Florida were looking at some sort of precision measuring device. They owned a small machining operation and said that this particular device would cost $125K new. HGR was selling it for less than $5K.
I was quite pleased with my $30 workbenches. One had been modified with large, lockable casters. On the way out, another customer noted that the castors alone would cost $100 new for a set. One could question the time efficiency of my purchase, but I wasn't working at the time so my opportunity costs were low.