Hmm, Tailscale is too convenient and that traffic is going dark from Cloudflare's all seeing eye.
916 karma · joined April 14, 2010
Hmm, Tailscale is too convenient and that traffic is going dark from Cloudflare's all seeing eye.
Aruba wireless (like many enterprise wireless vendors) has a mDNS proxying and filtering system which is essential for places like college campuses. Airplay and Miracast (infrastructure mode) both use mDNS for service discovery. In Aruba the system is called Airgroup. When seeing a new MAC address the wireless controllers queries the RADIUS server. The RADIUS server can return a configuration for that new MAC address which tells the controller what other devices can interact with this new device using mDNS.
I always assumed this vendor adds and removes Airgroup configuration to allow the phone and the TV to see mdns from each other while preventing this from other nearby devices on the same VLAN or SSID. This trick might be enough but also pushing a DACL to the wireless controller to properly packet filter all network traffic from unapproved devices would strengthen the solution.
Just copy Chrome and confine all modal dialog boxes such as HTTP basic auth and Javascript alert() to the individual browser tab. No individual tab should every be allowed to pop a modal that prevents interaction with any other tab, any other browser window.
This problem immediately goes away and you don't need to play rate limit wackamole games or do stupid things like have a dialog box that asks if you want to see another modal dialog box.
As someone who interacts with HTTP basic auth frequently Firefox's behavior here is maddening. Fix the bad UI.
Edit: Oh, and here is a 13 year old bug about the real issue: https://bugzilla.mozilla.org/show_bug.cgi?id=377496
Of course MDM is not required for any of this. Worst case is on Android you're forced to use Microsoft's Outlook app.
At this point if I was designing a VPN for client devices I'd have a mode that looked at as close to HTTPS as possible. There is one tool to tunnel over websocket but this was already sucking up too much of my play time. :)
Cisco AnyConnect, while expensive and bloated, works great as it initially connects on 443/tcp and then tries to setup UDP. If UDP fails it just sticks with the TCP connection and "just works".
Outbound port filtering is incredibly common on public and guest wifi networks and I found three use cases in my first week where OpenVPN on 443/tcp would have worked fine. The inability to use Wireguard over TCP and bypass most outbound port filtering by using tcp 443/etal makes it unusable in my daily life. I can understand why TCP isn't performant but my choice isn't performance vs non-performant. It's works somewhat vs GFY.
And yes I've seen the udp over tcp forwarding hacks. They don't work on iOS and some look outright dangerous (hello open proxy).
Hopefully this can be addressed before Wireguard hits 1.0.
"Hardware companies"
Does that mean bundled by carriers and crappy Android phones? Lovely.
https://www.latimes.com/business/technology/la-fi-tn-ride-ha...
"The company doesn't work directly with services such as Uber and Lyft, but a number of apps, such as Sherpashare (which is primarily used by ride-hailing drivers for services like Uber and Lyft), HopSkipDrive, eDriving and a variety of navigation apps use Zendrive's technology to monitor ride safety."
Hurray for malware. What other apps is this hiding in?
Oh no. Oh... no. follow link to dropbox.com Ugh. What happened?
I'm now under the impression Dropbox will go out of business and I need to explore alternatives.
Edit: I think I identified what makes me intensely dislike it. The color scheme and design screams "This is no longer for you, it's for hipsters."
I stopped looking at the keyboard every 10 seconds when I learned how to touch type.
The presenter spent most of his time looking at the keyboard and not the screen.
This gimmick will disappear when Apple decides a touch screen is needed to complete the slow merge with iOS.
Edit: Radio station downloading now seems to grab at least twice the amount it used to. Which puts it firmly in the "meh" category when it comes to usefulness.
If I want to watch music videos I'll go to the Youtube app. So damn annoying when I accidently tap the play video hover button when I really meant to swipe to the next song.
If it weren't for YouTube's popularity I'd say the integration was a sign of desperation.
It's not obvious but the way to do this is to "pin" (aka mark as keeping for offline) playlists on the device. Create a few travel playlists, pin them on the device, put the device on wifi or change the data settings in the app, go to the web client and mass drag and drop songs onto the travel playlists. I manage about 6 GB worth of offline music this way and it works decently. Once in a while you have to go into settings and tap "Refresh Music" to get it to recognize a new playlist but I maybe do that once a month.
Once a month Amazon seems to make a release that outright breaks a critical flow in the app. For the past couple weeks I've had to use the website to skim through books because every time the app tries to open the store view for a book the app instead opens Chrome with "about:blank" as the URL. /facepalm
I'll ignore the fact the tablet version gets a proper store interface (when it's not completely broken) but the cellphone version gets a regurgitated ancient web view that was last updated a half decade ago.
I can only conclude that Kindle isn't profitable for Amazon at all and they throw appropriate talent at it... that is none at all.
Does Apple give a rip about iBooks? Google doesn't seem to give a crap about getting indies on Google Play.
$649 is where I stop paying attention to the Nexus line.
The hours worked to afford the device and it's needed case and accessories make the 6" screen not worth it.
And trying to hide the cost behind a cellular contract brings that cost over a thousand dollars. Stupid.
If you've properly deployed these tools you've greatly limit the potential impact of a DHCP based worm.
Home router? Anyone test this against Linksys junk yet?
Webpage says it's sent but nothing ever arrives to the phone. I'll send an email to help@twilio.com with my phone number if someone over there wants to try a few test sends for debug info.
As a side note I just tested using the SMS page and it seems to work now. When I last tried it a couple months ago when swapping SIMs and trying to test SMS it silently failed with both sets of phone numbers and SIM Cards while every other SMS source I could try worked fine. That appears to not be an issue anymore so it's just MMS.
MMS to and from the phone works fine with Verizon and AT&T cellphones so I'd imagine there is some plumbing somewhere going wrong in my case.
Thanks.
In my opinion if you're not going to buy a Nexus device or a Moto E/G/X then you might as well buy Apple. The Android One program will hopefully add more to that.
Dear Galaxy Nexus users... It's time to let go.
Actually since you mentioned it:
"The purchase orders state that the purchase had to be split across multiple POs due to ADPICS controls. OHA explained that this was due to limitation on the authority of the OHA purchaser entering the POs into the ADPICS procurement system."
So they had to split the POs up to get them past the business rules implemented in their accounting platform? Heh.
The actual apps run on your phone and so your car gets updates when the software on the phone gets updates.
This mode is highly preferable to the end-user apps living in the dash computer as that will not get upgraded worth a damn over the life of the car no matter what.
This is exactly what I'd want to see in this situation and I can't wait to get an aftermarket replacement to cover the gap until I need my next car.
On our campus it's reaching the point where every switch we'll be buying will soon be PoE. I imagine many places are far ahead of us on this.
What is the max cable length of USB Pd?