Compare that with the man pages of some decent BSD. Or even Linux..
But yes. I have contemplated buying one of those windows internals. I will probably buy that book just because of your comment. It's not that expensive.
80 karma · joined August 10, 2018
Compare that with the man pages of some decent BSD. Or even Linux..
But yes. I have contemplated buying one of those windows internals. I will probably buy that book just because of your comment. It's not that expensive.
I would love to read up on windows internals, but there are no real resources out there. A few books that at first glance appears to cover it, but then just deals with the application layer and up to point-and-click.
This is why I don't use windows anymore. I don't ever again want a job where I have to debug why old program P stopped working after an update. I prefer to be able to learn stuff.
I read the samba hacker guide and how they had reverse-engineered the protocols over the years. MS Windows is not even compatible with ITSELF ffs lol ;D
That people treat this as news is for me an indication that people simply don't either read the news, or don't remember them.
I hope people maybe remembers now when they read it the 2nd time.. The US surveillance machine needs to stop.
It's neat for finding those wonderful little crazy communities that are hiding out in the anonymizing crypto nets (Tor, I2P, LokiNet, ..)
It's the only place left where there are ONLY real terminal junkies and nerds. No normies. I can relax.
Such as at the coffee (fika) break. It might be okay to just be silent. All you are going to talk about is rather obvious in either case.
I tried having comfortable silences with my coworkers. Some like it, some just go insane. It kind of depends on the person - maybe some people never learn to appreciate the silence.
That said, I do hope I get to answer some of these questions soon.
It's not retrofitting. If you make it work for the terminal it will always work from now on.
It comes outside the reaches from the graphical designers. Nothing with a graphical design survives more than 10 years.
How can you not know that stuff like this is happening?
It costs more to do a sciency Hollywood movie about than it costs to actually do the science. Sending an actual probe to the orbit of Mars is in general cheaper than making a sci-fi movie.
So...
That truly was quantity over quality. Oftentimes I had to wade through piece-of-shit code that really made my soul hurt. Really. Bad.
But in hindsight that was good. It's good to have spent 4 years ONLY writing code 8 hours straight 5 days a week.
But I never, ever, want to go back to anything like that.
Also makes it easier to hire people if you don't have to update any texts ;)
Thank you for existing.
Instead of reusing functionality that exists in the router already (ssh?), the authentication for winbox is something they built themselves. It was in the winbox auth that the main security flaw was. It just looked really bad to me.
The winbox client also downloads and runs any DLL that is sent by the winbox server. The winbox client has a windows certificate so all it's code is trusted. So own the router and you get the admins workstation too.
It just feels like maybe they hired some random guy without much appreciation for security for doing winbox.
The SMB server also had a rce a while ago.
That said, I guess that if you disable winbox and stuff that should not face the internet, you are probably safe?
Too much for me though. I would not feel safe.
I guess there is nothing good.. what is wrong with people :(
My conclusion was that I would buy my infrastructure from Allied Telesis. It's pretty much a Japanese version of Cisco, but it's still healthy.
Ubiquity was number 2. I refrain from buying from them only because of their glossy UI.
Mikrotik was on that list. Until I saw how horrible their winbox protocol was. And their implementation of SMB.. I must assume there are still plenty of unknown RCEs there.
This is a symptom of the rot in their management, and probably also a sign that they have hired too many incompetents.
It probably also is a sign of the current age. After the recovery from the IT-bubble programming got really hot. Thus: Too many of the new programmers wants to be programmers because it pays well - not because they love their craft. So therefore we have a bunch of well-paid but uninterested people seeking jobs at prestigious companies.
Culture matters. I want my socially maladapt terminal junkies back plz.
Homelessness is not an option for me. I just dug myself out of the hole, even if I was out of energy.
I had a text file on my computer where I wrote down the steps I had to take. Then I followed this todo-file for maybe 6 years. It was organized into sections: Now, next phase, next phase after that, and so on. It got more sketchy the further it is into the future.
I have been following this TODO-list for 6 years now. I am now at a point where I can add whatever I want to it, almost. I kindof succeeded.
How Eternal is the knowledge? Math is Eternal in the true sense, while that new webpage framework will be around for maybe just 2-5 years, and is thus not worth learning. (Although I am sometimes happy that people sacrifice their lifes on stuff like that, I would never do it.)
Vendor lock-in? I steer clear from that.
Is it being maintained? (Some things are okay not being maintained though. It depends on the type of tech.)
Surveillance potential. I am somewhat paranoid in my own personal life.
When procuring network-attached tech I usually dig through exploit-db and the CVEs and try to make myself a picture of how their security is being handled. Small companies are difficult to judge from this because they have little recorded history. (So I didn't buy any mikrotik router because of their shenanigan attitude to security, for example.)
Do the creator of the tech try to keep my hands away from digging into the machinery? Like hiding that it is really just a Linux/bsd box underneath? I stay away from that, if possible. (It's not always possible, almost all tech runs on Linux nowadays.)
I can be bribed to ignore any of these things that I usually avoid. For example, I learned MS Windows and some of their tech because I got bribed.
This SHOULD NOT be news.
Maybe you guys should revisit your school books.
No, this comment is not "too harsh" or elitistic.
We need simple open ISAs (like RISC-V) and a handfull of trusted organizations that inspect the manufacture processes to protect ourselves from this. A bit like how countries and organizations send people to inspect other countries democratic voting processes, or like how IAEA inspect nuclear stockpiles etc.
I call for:
+ Open source.
+ No creeping featurism.
+ Multiple inspection organizations that watch the process from source code to final chip product.