86 karma · joined August 29, 2012
So we need to be careful with how we interpret "Safe!"
I combine it with an ansible script to push out the (minimal) configuration to end nodes.
In my use case, I have a modest number of nodes. Although nodes learn of other nodes from each other, I use ansible to keep each node's config updated.
I use vpncloud (and previously, tinc) between docker hosts. So, you have to be careful about interface MTU's inside of docker, particularly if you use containers based on Alpine.
git -- Change history is your friend, and you get out what you put in (hashes verify data against corruption)
tinc -- There Is No Cabal: Mesh VPN lets you build a VPN across diverse environments including different clouds.
The "USERTrust RSA Certification Authority" certificate signed yet another layer of intermediate certificates.
The "USERTrust RSA Certification Authority" certificate was promoted to a self-signed certificate, now in the browser trust stores, using the same key pair as the original certificate that was signed by "AddTrust External CA Root." It has an expiration of 2038 (although that concept is a bit vague in a root certificate).
What "should" happen is that no certificate should be issued with an expiration date later than the issuing certificate. Then as the issuing certificate gets closer to expiration, a new one, with a new key pair, should be created and this new certificate should sign subordinate certificates.
In reality Company "B" may well be much less secure then "A", but the customer has no way of knowing that or making a judgement on which company is more secure.
https://ipfs.io/ipfs/QmcgWw89GFo3Z1w9ad1H6Gom4DV4t5VRBu5zhkW...
Also, for backup, rather then tar up the ".git" directory, I use "git bundle <backupfilename> --all" which creates a flat file with all branches included. This file can then be uploaded to GCS or S3.
My point is that Amazon tried really hard to give a good experience with lower end hardware then most Android devices. Encryption likely adds a significant performance cost.
Keep in mind, the iPhone has hardware support for its encrypted memory. It is my understanding that the main processor does not get involved in the actual encryption of the flash storage. Because Apple controls the hardware and the software, they can do this tight integration. Android is software and encryption on Android must be done in software unless and until a hardware vendor integrates bulk encryption into their memory system and provides an appropriate driver for Android to control it. If such a device exists, I haven’t seen it yet...
The inherent contradiction was lost on the people giving the orders. So...
"Microsoft may access and/or disclose your personal information if we believe such action is necessary to: (a) comply with the law or respond to legal process served on Microsoft; or (b) protect the rights or property of Microsoft (including the enforcement of our agreements)."
Note clause (b). I thought it was a little off that they can examine your health records to protect their rights and property. But it looks like they are not afraid to use it!
This ditty is still there. In fact if you go to the home page for Health Vault, it says:
"It's your HealthVault account You decide who can see, use, add, and share info, and which health apps have access to it. HealthVault won't provide your health information to any other app or service without your permission."
So as advertised it looks like you get to decide. You have to read pretty far down in their privacy policy before you find the clause I first mentioned. Now of course there are cases where your private information may be used without your permission, but most people would assume that requires some form of legal process... but not for Microsoft.