5,764 karma · joined July 28, 2010
[ my public key: https://keybase.io/tachang; my proof: https://keybase.io/tachang/sigs/3k4EnKOxZt-oQ7OIWzClI8l0yzGg3pl4mvp040CRyDQ ]
d5b3b0
Creator of OpenMiko (opensource firmware for security cameras) https://github.com/openmiko/openmiko
It must have been crazy hard to troubleshoot when you are flying blind because all your monitoring is unresponsive. Clearly more isolation with clearly delineated information exchange points are needed.
I feel like this comment belongs right along side the PAM source, if only to remind others that we weren't all that nutty coding it this way.
Thanks for this writeup!
It's funny how everything old is new again. We are just reinventing FDIC insurance for crypto.
The compromised hosts that are part of the botnet look exactly like normal traffic.
Source IP doesn't work since it is random and changes. You need to look at things such as HTTP headers, TCP window and any odd flags that might be set. If you're lucky the botnet isn't capable of running a copy of Chrome or Safari or using a random sample template from legit traffic. Lots of botnets are made up of low power IOT devices so once these devices are capable of running a full headless chrome it will get harder.
Not to mention when you do figure out how to discriminate traffic you have to code it. And the code to determine valid traffic vs invalid better run fast because you are getting hit with 100k requests per second. Oh did I mention the attacker can change their algorithm whenever they want? Hope you have a full tensorflow ML/AI pipeline that configures your hardware based ingress of choice just in time. All this while making sure your current production traffic is being served at a speedy pace and not blocking legit customers.
These are some of the issues Cloudflare and companies like them have to deal with.
Also, is Coinbase saying Lend isn't an investment contract? It sure sounds like one to me. Lend my crypto to Coinbase and I get a 4% return? I like the idea but it sure sounds like an investment contract to me.
Adding a bit of C to your tool belt will give you success wherever you go. The concepts it teaches are invaluable in understanding why things are built the way they are today. Everything from memory management, to trying to solve all these vulnerabilities, to why new languages have these crazy constructs.
Modern conveniences such as a dishwasher coupled with a focus on healthy eating (less fat) result in poorly taken care of cast iron pans.
Dishwashing soap these days are also a lot more efficient than they use to be. More and better surfactants eat away at any pantina that develops.
Yes you can drop a cast iron and nothing will happen to it. But to get eggs not to stick to it takes a bit of upkeep.
Does anyone give me more money for using IPv6? Sure I might be able to save some money by not using IPv4 but that is rare.
Government doesn't incentivize it. Ad networks don't either. There is very little penalty (financial or otherwise) for not going to IPv6.
IPv6 will not happen until those sticks and carrots get bigger.
I've expressed my disagreement on the public mailing list but it seems like it is happening anyway.