367 karma · joined February 19, 2021
> The lawful bases for processing are set out in Article 6 of the UK GDPR. At least one of these must apply whenever you process personal data:
> (a) Consent: the individual has given clear consent for you to process their personal data for a specific purpose.
> (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.
> (f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests. (This cannot apply if you are a public authority processing data to perform your official tasks.)
...
> Legitimate interests is the most flexible lawful basis for processing, but you cannot assume it will always be the most appropriate. It is likely to be most appropriate where you use people’s data in ways they would reasonably expect and which have a minimal privacy impact, or where there is a compelling justification for the processing.
> The processing must be necessary. If you can reasonably achieve the same result in another less intrusive way, legitimate interests will not apply.
> You must include details of your legitimate interests in your privacy information.
I included the legitimate interests bits because they seem most relevant to testing, but even if testing is not considered "necessary" in a particular use case, there still remain at least two more criteria that might satisfy the use of live data in testing, including explicit user consent. Much of the focus of GDPR is on privacy-invasive intrusive processing and prevention of harm, I think a lot of fuss around it can be dispelled when viewed from this angle.
Giving up and dumping everything into a monorepo, that's not going to help at all. At that point probably better off just giving up any hope of carefully split up and individually managed services
Cloud providers profiting from free software is an important issue, but it is largely orthogonal to the continuing need to protect free works in numerous traditional use cases
No familiarity with these devices, but there is at least a slim chance if it was an embedded device, they needed the flash or RAM for something else. Seen this happen elsewhere before
So I guess from my perspective, I'd treat this with roughly the same scepticism as a free hosting service provided by Google Analytics, at least until the bigger picture is made a little more clear.
> Since its introduction in 1973 and refinement in the 1970s and 80s, the model has become the de-facto standard for estimating the price of stock options
The only contemporary use for BS by professionals is as a convention for quoting volatility. As a pricing model it does not account for key effects such as the permanent "volatility smile" appearing in the aftermath of the 1987 crash (significantly increased price of downside options), and well understood behaviours like jumps and volatility clustering.
The only attacks I know of are low brow phishing, DoS and web site defacements.
.
> Given your exposure in this geography can you name any of it's neighbors
Saudi Arabia targetted at least Bezos' phone
Please elaborate on this. As someone with direct exposure to this area and in this geography, my experience could not be described this way at all.
Let's not forget Iran's first "military satellite" was launched with an over the counter unencrypted amateur cubesat transponder manufactured by a Californian company
Running CUDA in VMs
Running transcoders in VMs
Running <anything that needs a GPU> in VMs
bad DNS config push - 1 shot
routing loop - 2 shots
third party advertising your routes - 3 shots
power outage at data centre it turns out everything depends on despite decades and millions in engineering to avoid precisely that - 4 shots
Wolves ate through fiber - 5 shots
And it was a full moon - 6 shots
Single service failure, but service has not been restarted in 5 years, and no longer restarts in any documented fashion - 7 shots
And service developers left the company to found a startup - 8 shots
Expired internal SSL certificate - 9 shots
Daylight savings changeover-induced database corruption - 10 shots
Windows Update - 11 shots
Don't get me wrong, in this scenario I'd most likely be a drainee, just pointing out the thought must have crossed the minds of a more than a few managers.
I hated Kubernetes ops complexity at first, but there really isn't that much to it, and if it's too much, a service like GKE takes 70%+ of it away from you
Adding more mechanisms on top is pointless when the effort could be invested in, for example, automated auditing of SGs, which is vastly more potent from a hardening perspective than adding additional layers of technical redundancy that are still exposed to the same flawed human processes.
When you reach a team of 10-20 folk on a project, stuff tends to get confusing and/or lazy with elaborate configurations. Security design therefore is about more about managing that outcome through simplicity and process hardening than.. well.. I don't even know what threats a separate VPC protects against