3,342 karma · joined August 12, 2016
You can find me online at a few other places:
* Email: marcusb@marcusb.org
* Blog: https://marcusb.org
* Mastodon: https://mastodon.sdf.org/@marcusb
Certified “AI hater” — Ars Technica
---
[ my public key: https://keybase.io/marcusb; my proof: https://keybase.io/marcusb/sigs/M6JD8qft2hLYGUHk57yfm5NG9pN-BrilfjCak7rFOl4 ]
0 - https://www.amazon.com/Dealers-Lightning-Xerox-PARC-Computer...
But, of course, you know that, but you would rather dig and (try to) play semantic games than admit you are wrong. Do better.
https://github.com/hickory-dns/hickory-dns is our Git repo
Documentation for the resolver including an example: https://docs.rs/hickory-resolver/latest/hickory_resolver/ind...
Its more accurate to say that bubbles rely on most people being blind to the bubble's nature.
I think the first part of this is probably true, but I don’t think everyone knows it. A lot of people are acting like they don’t know it.
It feels like a bubble to me, but I don’t think anyone can say to a certainty that it is, or that it will pop.
I published my scripts[0] and notes[1] about doing append-only backups with Borg on rsync.net since at the time rclone studio wasn't supported. My strategy is to do Restic backups to a backup server at my house and Borg backups to rsync.net as my offsite backup, so the scripts handle both.
The post I linked above also outlines how I handle expiring old backups (requires either manual action with your privileged key, or a suitably isolated host that has the ability to purge the backups automatically.). You really don't want to fill up your disk (or hit your hard quota) with Borg. Recovering -- even deleting existing backups -- requires a bit of extra space unless you want to rm -rf.
0 - https://marcusb.org/hacks/backuptools.html
1 - https://marcusb.org/posts/2024/07/ransomware-resistant-backu...
This reads to me more like the error type returned by append with names is not (ErrorFlags, i32) and wasn't trivially convertible into that type so someone left an unwrap in place on an "I'll fix it later" basis, but who knows.
And, unless you are Rob Joyce, talking about the persistent part doesn't get you on the main stage at a security conference (e.g., https://m.youtube.com/watch?v=bDJb8WOJYdA)
I always had a sticker on my laptop - everybody had the same laptop (or maybe one of two models.) It was a reliable way to quickly identify mine in a big group at a meeting or conference.
His catch phrase was "all you gotta do is [insert dumb idea here.]"
It was anxiety inducing for a while, then it turned into a big joke amongst the engineering staff, where we would compete to come up with the most ridiculous "all you gotta do is ..." idea.
Your first example I was referring to - which you've now edited out of the article[0] to be more generic - stated:
> When Deutsche Telekom customers want to watch YouTube, that traffic flows directly from Google's network to Deutsche Telekom's network at a Frankfurt exchange point—maybe four or five router hops, minimal latency, no intermediaries. It's elegant. It's efficient. And it's exactly what Vodafone is abandoning.
Later:
> Deutsche Telekom pioneered this model in Germany, and the results have been catastrophic for customers. Not "slightly annoying" or "a bit slower"—genuinely, documentably terrible.
0 - original here: https://web.archive.org/web/20251107180616/https://coffee.li...
I… don’t think so? Your original comment was that companies claim nation state attack as a way to get government funding. That has nothing to do with assessing blame for an attack.
> Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who?
If you think you as a private entity can defend against a tier 1 nation state group like the NSA or Unit 8200, you are gravely mistaken. For one thing, these groups have zero day procurement budgets bigger than most company market caps.
That’s why companies reflexively blame nation state actors. It isn’t to get government funding. It is to avoid blame for an attack by framing it as something they could not have prevented.
> So we agree?
No, I don’t believe we do.
Not saying that these companies would turn down corporate welfare given the chance, but I’ll offer an alternative explanation: it shifts accountability away from the company by positing a highly resourced attacker the company could not reasonably be expected to protect against.
If you have a physical security program that you’ve spent millions of dollars on, and a random drug addict breaks in and steals your deepest corporate secrets people are going to ask questions.
If a foreign spy does the same, you have a bit more room to claim there’s nothing you could have done to prevent the theft.
I’ve seen a bunch of incident response reports over the years. It is extremely common for IR vendors to claim that an attack has some hallmark or another of a nation-state actor. While these reports get used to fund the security program, I always read those statements as a “get out of jail free” card for the CISOs who got popped.
Farm-scale irrigation is not silent.
Crop Dusters are not silent.
Combines and other tractors are not silent.
Burning fields are both not silent and release a tremendous amount of sooty smoke that spreads far beyond the boundaries of a farm.
Farms make a lot of noise.