72 karma · joined December 20, 2022
blog: https://schempp.dev/
contact: hn@schempp.dev
On page 43, it shows very clearly, that women who do not have children have almost no earnings gap.
Society can "fix" this in two ways: - introduce the same penalty for fathers, so that both earn less - which would IMHO lead to even less children - lift up families/mothers and help women not experience this gap, by having full time high quality child Care, have laws that allow mothers to take their children to Work, etc etc.
Second one is much harder to accomplish, because it costs money and time and effort.
The first one is Just forcing fathers to stay at home while mothers go back to Work.
Just because institutions are oversimplifying doesn't mean we have to
I would say against both genders.
Mothers carry their child for ~9 months, they give birth to that child. The bond between a mother and her freshly born child is bigger than that of the father.
Of course fathers are very important too, and yes fathers should spend more Time with their children in general.
But it's Just crazy to ask mothers to get back to work as soon as possible. Many mothers want to Work part Time, because they want to spend more time with their children. The issue is, that care work is not paid or valued nearly the same as work for money.
Also if you're feeding your young child like you are supposed to, the father simply can't feed the child, because we don't give milk.
Nearly all articles about this topic care only for how to get women back to Work instead of what's best for society and for families.
If that would be the Focus, we would talk way more about how to integrate children into the work Life and less on how to grow GDP.
ruroco DOES prevent replay attacks, by saving the deadline (which is in ns) in a blocklist. It does not matter if the deadline has "passed", the deadline is added to the blocklist as soon as the packet reaches the server and is deemed "valid". So each packet is only valid exacly ONCE
Once this UDP packet reaches the server the deadline will be added to the blocklist.
If an attacker sends the same packet again, the server will check its blocklist for the deadline. It does not matter if the deadline has been reached or not. once the packet reaches the server, the deadline of that packet will be added to the blocklist.
the deadline that is sent from the client is being added to the blocklist after the command was executed, so sending the same packet again will not work, because the deadline (which is in nanoseconds) is already on the blocklist and therefore the command will not be executed again.
This effectively means that replaying a packet is not possible, because the server will deny it.
Are you referring to fwknop? Thats not "port knocking" but Single Packet Authorization. That is very different from port knocking.
How can one incorporate secure cryptographic hashes with simple port knocking?
But if an adversary uses the SAME network, then the IP address that the server sees will be the same for the client and the adversary, so it only matters if the adversary takes the packet and sends it from a different network, which the adversary won't have to do, because they still control the network where the packet was originally sent from.
I would argue that it does improve security in the way that it reduces the attack surface of potential vulnerable services, because they are simply not accessible for adversaries.
On the other hand, having another tool running increases the attack surface, but imho that's very small.
Kind advice from my PoV:
Your comment could be read as "your project is shit, there is ostiary which has replay protection and yours doesn't".
I'm sure you didn't intend for you comment to not come across that way, and I also did not read it that way, but others could have.
Also keep in mind that ruroco is a very young project and is by no means finished. I was thinking about using one-time-pads or other encryption algorithms as well. I also posted this here to get feedback to improve my project.
So hopefully when I release version 1.0.0 all the issues that this project has atpit are resolved ;)
Ultimately reading firewall logs to do port knocking is most secure way, because - as you said - there is virtually no attack surface.
I would argue that port knocking is extremely inconvenient and does not work in every scenario. So for me it's a tradeoff between "ultimate" security and convenience.
I have, but I do not want to run a VPN solution on my private sever, for which I barely have any need. Also Wireguard, although VERY secure is still not "simple" software.
In addition there are usecases where Wireguard would not help, for example when I want to open up an http service for the current network that Im in.
that's because I run my ssh on port 80, but that's not standard, so I agree that it's confusing. Thanks for pointing it out. I will fix it :)
Ruroco can be used for more than just keeping sshd logs clean, for example I could also enable a service other than ssh, for example a private file server that I want to get access to when I'm on my phone (although I haven't implemented an android version yet, it should be doable).
I used to use port knocking, but at some point found myself in a hotel where they blocked ALL ports, except TCP 80 and 443 (did not check UDP at the time).
My ssh port is on 80, so I can use all of my tools, even if the network I'm in blocks everything else.
Thats exactly what I'm using it for - I'm the only one on my server :)
I have no protection against DoS attacks, but I'm working on it (there is also a WIP in the README about that :) )
Thanks for the feedback!
and decrypt with the public key, see https://github.com/beac0n/ruroco/blob/ce766751b51c8ff6246a2b...
using RSA, one can easily derive the public key from its private key (see https://security.stackexchange.com/questions/172274/can-i-ge...), that's why the private key is kept safely on the client
Also for SSH the public key is also stored on the server, while the private key is kept safely on the client, see https://www.ssh.com/academy/ssh/public-key-authentication#ke...
SSH can also be used with RSA: https://www.ssh.com/academy/ssh/keygen#creating-an-ssh-key-p...
The way I pronounce it is with long vowels.
So in an extreme way it would be ruuurooocooo :)
Thanks for the feedback! It doesn't describe how it prevents that attack, because it doesn't prevent this attack :).
As someone else wrote, I could put the IP address of the sender into the encrypted data and validate that in the backend and drop the packet + block the IP address.
I will add that in the next release!
https://www.maddox.ai/en/ | https://maddox-ai-gmbh.jobs.personio.de/?language=en
Our product, Maddox AI, is an AI-based visual quality control solution, which can automate manually performed quality inspection for manufacturing companies. Maddox AI is an asset-light SaaS solution, which addresses those visual inspection tasks that are still performed manually, as conventional (=rule-based) computer vision methods fail. In product development, we closely collaborate with leading AI researchers from the Cyber Valley. Prof. Dr. Matthias Bethge, Prof. Dr. Alexander Ecker and Dr. Wieland Brendel have been researching in the field of machine learning and computer vision for years and are part of our founding team.
Maddox AI is used by DAX-30 companies as well as by large medium-sized enterprises. Our team consists of scientists, former strategy consultants, mechanical engineers, and software engineers. We know that Maddox AI's success is only made possible by our unique team. As we continue to grow, we want to convince the best and brightest minds of our mission to establish Maddox AI as the modern quality management platform.
We are looking for new colleagues for the following positions:
(Senior) Software Engineer, Edge (m/f/d) | ONSITE Tuebingen | (https://maddox-ai-gmbh.jobs.personio.de/job/894530?display=e...) - Main Technologies: Python3, PyQT/QML <- If you are good in one of those, we want to get to know you :) - Other Technologies: Ubuntu, (Embedded) Linux, ONNX, TenorRT, CUDA, Nvidia Jetson Platform, L4T, Systemd, neoapi - As part of the edge software team, you will contribute to the development of our edge software framework, which is crucial to enable running models in nearly real time on the customer's manufacturing site. Your code will be responsible to connect all the dots: from image acquisition via our industrial cams, integrating cutting-edge machine-learning techniques into low-latency edge environments, providing industry-standard interfaces for full automation to implementing UI components for our touchscreen interface, and communicating with our cloud infrastructure. You will be working closely not only with your software engineering but also with machine learning and hardware engineering peers.
(Senior) Software Engineer, Frontend (m/f/d) | REMOTE (CET +/-2 hours), Berlin, Cologne, Tuebingen | (https://maddox-ai-gmbh.jobs.personio.de/job/894528?display=e...) - Technologies: Typescript, React, Redux, Next.js, Material UI, react-query, HTML5, CSS3 - As part of our frontend team, you will contribute to the development of our B2B cloud application that enables our customers to control various aspects of our AI-based visual inspection product through easy-to-use tools – from production monitoring to building new machine learning models. In order to take our visual inspection platform to the next level, you will be working together with our designers and product management to integrate consistent UIs into a user-friendly single-page application using a modern tech stack. Your work will include writing cutting-edge tools for our canvas-based image annotator, creating interactive visualizations for our dashboard, and designing and integrating new API interfaces in close collaboration with our backend developers.
https://www.maddox.ai/en/ | https://maddox-ai-gmbh.jobs.personio.de/?language=en
Our product, Maddox AI, is an AI-based visual quality control solution, which can automate manually performed quality inspection for manufacturing companies. Maddox AI is an asset-light SaaS solution, which addresses those visual inspection tasks that are still performed manually, as conventional (=rule-based) computer vision methods fail. In product development, we closely collaborate with leading AI researchers from the Cyber Valley. Prof. Dr. Matthias Bethge, Prof. Dr. Alexander Ecker and Dr. Wieland Brendel have been researching in the field of machine learning and computer vision for years and are part of our founding team.
Maddox AI is used by DAX-30 companies as well as by large medium-sized enterprises. Our team consists of scientists, former strategy consultants, mechanical engineers, and software engineers. We know that Maddox AI's success is only made possible by our unique team. As we continue to grow, we want to convince the best and brightest minds of our mission to establish Maddox AI as the modern quality management platform.
We are looking for new colleagues for the following positions:
(Senior) Software Engineer, Edge (m/f/d) | ONSITE Tuebingen | (https://maddox-ai-gmbh.jobs.personio.de/job/894530?display=e...) - Technologies: Python3, C, PyQT/QML, Ubuntu, (Embedded) Linux, ONNX, TenorRT, CUDA, Nvidia Jetson Platform, L4T, Systemd, neoapi - As part of the edge software team, you will contribute to the development of our edge software framework, which is crucial to enable running models in nearly real time on the customer's manufacturing site. Your code will be responsible to connect all the dots: from image acquisition via our industrial cams, integrating cutting-edge machine-learning techniques into low-latency edge environments, providing industry-standard interfaces for full automation to implementing UI components for our touchscreen interface, and communicating with our cloud infrastructure. You will be working closely not only with your software engineering but also with machine learning and hardware engineering peers.
(Senior) Software Engineer, Backend (m/f/d) | REMOTE (CET +/-2 hours), Berlin, Cologne, Tuebingen | (https://maddox-ai-gmbh.jobs.personio.de/job/894526?display=e...) - Technologies: Python3, Flask, Azure, MongoDB, Gitlab, PyTorch, ONNX - As part of our back-end team, you will contribute to the development of our APIs which is crucial to enable our data-centric approach to AI-based visual quality control. Your work will include writing server-side algorithms for analysing dataset quality and aggregating model predictions for visualisation purposes. Furthermore you will help taking our AI automation pipeline to the next level, reducing the effort for model training and deployment to a single mouse click.
(Senior) Software Engineer, Frontend (m/f/d) | REMOTE (CET +/-2 hours), Berlin, Cologne, Tuebingen | (https://maddox-ai-gmbh.jobs.personio.de/job/894528?display=e...) - Technologies: Typescript, React, Redux, Next.js, Material UI, react-query, HTML5, CSS3 - As part of our frontend team, you will contribute to the development of our B2B cloud application that enables our customers to control various aspects of our AI-based visual inspection product through easy-to-use tools – from production monitoring to building new machine learning models. In order to take our visual inspection platform to the next level, you will be working together with our designers and product management to integrate consistent UIs into a user-friendly single-page application using a modern tech stack. Your work will include writing cutting-edge tools for our canvas-based image annotator, creating interactive visualizations for our dashboard, and designing and integrating new API interfaces in close collaboration with our backend developers.