422 karma · joined November 20, 2009
[ my public key: https://keybase.io/netik; my proof: https://keybase.io/netik/sigs/gp4EeY8UT0l1f9kkZOyT4-IZLq_clsEVeST2k0J4Qtc ]
It seems that security is an afterthought at most startups.
But that takes a tiny skeleton crew, so maybe there's that.
Or, perhaps you're right and they're going to see if they can wait out the 2 year ban. Most likely they will change the name of the company to hide the bad reputation and then re-release the hardware testing platforms.
Bloomberg seems to indicate there isn't much left for any employee to do.
https://www.bloomberg.com/news/articles/2016-07-08/theranos-...
If you transmit something that looks like noise, and no one else sends something that looks like that particular kind of noise, then you are raising a flag that says "No, really, please, capture this data, it's interesting."
You know what would make for a better acquisition? Amazon.
Twitter has tons of customers, tons of dark fiber, lots of internal cloud technologies (mesos, etc.) and a huge international peering network of IP routers.
Amazon needs a way into social and real time news.
Most publicly traded companies have lockout periods if you have access to "insider information." Given that Twitter is (was) fairly transparent about company financials, this is probably still true.
https://www.washingtonpost.com/news/the-switch/wp/2013/12/10...
Many users don't know that something is on by default, and if the default is to geotag, people will nearly always forget to disable the geotagging.
You or I might know what it means when the 'place' icon is highlighted during a tweet. Non technical users might not understand the implication of thier actions.
It's less about 'making a fuss' and more about 'providing additional data to adversaries.' Remember, the NSA piggybacked on Google Analytics tokens for years to track users.
https://github.com/bitwarden/browser/tree/master/src/scripts
https://hbr.org/2015/03/why-data-breaches-dont-hurt-stock-pr...
They could start by incorporating every single feature that BlockTogether has as abuse mitigation.
Encrypted end-to-end DMs (which were blocked numerous times by useless product managers) would have been another excellent feature to protect users.
Disabling password logins, moving to SSH public key based login and hardware tokens (such as the SSH private key stored in Yubikey) is a much better solution than the one proposed here.
However, proper ingress filtering or local iptables/pf rules would stop any unwanted inbound traffic from reaching your server, and you should definitely be using ingress and egress filtering on your network.
Did you look at RFC4255?
Many of Apple's own web sites run Apple hardware for outward facing, large scale serving (I used to work there).
At the end of the day, Unix is Unix.
I run nginx on OS X on a number of Mac Minis without issue and long uptimes.
There have always been other methods for determining if an attacker is state sponsored. One example: Seeing your account, and a number of dissident or activists being attacked from a block of IPs or similar password attempts, probably means the attack is state sponsored.
That being said, in security, attribution is a very hard problem, and the methods used to determine state sponsored attacks are also quite hard to design.
There's a reason why companies won't elaborate on how they do this, but it is usually a combination of login/account intelligence and threat feeds.