424 karma · joined February 26, 2014
If you aren’t being specifically targeted, then you would care about low hanging fruits discovered by something like automated scanning. Not exposing your service to the internet does solve this assuming you’re confident in the stack which provides this isolation. But managing this stack and performing risk calculus here is actually where the security horse trading happens. I think most people aren’t safer managing this themselves — arguably they’re actually worse off.
I have high standards for the confidentiality of my data. I care about things like lateral movement and the massive attack surface that isolation tech to prevent such movement has. I also won’t design monitoring and alerting, ensure a patch state, or perform code audits on Nextcloud and all the isolation tech required to secure it to a comporable level of security. Because of this, I instead reason around the cost of exploitation. I want it to be higher than what I believe Nextcloud provides and I’d rather require an attacker to use an expensive 0day to extract my data off a cloud provider like Google versus a potentially cheap one against my own infra.
Generally you use these disclosures to make directional decisions about infrastructure. The list of fixed and disclosed CVEs combined with the legacy PHP code base doesn’t really pass the security sniff test. You really wouldn’t know for sure without doing a full code audit.
https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=nextcloud
A common misconception IMO is that running and owning your own infrastructure is somehow more secure. To that I lol, and I’m confident that the thousands of AWS/GCP/Azure/iCloud security engineers are all doing a more thorough job than you can. At the very very least they receive embargoed bugs which they often mitigate before the general public.
https://batteriesamerica.com/collections/icom-ic-v8-ic-v82-i...
Learn and be curious. If you’re working on the weekend, you get to do this 24x7.
New policy - five days RTO, two days WFH, per week.
Waymo has clearly been playing the “but it’ll be cheaper” game for a long, long time now. It makes sense if you squint really hard and fudge some numbers about unit economics.
If the expected outcome is for it to be eventually cheaper, then why when I open the app does it costs almost twice as much as an Uber or Lyft? You’d think they would want to at least convince investors and train customers that the savings are real and they’re going to prove it by passing it on.
“Alphabet _has to_ invest another $5B into Waymo”.
I’d like to remind everyone that it’s still a taxi business with taxi margins (best case).
Apple is very RTO heavy because they’re an old school hardware company. Hardware work is easy to demand in office work because: (1) apple secrecy and prevention of leaks and (2) access to lab equipment. #2 likely holds true for spaceX as well.
Adding Microsoft to the mix is weird as nobody I know there actually RTOs.
I think people need to actually specifically measure which roles (senior? engineering?) in tech we are discussing RTO about here. I agree that for most software engineering it backfired. But if you’re an apple hardware engineer, there aren’t many places in town that’ll pay you as much so you’ll accept whatever horrible RTO hand you’re dealt. Companies apply these rules to everyone which is very, very stupid IMO.
I think the most interesting part about this being on the inside is the rationale behind RTO. It’s always the same citing culture, collaboration, or other fuzzy things. It is never quantitative. Are you telling me that the people making these decisions are doing so without data? I think that’s unlikely, it’s just that the data isn’t in their favor and execs are smart enough than to let remote versus not remote become yet another bargaining chip for an employee, let alone senior ones.
TLDR, I think senior vs not senior in tech is likely too much of a generalization. But the people with the actual data aren’t speaking up probably because discussing the results don’t benefit them.
Would be interesting to see how much they’re _actually_ utilizing the NPU versus their GPU for AI workloads.
This page explains it pretty well: https://msrc.microsoft.com/blog/2022/01/an_armful_of_cheris/
Using nitrokey and some glue scripts you can get the cost below $500. If anyone is interested, let me know.
If the shoe were on the other foot how would you feel if someone forced you to be remote?
The issue will be once someone breaks the secure enclave in the CCD, all of the video they produce will now be trustworthy. CCDs are pretty lightweight in general as most of the heavy lifting is meant to be offloaded to the ISP—so the on-die processing for the CCD is generally very lightweight and wouldn’t have buffers large enough to sign each frame. Also there is no standardized way of creating a secured MIPI connection. You can do some clever things to mitigate for this, but it is far from what I’ll call “best practice” and more along the lines of a bespoke solution.
You’d need to read the iMX8 docs to know for sure, but it does support full secure boot IIRC.
Edit: Yup this appears to be true.
“The public key is included in the final binary and a hash of the public key is programmed in the SoC, in One-Time Programmable e-fuses, for establishing the root of trust.”
See https://www.variscite.com/blog/i-mx8-secure-boot-made-easy-c...
When there is a utility for it, humans invent a form of currency nearly immediately.
The problem with RCS is that the solution has been stuck in GSM consortium hell for over a decade.
I would encourage anyone who is curious to read more about it. It’s taken so long to gain traction that it has also become somewhat legacy. Also, it still requires a carrier sponsored phone plan? How is this “modern” in comparison to say every other carrier agnostic messaging app in existence?
Also this: https://twitter.com/RonAmadeo/status/1480679515298934786