[0] https://lilithwittmann.medium.com/bundesservice-telekommunik...
1,012 karma · joined March 29, 2015
[0] https://lilithwittmann.medium.com/bundesservice-telekommunik...
[0] https://lilithwittmann.medium.com/bundesservice-telekommunik...
[1] https://logbuch-netzpolitik.de/lnp419-und-aehnlich-verschwor...
Just a month ago the German activist Lilith Wittmann used an airtag to corroborate the suspicion that a branch of the German government she (or anyone else who should) never heard about before called "Bundesservice Telekommunikation" (Federal service of telecommunication) is just a front for the Bundesamt für Verfassungsschutz (Federal Office for the Protection of the Constitution, the federal domestic intelligence agency). Unfortunately I only found this [0] article in english quickly, a longer piece by herself in German can be found at [1].
[0] https://www.imore.com/german-woman-uses-airtag-find-governme...
[1] https://lilithwittmann.medium.com/bundesservice-telekommunik...
I would never do business with them voluntary but I got an domain registered with them through Google Workspace (back then called Google Apps) almost ten years ago. My guess would be that the affected Google customers alone may be in the thousands. It took them more than two days to get the DNS resolving again, which meant not even email was working since the MX records just vanished.
It's just a total shitshow. I'm now waiting for getting an Auth Code to transfer my domain to another registrar.
Well this works the other way around too. I found this especially true when delivering software which is considered an interim solution.
More than once I got root privileges on customer machines or seen my software run as root because the project owner found it too cumbersome to deal with his own employers security regulations. Or just wasn't given the budget to deal with it properly. Sometimes it's easier to get an exception than to follow protocol.
This is coming back to haunt you if something goes wrong or an interim solution wasn't so interim after all. If someone responsible for auditing permissions asks at this later stage it was always the vendors fault.
We're using this feature in production as part of a financial forecast application. This makes it possible to forecast spendings/revenues based on data from different points in time. For example the users can generate a forecast in december based on data as valid as in june and can compare how good their forecast model predicted the reality at the end of the year.
This works quite well but there are some pain points:
1. System-period (transaction time) data is immutable and can't be changed with queries. If "faulty" (in the sense of "technically correct" but not reflecting reality) data is imported to the database, the database will return this faulty data for this "as of" date no matter what and there is no easy way to drop this data later.
2. This is the main reason why logical backups (mysqldump) for historical data are not possible, since there is no way to write that data back with queries. This should be possible in the future but the correpondig (critical) bug ticket wasn't solved in almost 3 years.[1] You can use mariabackup (physical backups of the underlying file-system storage) instead but this requires console-access to the database server which isn't always allowed in corporate environments.
3. I'm not aware of any ORM framework which supports System-versioned tables (neither MariaDB nor PostgreSQL) so you have to write your own solution on top of an existing ORM or use raw queries.
[0] https://mariadb.com/kb/en/system-versioned-tables/ [1] https://jira.mariadb.org/browse/MDEV-16029
Temporal tables adding an additional "time axis" to SQL databases. A "valid from" and "valid to" field is added to each row and the SQL syntax is extended for allowing two new types of queries:
1. Query the data as of a specific point in time. E.g. "show all customers as of April 9th 2021". This not only limits WHICH customers you see, but also select the exact state of each customer as valid at this point in time. For example if the adress of a customer changed on April 10th, you will get the old address.
2. Query all versions of a specific entity. This makes tracking of changes or time series analysis possible.
This feature is transparent, so if you use "normal" SQL queries, you keep getting the current state of the data. I don't know if this is true for this PostgreSQL extension, but MariaDB even hides the "valid from" and "valid to" columns and only show them when you explicitly select them.
Additionally there a two types of "valid from"/"valid to" data, which can exist at the same time:
1. Application period: Those validity dates represent a period in the real world. If we stay at the customer address example, they can express "a customer informed me, that their addess will change on April 15th, so the current address is valid until then and the new address is valid from then".
2. System period (also called transaction time): Those validity dates are a kind of technical period. They represent when data changed in the database, e.g. the exact point in time when an UPDATE query was executed.
Audacity may had some quirks over the years but it's still one of the most (if not the most) accessible tool for audio editing by non-professionals with an adequate feature set. It's used by community radio stations all over the world since it's easy to teach and cross-platform while being free.
This is so true especially for long voice messages. I really don't like listening to people thinking aloud about what they want to tell me. I mean...this isn't a suprised-by-voicemail moment, they intentionally decided they wanted to send this voice message in the first place.
But it gets even worse if you (like me) don't like sending voice messages. Maybe it's just me, but to reply to a lengthy voice message via text I have to listen to it in parts multiple times to adress every question/topic which was raised in it.
I'm totally fine with people calling me, if they prefer voice. But please don't send me voice messages as long you're not in a car or otherwise unable to text and have a real important message.
> I very much do not want to be bombarded with voice messages in a professional context.
I had one client who started sending me voice messages and it drove me nuts. I realised that most people tend to forget what they said in a voice message faster then via other means.
So while I get your sentiment you're really arguing against the wrong person here.
Besides that in my opinion there is a significant difference between "falling through the cracks" and making wrong decisions poorer people aren't even allowed to make - and then wanting those poorer people pay for your errors.
Although I recognize the personal hardship this can cause, I fail to accept this as a general injustice. In the German healthcare system nobody is forced to choose a private insurance instead of the public one. Choosing a private insurance when you're allowed to (which often means because you're in a higher income bracket) is usually only cheaper if you're young and healthy. It's basically a gamble on your own health for wealthy people.
And if the wealthy young and healthy population don't contribute to the public health insurance system which also pays for the not-so-wealthy and not-so-healthy (older) population, the public insurance system isn't sustainable.
The real problem with this system is its division in public and private insurance. Mandatory public insurance would mean lower insurance fees for public insurance and the problem of being stuck in private insurance would no longer exist.
In the aftermath of the G20 summit in Hamburg there were some advancements to even tighten the law while at the same time the police was using illegal face recognition software.
- using the docker image is easy; not so using the jar file especially due to very little documentation
- confusing UI paired with lack of extensive documentation
- this makes it far from "easy" to be used by "everyone in your company" (quotes from metabase marketing claim): you really have to know how to do things, even easy ones like changing labels
- the UI contains many minor bugs which sometimes lead to unsavable metrics and you have just start from scratch
- no build-in way to export dashboards, which makes it nearly impossible to test your new metrics on a different system before pushing it to production; if you really want to do this, you have to juggle with database dumps
There might be some valid use cases for metabase, but I don't think it's very usable for non-technical users. I strongly suggest to evaluate it thoroughly before counting on it.
Nevertheless thanks for making it open source and free to use, so don't get me wrong.
I am not a lawyer but I know that this is a common misunderstanding in Germany. The landlord is not allowed to keep a key to the apartment he rented out, unless you're explicitly consent to it.[0]
You have to grant him access in case of an emergency and if you don't do that, forced entry may be legal (like in the case of a pipe burst).
Thanks for clarification, it slipped my attention that plaintext extraction isn't possible even with a compromised receiving endpoint as long as the data-diode is in place.
And thanks for your work. I'm currently experimenting with TFC on various hardware and considering it as topic of my (long due) bachelor thesis in Software Engineering.
Besides the software it uses a very simple made data-diode[0] circuit especially to prevent key- and plaintext-extraction by limiting the data flow in only one direction. This is used to connect three distinct computers (sending/receiving/networked) from which only one is considered compromised (the networked one).
The rational behind that is as long as your (sending/encrypting and receiving/decrypting) endpoints aren't compromised during installation it's very hard to compromise them later.
That can't be said about Wire on an unsave endpoint like an android phone. On the other hand, Tinfoil Chat isn't the easy to use messenger which you want to recommend to any non tech-savvy person.
You mean: was eating something big 55 million years ago ;)
The "law of a Member State" part is very concerning. If it's enough that content is illegal in one member state to have it taken down in the whole EU, very tough times lying ahead.
The first two things which came to my mind were the new Polish holocaust law and the current prosecution of various symbols of Kurdish groups (e.g. flags of YPG) in Germany.
Say goodbye to free speech.
You're absolutely right, but there are different types of hums and many of them you can directly be linked to a source. Just to name the two loudest in my direct neighbourhood:
* Some kind of ships at slow speeds make very loud humming sounds. The loudest in my expirience are big car carriers (to be specific: Grimaldi carriers in Hamburg). The sound is very unsettling since it's at such a low frequency, that it's more "feeling" than "hearing". But the good thing is that it's over after the ship passes by.
* Some procedures in the nearby ship repair dock are very unsettling too. Especially sandblasting ship hulls is very annoying and for some reasons they mainly do it at night.
But the most distracting hum of which I was talking about in my parent comment has yet to be linked to a specific source. And it lasts much longer than my other examples, typically for days. So it has to be something which is produced only in specific conditions. This doesn't mean that this is ruling out all of your examples (e.g. large refrigerators could only be in use when the storage capacity is needed, it could be specific vessels etc.).
None of my flatmates heard that sound, so I started questioning my perception until I found another person living in the same building hearing that sound. Our bedrooms are located one below the other and the sound is most perceivable in that rooms, but we can hear that sound at other places inside the building too while others can not.
Some time later, articles in various local newspapers about that hum appeared (search for "Brummen Hamburg" if you're interested, unfortunately only articles in german), telling stories about various people along the river "Elbe" hearing that hum. I started reading about the Windsor and Bristol hum that time too.
A local politician started investigating that issue together with scientist from a technical university but - besides some theories (e.g. a big power plant) which couldn't be proven - with no success. The acousticians where cited that some of them could hear the hum at various places too, but in terms of sound level they couldn't measure it distincly from the "general" background noises of the city (with harbour, industry and much highway traffic).
In the last few years there wasn't much news about it but the hum is still there in varying intensity and duration.
In my opinion the demand for a government controlled kill switch in every piece of hardware that is somehow able to harm people is much more threatening in so many ways than the insecurity the author is trying to reduce. Just a few:
1. Based on the asumption, that ones current government/state is for the good of all people, what gives him the confidence that this will stay that way? What if your beloved government goes rogue? That's a lot power for an autocratic regime.
2. Why even trust the government in the first place with that kill switch? They are the same people which are careless about infrastructure critical ITSec since decades.
3. An univervsal security module which is highly standardized is a very profitable target. While the author is aware that finding an attack vector of one particular vehicle can mean that all vehicles of that type can be compromised, he doesn't come to the conclusion that the same logic applies to his security module.
Maybe you should try that recipe to cure your onion juice trauma ;)
https://de.wikipedia.org/wiki/Verkehrsberuhigter_Bereich#/me...
The official meaning is "begining of a traffic calming area" (verkehrsberuhigter Bereich) but most people call it "Spielstraße" (literal translation "street for playing"). I don't know if the sign was designed after the common term for those streets or vice versa.
Oh dear...I really wish your kids have the best parents in the world. I really do, my parents probably believed that too, but unfortunately they were not - surprise!
But I'm really happy that I was born at least two decades too early for that shit. I hope kids can still outsmart their parents today. If not, we've lost.
I really applaud such curiosity.
Who is "we" in this context? At least in the Germany I know most people actually call this "Gefahrenabwehr" (literally: danger prevention) or "Staatsschutz" and can't remember any historic event which has shown that this is a bad idea.
If right-wing terrorist join the party people call it "Nationalsozialistischer Untergrund" (National Socialist Underground) [0]
[0] https://en.m.wikipedia.org/wiki/National_Socialist_Undergrou...
[0] https://www.reddit.com/r/Twitter/comments/6c1p1t/so_twitter_...