HNHacker News
TopNewBestAskShowJobs

tempfs

321 karma · joined June 2, 2017

submissionscomments
tempfs··on Installing Debian on Modern Hardware
Debian is not the best distro to start with if you are you brand new to Linux anyway. It tends to assume that you have some understanding of Linux in general I think. You won't find app stores or wizards everywhere trying to shepherd you along for basic tasks.

Ubuntu/Mint will do just fine for those users. They have all of that stuff and online forums to field questions.

Once folks have adjusted and decide to use Linux for the long-haul they will start trying various distros on their own and land wherever they like.

tempfs··on Red Hat announces no-cost RHEL for small production environments
Honestly, I can't remember the last time I had Debian stable go wrong in any application[server,desktop,laptops or raspian]. I use it everywhere and it is pretty fantastic.

Despite Debian being phenomenal in many ways, it doesn't offer up a head for the chopping block to replace yours if things go wrong in a corporate application. Good luck getting IT folks to deploy anything that doesn't offer them an out.

Using CentOS knowing that it is downstream from RedHat but that RedHat would step up and fix things in a semi-timely manner was good enough for many enterprises....at least until IBM got involved.

Ubuntu is also a weird choice generally speaking because Ubuntu just uses Debian's testing repo as a base and really only significantly varies in the kernels that they roll for various products/services.[cloud,live patching,etc.] They used to maintain their own desktop[Unity] and service management[upstart] and a bunch more variances from Debian...but that ain't really the case today.

tempfs··on When Amazon Switched from Sun to Linux
Yeah, no way to survive in the computing game very long with super high margins.

https://www.macrotrends.net/stocks/charts/AAPL/apple/profit-...

tempfs··on Apple's privacy labels show WhatsApp and Facebook Messenger hunger for user data
Expect more of this pushing competitors out as Apple transitions further into the 'services' business model by monetizing their vast trove of user data.

MSFT and GOOG have been doing this too for years ofcourse.

While GOOG has had to be content only with what they can read from emails/calendars, texts, web searches, calls/voicemail, maps/location data and anything else that they can scrape from an Android device.

MSFT has had all of that a much, much more since they own the whole OS for workstation/server class devices where actual work gets done. MSFT will claim that all that data is for quality control and now security services but ofcourse they are going to squeeze every last drop of money they can from it. To expect otherwise would be like asking an alcoholic to guard a brewery and never sample the product, completely ridiculous. The US has no serious legal repercussions for doing so. Probably because the US intelligence community depends on that data since IT is forbidden from collecting it from Americans on its own.

Gee, I wonder why...

tempfs··on SolarWinds hackers were able to access Microsoft source code
Umm, that IS a big deal for the most deployed normal-user OS in the world.
tempfs··on No, Cellebrite Cannot “Break Signal Encryption”
This whole thing was just BBC clickbait and Cellebrite advertising to the idiots in law enforcement.

No one that actually knows even a tiny bit about how shit works believed the story for even a moment.

tempfs··on Original Dartmouth College BASIC manual (1964) [pdf]
"One time I found John Kemeny’s email and showed him my amazing BASIC6 monstrosity. He wasn’t very happy about that. "

actual LOL.

Kemeny seems like he was the kind of guy that had a good sense of humor and every good comp-sci professor needs counterexamples.

tempfs··on Apple M1 vs. Ryzen 3900X vs. Intel I9 in Software Development
I mean Raspberry Pi's are ARM and there are more than a few of these are running Linux(Raspian/Arch/etc/).

Linux will run on pretty much anything given an ounce of driver support. I'm not that overly worried about Linux and ARM.

Microsoft is the one that should be worried!

tempfs··on U.S. Treasury breached by hackers backed by foreign government – sources
Seems like the US Gov went all in on O365 and is now paying dearly for it.

Maybe trusting Microsoft with the keys to your kingdom is a bad idea.

tempfs··on Winamp for Windows 10
Last release was April 19, 2016...
tempfs··on .NET Orleans
Fast? #lolno
tempfs··on Update on Firefox Send and Firefox Notes
Seems pretty clear by now that Mozilla is on a path to just slowly transform Firefox into Chrome or try to abandon it 'to the community' like they did with Thunderbird. Either way they've clearly signalled that they could not give a shit about Firefox any more.

Since Edge is basically Chrome with Microsoft's telemetry baked in that means that your browser choices will either be the one made directly by an ad company or Chrome repackaged by some other company that just wants to pipe the browser telemetry back into their already egregious OS telemetry pipeline.

It is definitely time for a fork or a fresh start with actual privacy, security and simplicity in mind.

tempfs··on Latest Windows 10 Update Could Hurt Your PC
Mac updates are definitely problematic, but I honestly can't remember the last time running apt dist-upgrade has ever broken anything on Debian.
tempfs··on Practical Linux Hardening Guide
sudo apt install byobu

sudo purge-old-kernels

tempfs··on Practical Linux Hardening Guide
Nothing externally accessible should allow password login at all.

SSH key-based logins are so much more secure and convenient as heck once you invest the time to learn how they work.

tempfs··on Practical Linux Hardening Guide
You run your own Software repo(s) on site and you only allow software to appear in that repo that you trust. You use applications like puppet to automate installations from your repos. LDAP can store users,groups and attributes that can be used into determining which groups get what software baselines.

Not really all that different from what goes on in the Microsoft world with WSUS/Appstores/etc. Just the implementation is different and much more customizable.

tempfs··on Departing Facebook security officer advocated for shifts in company’s culture
You mean like every television station and newspaper that preceded them for decades and decades now?

The medium may change but the game does not.

You keep the cattle ignorant, fearful and nicely divided into two groups that you can steer and pit against each other on a whim whenever it suits your agenda.

tempfs··on AT&T promised lower prices after Time Warner merger, but it’s raising them
AT&T carries directly or peers with basically every other major internet carrier in the country.

This makes them defacto critical national security infrastructure and thus completely immune to the kind of recourse and accountability that all corporations should be subject to.

The technicality of being an independent and non-governmental entity allows them to collect and in turn share back[to the NSA] information about the traffic that crosses their fabric circumventing those pesky laws which purportedly prohibit the NSA from operating within our borders and inspecting local-only traffic.

AT&T is only going to be checked by legislation now as it has always been. The last time they were broken up they magically reassembled themselves because voters allowed it.

Until we as a country decide that communication infrastructure, like roads, can't be owned by quasi public/private abominations like AT&T but instead only held by us, the people and our government we will continue to get the worst from this present unholy union.

tempfs··on What SSH Hacking Attempts Look Like
Some notes from an InfoSec person.

- Have a stand alone SSH server that is something like a R-Pi[type B] running an OS that gets patches regularly via unattended-upgrades and reboots itself at least once a week.[could also be a minimal VM like AlpineOS if you need Gbps+ line speed]

- Have this R-Pi and your network gear plugged into a UPS that can withstand at least a couple of hours of power outage.

- Use non-standard ports on your perimeter FW for forwarding to the R-Pi.

- Run fail2ban or something similar. Set a bantime of at least an hour[3600 sec] after no more than 5 attempts in 600 sec. This is mostly to discourage anyone who stumbles across your perimeter listening port.[which enough will] Password login will be disabled anyway, but a bot might not check for allowed auth types.[nmap -Pn -p 22 --script ssh-auth-methods <target>]

- No passwords allowed in /etc/ssh/sshd_config[PasswordAuthentication no]. Use public key based authentication.[PubkeyAuthentication yes] Put the public SSH key[id_rsa.pub] of any machine that you wish to authorize into ~/.ssh/authorized_keys on your R-Pi. This way you can authorize and de-authorize remote machines[with particular users] at will.

- add 'AllowUsers xxxx yyyy' to your /etc/ssh/sshd_config

- No root logins allowed![PermitRootLogin no]

- Maybe limit via perimeter or on the R-Pi which source IP ranges are allowed to access to SSH.[whitelisting]

- Periodically review your logs of perimeter FW, R-Pi FW and /var/log/auth.log to see what's going on. It should be pretty quiet, but look at them anyway once a week.

- Sleep well knowing that you have a simple, layered and robust defense strategy that also has power-event survivability.

Others have mentioned port-knocking which is a cool trick but not something that I typically use in an actual daily defense strategy because I'm not sure how much value it really adds.

Don't use your perimeter device to host SSH services. It will not get patches fast enough when vulns come up.

tempfs··on Microsoft Adds an OpenSSH Client to Windows 10
Shhh. It will only be another decade or two for Microsoft to complete their ugly rewrite of Unix.
tempfs··on Power9 to the People
Debian is available for POWER9.

This means you'll have at least KVM so you can run nearly anything on top of that including Windows VMs with PCI-passthrough for gaming,etc.

The cost is non-trivial but I've been working up my nerve to pull the trigger and go this route.

tempfs··on Reverse engineering guide for beginners: Methodology and tools
Context: Visiting a website written by/for reverse engineering, a subset of Hacking.

Assertion: Visiting a hacking website with Javascript disabled is a bad thing.

Hmmm...

tempfs··on Visualize data instantly with machine learning in Google Sheets
Excel is the appropriate tool for one-off adhoc analysis.

When something needs to be regularly produced, then and only then should it be moved to a formal BI solution.

People have a lot of questions and Excel is an approachable tool for small analysis that users can self-serve with.

← PreviousPage 3 of 3