Skip to main content

isithran reshared this.


Every company saying that their data is encrypted at rest with "strong encryption" is saying nothing. It's a free, effortless and shameless statement to boost the org's false security posture to the untrained masses. It's even worse when they say it to justify that their security was sufficient after a breach.

Encrypted data at rest just means they use the cloud. It's standard cloud practise. They give it basically for free at a button toggle. "Using military grade encryption" yes I know it's AES. That shouldn't make you feel any safer. Optus even said their unauthenticated API was protected by double layers of encryption! (TLS in transit and AES at rest!). That meant nothing, and did nothing to protect their breach. Why?

Because the threat models that encryption at rest protects against is someone walking into some data center and grabbing hard drives. And no one does that. Every piece of encrypted information stored by your business is constantly decrypted at some point for use - especially customer and production data. Any attacker who compromises your employees with access to cloud resources, or an application/system with access to those cloud resources will have credentials and permission to decrypt the data. Because at the end of the day encrypted data is just as useless to you as it is to the attacker.

isithran reshared this.

in reply to h4sh

when we, 1Password, talk about our layers of encryption we don’t even mention the encryption that comes free with AWS. What matters is data encrypted with available only to our users.
in reply to Jeffrey Goldberg

yea no, I get that, and SRP is not in the typical encryption bullshit list that I meant. 1password being a password manager obviously needs to have its encryption described on the tin, in technical detail, which it does quite well.
in reply to h4sh Soatok Dreamseeker reshared this.

@h4sh, thank you. I wasn't taking your post as being about us. I, too, get very irritated when services call "encryption at rest" is a defense against an exceedingly narrow threat. (Someone walks away with the hard drives.)

I get even more irritated when auditors and the like conflate that with what we do.
@h4sh
in reply to h4sh Soatok Dreamseeker reshared this.

@WPalant this is how I feel about podcasters saying server side AES on S3 will solve public bucket leaks


- "How obscure are your musical tastes?"
- "Well, today I found out I've got a full shelf of CDs the national library in charge of the mandatory deposit in my country does not even have in its database, which lead me to read back the law to ensure I wasn't liable to a hefty fine."
in reply to lomn

Hum, that's not really an incitation to share...
in reply to isithran

tbf I share 99% of my library being online daily. But I still keep a few exclusive recordings which I know are either very rare to come by or shit I recorded from livesets from when I used to work as a sound engineer.

The rare records no one would actually be interested in, the live sets could easily be tied to me if they happend to leak on yt or something.


Blasting Cbat with the home theater rig made the periodic bed noises from upstairs that have been going on for more than an hour stop straight away.

I think the message has been received... 😈

isithran reshared this.


Note this is a choice some IT person made years ago and nobody realizes is optional, or something is actually broken and people just got used to it. Re-Auth could be entirely seamless if they wanted, or only enforced for certain apps. This is not intrinsic.

Something I see a lot is people accepting bad IT experiences as mandatory. Like this is life, get on with it. But this isn't remotely true.
It's a choice, sometimes just not a choice an organization realizes it has. I have to be the person calling bullshit on stuff because I know. Because I understand what's normal outside the org, or I have literally done their job before as an IT Generalist.

The business malaise in accepting deteriorated user experiences is frankly shocking.
You're being led like a dog by people who aren't being challenged to do better. Who often are not stupid and can do better, but have no mandate to venture it.

reshared this



Honestly, one good thing for 2023 would be to set back up a blog, importing my old articles, doing old links management and posting at least once per month.

isithran reshared this.


can't wait for 2050s ham radio repeaters where instead of old guys talking about the wife or whatever diseases they have, there's a bunch of trans girls complaining about drama in their polycule

reshared this




A lot happened in 2022 (in a good sense as far as I'm concerned). A few rough times, but I got to make things moving 💜. Let's make 2023 even better ✨

Happy new year, and all the best to all of you 🎇
Unknown parent

isithran
Thanks, all the best to you too.
This entry was edited (2 years ago)

isithran reshared this.


Ah ! À partir de demain un 02 ne sera plus forcément un 02 #téléphone #arcep

« A partir du 1er janvier 2023, les contraintes géographiques des numéros 01 à 05 s’assouplissent. Concrètement, il sera possible de conserver son numéro de téléphone fixe, notamment en cas de déménagement, dans une autre zone géographique de France métropolitaine. »
https://www.arcep.fr/demarches-et-services/utilisateurs/degeographisation-des-numeros-de-01-a-05-ce-qui-change-au-1er-janvier-2023.html

reshared this




TIL that friendica support CWs through ActivityPub, but hat not yet implemented support for posting with them


isithran reshared this.


A very interesting take on the universe as seen from the perspective of the 2m amateur radio band by the #LOFAR radio telescope.

RT @cosmos4u@twitter.com

V-LoTSS, The Circularly-Polarised #LOFAR Two-metre Sky Survey: https://arxiv.org/abs/2212.09815 -> https://twitter.com/AstroJoeC/status/1605512117376778242

🐦🔗: https://twitter.com/cosmos4u/status/1605750235875131392

isithran reshared this.

Unknown parent

Scott Tilley
@doctroid It changes constantly, but the later will give you a sense of the theme.



I was unable to pull the data wire, since the duct was obstructed, so I went the wireless way. Next step: attempting to switch telemetry from legacy to standard format.
in reply to isithran

j'avais évité ce truc car zéro intégration avec home-assistant et pas envie de bricoler... dommage ça semblais quand meme intéressant. enfin, 50€ pour ça ça reste quand même du vol.
Unknown parent

isithran
@Louis Vallat zigbee2mqtt -> mosquitto -> telegraf -> influxdbv2 -> grafana

isithran reshared this.


it's @spacegirl video day!

https://www.youtube.com/watch?v=gRSyRy-Yq-k

isithran reshared this.

Unknown parent


isithran reshared this.


I think I found my next antenna. Need to find the real estate agent that has this listing!

https://www.youtube.com/watch?v=M9RxlUNIBBo

isithran reshared this.



isithran reshared this.


In 1959, the IBM 1401 computer was built from boards called SMS cards. A single board might hold just 3 logic gates so the computer needed thousands of boards. Silicon transistors weren't popular yet, so they used germanium transistors. Source: https://www.righto.com/2021/03/germanium-transistors-logic-circuits-in.html #history #computing

isithran reshared this.


isithran reshared this.


I present a no-context slide from my !!Con talk this November

reshared this



Pew pew lasers (7/*)
Slowly getting there (15J/cm², 3ms, ø 15mm). Some persistent spots, but significantly less tingly despite the 15% power increase.

isithran reshared this.


We have to deromanticize community. It's not some pristine untouched forest of soft moss and good vibes. The corporations count on that misconception to stripmine us for content.

Community has always been as weird and messy as humans are. It's work. It's relationships. It's hard. There isn't a magic number. They aren't inherently anticommercial. They don't all look or act the same.

That's one of the reasons I wrote this and am driven to write more: https://powazek.com/posts/3571

reshared this


isithran reshared this.


I slept very poorly last night due to the news that Musk gave privileged / possibly PII & DM level access of Twitter mod access to a variety of strident anti-LGBTQ (especially anti-trans) bigots who masquerade as journalists. This is an incident which would require user notification under California law, if it weren’t for the platform owner granting it. It still might be a violation of privacy laws. It’s absolutely a disaster for all LGBTQ people who used Twitter.

reshared this


isithran reshared this.


Content warning: News article on trans legislation in Scotland

reshared this



Got recognized in the street by somebody I either don't know or don't remembered 💀💀 0/10 won't recommend the associated feelings.
I wonder how famous people cope with this.


isithran reshared this.


In August 2011, Los Alamos techs posed 8 plutonium rods on a work table to take a few photos.

Had these rods rolled into each other there would have been an instant criticality event. (Think "Demon Core")

Worst still, a supervisor who saw the display ordered the techs to safe the rods, ignoring the protocol to evacuate EVERYBODY (b/c even a hand could moderate the neutrons & cause criticality).

It caused a 4-year, billion-dollar shutdown.

...

Smart people + overfamiliarity = stupid things.

reshared this



Deconstructing the myth of the Tatar Yoke - Marlies Bilz-Leonhardt
DOI: 10.1080/02634930802213916

isithran reshared this.


in the good timeline, GPT finally trains humanity to understand that someone who's eloquent is not therefore automatically trustworthy

reshared this



New bait & switch technique: fake options and close button cc @Deceptive Design


isithran reshared this.


The consistent increased risk of diabetes after Covid across all age groups, highest in the first 3 months after infection, from a systematic review of 9 studies, ~40 million people
https://bmcmedicine.biomedcentral.com/articles/10.1186/s12916-022-02656-y

reshared this



Transgender day of remembrance


For #TDoR2022, I'm having a thought for @lumi_enby@twitter.com who left us on Dec 31st, as well as all of us who didn't make it because of transphobia. We miss you.🕯️
#TransgenderDayOfRemembrance




Self hosted maston, now with network failover :3


Finally got rid of Google Authenticator (I'm using Aegis as a replacement). The transfer was a bit tedious, because you need to export up to 4~6 accounts each time with the QR code technique but it worked.


It's been 0 day(s) since MS Sharepoint applying an implicit limit of 100 results on list queries broke something in production.

isithran reshared this.


Watching the wild ride that is South Australia power network islanded and having too much uncontrollable power generation (solar). They are apparently tapping sub station transformers to beyond 253v to trip solar inverters.

isithran reshared this.


isithran reshared this.


This a small python script you can use to post from the command line.

Go to Preferences>Development and create a new application. Then grab the access token and put it in the script along with your instance name.

###
import requests as r
import sys
h="https://YOURINSTANCE"
t="YOURTOKEN"
a=sys.stdin.buffer.read().decode("utf-8")
d={"status":f"{a}"}
u=f"{h}/api/v1/statuses"
p=r.post(u,data=d,headers={'Authorization':f'Bearer {t}'})

###

Then just printf or echo your post and pipe into it

reshared this

in reply to netspooky :verified:

a couple of years ago I wrote a (partially complete) "Modbus Tweets" account on the bird site. Never finished it. Kinda wanna dust it off for Mastodon though. I was going to have one of my home's lights operable via @ and DM, just base64 encode a modbus request and get a base64-encoded response...
in reply to K. Reid Wightman :verified: 🌻

@reverseics that's such a sick idea. The twitter dev API is annoying because you need to apply to do an application and can get rejected (like me) for not having a good enough reason to have a token. There's a lot of potential for really easy automation with mastodon and enough access controls to make it work without as much hassle

isithran reshared this.


the misinfo knows what to inform you about because it knows what it isnt

isithran reshared this.