isithran reshared this.
Every company saying that their data is encrypted at rest with "strong encryption" is saying nothing. It's a free, effortless and shameless statement to boost the org's false security posture to the untrained masses. It's even worse when they say it to justify that their security was sufficient after a breach.
Encrypted data at rest just means they use the cloud. It's standard cloud practise. They give it basically for free at a button toggle. "Using military grade encryption" yes I know it's AES. That shouldn't make you feel any safer. Optus even said their unauthenticated API was protected by double layers of encryption! (TLS in transit and AES at rest!). That meant nothing, and did nothing to protect their breach. Why?
Because the threat models that encryption at rest protects against is someone walking into some data center and grabbing hard drives. And no one does that. Every piece of encrypted information stored by your business is constantly decrypted at some point for use - especially customer and production data. Any attacker who compromises your employees with access to cloud resources, or an application/system with access to those cloud resources will have credentials and permission to decrypt the data. Because at the end of the day encrypted data is just as useless to you as it is to the attacker.
Encrypted data at rest just means they use the cloud. It's standard cloud practise. They give it basically for free at a button toggle. "Using military grade encryption" yes I know it's AES. That shouldn't make you feel any safer. Optus even said their unauthenticated API was protected by double layers of encryption! (TLS in transit and AES at rest!). That meant nothing, and did nothing to protect their breach. Why?
Because the threat models that encryption at rest protects against is someone walking into some data center and grabbing hard drives. And no one does that. Every piece of encrypted information stored by your business is constantly decrypted at some point for use - especially customer and production data. Any attacker who compromises your employees with access to cloud resources, or an application/system with access to those cloud resources will have credentials and permission to decrypt the data. Because at the end of the day encrypted data is just as useless to you as it is to the attacker.
- "How obscure are your musical tastes?"
- "Well, today I found out I've got a full shelf of CDs the national library in charge of the mandatory deposit in my country does not even have in its database, which lead me to read back the law to ensure I wasn't liable to a hefty fine."
- "Well, today I found out I've got a full shelf of CDs the national library in charge of the mandatory deposit in my country does not even have in its database, which lead me to read back the law to ensure I wasn't liable to a hefty fine."
like this
in reply to isithran
tbf I share 99% of my library being online daily. But I still keep a few exclusive recordings which I know are either very rare to come by or shit I recorded from livesets from when I used to work as a sound engineer.
The rare records no one would actually be interested in, the live sets could easily be tied to me if they happend to leak on yt or something.
The rare records no one would actually be interested in, the live sets could easily be tied to me if they happend to leak on yt or something.
Blasting Cbat with the home theater rig made the periodic bed noises from upstairs that have been going on for more than an hour stop straight away.
I think the message has been received... 😈
I think the message has been received... 😈
[object Otter] :verified_paw: likes this.
isithran reshared this.
Note this is a choice some IT person made years ago and nobody realizes is optional, or something is actually broken and people just got used to it. Re-Auth could be entirely seamless if they wanted, or only enforced for certain apps. This is not intrinsic.
Something I see a lot is people accepting bad IT experiences as mandatory. Like this is life, get on with it. But this isn't remotely true.
It's a choice, sometimes just not a choice an organization realizes it has. I have to be the person calling bullshit on stuff because I know. Because I understand what's normal outside the org, or I have literally done their job before as an IT Generalist.
The business malaise in accepting deteriorated user experiences is frankly shocking.
You're being led like a dog by people who aren't being challenged to do better. Who often are not stupid and can do better, but have no mandate to venture it.
Something I see a lot is people accepting bad IT experiences as mandatory. Like this is life, get on with it. But this isn't remotely true.
It's a choice, sometimes just not a choice an organization realizes it has. I have to be the person calling bullshit on stuff because I know. Because I understand what's normal outside the org, or I have literally done their job before as an IT Generalist.
The business malaise in accepting deteriorated user experiences is frankly shocking.
You're being led like a dog by people who aren't being challenged to do better. Who often are not stupid and can do better, but have no mandate to venture it.
isithran likes this.
reshared this
A lot happened in 2022 (in a good sense as far as I'm concerned). A few rough times, but I got to make things moving 💜. Let's make 2023 even better ✨
Happy new year, and all the best to all of you 🎇
Happy new year, and all the best to all of you 🎇
like this
isithran reshared this.
Ah ! À partir de demain un 02 ne sera plus forcément un 02 #téléphone #arcep
« A partir du 1er janvier 2023, les contraintes géographiques des numéros 01 à 05 s’assouplissent. Concrètement, il sera possible de conserver son numéro de téléphone fixe, notamment en cas de déménagement, dans une autre zone géographique de France métropolitaine. »
https://www.arcep.fr/demarches-et-services/utilisateurs/degeographisation-des-numeros-de-01-a-05-ce-qui-change-au-1er-janvier-2023.html
« A partir du 1er janvier 2023, les contraintes géographiques des numéros 01 à 05 s’assouplissent. Concrètement, il sera possible de conserver son numéro de téléphone fixe, notamment en cas de déménagement, dans une autre zone géographique de France métropolitaine. »
https://www.arcep.fr/demarches-et-services/utilisateurs/degeographisation-des-numeros-de-01-a-05-ce-qui-change-au-1er-janvier-2023.html
reshared this
Tech test, nothing sensitive in that post
But do CW work with friendica if I'm posting from Tusky?
Tavi likes this.
TIL that friendica support CWs through ActivityPub, but hat not yet implemented support for posting with them
Tavi likes this.
isithran reshared this.
A very interesting take on the universe as seen from the perspective of the 2m amateur radio band by the #LOFAR radio telescope.
RT @cosmos4u@twitter.com
V-LoTSS, The Circularly-Polarised #LOFAR Two-metre Sky Survey: https://arxiv.org/abs/2212.09815 -> https://twitter.com/AstroJoeC/status/1605512117376778242
🐦🔗: https://twitter.com/cosmos4u/status/1605750235875131392
RT @cosmos4u@twitter.com
V-LoTSS, The Circularly-Polarised #LOFAR Two-metre Sky Survey: https://arxiv.org/abs/2212.09815 -> https://twitter.com/AstroJoeC/status/1605512117376778242
🐦🔗: https://twitter.com/cosmos4u/status/1605750235875131392
V-LoTSS: The Circularly-Polarised LOFAR Two-metre Sky Survey
We present the detection of 68 sources from the most sensitive radio survey in circular polarisation conducted to date.arXiv.org
Unknown parent
I was unable to pull the data wire, since the duct was obstructed, so I went the wireless way. Next step: attempting to switch telemetry from legacy to standard format.
in reply to isithran
j'avais évité ce truc car zéro intégration avec home-assistant et pas envie de bricoler... dommage ça semblais quand meme intéressant. enfin, 50€ pour ça ça reste quand même du vol.
isithran likes this.
isithran reshared this.
it's @spacegirl video day!
https://www.youtube.com/watch?v=gRSyRy-Yq-k
https://www.youtube.com/watch?v=gRSyRy-Yq-k
What is a relay?
Let's talk about how relays work, and how we can use them in basic circuits :)I scanned The Design of Switching Circuits and uploaded to the Internet Archive...YouTube
isithran reshared this.
isithran reshared this.
I think I found my next antenna. Need to find the real estate agent that has this listing!
https://www.youtube.com/watch?v=M9RxlUNIBBo
https://www.youtube.com/watch?v=M9RxlUNIBBo
Top Secret Abandoned Satellite Dish Found On A Mountain. Explore # 107
Top Secret Abandoned Satellite Dish Found On A Mountain. Explore # 107B.C. CanadaDoing some digging online I came across this top secret abandoned satellite ...YouTube
isithran reshared this.
In 1959, the IBM 1401 computer was built from boards called SMS cards. A single board might hold just 3 logic gates so the computer needed thousands of boards. Silicon transistors weren't popular yet, so they used germanium transistors. Source: https://www.righto.com/2021/03/germanium-transistors-logic-circuits-in.html #history #computing
Germanium transistors: logic circuits in the IBM 1401 computer
How did computers implement logic gates in the 1950s? Computers were moving into the transistor age, but transistors were expensive so cir...www.righto.com
isithran reshared this.
We have to deromanticize community. It's not some pristine untouched forest of soft moss and good vibes. The corporations count on that misconception to stripmine us for content.
Community has always been as weird and messy as humans are. It's work. It's relationships. It's hard. There isn't a magic number. They aren't inherently anticommercial. They don't all look or act the same.
That's one of the reasons I wrote this and am driven to write more: https://powazek.com/posts/3571
Community has always been as weird and messy as humans are. It's work. It's relationships. It's hard. There isn't a magic number. They aren't inherently anticommercial. They don't all look or act the same.
That's one of the reasons I wrote this and am driven to write more: https://powazek.com/posts/3571
A community isn’t a garden, it’s a bar.
It’s almost 2023. The world is different, the online world is very different, and I’m pushing 50. So I think it’s time we all start talking about online gathering places with a mo…Derek Powazek
reshared this
isithran reshared this.
I slept very poorly last night due to the news that Musk gave privileged / possibly PII & DM level access of Twitter mod access to a variety of strident anti-LGBTQ (especially anti-trans) bigots who masquerade as journalists. This is an incident which would require user notification under California law, if it weren’t for the platform owner granting it. It still might be a violation of privacy laws. It’s absolutely a disaster for all LGBTQ people who used Twitter.
reshared this
Got recognized in the street by somebody I either don't know or don't remembered 💀💀 0/10 won't recommend the associated feelings.
I wonder how famous people cope with this.
I wonder how famous people cope with this.
f4grx Sebastien (OLD ACCOUNT) likes this.
isithran reshared this.
In August 2011, Los Alamos techs posed 8 plutonium rods on a work table to take a few photos.
Had these rods rolled into each other there would have been an instant criticality event. (Think "Demon Core")
Worst still, a supervisor who saw the display ordered the techs to safe the rods, ignoring the protocol to evacuate EVERYBODY (b/c even a hand could moderate the neutrons & cause criticality).
It caused a 4-year, billion-dollar shutdown.
...
Smart people + overfamiliarity = stupid things.
Had these rods rolled into each other there would have been an instant criticality event. (Think "Demon Core")
Worst still, a supervisor who saw the display ordered the techs to safe the rods, ignoring the protocol to evacuate EVERYBODY (b/c even a hand could moderate the neutrons & cause criticality).
It caused a 4-year, billion-dollar shutdown.
...
Smart people + overfamiliarity = stupid things.
reshared this
isithran reshared this.
The consistent increased risk of diabetes after Covid across all age groups, highest in the first 3 months after infection, from a systematic review of 9 studies, ~40 million people
https://bmcmedicine.biomedcentral.com/articles/10.1186/s12916-022-02656-y
https://bmcmedicine.biomedcentral.com/articles/10.1186/s12916-022-02656-y
Risk for newly diagnosed diabetes after COVID-19: a systematic review and meta-analysis - BMC Medicine
Background There is growing evidence that patients recovering after a severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2) infection may have a variety of acute sequelae including newly diagnosed diabetes.BioMed Central
reshared this
Transgender day of remembrance
For #TDoR2022, I'm having a thought for @lumi_enby@twitter.com who left us on Dec 31st, as well as all of us who didn't make it because of transphobia. We miss you.🕯️
#TransgenderDayOfRemembrance
#TransgenderDayOfRemembrance
lomn likes this.
Finally got rid of Google Authenticator (I'm using Aegis as a replacement). The transfer was a bit tedious, because you need to export up to 4~6 accounts each time with the QR code technique but it worked.
lomn likes this.
isithran reshared this.
This a small python script you can use to post from the command line.
Go to Preferences>Development and create a new application. Then grab the access token and put it in the script along with your instance name.
###
import requests as r
import sys
h="https://YOURINSTANCE"
t="YOURTOKEN"
a=sys.stdin.buffer.read().decode("utf-8")
d={"status":f"{a}"}
u=f"{h}/api/v1/statuses"
p=r.post(u,data=d,headers={'Authorization':f'Bearer {t}'})
###
Then just printf or echo your post and pipe into it
Go to Preferences>Development and create a new application. Then grab the access token and put it in the script along with your instance name.
###
import requests as r
import sys
h="https://YOURINSTANCE"
t="YOURTOKEN"
a=sys.stdin.buffer.read().decode("utf-8")
d={"status":f"{a}"}
u=f"{h}/api/v1/statuses"
p=r.post(u,data=d,headers={'Authorization':f'Bearer {t}'})
###
Then just printf or echo your post and pipe into it
reshared this
in reply to netspooky :verified:
a couple of years ago I wrote a (partially complete) "Modbus Tweets" account on the bird site. Never finished it. Kinda wanna dust it off for Mastodon though. I was going to have one of my home's lights operable via @ and DM, just base64 encode a modbus request and get a base64-encoded response...
in reply to K. Reid Wightman :verified: 🌻
@reverseics that's such a sick idea. The twitter dev API is annoying because you need to apply to do an application and can get rejected (like me) for not having a good enough reason to have a token. There's a lot of potential for really easy automation with mastodon and enough access controls to make it work without as much hassle
isithran likes this.
Jeffrey Goldberg
in reply to h4sh • • •h4sh
in reply to Jeffrey Goldberg • • •Jeffrey Goldberg
in reply to h4sh • • •I get even more irritated when auditors and the like conflate that with what we do.
Cendyne
in reply to h4sh • • •