Paco Hope boosted

IDEA ABOUT SOCIAL MEDIA REFUGEES:

We might help these refugees feel more welcome by leveraging the psychology. Comment, boost their stuff for a few weeks, so that the dopamine levels don't drop as low. After a while, ease off and condition them to the calmer way of Mastodon/Pleroma.

This way, their brain might tell them "This is more fun than XYZ" and start recommending!

I disable location services most of the time and disable background app execution all the time. Is it any wonder why?

Someone actually modified our internal ticketing system to offer the option of seeing random cats or dogs instead of staff members' employee photos. It's awesome.

Oh, man. The 2000s called and they want their integer overflow bugs back.

"unprivileged users with UID > INT_MAX can successfully execute any systemctl command"

github.com/systemd/systemd/iss

When—in 2018—I find a CV written in , I think "here's a geek." Only a PhD considers doing a commercial CV in LaTeX.

I have to admit, once I got and running in my account, I just had to Log All The Things. Got some great ability to analyse out of it.

I’ll be honest: the value prop on CloudWatch is really poor. I was spending more per day on it that to run just an ELK instance sufficient to my needs. But I can also see the slippery slope. Once you get a bit of facility with Kibana you want to Log All The Things! And that gets expensive

Despite my router being annoying, I managed to get running on in looking at my on-prem network. github.com/robcowart/elastiflo

I love my miktotik router for the capabilities it has at its price point. But it’s doing something annoying that is driving me crazy.

If you’re in in , I hope the monthly dc4420.org/ meet up is in your diary. Definitely worth it when I can make it.

When I read a report like this on the deceptive design practices, the constant nagging for location access, etc. I sorta shrug. It's obvious to me. But then I have to ask WHY do we allow this? We, who know better, don't advocate on behalf of those who don't know better. How do we fight this business model? How do we fight and prevent this being the norm? forbrukerradet.no/side/google-

@feld If you're interested in virtualisation and side-channel attacks and all, you're probably interested in Firecracker too. Just announced yesterday: aws.amazon.com/blogs/aws/firec

For those of you interested in , you no longer need to go to the FUD and magic 1U box shows on the US West Coast. has announced its own security conference "Re:Inforce". First one will be in the end of June 2019 in Boston. aws.amazon.com/blogs/security/

If you find an absolutist who thinks dogmatic things, point them to this twitter exchange between a math prof talking about abstract cylinders in calculus, and a cat food company who has to manufacture cans of cat food and sell them

twitter.com/mathematicsprof/st.

Paco Hope boosted

"Infosec/IT Black Friday/Cyber Monday 2018"

pastebin.com/aLBfQT6H
Thanks to @oscaron@tiwtter.com

Are there any other deals people shouldn't miss?

So much of IT law hinges on dirt. The dirt that is under the rack that holds the hard disks determines what law applies to the data held by the hard disks and to the owner of the data held on the hard disks.

If you're trying to do digital in the on , there's a really good PDF on this web page that lays out high level principles. aws.amazon.com/mp/scenarios/se. It's also worth it to go take a look at threatresponse.cloud/ for a lot of free tools.

Gotta admit this script was useful. I had a couple big pig memory programs on an ubuntu linux instance. This listed all the running processes and how much RAM they were using. Totally fingered the culprit and made my life easier.
zyxware.com/articles/4446/show

If the possibility public buckets kept you awake at night (despite all the blogs and code that's been released to prevent/manage them), you finally have a single, account-wide kill switch. aws.amazon.com/blogs/aws/amazo

Show more
Infosec Exchange

A Mastodon instance for info/cyber security-minded people.