Quick tip. If you're trying to download really old versions of macOS, they're hard to find (e.g., El Capitan, etc.). You can find lots of dodgy sites that you don't want to deal with, but it's hard to find legit Apple web sites. The trick is to search for "enterprise". Then you can find pages like this, which has a legit link to an Apple DMG. support.apple.com/en-us/HT2068

One of the more obscure and least understood principles is "psychological acceptability." Nobody spends any time on it. Just google a phrase and see that everyone plagiarizes everyone else. Search for "principle that aims at maximizing the usage and adoption of the security functionality"

@zenhack I hear ya. Been running my own server since 1996. It gets harder and harder. An SMTP server is a house of cards. One daemon stops or one config is wrong and everything falls apart. I’m still hanging in there. But I hear ya.

Simply put, #BlackLivesMatter more than #infosec or all the other things I usually toot about. I did a little bit this weekend to help. Trump sent me $2500 I didn't need in the CARES Act. I've given every last cent of it to people he wouldn't have given it to, and who need it more than I do. blog.paco.to/2020/black-lives-

I have just used "Why is Gamora" to answer a customer question about TLS certificates. That's probably the high point of my week. :)

@nspanti @angristan What's the argument: no one should use CDNs because CDN providers can lie and surveil traffic when they say they don't?

Some people might call this "parody". In my world, it's a bit more like "Tuesday". youtube.com/watch?v=JMOOG7rWTP

@WPalant I just saw this reply. But I answered it in my post. It's one EC2 instance at AWS. The IP range it comes from is a /14 range (250K IPs). I own 1 IP address from Amazon and outlook.com has no way to verify that. They did eventually get back to me after a week. They put in a mitigation. But when you're the little guy, life is hard. I only have 20 users or so.

I had a non-delivery notification from my personal mail server to outlook.com. It said "your ISP's network is on our block list.' My ISP is AWS and the network is a /14. It's bonkers.

It's like living in a 500-unit apartment complex and a company says "unit 402 didn't pay for their purchases last month, so we're not selling anything to anyone in that complex any more."

Green text, meet red text. Red text, meet green text. Now that you guys are acquainted, would you like to go off, have a little chat, and come back to me with a USEFUL error message?

If you have some spare compute cycles and you want to donate them to fighting , there's a medical research programme called "Folding@Home" which is similar to SETI@Home, but for medical research: foldingathome.org/2020/03/15/c

@jjbaumgartner yeah I’ll just add another protocol where we disagree. There’s no need to slice and dice and imagine that things unsaid are implied in the worst possible way. Even NIST recanted it’s recommendation to change passwords for government and enterprises. Do some research on it. It was never founded in anything. Someone just sorta made it up and it stuck. There is not a lot of justification for it.

@ebel I feel your pain. After 10 years living in Europe I moved back to the US. It's infuriating. Makes me want to get European cookbooks / recipe books. It'll all be in millilitres and sane units.

I see a lot of articles say things like "They now run this service in the cloud—which brings its own set of security challenges." I wish they would equivalently write "They run their IT in their own data centres—which brings its own set of security challenges."

DIY infrastructure? Oh that's obviously secure. Professionally-run commercial clouds? Whoa, they're risky.

