Skip Navigation
InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)SD
Posts 9
Comments 891
US senators propose mandated MFA, encryption in healthcare
  • Ya, I know that's exactly what's going to happen. But, you have to start somewhere. Just getting management used to the idea that data must be encrypted is a start. That will then push the software vendors in the space to make fundamental changes, which will hopefully improve things a bit.

    I actually have a pretty good example from my time in the US FedGov space. We were required (by our checkbox security) to enforce FIPS-140 compliance on all our systems. When working to setup a server for a new product, it just would not run with FIPS-140 in enforcement mode; so, I started digging into the product and found that they were still using the MD5 algorithm in their user password hashing process. Given how much the vendor really wanted our business (we were their "foot in the door" for more FedGov money), I sent an email to our customer service rep essentially saying "ya, MD5 as part of the password hashing is a deal breaker". A couple weeks later a new version of the product dropped and surprise, surprise, MD5 was no longer part of the password hashing process.

    The reliance on checkboxes sucks; but, they can be a useful club to make improvements. A shift to real security takes time and a lot of effort. But, that journey starts with a first step.

  • Why do you suppose _sour_ candies are so popular these days? It wasn't a market when I was a kid.
  • Similar age and ya, I remember sour packets being popular in middle school. Can't recall the name, but it was similar to the artificial sugar packets used for coffee, except it had a mixture of sugar and citric acid (the "sour" flavoring) in them.

  • US senators propose mandated MFA, encryption in healthcare
  • While I'm not a fan of checkbox security. Given that major parts of the healthcare industry don't even seem to get over that bar, maybe it's time to put something in place to give network defenders a lever to pull on to get the basics sorted.

    Not having MFA and encryption for data at rest should be treated as willful negligence when a company is breached.

  • Xbox killing avatars on PC, Xbox One, Xbox Series X/S
  • Good riddance. I understand the whole Mii thing got popular and Microsoft wanted to chase that wave. But, they were just such an obvious "me too" addition to the XBox 360 at the time and coincided with Microsoft changing out the functional XBox 360 main panel for the ad laden shit-fest that was the newer designs. But, maybe I'm just old and hate superfluous crap between me and playing my games.

  • China Wiretaps Americans in 'Worst Hack in Our Nation's History'
  • Threat actors used an existing backdoor in a communications system to intercept communications in that system? Color me whatever the opposite of "shocked" is. This is exactly the problem which was brought up by security researchers when the NSA was asking for a frontdoor which would let them break encryption. Thankfully, we held the line in that battle of the Crypto Wars. But, the war never ends and we need to make sure folks remember this clusterfuck the next time the NSA starts pushing to break encryption.

  • Vivek Ramaswamy's 'jackhammer and chain saw' plan to force federal workers back into the office
  • he said. “You don’t even have to talk about you’re in a mass firing, a mass exodus. Just tell them they have to come back five days a week from 8 a.m. to 6 p.m.”

    Even with a 1 hour lunch, 8am to 6pm would be a 9 hour work day. So, bro is expecting folks to just accept a 45 hour workweek along with a complete return to office. Pretty sure he's going to get his 25% reduction. It's just going to be all of the most talented people saying "fuck that".

  • Why do the English pronounce the first name "St. John" as "sinjin" but they pronounce the last name "Saintclair" as "saint clair" (and not "sinclair")?
  • It may be a case of laziness which has started creating a local dialect. This is one of the ways living languages change over time, people start sluring words and sounds together until there is almost nothing left of the original words and there is a new word in their place.

  • Windows Defender be like...
  • Na, my experience is that Defender is fine with users downloading browsers and "updates" from random Russian sites. It's happy to let the users install that software and only bothers to log a "hey, maybe this was bad" alert some time later. Edge, on the other hand, loses it's shit when you visit the official download sites for Chrome or FireFox.

  • Police officer tells court of failed attempts to disarm 95yo holding knife
  • The incident involved two knives. Here's a picture of them (from the linked article):

    The officer tased a 95-year old woman, who needed a walker to move about, because she was holding a steak knife.
    Ya, I get not wanted to get a bit of a ragged cut, but Jesus Zombie Christ, that situation sounds less threatening than a box full of kittens.

  • AI PCs flood the market. Their makers hope someone wants them; Despite 49% surge in shipments, buyers seem unconvinced.
  • I’m still hoping that the somewhat irrational anger towards “AI” stuff subsides

    I think this anger is linked to the irrational exuberance for "AI".

    Personally, I kinda hate AI. Not because of any sort of fear of job loss or anything like that. It's because "AI" has been rolled out heavily in the Cybersecurity space, making my work life hell because of it. Models are only as good as their training and this means that any AI model which is going to spot anomalies in a network needs to spend a good amount of time being trained. However, what the vendors sell are touted as unsupervised models. They just need to spend a while on your network and they can automagically learn what "normal" is and then alert you on "abnormal". This ignores the fact that you still need your analysts chasing false positives constantly from this black box. And that "black box" aspect is a major problem. You'll get an AI/ML based alert with exactly fuck all in detail on why the alert triggered. If you're lucky, you might get a couple log entries along with the alert, but nothing saying why those entries are suspicious.

    I will grant that, there are a few cases where the "AI" in a product has worked. Mostly, it's been in language processing. Heck, having an AI half-write a function for you in a tool you don't use very often is quite nice. You almost always need to rework the results a bit, but it can get you started. But, my first question for any vendor talking about "AI Detections" is "how do we tune false positives?". It's just too big of a headache. And most of them try to downplay the need or dodge the question. Or, you have to babysit the model, effectively making it a supervised model. Which, fine. Just stop telling me how much time it's going to save me, when I'm going to spend more time supervising the model than searching for threats in my environment. And, for fucks sake, design that shit to explain itself.

    As for putting AI in my system. I can see a use case for language processing. Heck, I'd love to have the Star Trek style, "hello computer..." type stuff actually work worth a damn. Google and Siri are pretty close, though even those can be shit on toast when trying to do anything slightly complex. And having all that done locally, without having to send data "to the cloud" sounds great for privacy and security (until MS adds a keylogger as part of the OS). But, given how much time my GPU sits at or very near idle, I do wonder if the extra chip is worth the silicon or space.

    In the end, I'm expecting this to go much the way TPM has. We'll all end up with it in our systems, whether or not we know, care or use it. All because manufacturers just start soldering it on to everything. Maybe someone will find a good use for it eventually, distributed AI porn, maybe? But, like a lot of AI, it seems like a solution in search of a problem.

  • What your coffee preparation method says about you
  • BLUF: It's been a mixed bag, but I would call it "worth it".

    I've used Ubuntu a bit before. That's what my home server runs on and has for years. Granted, most of it's functions live in Docker containers. I also used both Debian (via Kali) and Ubuntu at work (yes, I know Ubuntu is Debian based, but it's also big enough to have it's own dedicated ecosystem). I work in Cybersecurity and use Linux based tools for image acquisition, digital forensics and data recovery. Kali makes for a great "it just works" system to validate vulnerabilities and poke at a network. And, between a lot of tools targeting Ubuntu and frameworks like SANS SIFT, Ubuntu gets used a lot. I also supported several Red Hat based servers at work for various tools. I'm far from an expert on Linux, but I can usually hold my own.

    In a lot of ways, Arch wasn't an obvious choice for me. And I seriously considered going with Ubuntu (or another Debian based OS (e.g. PopOS)) at first. It's worth mentioning that my primary use for my desktop is video games. So, that heavily effected my choices. That said, the reasons for choosing Arch ended up being:

    1. I have a SteamDeck and most of my games "just work" on it. With Arch being the flavor of Linux Valve is targeting, following their lead seemed like a good idea. I expected that a lot of effort to get games working on "Linux" would ultimately be focused on getting games working on Arch.
    2. I wanted a "minimal" system. I can be a bit of a control freak and privacy nut. I already self-host NextCloud, because I don't want my pictures/data sitting on someone else's computer. So, the "install only what you need" nature of Arch was appealing.
    3. I did do some testing of Ubuntu on my system and had driver issues (nVidia GPU) and some other problems I didn't put the time into running down. In the end, it put me off Linux for a while before I came back to it and ran Arch.

    One of the things I did, which was really helpful, was a "try before you buy" setup. I was coming from Windows 10. And, as mentioned above, gaming was my main use case. So, that had to work for me to make the jump. Otherwise, I was going to milk Windows 10 for as long as possible and then figure things out when it went EOS. So, I installed Arch on a USB 3.0 thumbdrive and left my Windows OS partition alone. I also mounted my "Games" drive (M.2 SSD) and installed games to that. It was still NTFS, but that only created minor bumps in the road. Running that configuration for a couple months proved out that Arch was going to work for me.

    When it came time to fully change over, I formatted my Windows OS partition as ext4, setup the correct folder structure and rsync'd everything from the thumbdrive to it. So, everything was the way I'd had it for those couple months. I did have an issue that my BIOS refused to see the OS partition on the SATA SSD I used for my OS partition; but, that was MSI's fault (I have an MSI motherboard). And that was resolved by changing where GRUB is located in my /boot partition.

    Overall, I've been happy with the choice I made. Arch hasn't always been easy. Even the Official Install Guide seems to come from a RTFM perspective. But, if you're willing to put the time into it, you will learn a lot or you won't have a functional system. And you'll end up with a system where you can fire up a packet capture and have a really good idea of what each and every packet is about. As for gaming, so far I've had exactly one game which didn't run on Linux. That was Call of Duty 6, which I was considering giving a go to play with some folks I know. But, Activision's Anti-Cheat software is a hard "no" on Linux. So, I had to pass on that. Otherwise, every game I have wanted to play either had native Linux support or worked via Proton/WINE.

  • Swords suck, spears are a way more effective weapon
  • You only get a short time with the pointy end of the spear and then once a sword wielder is inside your range, you’ve got an unwieldy stick and they have a sword. Good for stand off melee maybe but prob not.

    Yes, but getting in close without getting stabbed is really hard.
    Here's an actual example of modern HEMA folks giving it a lot of goes:
    https://www.youtube.com/watch?v=uLLv8E2pWdk

  • Firefox for Android Private Browsing and gmail

    I recently used Firefox Nightly on my Android device, in a private tab, to login to gmail. After I closed the browser, both via the "quit" menu icon and via swiping the Firefox away in the Overview, I had expected the session information to be deleted and the next time I came back to gmail via a private tab, to be required to login again. However, this was not the case. Despite closing out the browser, something seems to have survived and the I was immediately logged back into the gmail session.

    Is this some sort of expected behavior? Shouldn't closing out the browser delete all session information from a private tab? Is there something I missed that maybe I'm not actually "closing" the browser?

    3

    Horribly inefficient party favors

    My daughter wanted a "Gorilla Tag" birthday. And my wife wanted me to print some party favors for the guest kids. Not my model, but they are churning out ok-ish.

    13

    Display cabling choice

    I'm currently purchasing a new GPU and specifically settled on the MSI 4070 Super. I'm all set for everything except connecting the display to the card.

    Currently, the display I have (which isn't being upgraded for now) only has two input options: DVI and VGA. The new GPU only provides HDMI or Display Port. This isn't really a problem as adapters/cables exist to go from Display Port/HDMI to DVI-D.

    But, the question I have is, which is the better option, or does it make any difference? And, are there any "gotchas" I should watch out for when buying the cable?

    I realize that I am likely over-thinking this, but I would rather ask a stupid question than make a stupid mistake.

    5

    Controller aim speed

    Just got started with this game (PC - Steam version). It's fun so far. I had really wanted to use my controller. But, the aiming movement is so sluggish. I've tried pushing the "Aim Sensitivity" up to 10, but still felt like I was turning through molasses. Is there anything which can be done to speed that up, or is the controller just fundamentally slow on PC?

    Using an Xbox controller via Bluetooth. And the issue isn't lag, it's the rotation speed in game.

    6
    apnews.com Virginia lawmakers pass long-overdue budget bill with tax rebates, extra aid for schools

    The politically divided Virginia General Assembly has approved long-overdue budget legislation, sending it to Republican Gov. Glenn Youngkin.

    Virginia lawmakers pass long-overdue budget bill with tax rebates, extra aid for schools

    The politically divided Virginia General Assembly approved long-overdue budget legislation Wednesday, voting in an unusually fast-paced special session to both reduce taxes and boost spending on public education and mental health as part of the package.

    0

    GETTING THERE: VRE adjusting in post-pandemic world

    The free Friday ride program seems to be having the impact the Virginia Railway Express wanted when the commuter rail system decided to offer it earlier this year.

    The program started on June 2 and will run through Sept. 1. The aim is to draw new and non-traditional riders to take train trips north and back home.

    So far, the program has increased average daily rider trips for those Fridays by around 40%, from about 3,500 to 5,000

    1

    Live Stream of Virgin Galactic Launch: Galactic 01 (1500 UTC)

    Virgin Galactic will be launching their first commercial, sub-orbital space flight today. Link is to the Live Stream for the event.

    0
    apnews.com Mother of 6-year-old who shot teacher pleads guilty to using marijuana while having a firearm

    The mother of a 6-year-old Virginia boy who shot and wounded his teacher in Virginia has pleaded guilty to a federal charge of using marijuana while possessing a firearm. It’s a crime under federal law that’s facing increasing scrutiny as more states legalize the drug. Deja Taylor is accused of lyin...

    1
    PowerShell @lemmy.world sylver_dragon @lemmy.world

    What have you done with PowerShell this month?

    As a way to kick off migration from Reddit to Lemmy, let's start with a classic thread. So, what have you done with PowerShell this month?

    For bonus imaginary points, have you done anything in regards to the Great Reddit Migration?

    6