Remote
Dan Kaminsky once said I know how computers work.
248
Followers
27
Following
50
Posts
Joined January 23, 2023
Pronouns:
he/him
Posts
Replying to
@xrobau@mastodon.au
@xrobau@mastodon.au @LapTop006@aus.social SATA SSDs are unlikely to be fast enough to make good cache vdevs. I’d skip it unless you check your ARC stats and have less than a 99.5% hit rate.
https://infosec.exchange/@bob_zim/115465564078061185
And using a single SATA SSD for both cache and log at the same time will definitely hurt performance compared to just using the capacity devices.
A special vdev is more likely to improve performance, but it’s also risky, as it contains the filesystem structure itself (lose the special vdev, and you lose the tree telling the OS what data is where).
Open post
Replying to
@Dss@infosec.exchange
@Dss@infosec.exchange @briankrebs@infosec.exchange They should have taken even the barest of steps towards securing an environment. Telling the software not to misbehave isn’t a security control. Don’t use default credentials. Don’t allow untrusted software currently under test to access a network at all. Maybe take a look at the environment of the software under test more often than once a week. The flagrant disregard for the most basic security practices means either they’re either idiots or hucksters. I don’t see a third option.
And to claim “We didn’t know this thing we built would go out and do felonies on behalf of our company”? Really? Then why did they give it the capability to do that?
0
1
0
0
Open post
Replying to
@Osteopenia_Powers@newsie.social
@Osteopenia_Powers@newsie.social @jcrabapple@dmv.community TPMS isn’t actually Bluetooth, it’s an unencrypted wireless protocol on either 315 MHz or 433 MHz, depending on locale. The lack of encryption is part of the problem, as each sensor broadcasts a probably-unique identifier. Bluetooth is much more private, though still usually identifiable.
12
1
2
0
Open post
Replying to
@briankrebs@infosec.exchange
@briankrebs@infosec.exchange Is there independent confirmation of any of this, or is it all just from OpenAI (known lying liars who lie) and Hugging Face (whose entire business depends on hype from OpenAI and its ilk)?
If it’s true, both OpenAI and Hugging Face come off as blitheringly incompetent, top to bottom.
18
1
2
0
Open post
Replying to
@helediron@techhub.social
@helediron@techhub.social Intel has their enterprise drive controllers set themselves to read-only when they hit the rated endurance. All the other brands which fab their own flash last *much* longer than their rated lifespans. Flash does wear out eventually, but you have to *really try* to get there.
0
0
0
0
Open post
Replying to
@alice@lgbtqia.space
@alice@lgbtqia.space @mycrowgirl@flipping.rocks Reminds me of a great shirt design I got from Woot years ago, before Amazon bought them.
https://shirt.woot.com/offers/bats
0
0
0
0
Open post
Replying to
@GossiTheDog@cyberplace.social
@GossiTheDog@cyberplace.social “At least 12 states are affected!”
Wow. Sounds bad. Which ones?
“Not telling!”
0
0
0
0
Open post
Replying to
@bob_zim@infosec.exchange
@wbud@tech.lgbt On the topic of a credit card for emergencies, be sure to set it up to pay for some regular bill, like a streaming TV service or something. If a card goes too long without a charge on it, the issuer sometimes closes the account rather abruptly. The company which issued my first credit card closed the account (tanking the average age of my credit lines) with no notice just as I was applying for mortgages. It sucked so much.
0
0
0
0
Open post
Replying to
@wbud@tech.lgbt
@wbud@tech.lgbt Several years ago, US payment processors did what was called the “liability shift”. The networks now largely disclaim liability for fraud via magstripe-only transactions as a way to push the long tail of stores which accept credit cards to update to EMV-capable terminals. That tail is *really long*, though.
I personally have paid for things exclusively with NFC via phone or watch for the last few years, but I live in a pretty big city. The more rural you get, the more likely you are to run into a store with an older terminal. I would keep at least one emergency use card with a magstripe, but I would feel comfortable removing the stripe from my primary card.
0
1
0
0
Open post
Replying to
@wbud@tech.lgbt
@wbud@tech.lgbt @alice@lgbtqia.space @deviantollam@defcon.social On the payment processor side, the type of card data capture is part of the transaction. The technical capability exists at the payment network level to say, for example, a typed-numbers transaction is limited to $10, a magstripe transaction is limited to $20 (the stripe has more data than just the card numbers), a tap is limited to $50, a chip-without-PIN is limited to $100, and a chip-with-PIN has no limit.
Whether the bank actually does anything with that technical capability or not is up to the bank. Worth asking them, though.
0
0
0
0
Open post
Replying to
@taedryn@anarres.family
@taedryn@anarres.family @foolishowl@social.coop @gwynnion@mastodon.social Exactly. I’ve personally seen a lot of datacenters, and I’ve never seen one which employs even 50 people full-time per square kilometer.
Historically, economic engines like factories took in a lot of money, but also paid out to a lot of people. They diffuse money. Never perfectly, but you could honestly say a new factory would bring employment and thence income to the local populace. Offices, too.
Datacenters pay out dramatically more to dramatically fewer destinations (most of which are big companies). They concentrate money. The “business real estate good!” mentality largely hasn’t noticed this difference.
0
1
0
0
Open post
Replying to
@younata@hachyderm.io
@younata@hachyderm.io Check out the developer tools like ViewFrame. You could see on the device how the interface of most applications was built, and NewtonScript was a really nice language for building them.
0
0
0
0
Open post
Replying to
@farooqkz@mastodon.bsd.cafe
@farooqkz@mastodon.bsd.cafe @iogrt@functional.cafe Nushell is a lot like PowerShell. It passes around real data structures, not just blobs of text you have to parse. Very pleasant overall.
1
1
0
0
Open post
Replying to
@huronbikes@cyberplace.social
@huronbikes@cyberplace.social @GossiTheDog@cyberplace.social That’s more-or-less what “hyperconverged” is, yes: a bunch of physical servers which provide both compute and storage. The networking is still usually separate, and usually Ethernet rather than a real high-performance interconnect.
0
0
0
0
Open post
Replying to
@thomasfuchs@hachyderm.io
@thomasfuchs@hachyderm.io @molly0xfff@hachyderm.io Did you mean AirsPod Pro?
0
2
1
0
Open post
Replying to
@catsalad@infosec.exchange
0
0
0
0
Open post
Replying to
@GossiTheDog@cyberplace.social
@GossiTheDog@cyberplace.social Well if they aren’t supplying the public grid, they can just be built *outside* the environment. And for convenience, that oil tanker was already towed there!
1
0
1
0
Open post
Replying to
@mrgrumpymonkey@mastodon.social
@mrgrumpymonkey@mastodon.social @aces_funhouse@kinkycats.org @AltAfterDark@masto.thefword.club They’ll be too busy thinking about power genitalia?
0
0
0
0
Open post
Replying to
@mrgrumpymonkey@mastodon.social
@mrgrumpymonkey@mastodon.social @aces_funhouse@kinkycats.org @AltAfterDark@masto.thefword.club For example, consider some of the more famous misreadable domain names: #americanScrapMetal #anAlbumCover #bitefArtCafe #chooseSpain #expertsExchange #moleStationNursery #penIsland #powergenItalia #speedOfArt #teachersTalking #therapistFinder #whoRepresents
VoiceOver on iOS reads all of those perfectly. Without the uppercase letters giving it hints, it gets some of them hilariously wrong.
0
2
0
0
Open post
Replying to
@evaw@mastodon.world
@evaw@mastodon.world @Linebyline@mastoart.social @futurebird@sauropods.win Even if those experimental results are verified (still up in the air), it’s unlikely it can be scaled up to pump more than a few microjoules. Quantum effects are notoriously difficult to maintain at useful scales.
0
0
0
0
Open post
Replying to
@engelke@hachyderm.io
@engelke@hachyderm.io @violenteastcoastcity@mastodon.social Also note the GMRS license covers immediate family members, so you probably only need one.
0
0
0
0
Open post
Replying to
@cynblogger@sfba.social
@cynblogger@sfba.social @violenteastcoastcity@mastodon.social Most acoustic tube headsets have either a throat mic (for reliability in noisy environments) or a remote mic commonly mounted at the wrist (for not obviously looking like you have a radio).
0
0
0
0
Open post
Replying to
@SteveBellovin@infosec.exchange
@SteveBellovin@infosec.exchange @mattblaze@federate.social @20002ist@thepit.social “No, it’s either/or.”
0
0
0
0
Open post
Replying to
@ocnurb@woof.group
@ocnurb@woof.group @rrb@infosec.exchange And note most SSDs have two levels of secure erase.
One takes a few microseconds to flush the key used to encrypt the data on the flash. This is secure unless the SSD vendor lies, but it leaves the data in place, so pages still need to be erased before they can be written. This is what phone wipes do, but desktop SSDs can typically do it, too.
The other type uses dedicated circuitry in the flash chips to set all the pages (including faulty pages and spare pages) back to a neutral state. This takes several seconds and more power, but it restores out-of-the-box performance. This is common on desktop SSDs.
4
1
0
0
Open post
Replying to
on toot.wales
@gilesgoat@toot.wales @RobeeShepherd@mastodon.art Not quite. There are three main distinguishing characteristics:
• The elements change length significantly - a Yagi-Uda’s elements are all almost the same length
• The elements are all connected - in a Yagi-Uda, the driven elements are connected to the feed, but the reflector and director elements are electrically isolated
• The alternating directions of the elements - Yagi-Uda antennas are symmetrical across the antenna’s axis
Log-periodic antennas change element length dramatically over the length of the antenna, the elements are connected into two groups, and the groups alternate with each element (core-up-shield-down, core-down-shield-up).
0
0
0
0
Open post
Replying to
@evaw@mastodon.world
@evaw@mastodon.world @futurebird@sauropods.win Ish. Space doesn’t impart new heat, but vacuum is *strongly* insulating, so it’s ridiculously hard to dump the heat you have. And the sun imparts a ton of new heat.
0
0
0
0
Open post
Replying to
@joshbuddy@sfba.social
@joshbuddy@sfba.social @ainmosni@social.ainmosni.eu @tante@tldr.nettime.org @toriver@mas.to @ErikJonker@mastodon.social Exactly my point. Perfect enforcement is almost always wildly wasteful.
As long as you don’t expect it, you can make useful rules about the behavior you want to see or not, give moderators discretion to act on those rules, and audit the moderator actions to ensure they aren’t using the rules to harass people.
0
0
0
0
Open post
Replying to
@joshbuddy@sfba.social
@joshbuddy@sfba.social @ainmosni@social.ainmosni.eu @tante@tldr.nettime.org @toriver@mas.to @ErikJonker@mastodon.social That’s not really a difference, though. Certainly not a meaningful one. For-profit businesses love wildly inefficient rules, too. At my current job, I had to figure out which are our approved vendors, get quotes from three of them, and spend tens of hours filing paperwork to get approval to buy a $20 thumb drive to reimage a failed server. Took months.
0
1
0
0
Open post
Replying to
@joshbuddy@sfba.social
@joshbuddy@sfba.social @ainmosni@social.ainmosni.eu @tante@tldr.nettime.org @toriver@mas.to @ErikJonker@mastodon.social Not sure about other countries, but the US is composed almost entirely of rules which cost far more to enforce than they save. New York City spent tens of millions on cops to fight tens of thousands of dollars of fare evasion (e.g, turnstile hopping) for the subways. San Francisco routinely spends tens of millions of dollars on cops to harass unhoused people and throw their stuff away, when it would cost less than a tenth of that to simply pay for apartments and social workers for all of them.
In this case, the rule isn’t meant to be perfectly enforced.
0
1
0
0
Open post
Replying to
@ricci@discuss.systems
@ricci@discuss.systems So making changes to something without regard for the identity of who might be affected doesn’t count as involving human subjects? Does that mean the Stanford IRB think the Tylenol murders were victimless?
0
0
0
0
Open post
Replying to
@DrHyde@fosstodon.org
@DrHyde@fosstodon.org @drahardja@sfba.social Yeah, but it feels like the result you would get from somebody arguing that has to be supported when defining the standard.
0
0
0
0
Open post
Replying to
@DrHyde@fosstodon.org
@DrHyde@fosstodon.org @drahardja@sfba.social It feels like it was meant to allow the charger network to push updates to the car, like how cable companies can push updates to cable modems even if the cable company doesn’t own the modem.
0
1
0
0
Open post
Replying to
@drahardja@sfba.social
@drahardja@sfba.social Yeah, I posted about this on the dead bird site about a decade ago, though I was more curious about ransomware spreading from charger to car and artificially limiting range.
Got *so many* replies from people who didn’t have the first idea how car charging connections work. Ed Zitron basically called me an idiot and started a pile-on, which was “fun”.
0
0
0
0
Open post
Replying to
@miclgael@hachyderm.io
@miclgael@hachyderm.io If your threat model doesn’t include insiders at the company impersonating you to gain access to your account, sure! And it’s reasonable for that not to be in most threat models.
It’s in my threat models for my banks, though.
0
0
0
0
Open post
Replying to
@miclgael@hachyderm.io
@miclgael@hachyderm.io Ultimately, passkeys (and WebAuthn more generally) is asymmetric authentication versus symmetric authentication.
Passphrases are passed in the clear—usually over an encrypted transport, but the clear passphrase hits the memory of every service on the path to the authentication service. The authentication service then hashes it and confirms if it matches the stored hash. The clear passphrase can be logged by any of these services, and this has happened many times at some major companies like Google.
TOTP and similar no longer passes a clear value, so the webserver may not be able to log your secret, but the authentication service which approves or rejects the codes still has a clear secret in its memory. Fewer places to check for logging, but it’s still possible.
With asymmetric authentication, the server never gets secret data. Nothing on that end can possibly log anything which could be used to impersonate you. Though most of the time, this authentication is used to generate a symmetric token stored in a cookie, so cookie stealing or forgery is still potentially a risk.
0
1
0
0
Open post
Two of my banks recently implemented #passkeys, and the contrast between them is stark.
I went to log in to one and they wouldn’t let me in until I “verified my identity” using a text message code to a phone number they apparently got from some data broker or by uploading my government ID and a video (obviously not happening). When I eventually got their support to let me in, the site forced passkey setup with no options at all. There’s no way to set up more than one passkey, no way to revoke access from the one I set up, and no way to log in via password anymore. They made every single decision in the most incorrect way possible. Utter garbage. Unfortunately, they’re the only option available to me for the particular account I have, so I’m stuck with them.
Meanwhile, Wealthfront reopened a support ticket I filed years ago requesting passkey support to let me know they had added it. I logged in with a password, and the site offered to set up a passkey. In my user profile’s authentication page, there’s a section listing all my passkeys (and app-specific password names, etc.). It allows me to specify friendly names to track which is which, add more, and remove keys I no longer control. It’s pretty much perfect!
#passkey #webauthn
0
0
0
0
Open post
Replying to
@filippo@abyssdomain.expert
@filippo@abyssdomain.expert That all sounds very reasonable. Some site operators have implemented passkeys alarmingly poorly, I suspect due to a lack of understanding of how sites should handle the public key. Explicitly treating them just like credentials people already know how to store should help clarify it.
3
0
0
0
Open post
Replying to
@obot50549535@left-bank.net
@obot50549535@left-bank.net @jmax@mastodon.social @Natasha_Jay@tech.lgbt Exactly right. They (and many cats) also use their tails to maintain stability when turning aggressively. It’s particularly visible in videos of cheetahs chasing prey.
0
0
1
0
Open post
Replying to
@Affekt@hachyderm.io
@Affekt@hachyderm.io @ApostateEnglishman@mastodon.world @stux@mstdn.social Laser safety glasses are expensive, but they’re a lot cheaper than new eyes.
Geared tripod heads, high-magnification spotter scopes, and spotter scope mounts aren’t terribly expensive, but you get parallax over distance.
Dichroic mirrors and mounting systems to let you eliminate parallax are expensive, but then you can use a common CO2 bench laser.
2
0
1
0
Open post
Replying to
@piebob@metasocial.com
@piebob@metasocial.com @foolishowl@social.coop If anything, “abolish ICE” is too wishy-washy centrist! *Prosecute* ICE! Everyone who has ever received any money from the agency. Everyone from another agency who has ever consulted for them. Every cop who has ever been at the site of an ICE action without arresting them.
0
0
0
0
Open post
Replying to
@bob_zim@infosec.exchange
@SpaceLifeForm@infosec.exchange @cR0w@infosec.exchange Turns out I’m wrong! There are purely post-quantum key exchange methods, but they’re not recommended. The point of hybrid exchanges is even if learning with errors (the problem underpinning module lattices in PQC; like the discrete log problem for RSA) is easier to solve than we think (and we’re pretty sure it isn’t), they’re still no weaker than Curve25519.
0
0
0
0
Open post
Replying to
@SpaceLifeForm@infosec.exchange
@SpaceLifeForm@infosec.exchange @cR0w@infosec.exchange All the post-quantum TLS key exchange methods I’m familiar with are also hybrid exchanges using module lattice encapsulation of ECC keys. For example, 0x6399 (X25519Kyber768Draft00) and 0x11ec (X25519MLKEM768; new name after Kyber was selected by NIST to become ML-KEM).
It’s possible to use module lattice encapsulation with RSA or DSA, but I don’t think anybody bothers.
2
1
0
0
Open post
Replying to
@cR0w@infosec.exchange
@cR0w@infosec.exchange The concern is somebody who records the session negotiation might, at some future date, be able to crack it and learn the hard-coded password on every single morphine pump or whatever.
Because medical and OT manufacturers all absolutely use hard-coded passwords.
0
0
0
0
Open post
Replying to
@SpaceLifeForm@infosec.exchange
@SpaceLifeForm@infosec.exchange @cR0w@infosec.exchange ECC is a mandatory part of all of the post-quantum key exchange methods OpenSSH offers. sntrup761x25519 uses Streamlined NTRU with Curve 25519. mlkem768x25519 uses ML-KEM and Curve 25519.
2
1
1
0
Open post
Replying to
@lcamtuf@infosec.exchange
@lcamtuf@infosec.exchange That looks like plumbing for radiant heating?
0
0
0
0
Open post
Replying to
@h3mmy@lgbtqia.space
@h3mmy@lgbtqia.space A friend routinely brings up how irritating it is that she can’t get refills of her ADD meds. Instead, the doctor gives her multiple paper prescriptions, and they won’t write another if she loses one. So to get her medication which helps her not forget things, she must absolutely not forget or lose several small, easily-lost things.
0
0
0
0
Open post
Replying to
@cainmark@mstdn.social
@cainmark@mstdn.social Tell her those three words every woman longs to hear!
http://www.smbc-comics.com/?id=3517
0
0
0
0
Open post
Replying to
@glaskows@mastodon.gamedev.place
@glaskows@mastodon.gamedev.place @alice@lgbtqia.space To be clear, I have nothing to do with the project, I’ve just been aware of it for some time. Fundamentally like vibration in game controllers, but potentially with more actuators or different capabilities of those actuators.
0
0
0
0
Open post
Replying to
@glaskows@mastodon.gamedev.place
@glaskows@mastodon.gamedev.place @alice@lgbtqia.space Not enormously difficult.
https://buttplug.io/
0
1
0
0
Open post
Replying to
@btdorn@infosec.exchange
@btdorn@infosec.exchange @heygarrett@social.lol The idea is to shield the fan motor (and blades, etc.) from the gunk you’re removing from the air. If the fan is pushing air (fan before filters), the motor is on the dirty side. If it’s pulling air (filters before fan), the motor is on the clean side.
0
0
0
0
Remote instance
infosec.exchange
Open on original server