New boss -> ex-boss.
No wonder he didn't last long. Far too inquisitive.
BOFH logo telephone with devil's horns "Well that's serious!" I say to the Boss, once he's finished reporting the serious breach of IT policy. "Yes, I thought I should pass it onto you when I heard about it." "Oh yes," the PFY nods, "We need to keep on top of this sort of thing before it gets out of hand!" "And there's the …
As one who once (and only once) forgot to use gloves and didn't wash his† hands adequately after processing some rather hot chillis before taking a slash, just the mention of said enema brings tears to the eyes. († "His" advisedly; "her" doesn't bear thinking about.)
Doubtless it would be exceptionally effective when not actually fatal,
The difference between a chemist and a physicist is that a chemist washes his hands before using a toilet, the physicist after.
This is exactly why I am always extremely careful about using rubber gloves when handling the likes of Madame Jeanette peppers, and even then wash my hands very thoroughly, and still take a lot of care not to touch any sensitive bits of the anatomy, to avoid any, let's say, eye-watering results.
As a fine of the spicy myself might I suggest Habaneros or scotch bonnets?
Habaneros are usually slightly less hot than the good Mme, but a bit sweeter.
Scotch Bonnets are another good choice if you prefer the color to be lively like the taste.
On something like pulled pork, or mixed into a gravy poured across a roast both are amazing. With Stewed Okra, or Eggplant they make you forget you're either a slimy squishy veggie.
Or, less harsh on the skin, wash your hands with cooking oil, followed by washing-up-liquid, followed by soap and water. Capsaicin is fat-soluble, the oil dissolves it, the washing-up-liquid solubilises the oil, the soap and water removes it.
Better than putting bleach on your skin, which is arguably worse for it than chilli.
The fat-soluble bit means that should your brain tell you that you have the lower part of your head aflame, due to a mouthful of capsaicin, then a (partial) remedy is to allow some chocolate to melt in the said mouth. It'll still take the capsaicin southward when you swallow it, of course, so there will be consequences...
Heh, amateur hour! I've done that multiple times and only experienced an uncomfortable warm burning sensation for a while. It wasn't that bad :-) I've also then thrown the large handfuls of mixed chopped bird's-eye, scotch bonnet and jalapeño that resulted into an excessively hot wok, which led to my discovery of how to fill your own house with clouds of homemade tear gas! My red Thai curry was so hot that I had that Hans Blix knocking on my door looking for WMDs!
I've also eaten a drop of pure capsaicin extract that was about 1.5x the strength of CS gas. That literally incapacitated me for about 45 minutes.
I think that all this exposure therapy might have helped me last year when I was (illegally, I might add, but it's a long story) pepper-sprayed point-blank in the face by the local police, and I was able to pretty much shrug it off.
Bloody hell, I haven't half been through some wacky shit in my life :-D
Surely it basically already was MoviPrep?
(And in case you didn't spot it, the arrow after 'antidote' was pointing at the beer icon. Although, despite the long association of lager with curry, it doesn't really help much because of its lack of fats and oils to dissolve the fat-soluble capsaicin. Which is why Indians drink lassi with their curries...)
Capsaicin is marginally more soluble in alcohol than it is in water; the problem is that beer (even the 5% fizzy piss frequently sold in curry houses) is still 95% water; proof of capsaicin's solubility in ethanol can be found in the existence of chilli vodka. It's probably also proof that there is no God if you feel the urge to drink it.
"'s probably also proof that there is no God if you feel the urge to drink it."
That does not disprove the existence of God. It does, however, prove the existence of Satan, which then proves the existence of God.
Anon only because I do not want to admit a late start on reading comments.
I used to work with a guy who liked very spicy food. He bought into the office a bottle of his home made extra strong sauce.
After warning the office that a tiny amount could numb your tongue one person decided he would have a heaped tablespoon. He was advised to not do it but did it anyway
About 10 minutes later you could have used him as a navigation beacon and he was sweating so much it was visible going down his face. We had no choice but to bundle him into a car and send someone to drive him home.
We next saw him 5 days later…..
At Bradford Uni (1970s ) we used to warn visitors about the local curry strength.
And there was always one idiot who wouldn't listen.......
OTOH I visited Brum once, during my 2nd year.
And all the students warned me about the curry strength, so I was really disappointed.
Younger daugher did a tour of SE Asia a few years back. And was disappointed that they wouldn't accept her chilli tolerance. She can eat chilli strength that would floor most spicaholics.My home grown Scotch Bonnets are just so much ketchup to her.
A bunch of us from work went to a Curry house in St Albans about 30 years ago. One of the party was already "tired & emotional" by the time we ordered, & was daft enough to be that white man who says "bring me the hottest curry you can make" to the staff.
It's still the only time that I've seen sweat actually pouring out of someone's ears (as well as every square inch of the rest of him.) He managed about a third of it, & he didn't turn up for work the next day "due to a hangover" apparently.
I take issue with the hot hands discussion. It's not nearly as bad as when you...
1. Cook up a hot phal and find it immensely tasty and warming, all hands nicely washed, and go back to work.
2. Drink a cup of tea - you might prefer coffee, but I can't say if it makes a difference
3. About 1 hour or so later, the kidneys have processed the tea
4. Receive a most painful shock that lasts for a good half an hour as all the capsaicin comes out, and lingers at full strength.
I'll take accidentally not washing off all the fire and handling nether regions in favour of this. Especially when you've over egged step 1 and the kidneys haven't processed it all out of your system and round 2 (or three happens)...
VPNs nowadays.
Of course it may be odd to see a VPN connection initiated from inside the network when they probably have no legit reason to do that.
External torrent boxes are probably better.
With that said, it's always a good idea to take copies of whatever is torrented for evidence - especially if it's something interesting ;)
I've occasionally needed to VPN out of my company's network, albeit into other company or partner networks. You could detect which VPN I've connected to and identify whether it's a trusted one relatively easily, but it's more complex than all VPNs being unexpected.
Ii thought that once when a couple of us from the UK went to a European site to do a data centre migration while they were closed for summer.
We saw some data traffic via the firealls when everyone should have gone home. We waited and it was still going. Said IT boss of the site went around and cofirmed only us 3 were there.
We traced the taffic, go the IP, accessed the machine with our creds and saw a "torrents" folder. Happy days, portable HDD now being removed from the bag in preperation.
Looked at the users folder and said the user was the IT bosses deputy with a huge HDD for those days.
So, we sorted the machine, went into the folder to "gather evidence" for later viewing....... lets just say the names of the folders stopped us dead in our tracks !
Said IT deputy kept their job, but I wouild love to have been a fly on the wall for that meeting.
Back in the day when bandwidth was limited and expensive but $BIG_COMPANY where I worked had a bunch of T1s, I soon found out that it was nearly impossible to distinguish legitimate SFTP file transfers from less legitimate transfers running over an SSH tunnel. And guess what - it still is.
A few years ago, a colleague got a stern email from IT saying they'd found MP3s on her computer and that they needed to be deleted ASAP or her manager/HR would be informed...
The selfsame IT guy then came to her desk and told her to leave them there until the next day before deleting them "in case she had anything good"
Well, not the chilli oil enema bit, and it wasn't the boss, it was $SMARTARSE_CONTRACTOR, but anyway, this was quite a few years ago, and I was working for a startup in the short-lived UWB/Wireless USB field. I was mostly a developer, but I was also assistant admin - not a PFY; I had been the only admin when the headcount was only a dozen employees, and we took on a full-time admin as we expanded.
Anyway, the hardware boys in the testing lab had been constantly complaining about having to log in to their testing PCs - apparently passwords are a software thing that hardware guys just can’t comprehend - and management wanted us to do something to keep them happy. So, against our better instincts, we gave them a shared, passwordless login for the lab PCs just to shut them up. (We also cordoned off the lab PCs in an isolated subnet separated from the main network - we weren’t mental!)
Not that much later, we had an afternoon when the entire office network and internet access were running really slowly and everyone was complaining. It only took a few minutes rummaging through the firewall logs for the head admin guy to identify the problem: one of the lab PCs was hogging every bit of bandwidth we had with BitTorrent traffic. I marched on over to the lab, yanked the network and power cables from the offending PC and seized it. The network immediately recovered.
After that, I took the hard drive out and set it up - read-only of course - as a secondary in my own PC. $SMARTARSE_CONTRACTOR probably thought he was being pretty slick by using a shared login for plausible deniability, but he had reckoned without the browser cache and history. The sequence of events was plainly recorded. He had been logged into his Yahoo email in his own real name; he received an email with a torrent link to the brand new Narnia movie that had literally just been released in cinemas that day; he searched up the uTorrent client, went to the download page and downloaded the installer; he ran the installer (timestamps on the Program files directories were consistent); went back to his Yahoo email for the torrent link again; and then the torrent chunk files started getting created at around the same time everyone noticed the network getting congested.
Anyway, we presented all the forensics to management, and I think HR got involved; we deleted the torrent client and data files and restored the lab PC, and then… nothing much happened. Management wouldn't go back on their insistence that logging in was too onerous for the precious hardware snowflakes, and $SMARTARSE_CONTRACTOR didn’t get insta-fired, although I think his contract might not have been renewed when it was up. Me and full-time admin guy spent the rest of the day face-palming, but overall, not a single lesson was learned.
People, eh? What a bunch of bastards! :-/
Well, we blocked torrent after that, but we had some pretty high-bandwidth applications that needed to run unconstrained (think uploading VLSI layout files to chip foundries), so we couldn't just do it on bandwidth alone.
Ironically, if $SMARTARSE_CONTRACTOR had only thought to use uTorrent's built-in rate-limiting controls, we might never have found out at all. Until the company received a lawyer's letter, that is...
It was many, many decades moons ago now but I recall working at a client site which had a problem with peer to peer connections (it may even have been Napster or LimeWire - otherwise known as 'virus down the wire’; but like I say it was a long time ago), which if you blocked the port(s) it was using, it would simply choose another one - so it became a game of whack-a-mole.
The solution was to not block the ports, but find the default port it used and then throttle traffic to a a few dozen kb/s. As far as the application was concerned it was connected and was working, except in practical terms it was simply unusable.
Sometimes the ’nuclear option’ is not the best one and a more subtle approach is required.
"I'll just get this for you," said the BofH, blocking others' view of the NUC with his body, powering it down, and palming the USB thumbdrive with a pre-release copy of Silo season 3 which was attached to the NUC.
Fortunately the thumbdrive contained only backup copies of the torrented material stored on the NUC's internal drive.
I use Resilo Sync which is torrent based. Surprisingly, never had anyone complain when I have taken my laptop to a client and logged onto their guest network. Once site I was in almost every day for 18months and not a thing (we had a guest wifi account which had to have a valid email address and a valid internal sponser address [my own client provided account sufficed as the sponsor], so a double check that my laptop torrenting was me !)
I think a lot of network admins, at least many I've met, don't care, especially on a guest network. As long as you're not attacking their infrastructure and not degrading their network, a lot of them are content to ignore you. Security cares more when someone does it from the non-guest networks because they have to tell whether it's malware or not, so they're more likely to stop such activity, but usually more to eliminate the possibility of risk than because they consider it a problem worth caring about.
If you follow the Web Comic Grrl Power, the main character whose surname coincidently is Scoville*.
TLDR she gets stranded a deep space trading post eats Grakz (The spiciest/hottest food in the galaxy) with ease proclaiming it to be no big deal.
Her superhero name is Halo, but has a different ring of fire when she later discovers it's 10x hotter on the way out, than it is going in, not only that but tends to turn the air red with little "motes of plasma" that float around the person in the act of voiding their bowel.
Pages #686, #711 & #712 the comic is occasionally NSFW.
That reminds me of my first year at university. One of the seniors in my rooming house recommended a hot Italian sausage sub sandwich from a local pizza restaurant, but warned me and my roommate that the next morning we would likely suffer a fire polished a-hole. Boy was he ever right! Those were some of the best sub sandwiches I have ever had, but it took until about the fifth time I ate one before my bum finally adjusted and there was no next morning torture.
Quite a while ago, I became the defacto network administrator for a remote office of a client location for the project I was working on for a short while. There were direct network links to the main client office, but general internet access for corporate mail was provided by an ADSL link, just normal consumer grade ADSL.
For a few days, people started getting dropped VPN connections to the corporate network going via the ADSL link. They would not stay up long enough to synchronise the Notes database copies.
I was asked to investigate, so I turned on monitoring access to my desk from the managed switch connected to the ADSL router, and fired up Etherape to identify the traffic.
But there was a strange thing. Total download traffic was below the inbound speed of the ADSL link, but TCP sessions were still breaking down. Looking at the traffic for a while, I identified that someone was using the eMule protocols to download media, and as this is a peer-to-peer filesharing protocol, it was also generating significant outbound traffic. We found that the transmission of the data to the gestalt was saturating the uplink of the ADSL connection (Asymmetric Digital Subscriber Line), and we were getting timeouts on the outbound TCP ACK packets, leading to the far end repeatedly re-transmitting packets that had actually been received correctly.
From the manual DHCP address allocation I was able to work out who had the guilty system with the registered MAC address.
Senior manager took a quiet walk down the corridor to find the culprit, who didn't contest the evidence, and they were given a stern warning not t do it again. Sanity returned to the network straight away, and I never had the problem again.
Back in the 1990s, I became a junior co-admin for the Usenet/NNTP server at $BIGCORP. The senior admin ran a tight ship, importing only the appropriate sci.*, comp.* and news.* groups. People were surprised that he also brought in the rec.* groups. He did because (a) he knew people would use them, (b) they were mostly harmless, and (c) people were more motivated to learn the Usenet tools by reading rec.arts.comics and the like on their own than if we tried group training on the tools. The reasoning was that people who were comfortable using Usenet would use it to be better and become more efficient in their actual jobs, and he was right.
The company was on a metered T1 line. That meant it paid $X per hour to the ISP, where $X was a function of the peak usage during the hour and the time of day. Off peak times, from 2am-6am, were something like 10% the cost of 12pm-4pm. We scheduled all of the internet traffic that we could (offsite backups, remote administration, pushing customer database updates, etc.) to those hours to keep costs down. It was complex, and ugly, but it worked.
Getting Usenet as a resource in house had helped developers and business types quite a bit (the web was still in its' infancy), and it only increased our monthly ISP cost by something like 5%, so it was definitely worth the cost.
And then, the alt.* hierarchy was brought in.
Some bigwig wanted some group that was in alt.*. We fought it, because the way our contracts and the tools worked back then, it was all or nothing. If we brought one alt group in, we brought them all in, and that was a bad, bad idea. The senior admin and I both knew what would happen so we tried to stop it, but we were overruled. And so, alt.* became available.
Our network costs absolutely exploded. Usenet usage went from being under 10% of network usage to over 92% within a month. And overall usage increased by more that a factor of eight. Worse, the majority of the increased usage was happening at peak times. In real world terms, that meant our network costs increased astronomically in the first month after the alt hierarchy was added.
Management went berserk at the costs, and demanded answers. Since "we told you this would happen" wasn't quantifiable, the senior admin and I went through the logs. Neither of us were surprised to find that nearly 100% of the increased usage was Usenet traffic. We were also not surprised that it was almost all alt.* groups. Nor were we shocked that the overwhelming majority of the usage was in the alt.sex groups.
We were surprised that the overwhelming majority (over 85%) of the sex traffic (literally) was attributable to only six users, in a company of thousands.
The icing on the cake was that those six users were all either reporting to a CxO, or a CxO himself/herself.
You can tell a lot about a person by the porn they watch, and boy howdy, did the senior admin and I learn a lot about the execs running our company. I thank $DEITY that none of them were into child porn or anything illegal like that. On the other hand, you look at that that sixty year old exec with nine female reports differently when you see he's subscribed to a dozen Gor groups. And given what the female execs were downloading, as a testicle retaining male, I'm grateful I didn't report to them.
To be fair, the porn downloads weren't exclusively limited to the executive suite. We found some other outliers. One tech geek actually consumed more porn than any of the execs. However, he was clever enough to have set up a cron job that ran at three in the morning to do it. From what we could tell, there was some public domain Russian porn server that had daily download limits, and he was hoovering as much porn off of it as possible every single night. But because he did it at off peak hours, his usage barely registered compared to the executives, at least cost wise.
The problem was very solvable, at a technical level. However, on the political level, we realized that identifying the six executives as the culprits by name might not be in our best long term interest. So, in the interest of self preservation, when we posted our findings we listed the names of the alt.sex groups that were being downloaded from, the amount that had been downloaded, and the date and time that the downloads occurred, without listing the culprits.
Overnight, the problem went away. I suspect a lot of nontechnical users (ie. executives) hadn't realized that we saw what they were doing.
At least when dealing with torrents, you can block the ports. Having to actually look at the content being downloaded and determining whether it violates DCMA (it didn't) or basic human decency (it did) is a different story.
No, in the 1990s, Usenet was still primarily a text based system. The alt.binaries groups weren't that well known, or well populated, because high speed internet wasn't commonly available, and CD burners were still pretty expensive.
Sure, a person could bring a cracked game or software into work, or his university, and upload it from there, and some did. But it was nowhere what it became in the early 2000s. Also, because of capacity limits, a lot of the NNTP peers (including the ones we were connected to) simply didn't carry groups that had traffic over a certain level, unless someone specifically requested it. And since no one was about to make a formal request for alt.binaries.cracked-software or the like, it didn't happen.
I remember when the Star Wars Episode One trailers came out. A thirty second, 320p or 480p video in RealMedia (remember that?) could take six minutes to transfer. Few people were uploading 300MB games to alt.binaries at that time.
"No, in the 1990s, Usenet was still primarily a text based system. The alt.binaries groups weren't that well known, or well populated"
Well, I first got onto Usenet in around '94 or '95, and they were fairly well known and got a lot of traffic at that point. I think the newsgroups.txt line was already "megabytes of copyright violations". But that was back in the days of exponential growth, so even a year's difference between when you were talking about and that could make all the difference.
(Fun fact: when I first got web access, I could go to Netscape's "What's New" webpage every day and check out every new site they listed during my lunch break. Within six months that was completely impossible, because it would have taken more than a day to even briefly visit every new site.)
Icon because I'm feeling really old these days!
I think my first post was in 1982 or 1983. I was there when the lore was written, before the Great Renaming in 1987, and long before the web existed. Those were the days of Gopher, Archie, and even Veronica.
Also, what was being distributed varied significantly based on peering agreements. I graduated from one university, did work with another, and had contracts with two large corporations around that time. I They were all on usenet, but they all had completely different peering setups, so their content was wildly different. They all had the core groups, but as you branched out, what was carried varied significantly. I remember a few ISPs back then actually public email addresses for their usenet admins for people who wanted to request specific groups.
And yeah, it had megabytes of copyright violations, but it was insignificant to what it is today. But unless you were at a university, you didn't have the bandwidth to download a half dozen installation CDs. Once cable and DSL become common, that changed, but I don't think that really happened until about 1998 or so.
Fun facts:
"chilli" is a documented alternate spelling of "chili", which is how the name of the type of pepper, its oils, the dish made with such peppers, and etc. is typically spelled.
BUT, the plural of "chili" is always spelled "chillies"; "chilies" is NOT a recognized spelling.
The English language, man...