* Posts by MONK_DUCK

18 publicly visible posts • joined 21 Dec 2023

Crypto takes a dip as Trump signs Bitcoin Reserve order

MONK_DUCK

Exactly the same affair with gold, if America dumps in the price crashes and lots of angry people. There is a moral here, stop buying fairy dust.

Please fasten your seatbelts. A third of US air traffic control systems are 'unsustainable'

MONK_DUCK

Re: Get it Effin' Done

Maybe but then again maybe you are the only customer of a custom tape drive and, the company doesn't want to repair them 20 years after they went end of life.

UK government spends another £1B on cloud migration and services

MONK_DUCK

Re: Security?

As we all know, every workload in the cloud is 100% secure and completely impenetrable, and nothing needs to be proven as the vendor has iso 27001 compliance and a soc2.

Andrew Tate's site ransacked, subscriber data stolen

MONK_DUCK

Re: Hurrah

The numbers don't lie,

Admins using Windows Server Update Services up in arms as Microsoft deprecates feature

MONK_DUCK

Well that's just useless for everyone that needs the ability to roll out new machines without relying on an unreliable cloud or internet. I guess it does push us more towards RHEL etc... but that is a lesson in how to shoot yourself in the foot.

White House thinks it's time to fix the insecure glue of the internet: Yup, BGP

MONK_DUCK

It really just comes down to legislation, once a few of the bigger counties or blocks demand it, it will start to shift. If India or EU makes it a requirement then the revenue hit will force many companies hand. It really just comes down to how much they care about it and the time frame. Wouldn't surprise me to see them start with the ISPs, move to critical national infrastructure next and onwards from the large to small caps.

AT&T sues Broadcom for 'breaking' VMware support extension contract

MONK_DUCK

Completely agree the conversations from the mid and large caps all seem to be around accelerating their migration plans, rather than if they are moving away from vmware.

Nvidia's latest AI climate model takes aim at severe weather

MONK_DUCK

Re: Weathermarket

Of course they can, in fact they already are doing it, and once several finace houses are doing the at scale the benefits of it will be gone and we will just go back to looking at the fundamentals.

Raspberry Pi Pico 2 lands with (drum roll) RISC-V cores

MONK_DUCK

Should help get risc-v out to more developers in an easy to access manner, which can only be a good thing.

Under-fire Elon Musk urged to get a grip on X and reality – or resign

MONK_DUCK

Re: So what?

They advised the companies not to go on a platform full of crazy conspiracy theorists, run by a guy who supports crazy conspiracies.

MONK_DUCK

Musk only has one ability, to make hype, he is trashing his companies. True he is very good at making little to nothing grow but when reality come he mucks it up. He grew Tesla and now it's massively overvalued with mediocre product line coming up. He arranged to buy Twitter and wrecked its revenue.

They really need to find a way to remove him from the board of Tesla and X, he's wrecking them both and wiping out shareholder value.

Twitter tells advertisers to go fsck themselves, now sues them for fscking the fsck off

MONK_DUCK

I can't imagine many companies I've worked with wanting to be associated with a lot of content on twitter, there are no laws that say they have to advertise next to nazi incels.

Starlink offers 'unusually hostile environment' to TCP

MONK_DUCK

"The CUBIC TCP network congestion avoidance algorithm could also do a job, in harness with Selective Acknowledgement (SACK – aka RFC 2883)."

Interesting analysis though cubic tpc came out 2007 and is used by all the major desktop OS' and probably server. Likewise Selective ACK has been around for decades so as long as you are using a recent patched OS and not building your own tcp stack, you're probably fine.

Exchange Server SE set to debut just before 2019 version breathes its last

MONK_DUCK

Costs

Aside from extreme privacy or regulatory requirements running an on premise email server is one of the more expensive options these days, especially if you've got under a 100 users.

I loved running a lot of mail servers 20 years ago but it's starting to feel like admins could be doing other things for a commodity service.

Dating apps kiss'n'tell all sorts of sensitive personal info

MONK_DUCK

The regulators have a lot to answer for allowing companies to request, store and share unrequited data.

The fines need to be massively hiked and criminal charges made possible against the executives, legal team, security team, testers and developers if they haven't acted appropriately e.g. By not raising issues, concerns, lack of testing or not dealing with those identified issues.

Google One VPN axed for everyone but Pixel loyalists ... for now

MONK_DUCK

Let me guess that they don't cut the price of Google One when they do turn it off. For those who did buy it with that feature included. To be fair it worked pretty well in hotels and the few odd places with open WiFi.

Cyber sleuths reveal how they infiltrate the biggest ransomware gangs

MONK_DUCK

Re: The solution being a read-only USB device

Good luck at running infrastructure for 10k users without some form of central AAA. Your point stands but you need something otherwise users could be required to have hundreds of different passwords to various data sources. Most of the issue seems to be excessive privileges, especially around access to data and network resources.

SSH shaken, not stirred by Terrapin vulnerability

MONK_DUCK

Can this be fix though

Trying to figure out if the fix can actually work fully, the article mentions the server and client both must both be patched. Could not a MITM simulate an unpatched client or server.

Guess I'll have to read the paper itself.