* Posts by EnviableOne

2052 publicly visible posts • joined 28 Jan 2016

EU: These are scary times – let's backdoor encryption!

EnviableOne

Re: Ursula said it

As such, multitudes of EU legislation are held up by small groups like the Flemish farmers in Belgium.

The trilogue meetings, defined as 'informal tripartite meetings on legislative proposals between representatives of the Parliament, the Council and the Commission', are where business gets done.

Then the decisions in trilogue are ratified by the parliament, the council and the commission.

So representation is maintained in all three bodies, the people directly elect the parliament, the council are made up of the elected representatives of each member state, and the commission is appointed by the other two.

I admit the EU has exceeded its original mandate, but as one the largest free trade blocks in the world with low to no tarrif agreements with most of the planet, a respect for privacy and human rights, and institutions defined to defend them, it is far greater than the federal united states at both getting things done, and doing so effectivley.

GCHQ intern took top secret spy tool home, now faces prison

EnviableOne

math(ematic)s

Privacy died last century, the only way to go is off-grid

EnviableOne

Re: Big Trouble

Amazon are the only corp you have a chance of taking down with GDPR fines. due to being hamstrung by the former bookshop, they are only making about 2.5-3% profit on turnover so a max GDPR fine of 4% of turnover can wipe out their annual profit.

Meta, Alphabet, Apple, Microsoft are making nearer 30% on turnover, so 4% fine is a drop in the ocean

FCC on the prowl for Huawei and other blocked Chinese makers in America

EnviableOne

Hangzhou Hikvision Digital Technology, Dahua Technology

good luck weaning the USAians off these two they produce feature rich CCTV at 1/10th the price of anything comparable in the market,

most corporate cctv systems use either or both of their camera's and they have a life span that means the cost to replace can be deferred for years.

distributers are keeping dwindling stocks and raiding grey (and possibly black) markets to get the customer what they want.

Cyber-crew claims it cracked American cableco, releases terrible music video to prove it

EnviableOne

DNSSEC only authenticates that you are speaking to the DNS server you think you are, not whether the response is poisoned.

If the legitimate server is hijacked it wont save you

Windows 11 roadmap great for knowing what's coming next week. Not so good for next year

EnviableOne

MS Excel

the tool thats just good enough (i.e. not impossible) at everything to mean Manglement wont pay for the propper tools.

EnviableOne
Windows

Re: Am I alone in thinking ...

thats about the M25 which is a whole other story...

China’s FamousSparrow flies back into action, breaches US org after years off the radar

EnviableOne

Just wondering if the group have recently emerged from re-education....

making them the FormerFamousSparrow FFS...

There are 10,000 reasons to doubt Oracle Cloud's security breach denial

EnviableOne

the UAE have enough money, they should be able to survive an Oracle defamation sue-ball

EnviableOne

Re: Employment

Tried, Rose87168 asked for 100k Monero (approx. £20m) to disclose the details, fix it, and destroy the data, which Larry's Lawsuit House declined.

From the posting, Rose sounds like someone who is very green and lucked into an exploit on a big fish.

also possibly someone not entirely of an age to benefit from a work contract with Big Red.

Trump orders all government IT contracts consolidated under GSA

EnviableOne

Re: 'appropriate kickbacks' rule the nest.

Tie that to the A woman can't run the country brigade and you have all the answers

Microsoft's many Outlooks are confusing users – including its own employees

EnviableOne
Windows

Re: mutt -- it sucks less.

but it doesn't work with Winders

Microsoft: So what if it costs 4X as much to run Windows Server in AWS, Alibaba, and Google?

EnviableOne

thats another issue, Apple dont let you run it on a mac

'Uber for nurses' exposes 86K+ medical records, PII in open S3 bucket for months

EnviableOne

Re: Why TF? ! ...

this is why I love the data minimisation clause in GDPR.

This way, if you don't need it, you don't need to collect it. (the potential fines are too big of a risk)

VMware splats guest-to-hypervisor escape bugs already exploited in wild

EnviableOne

AHV FTW!

Nutanix Here we come

Cybersecurity not the hiring-'em-like-hotcakes role it once was

EnviableOne

Re: Do try not to exclude neurodiverse candidates

TBF it works both ways,

I heard tale of a recruiting manager who insisted the SSH worked over UDP...

The neurodiversity is very much a thing, and not all of us are completely useless with real people.

If you're neurodiverse, you are generally quite good at working things out and working out how to simplify complex things, that work for you, in terms others can understand.

The benefits of neurodiversity is that they tend to have a hyperfocus mode, so get deeply knowledgable in one specific area, this makes them great SMEs

So … Russia no longer a cyber threat to America?

EnviableOne

forgetting Hanlons razor

"never attribute to malice that which is adequately explained by stupidity"

who goes bankrupt running a casino?

Ransomware criminals love CISA's KEV list – and that's a bug, not a feature

EnviableOne

Re: Duh, and in other news, water is wet

Come on, Palo and Forti have had issues, but not as bad or often as Ivanti, and if I was going to have a do not use list Forti would also be on it.

At least Palo are normally quick with patches.

Other candidates are F5 where the Big IP is constantly full of holes.

The other big vendors have plenty bugs, but they are dealt with quickly and and in a professional manner.

Broadcom are gonna drive VMware into the ground, and D-Link are another consumer networking problem, along with TPLink and others more worried about cost than security.

The real issue is software is not being made secure, and people are not patching... one is in the control of vendors and the other the Gen Pub. and both can be mandated by legislation.

We need to make vendors responsible for their software security and people accountable for doing basic maintenance.

Hundreds of Dutch medical records bought for pocket change at flea market

EnviableOne

Re: Remote data destruction

if you need the data, the Center for Memory and Recording Research at UC San Diego did it all.

They proved unless you can move the heads of the centre of the track, multiple overwrites make no difference.

They also developed an OS tool to trigger the secure erase unit command

Mobile operators brace for bigger, faster headaches with 6G

EnviableOne

Re: > My 4G service (EE) is abysmal

I check my phone and note with dismay that while outside in the rain I had 4G, now that I’ve sat down, my connection is rapidly dropping through 3G to 2G, then to Edge, then to fax modem, then to Morse code over telegraph, and finally settling on smoke signals. Weak ones.

-Alistair Dabbs

Russia's Sandworm caught snarfing credentials, data from American and Brit orgs

EnviableOne

Only 4 eyes

so who forgot New Zeland, either GRU or Microsoft can't tell the difference between Kiwis and Aussies

UK court says Chinese operation must sell Scottish chip biz stake without delay

EnviableOne

Re: Bin it.

Their USB to serial chips make all the old-fashioned console connections work

Sophos sheds 6% of staff after swallowing Secureworks

EnviableOne

Re: Time to leave

Thoma Bravo are different. they make their companies materially better

at one point or another they have owned part or all of:

Barracuda, Bluecoat, BeyondTrust, Connectwise, Darktrace, Delinea, Entrust, Exabeam, Imperva, Impravata, Landesk, Logrythm, McAfee, Proofpoint, Sonicwall, Sophos, Tripwire and Veracode.

and a couple of others

Feds want devs to stop coding 'unforgivable' buffer overflow vulnerabilities

EnviableOne

Re: Except these are products that people *buy*

Every FOSS licence confers no warranty that the code is fit for the purpose you use it for.

If you use someone else's code you have to provide that warranty if you are going to sell it.

Have I Been Pwned likely to ban resellers from buying subs, citing 'sh*tty behavior' and onerous support requests

EnviableOne

1Password is a previous sponsor of HIBP, and is not a reseller.

they do (or did) use the data in their watchtower feature, but it does not form the complete solution and has no effect on their relationship with HIBP

EnviableOne

Re: He's worked with resellers to help those who can’t pay by credit card

HIBP uses Stripe (other providers are available) which provides a huge array of payment options and manages it all for you.

If you can't pay Stripe, you will struggle to pay anyone

UK Home Office silent on alleged Apple backdoor order

EnviableOne

Re: Which is exactly....

Trump and minions already do see the PATRIOT act.

They also have rights to all of the rest of our data stored with US companies (like Apple) thanks to the CLOUD act.

But all of these Acts are against the International treaty of the Universal Declaration of Human Rights, which is a fundamental treaty of the UN, that all countries had to sign up to:

Article 12 is a doozie:

"No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks."

so not only are they not allowed to do it, they even have to prevent it from being done in law

The biggest microcode attack in our history is underway

EnviableOne

Re: Yes what we had was corrupt, and it was mostly OK

to quote Winston Churchill.

It has been said that democracy is the worst form of Government except for all those other forms that have been tried from time to time.…’

Winston S Churchill, 11 November 1947

EnviableOne

Re: What is this article about again ?

htey did that last time, the SCOTUS was stacked in his favour, which is the ultimate check on the power of the other branches of government

UK armed forces fast-tracking cyber warriors to defend digital front lines

EnviableOne

Re: Isn't it time

yeah, the RAF was supposed to replace the NAS and AAC, but they wouldn't relinquish control, so you will probably end up with the Royal Cyber Force, and still have one for each service.

Spending watchdog blasts UK govt over sloth-like progress to shore up IT defenses

EnviableOne

Not a Skills Gap

it's there in black and white, the skills are there, and the GAP is the gov expects them to work for less than they are worth.

while there are a few charitable individuals who are prepared to take the lower remuneration, in exchange for helping society as a whole,

the rest of us value the struggle needed to get to a level where we can help and need appropriate recompense for the added stress and threat that comes with a high-profile role, and the chance that even though there are external audits now, the problems are somewhat systemic, and need organisational overhaul, beyond the remit of the role.

Trump admin's purge of US cyber advisory boards was 'foolish,' says ex-Navy admiral

EnviableOne

Re: So long, & thanks for the fish.

Unfortunately, he won the popular vote this time round, so MOST Americans who expressed a preference can be tarred with that brush.

the real reason he got into power though, is not his supporters, it's the misogynistic Old World US that would rather have the Chetto in Chief back or any man than have a woman president.

The US is a relic of its origins, the people that moved across the ocean rather than evolve with the reformation of the church.

if you look at the majority of Western democracies that are thriving they are run by women under 35, and neither of those criteria has ever been US president, in fact, Obama was the youngest president ever when he took office, and the average age of the candidates last time round was twice that

Ransomware attack at New York blood services provider – donors turned away during shortage crisis

EnviableOne

Business continuity

Where is their BC plan, no one should be stopped from doing business by the loss of access to infrastructure.

There should be contingencies, paper forms, cloud-based systems and alternate locations available.

this should be sufficient to carry on any business for 3-4 days in the event of an attack.

then there should be a good enough DR plan that systems can be restored or rebuilt within that window and records updated from the temporary systems.

UK floats ransomware payout ban for public sector

EnviableOne

Re: A public sector only ban wouldn't work

It's not hard to stop the script kiddies, just apply the Cyber Essentials principals

Secure configuration, deploy UAC, deploy EDR, Patch and Firewall.

that stops you from being the low-hanging fruit.

After that, it's about your threat level and if people are specifically targeting you, if they are determined enough or resourced enough they will get in.

You need to deploy the advanced controls on top to detect and respond in a timely manner.

Thats the art of the Cybers in a nutshell

EnviableOne

Re: There should be a law against it...

I believe NCSC have its called the Cyber Assessment Framework now in version 3.2 https://www.ncsc.gov.uk/collection/cyber-assessment-framework

as for providing the money to meet it, there are so many legacy apps designed to work on old systems and protocols, that retrofitting security around it is a £££££ effort.

and if UK.GOV go to their usual suppliers (Crapita, sOpera, Atloss, Dolittle, etc.) it becomes a £££££££££££ effort

Nvidia snaps back at Biden's 'innovation-killing' AI chip export restrictions

EnviableOne

Re: Going Dutch?

Not Just AWS, MS too, and others, the Netherlands are a tax efficient place to stash things.

doesn't hurt that they have ASML who's tech is just about essential to produce AI chips

Database tables of student, teacher info stolen from PowerSchool in cyberattack

EnviableOne

Re: Sounds like they were violating FERPA

It is also violating COPPA too, bearing in mind we are talking K-12 personal info at least half of it is Under 13s

US adds web and gaming giant Tencent to list of Chinese military companies

EnviableOne

Re: Haribo

Haribo GmbH & Co. KG, doing business as Haribo is a German confectionery company founded by Hans Riegel Sr. It began in Kessenich, Bonn, Germany. The name "Haribo" is a syllabic abbreviation formed from Hans Riegel Bonn. The current headquarters are in Grafschaft, Germany.

Germans are good, well at least now, and trump likes candy, so I don't see there being any restrictions placed their

Intel debuts laptop silicon that doesn't qualify for Microsoft's 'Copilot+ PC' badge

EnviableOne

Thats It

Intell has finanly signaled its out of the mainstream processor space.

Qualcomm will grow its ARM on the desktop to share the market with AMD the final holdout on x86/AMD_64.

Good news for TSMC!

The unlicensed OneDrive free ride ends this month

EnviableOne

Re: Unlicensed

the point is, until now it hasn't, MS has been giving away the cat pics for nothing and the bits for free.

someone with VP in their title worked out how much that storage space was costing MS in lost revenue, and decided that it was a chance to pad those bonus $$$$

First launch of Blue Origin's New Glenn rocket slated for January 10

EnviableOne

Re: Blue Origin has named the date for the first launch of its New Glenn rocket – January 10

SpaceX isn't the only player in the game,

it's just they knock the existing suppliers (Lockheed Martin Space and Boeing Defense, Space & Security) out of the pork barrel,

They only need 1/10 the pork to get the thing off the ground

They also have the first-mover advantage in recyclable launch systems and proven records of getting to space.

BO have a lot of catching up to do, to get 1/10th of spaceX experience, and proof of reliability.

they managed 3 launches last year to Rocket Labs' 14, CASC's 49 and SpaceX's 134

FCC boss urges speedy spectrum auction to fund 'Rip'n'Replace' of Chinese kit

EnviableOne

Re: Chinese backdoors bad

OpenRAN is comming,

OpenTel should be next

US reportedly mulls TP-Link router ban over national security risk

EnviableOne

Re: It won't

even though all their kit, including the custom ASICs are made in china (Shenzen I think)

Coder wrote a bug so bad security guards wanted a word when he arrived at work

EnviableOne

Time to move to octopus

BOFH: Don't sell The Boss a firewall. Sell him The Dream

EnviableOne

Re: Firewall or AI

Next up: learning about IPv6, but that will definitely be for next year...

like it was last year, and the year before and so on...

Crooks stole AWS credentials from misconfigured sites then kept them in open S3 bucket

EnviableOne

Chances are this is just a marshalling area, but it's bad OpSec to leave everything in the cache after you extract it.

Cisco combines Meraki and Catalyst into single wireless brand

EnviableOne

final Nail in the Meraki Coffin

here it is folks, Meraki is finally Borged.

the UI is going south, the HW eco-system is gone,

and its good by to bob the meraki blob

even @MerakiSimon left the building

UK plans to revamp national cyber defense tools are already in motion

EnviableOne

Re: Motion?? Specifics??

Considering ACD started as Mailcheck (DMARC, and TLS email the easy way) and Webcheck (learn how to do HTTPS and CSPs the easy way)

then branched out to PDNS (DNS Filtering) then added NEWS (NEWS Early Warning System - yes someone has a sense of humour, but was made to grow up) (working with threat intelegence to tell you you have been compromised) then added Exercise in the Box (how to excercise your IR plan the easy way) then added Logging Made Easy (a prebuilt ELK stack with easy to use defaults to centralise logging) oh and this little thing called Cyber Essentials (what to do to get the basics right) and the not bad generic cyber training available for free

I think there has been a considerable impact, especially for local councils, NHS and Emergency services, who have a treasure trove of data on you and next to no cash to afford the expertise to protect it.

NCSC have done a great job to keep the crown jewels safe.

Microsoft 365 remains 'degraded' as Azure outage resolved

EnviableOne

At this point outages are priced into the MSFT shares.

Its diversified enough and has a dominant market position that allows it to not be affected.

whether the dominant market position is deserved or not is down to your interpretation.

EnviableOne

Re: Weird..

Hanlons razor to the fore.

but there are those that are in more than one cloud, in more than one region, and more than one availability zone.

if your going to go cloud, do it properly, if your not big enough to do it properly, don't do it.