CyberSeeker

joined 11 months ago
[–] CyberSeeker@discuss.tchncs.de 82 points 4 days ago (1 children)

Shouldn’t be this hard to find out the attack vector.

Buried deep, deep in their writeup:

RocketMQ servers

  • CVE-2021-4043 (Polkit)
  • CVE-2023-33246

I’m sure if you’re running other insecure, public facing web servers with bad configs, the actor could exploit that too, but they didn’t provide any evidence of this happening in the wild (no threat group TTPs for initial access), so pure FUD to try to sell their security product.

Unfortunately, Ars mostly just restated verbatim what was provided by the security vendor Aqua Nautilus.

[–] CyberSeeker@discuss.tchncs.de 0 points 3 months ago (1 children)

Only the cyber truck. Model S and 3 refreshes are still on the legacy platform, with a lithium ion 12V.

[–] CyberSeeker@discuss.tchncs.de 0 points 4 months ago (1 children)

So the article repeats, several times, “waymo relies on remote operators”. I don’t think the author knows what “self-driving” means.

[–] CyberSeeker@discuss.tchncs.de 8 points 6 months ago

Don’t bother with the cert if it’s not your job, but at least look into CCNA Routing and Switching. There are tons of courses available, both in person and online, as well as numerous YouTube videos on the subject.

See if your local library or community college has an adult education center that provides a course. At some point, you will need to learn subnetting, which is just math, but practice makes perfect, and your life is easier if you have it committed to memory.

Proper written work is still one of the most effective ways to do this.

[–] CyberSeeker@discuss.tchncs.de 3 points 6 months ago (1 children)

While true, it’s pretty asinine to hold companies operating in China accountable for complying with Chinese law. It sucks, but they aren’t just going to abandon the Chinese ~cash cow~ market.

[–] CyberSeeker@discuss.tchncs.de 12 points 6 months ago

Or, the real sign of gentrification is that the Google Maps car drives by your neighborhood more than once every five years. Guarantee that’s not happening in the projects.

[–] CyberSeeker@discuss.tchncs.de 6 points 6 months ago

How diverse is your investment portfolio? How many different stocks and securities have you sold last year? Were these subject to short term or long term capital gains? Did you rebuy any of those, making the security subject to the wash rule?

If you have a family, a house, multiple W-2s, 1099s, a retirement account, and a 529, things are still pretty “simple”. TurboTax does not let you use their free file if you’ve traded stocks, but for most other products, even some low volume trading in a brokerage account is considered fairly standard.

At the end of the day, it comes down to how organized you are, and how much time it will take you to do data entry. Usually, your tax documents have clear headers, and usually, these match up to the fields in the tax application. But not always, and the more documents you have, the more hours it will take, and the more likely you are to run into a speed bump that will cause frustration.

So, how much is your time worth to you? If it’s worth more to you than the cost of a tax professional, it’s an easy decision.

[–] CyberSeeker@discuss.tchncs.de 2 points 7 months ago (3 children)

Sorry if I’m about 10 years behind Linux development, but how does Docker compare with the latest FlatPak trend in application distribution? How you have described it sounds somewhat similar, outside of also getting segmented access to data and networks.

[–] CyberSeeker@discuss.tchncs.de 1 points 8 months ago

Digital signature as a means of non repudiation is exactly the way this should be done. Any official docs or releases should be signed and easily verifiable by any public official.

[–] CyberSeeker@discuss.tchncs.de 3 points 9 months ago

This. They clearly overextended due to the boom in streaming during the pandemic, and are now reacting to the contraction in content consumption both here, and on YouTube.

[–] CyberSeeker@discuss.tchncs.de 21 points 11 months ago* (last edited 11 months ago) (1 children)

Why are you running a VPN? If you are simply shielding your internet activity from your ISP, Google won’t give a shit where you sign in from.

If you are browsing to shield your identity, you want to be fully disassociated with any non-secure browsing habits. If this is your use case, even if you are using discrete internet accounts, tracking cookies are common enough that, you would still be identifiable from your browser fingerprint. It all depends on what your risk factors are, and how much you want to spend to mitigate them.

[–] CyberSeeker@discuss.tchncs.de 1 points 11 months ago* (last edited 11 months ago)

I wouldn’t immediately jump to that conclusion. There are plenty of legitimate business opportunities that do not imply “taking money to promote products”. In-line advertising and properly disclosed free samples are standard operating procedure for the tech industry, but they are completely above board, and by themselves do not imply bias.

Nearly every content creator’s YouTube channel About page or website will have a similar line, somewhere.

view more: next ›