Show more

Have an old hardware RAID or other battery-backed up HBA? Don't forget to check your batteries now and then.

"To overcome these limitations, we drew inspiration from the Morris worm, which exploited the DEBUG vulnerability in Sendmail by executing the body of a mail as a shell script:"

openwall.com/lists/oss-securit

RPKI deployment varies significantly between RIRs: between 1.38% (ARIN) and 15.11% (RIPE NCC) of ASes are included in one or more Validated ROA Payloads (VRPs), and between 2.7% (AFRINIC) and 30.6% (RIPE NCC) of the total IPv4 address space administered by RIRs is covered by VRPs.

blog.apnic.net/2020/01/29/is-r

No worries, we're fixing mobile too ¯\_(ツ)_/¯

"If Chrome fixes too fast it could break the web ... Much of the content on the web is supported by advertising revenue, and advertisers will shift to mobile apps"

cnet.com/google-amp/news/if-ch

The 'Useful Idiots': How These British Academics Helped Russia Deny War Crimes At The UN

Lecturers from the Universities of Edinburgh, Leicester and Bristol have accused rescue workers the White Helmets of mass murder in Syria – to condemnation from Amnesty International and others.

m.huffingtonpost.co.uk/entry/t

There's an awesome browser fingerprinting demo at amiunique.org

And I'm pleased to catch most (all?) of their fingerprinting techniques :)

webcookies.org/cookies/amiuniq

RT @aoifewhite101
DuckDuckGo is the big winner on Google’s Android search app choice screen - but it worries the way it’s designed might not steer users to alternatives bloomberg.com/amp/news/article

Google’s search preference menu for the EU is designed in a way that undercuts the very reason it was created, making it harder than necessary for people to choose a non-Google search engine alternative. We propose user-tested design improvements: spreadprivacy.com/search-prefe

Ticket title: Jenkins upgrade - CRITICAL vulnerabilities
Ticket type: Improvement

¯\_(ツ)_/¯

EFF: BREAKING: We’ve confirmed that the Ring doorbell app on Android covertly shares personally identifiable information on its users with third-party companies, including Facebook. eff.org/deeplinks/2020/01/ring

Russian BN-800 fast breeder reactor has just started commercial operations on reprocessed uranium-plutonium MOX fuel, meaning that it's now possible to "burn" nuclear waste

vz.ru/news/2020/1/28/1020621.h

There's an eternal conflict between DevOps and DevSecOps - for the former "OLD IS GOOD" (tested & stable), for the latter "OLD IS EVIL" (vulnerable). Unfortunately, business shares the first point of view, while the Internet prefers the latter.

DevSecOps case study 2:

Most 3rd party vendors no longer publish packages for unsupported distros.

So if your client is on Ubuntu Trusty 14.04 that has been out-of-support for the last year, and even if they pay extended support (ESM), you are either stuck to Nginx 1.4.6 from ESM that should in theore get patches from ESM, or to Nginx 1.14 from Nginx but no longer receiving any patches for a year or so.

DevSecOps case study 1:

if your client has 5 years ago chosen a convenient repack of Nginx like OpenResty or OpenWAF as their main web server, you may not be pleased to learn that both of them were discontinued (OpenWAF in 2017) or barely updated (OpenResty half year ago).

Strategically it would be perhaps better to use a native Nginx package from Nginx upstream and internally compile NAXSI into a DEB - at least you'd be running an up-to-date Nginx.

Now I had to upgrade from 1.7 (!).

An Avast antivirus subsidiary sells 'Every search. Every click. Every buy. On every site.' Its clients have included Home Depot, Google, Microsoft, Pepsi, and McKinsey. vice.com/en_us/article/qjdkq7/

"Greens caused gigatons of carbon dioxide to enter the atmosphere from the coal and gas burning that went ahead instead of . I was part of that too, I apologize." (Stewart Brand, 2009)

Show more

kravietz 🦇's choices:

Mastodon 🔐 privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!