I owned several versions of Little Snitch too. It started to be annoying when you had to approve each request, especially when running command-line scripts. Then I moved to run in silent-approval mode. At that point, there was no reason to have LS any longer, so I uninstalled it. Haven't used it in years now. But not to discredit LS, it is an amazing software when you need it.
I share the same feeling with smitty1e. But I have to admit, my military experience, GI Bill, and security clearance opened many doors for me. As you put it, it gave me a major leg up in life. I would make the same choice again unless I had better opportunities.
These devices are funded by government/school systems. When you receive them, you have to sign a TOS or User agreement, where highly likely contains a verbage similar to "This device is subject to monitoring". This is the magic statement; it notifies you that they could be watching, and you are aware and agree to the search.
The consent banner is typically mandatory on all government IT systems.
Here is the one for the DOD: https://dso.dla.mil/
IIRC from my military time, the first generations of the patriot missiles (PAC-1, PAC-2) were designed to explode when in vicinity of the target. The PAC-3 missile was the first to introduce kinetic damage before the payload would explode.
It depends on how you define top-tier hackers. State sponsored attackers (hackers with ties to governments, regime, etc.) have a lot more capital at their disposal. Sometimes they work inside government funded facilities. They could use matrix, signal, forums, IRC, for chat. Browsing usually comes to preference but a hardend version of firefox is preferred. OS, whatever they want. Usually you would attack from a custom distro or a kali box. These hackers are well funded.
Lone hackers, they would probably use Tor, Signal, Tails, Kali, to remain anonymous online but have the tools necessary. The most important thing for them to stay anonymous is to have jumpboxes. You would use stolen credit cards or gift card to rent a VM from a host like Linode or Digital Ocean, and use that system to proxy the attacks. You can add any number of jumpbox to make it harder to track the origin of the attack.
I have not received an email from Google about the changes. It lead me to think that it is for accounts that have more than 1 active user. I have a G Suite Legacy with 1 account only. The change make sense to block companies from abusing the free legacy version. However, Google should allow users to downgrade to 1 account or migrate the data to gmail accounts.
I don't miss the physical media. I am happy purchasing digital content. It makes management and organization very easy. What I do miss is owning the content. If you purchased a Music CD or a Movie DVD, it was yours. You could watch it any time and nobody could take it away. Now, if your iTunes account gets disabled, you lose all your purchased content.
If the attacker opens the document on a computer connected to the internet, it will.
IIRC, the way it works: the document contains external resources with a unique identifier attached to the campaign, which the document viewer will attempt to connect and fetch. When the document viewer makes the request to retrieve the online resource, it will trigger the alert, collect IP, GEO information, and whatever other data it can collect.
You can use this over the internet, or host internally for internal networks without access to public internet.
You could use a Canary / beacon. I have used this before to detect/confirm insider threats in organizations. You could create a PDF with instruction on how to view the data inside the SD. When the attacker opens the document, it would send an alert that the document has been opened.
> I was once looking for a solution to some technical problem, clicked on a promising web result, and found myself at my blog. I had posted a solution several years earlier but had forgotten about it.
That is funny.
Once I recognized that I have been researching the same topics I have researched before, it motivated me to change my blog from a "Hack the Box" showcase blog, to adding my technical journal on topics that were hard to find online and sharing my experience with certifications.
I have been thinking of adding more personal entries, but I don't want to make the blog a social media.
I use my blog to keep a journal on technical issues that were hard to fix, or was hard to find web sources about the subject. One of my top post is about using PFSense router with Verizon FIOS. It usually receives 2-3 unique visitors a day. It is simple and not interesting, but it helps a few people, so I keep it online.
I got hired via LinkedIn, but it wasn't necessary to have an account to get the job. The position I got hired for had a job announcement on the corporate website. LinkedIn was just another source of job listings. LinkedIN was a great tool for discovering positions, whereas without LinkedIn, I would have missed them.
There is the usual job opportunity spams, which for IT Security is not bad. I have received several initial introduction from recruiters from respected companies.
What I like about LinkedIn is that I can find out instantly if I know someone who already works at the company I am interested in applying. Being able to ask someone about the company's culture can help you make the decision if you want to accept employment or skip to the next one.
When Google Chrome came out, it was fast, reliable, secure, and it was not Internet Explorer. Chrome was what everyone needed back then. The competition was Firefox, which performance was getting slower (before Quantum). The problem was that Google shifted priorities for Chrome (or played the long game) to better support Google/Alphabet's interest.
As long as it is work related, it is not unethical to educate yourself in something new. For example, a new tech stack, similar discipline, or business administration. Employers and employees benefit when the employee keeps learning and bring more diversity and experiences to work.
Hopefully, this fixes the pay cap on the current positions. Government contractors would receive compensation of 25%-50% more than federal employees for the same work.
It is hard to retain federal employees when private sector are poaching these employees because they already have the training, skills, and security clearance.