Well-written, I appreciated the absence of the kind of over-excited writing you often see in these kinds of posts.
At least with the second app (admittedly judging by that UI) this is a classic case of some team that has only every built apps that sit behind the firewall being made to “move to cloud,” without any understanding of what it means that their code is exposed to the internet.
I’ve seen a lot of orgs “solve” this not by fixing their code but by using Direct Connect to keep everything within the corporate network boundary; since after all compromised VPN credentials are another team’s problem!
This is not a Google-wide thing… this is from Google’s Context-Aware Access product, which is configurable in Google Workspace environments. OP should direct their ire at their corporate IT or infosec team.
Another fun Zendesk “feature,” that, to my knowledge, has never been fixed is if you CC it on a thread with any other email address that auto-replies, it will get stuck in a loop and ping-pong emails back and forth until the mailbox fills up.
You’ll still have the ability to install arbitrary drivers and support software obtained directly from the manufacturer, this change only means that Microsoft won’t automatically supply OEM driver files via Windows Update.
Holy moley, my first “real” computer ran 98SE and had BLACK ICE, which behaved exactly the way you described.
I remember I would take the IP addresses of the “attackers” and plug them into a McAfee graphical tracert tool, and it felt like nothing short of something out of GoldenEye.
Maybe so, but regardless of the facts this would almost certainly not be worth pursuing… In the US, courts are generally prohibited from enforcing foreign libel judgements against US persons if the country in which the judgement was won has looser libel standards than the US.[0]
An interesting tidbit from the Bloomberg live thread[0]:
>The FDIC prefers to close a bank over the weekend, shutting it down on Friday and reopening Monday, Steven Kelly, senior research associate at the Yale Program on Financial Stability, told me.
>“The midday takeover suggests the bank couldn’t responsibly operate until the end of the day,” Kelly said.
Related to (2) is an RWSL[0] system, which was supposedly in use at the time of this event and is designed to stop exactly this sort of thing… whether it was functioning, the pilots didn’t see it, etc, will surely come out in the ensuing investigations.
ETA: another comment suggests that while JFK has RWSL, it was not installed at the intersection where this occurred.
The Board doesn't have a choice, under CIPA[0], content filtering is a requirement for the FCC's E-Rate program[1] in which the government pays some of the cost of the school's internet connection.
Android support != Nexus hardware support. It seems like you're much better off support-wise if your phone's screen is shattered than if you are having any sort of issue with the software...
At least with the second app (admittedly judging by that UI) this is a classic case of some team that has only every built apps that sit behind the firewall being made to “move to cloud,” without any understanding of what it means that their code is exposed to the internet.
I’ve seen a lot of orgs “solve” this not by fixing their code but by using Direct Connect to keep everything within the corporate network boundary; since after all compromised VPN credentials are another team’s problem!