I simply meant that if you monitor a given application using on-system network tools, you quickly get an accurate idea of what/who that application talks to. And browsers are super-chatty to all sorts of destinations that are not immediately apparent to an end user who is just clicking around the web.
One should be wary of anyone selling you a solution to your problems they know nothing about. Naturally, the only way to be entirely secure is to shutdown all the applications and decommission all the computers, a solution which the business side tends to finds unreasonable. Thus the tender balance between business needs and business risk emerges as the deciding principle.
But the numbers are the numbers in heterogenous environments, regarding security problems by platform. And if it rains perpetual Windows-based incidents on your security staff, and you don't consider the numbers when evaluating what you will and will not do, compute/services-wise, then you are statistically likely to see the same rate of incidents, at whatever cost that comes to the business, indefinitely.
If every car in your neighborhood that gets broken into is manufactured by a single manufacturer, it is in your interest in asking why that is, and perhaps considering that fact when shopping for a new car.
Very curious. Just based on the incidents we see, and analyze over time, almost all of them are compromised Windows systems. When I say "almost", I'll provide these stats: ~4500 Windows incidents over 5 years, vs. two Linux incidents.
Similarly, looking at vulnerability counts by vendor doesn't paint a rosy picture of our largest vendor Microsoft, either. But it pales in comparison to the incident statistics, which speak for themselves.
To Microsoft's credit, they've managed to turn their weaknesses into a secondary industry, wherein they now no longer sell just the disease, they also sell the cure. "Oh, your Windows systems have security problems? Have we told you about our expansive security solutions? They're only an additional $your_budget_doubled per year!"
No, LetsEncrypt was not an EFF project to begin with. Look, it works how it's documented to work. If you wish it worked some other way, to solve your particular suggested workflow, you're likely free to fork it and make it work that way.
No, it's not the LetsEncrypt people who make certbot. Certbot is an EFF project, managed by separate people. Additionally, most of the DNS implementations will require the use of a specific plug-in/library for your selected DNS platform, and those, also, are developed separately.
Regarding "the DNS record they had you add to begin with is still there", it generally isn't. Part of the automation process for certbot using the DNS-01 challenge is the removal of the DNS record, following successful validation of said record. In any complex DNS environment, leaving TXT records around just increases the debris.
For the Microsoft.com domain, proper, there seem to be no existing CAA rules, allowing each and every CA on earth to issue certificates based on whatever criteria the CA requires. What could possibly go wrong with that approach?
The article contains solid advice that certainly transcends coding, alone; in my free time, I try to essentially "find work". Sometimes that work consists of writing software to solve weird little home "problems" that may or may not be actual problems. Sometimes that means building something as a joke, just for fun.
Sometimes that work consists of over-engineering a water heater box-turned-space shuttle for my daughter. Or recording my dog's wheezing and turning it into "classic industrial" music. It all feeds the same internal need, though; to learn, to build, and to produce something, rather than to passively consume other people's products. It keeps my brain alive, and I find improved performance/innovation in other work-related projects, as a result of just staying active, mentally.
And if you're the kind of person that travels in one of these, you likely also have a few additional vehicles in front of and behind your vehicle filled with highly-paid professionals ready and willing to carry you the last mile if your vehicle stops reason for any reason, to include mechanical failure.
The whole armored vehicle market is a relatively small one; it's interesting to learn that BMW is direct participant; I previously had no idea. I foresee a lot of wasted time scouring eBay looking for a project my family will resent me for later in my immediate future!
I was surprised to not see IR beacons on LEO units. In military operations with air surveillance, individuals/vehicles often use IR flashing and IR reflection to mark themselves to air assets. If MPD has the money for 1) an air surveillance unit (this cost is not trivial; SFPD, for example, hasn't had their own aviation section in decades due to the cost), and 2) decent thermal optics on said surveillance unit, then it surprises me they don't spring for sub-$100 IR beacons to distinguish their own personnel from everyone else, and enable rudimentary "blue force tracking", as it were.
Agreed. I invariably lose hours to Folklore every time I end up there. I previously worked for an original Mac team engineer, and he had some fascinating stories, but Hertzfeld's writing allows me to revisit those and so many more tales from that period of Apple/Silicon Valley history, and all without annoying my former boss for more stories.
`brctl status` will return sync status data without requiring Finder. It isn't pretty, but it's usable via stdout and whatever tooling you'd want to use.
SFPD won't do anything about property crimes, to include vandalism, other than to take a preliminary report, on a schedule determined by the department (eg: you call them, they show up 8-12 hours later, uninterested in taking your report). This is because, currently, their DA's office isn't going to prosecute any property crimes.
That can all change, but speculating about the nature or timing of any changes like that is well outside my area, so I'll sit and watch from a distance.
And, again, I'm not vested in any outcome here. It'll work out however it works out, and I'm 2000+ miles away from it, so it won't have much effect on my life.