I used to use linked'[email protected]. It (slightly) broke the interface for reasons I won't understand, but I eventually got lazy and changed it to a normal email. The extra page refreshes were driving me crazy. Seems I should have kept it.
I am a fan of NIST. They seem to be pushing forward with less than average amount of bureaucracy. By definition everything should be public and they don't have any responsiblity for enforcement of the rules which might be a slow pitch to your question.
Drawing from my roots the Canada Wheat board was always surrounded by heated arguments and controversal decisions. There was the UN wheat scandal but that is more a matter of if you believe they are evil and not their level of incompetancy.
They received a significant amount of name calling due to their decisions and policies, but I can't recall any significant missteps in their application of the policies they set out to act upon.
You could make a case for everyone being bumbling and third-rate today. Post an edge case and have a lack of information to counter. I think by not addressing concerns head on gov't agencies are inviting for this type of behavior. I don't agree that stating that you have white labs as a defense for possibly tainted equipment is a full answer. I assume there is more coming since having a white lab test of equipment would be unreasonable for every piece of equipment due to workload. Not testing every piece of equipment to be used isn't a solution either since if Huawei is "evil" then they will just taint the box going to the correct provider.
If the Canadian government doesn't want people talking negatively about them then there needs to be more transparency. Not to the level of risking a breach, but something along the lines of a list of safeguards they are implementing. I wouldn't ever consider one safeguard a solution. If somebody feels the need to call out where the information is, I would legitimately like to read it.
>Maybe i'm just being paranoid but I'm a security engineer. I'm supposed to be.
No, you really shouldn't. Every bad thing can happen unless you protect against it, but being paranoid isn't helpful for this industry.
This was going to happen eventually. If they didn't want this to happen then the funding would be there to have this system built up with triple redundancy (or possibly 7 times, maybe they have triple). We all do the best with the funding we have. The good thing about this is that they assessed the problem and they had remediations for it. They announced it publicly (using several methods) and they have an alternative line.
Given the typical vehicle up here in the North, if the bus has even a few people on it probably is an environmental win. Generally if a person is needed up here then a person will go down and get that person and return with them. Cars are less common than trucks and a "small" truck is a 1/4 ton. Additionally, the greyhound is a popular shipping choice for industry because of the time to ship. Most of the packages/mail gets sorted in Vancouver and then returns back up to Prince George. Putting on the Greyhound and it getting to where it needs to go next day was amazing. Shipping times were often better from Alberta and BC with the major players since the package didn't have to double back. Hotshot services are typically field based, but it isn't rare for somebody to hot shot packages between cities since it can take days through other methods now.
Outside the filehash thing there isn't anything wrong with his responses. The project chose to get third party products from sources outside their control. There is nothing "technically" wrong with it. The thread is littered with poor security practices, but I see TightW's response as more painful. The admin is already clearly aware of the concern and is stating why it is setup that way. I would much rather see somebody state the practices are wrong rather than just calling this guy out since it is really counter-productive.
Why would I assume that Concurrent runs == Seperate Runs or that other caching mechanisms aren't in place or really anything. Computers do really odd things trying to optimize and making assumptions that your system is the same over a period of 30 minutes when you don't even know it is the same 30 minutes is concurrent. There is all sorts of stuff that gets in the way of performance tests and I would like to know how it is mitigated. Again, I am sure there is proper process, but why wouldn't know want to know what that is?
These articles drive me crazy when they don't mention the testing process. Yes, he is using a "server class" machine, but did he disable the features on a hardware level that would skew the test. Answer: probably. I'll assume he did some sort of clear to makes sure that the data wasn't cached on the hard drive or assume that all the reads were in memory. I can't even tell if he ran the test over several iterations.
It isn't that I am doubting the results, but without some trail on how to get the results I can't make this useful information. For example if I were architecting a system and was using this as information I have no idea if I run this in a VM that I need enough memory to get these results.
You haven't seen my collection of cat pics torrent ;)
Also from a more serious stance the danger is the malware vector or the destruction of the ability to have integrity and not the data in the torrent itself.
Do they have a feed into security yet? At the time I reported the release of all the emails and I couldn't get past first line support. They kept telling me that spam wasn't their problem.
I am pretty excited about this as I have few cross-platform languages that I can use (due to conditions at work). I am wondering how many distros will adopt it into their repos.
"Ciphers are math at work" and then gives a substitution cipher as an example. This topic is challenging enough to explain without trying to explain the f(x) -> y concept without a real need for it, but pretty picture right? I know I am taking this too seriously.
The linked in 2012 breach started getting posted everywhere in weeks previous with high visibility. I don't believe it to be related, but I am sure someone may.
This is oddly worded to me and likely going to cause grief as it sounds like your app can only run on IPV6. I would interpret is as your app must be able to run internet connected when IPV4 is not available. This likely includes your local loopback if you are using 127.0.0.1 (which I infer from the hard code statement).
Or another weird to put it, your application must be IPV6 with the option of a IPV4 add-on.
I am wondering how google (mentioned as an offset to bing) is going to handle the availability tweeking and facebooking feature. It will be interesting to see if my searches now reference some persons personal collection of data and take me away from page source. Search engines are all about recent/modified content and might go to the less official/slightly modified sources. The search engine communities are full of intelligent people, but I still can't get the same 5 pages from stack overflow showing up when I have a problem, no matter how I change the search terms. I usually end up going to the site and then going to the reference link in the answer.
Does this mean that the bash/root runs as Local System and not as admin (or the current admin user)? I am guessing, but it seems like a likely way this got missed.
So they removed the very specific search engine friendly, but human unreadable code (such as 0x00000f4) and are now requiring me to carry a cell phone with a working QR Code scanner and forcing me to use microsoft (not bing) search support that is specific to their website as a jump point. I am sure that a search for HARD_DRIVE_CRASH will always come up with troubleshooting tips, but I'll have to wade through 5 pages before I get to the advanced topics that I need.
I know there is an argument for making this more readable, but if you are at the level of fixing blue screens chances are you can use a search engine.
I live in a a pocket region doesn't have Daylight Saving. This year we added the town of Fort Nelson to our little time zone. Nobody concretely seems to remember why we started to do this, but it is generally agreed on that we do it for business reasons. Much of our business is tied to our neighbors to the east in a different time zone. With the winter months typically being more busy. Coordinating resources is much easier given this system. I thought I would throw a counter argument into the ring, although I would state it is an edge case.