• 0 Posts
  • 142 Comments
Joined 1 year ago
cake
Cake day: July 2nd, 2023

help-circle




  • Using Kali? Easy if you have training. The capstone for our security course a decade ago was too find and exploit 5 remote machines (4 on the same network, 1 was on a second network only one of the machines had access to) in an hour with Kali. I found all 5 but could only exploit 3 of them. If I didn’t have to exploit any of them 7 would be reasonably easy to find.

    Kali basically has a library of known exploits and you just run the scanner on a target.

    This isn’t novel exploit discovery. This is “which of these 10 windows machines hasn’t been updated in 3 years?”




  • Separation of data between accounts makes them fall under different retrieval requirements.

    As one account, a request for all of the data from that account contains both chunks. Separation of those accounts separates the need to accommodate requests for data from one on the other.

    It can also mean that internally they may have a sufficient mechanism that data that was previously identifying to no longer being identifying (breaking userid to data pairings for example) which is sufficient to “anonymize” the data that it no longer needs to be reported or maintained.


  • GDPR and pii reasons most likely. It’s a nightmare keeping track of why certain data is on certain accounts. This can vastly simplify the GDPR compliance mechanisms. If your GOG account is merged with your PR account, there is probably significantly more “sensitive” data (CC numbers, addresses, etc) in the GOG account. This probably exempts some data that either cdpr or gog tracks from deletion or retrieval requests.


  • A question to consider seriously: name a company that has a full OS that supports modern tooling/development environments with consistent graphical fidelity across a wide range of hardware that a manufacturer can pay to maintain the host OS, provides guarantees to OS LTS/security patching and has a proven track record in deploying, supporting and delivering kiosk support.

    The only serious answer is Microsoft, and maybe Canonical… But Canonical hasn’t been around for as long as most of these kiosks have.

    There are a couple of huge blockers for manufacturers looking at companies that provide Linux support:

    1. Industry track record. Red Hat, Canonical, Google and Oracle are basically the only large scale players in the enterprise Linux support. Red Hat basically only provides support for server/backend infrastructure. Has Google had anything other than Gmail and maps last for more than five years? So that leaves us with Canonical. What’s the longest release Canonical has? 4 years now? Microsoft has 15 year support contracts. The only other player in the market that even comes close is Oracle (Oracle still supports Java 1.4 for example: 22years)

    2. Consistent graphical performance: until the last 5 years graphical fidelity on Linux has been a shit show. A decade ago, getting even the largest players to support Linux was a huge undertaking. Basically the only consistent graphics support was the result of android and that is basically only mediatek.

    3. Development environments. Windows wins this hands down without even a question. Go back 15-20 years and it’s even more obviously in Microsoft’s favor. NET gui apps are brain dead easy to make, super consistent and stupid easy to maintain. This drastically decreases development time and cost allowing companies to pay for the crazy expensive support contracts.

    The numbers these companies deal with isn’t thousands or even hundreds of thousands of dollars. It’s tens or hundreds of millions. There is no way in hell a manufacturer is going to give an untested bespoke Linux distro maintainer 25 million to keep that Linux distro running for the next 10-20 years. There isn’t a feasible way for a small company to even support at that price for that length of time.

    Oracle and RedHat are the only truly feasible options, and it costs more to develop GUI apps on either platform when there isn’t a 20 year track record of known success. It’s obvious why companies pick Microsoft.







  • fkn@lemmy.world
    cake
    toMemes@lemmy.mlWhat a classic song though
    link
    fedilink
    arrow-up
    4
    arrow-down
    1
    ·
    5 months ago

    Them: “How do I get to your place in my career?”

    Me: “What do you mean?”

    Them: “You… Have the position I want eventually. What did you do?”

    Me: “Well. 20… No that cant be right… I mean… Yeah… 20 years ago… I graduated college… Then uhh. I’m… Uh…”

    At this point either you make up some bullshit or you say it’s just experience. Then you realize what a midlife crisis is and wonder if you are having one which like like 20% of the definition of a midlife crisis.


  • fkn@lemmy.world
    cake
    toMemes@lemmy.mlWarm Water Port Envy
    link
    fedilink
    arrow-up
    4
    arrow-down
    1
    ·
    5 months ago

    Most Americans on the west coast call any place a shipping container can unload or an aircraft carrier to dock a port.

    A grand total of zero Americans would ever think to disambiguate a warm water port or not. Especially from Texas. That’s the weird part. Not the word port itself.

    Harbor is usually reserved for non-commercial or fishing use only.