Linux nerd and consultant. Sci-fi, comedy, and podcast author. Former Katsucon president, former roller derby bouncer. http://punkwalrus.net

  • 0 Posts
  • 104 Comments
Joined 1 year ago
cake
Cake day: June 22nd, 2023

help-circle
  • Someone did a study at MIT about tin foil hats, and found that not only do they not screen radio interference, in some cases, can actually magnify them.

    Conclusion: The helmets amplify frequency bands that coincide with those allocated to the US government between 1.2 Ghz and 1.4 Ghz. According to the FCC, These bands are supposedly reserved for ‘‘radio location’’ (ie, GPS), and other communications with satellites (see, for example, [3]). The 2.6 Ghz band coincides with mobile phone technology. Though not affiliated by government, these bands are at the hands of multinational corporations. It requires no stretch of the imagination to conclude that the current helmet craze is likely to have been propagated by the Government, possibly with the involvement of the FCC. We hope this report will encourage the paranoid community to develop improved helmet designs to avoid falling prey to these shortcomings.


  • Probably HR (or the NCS equivalent) never told the right people. I am not saying this is actually what happened, but a lot of IT bemoan the fact they are never told some rando employee was fired because HR neglects to inform them. Sometimes it takes months to discover, and even with a 90 day password/login lockout, some halfway decent admin could get around this by secretly building a back door, and using the messed up communication and politics between departments to hide this. Even in the 1990s, I saw people put in “time bombs” in their code that “if such and such is not updated in 6 months, run destructo-script A.”

    But imagine someone like Kandula Nagaraju here. Worked in QA, probably did a great jobs with some skills, but had the personality of swallowing broken glass. He was terminated in October 2022 due to “poor work performance,” which could mean anything. “Not a team player.” Or maybe he really was an idiot: I mean, a smart person would have a conniption, but get employed elsewhere and then slam his former company at parties. “Those NCS folks didn’t know what they had with me!” But this guy was probably someone with some anger management issues, probably a jerk, and possibly stupid. He might have had revenge fantasies, and set up a small virtual server posing as a backup code mirror. But outside the audits, it allowed ssh from the outside, and hid it through a knockd daemon. Or maybe only launched ssh at certain hours before shutting it down again. Silently working away in a sea of virtual servers with little to no updated documentation. He gets in, has internal access, and runs a script with admin credentials because they don’t rotate their AWS keys/secrets quickly enough. Or didn’t even know he was let go.

    After Kandula’s contract was terminated and he arrived back in India, he used his laptop to gain unauthorised access to the system using the administrator login credentials. He did so on six occasions between Jan 6 and Jan 17, 2023.

    That’s embarrassing to the company. Not only did he get in, but SIX TIMES after he was let go. he probably knew what order to run the delete commands (like, say, an aws “terminate-instances” cli command from a primary node), and did so one by one, probably during hours with the least amount of supervision, where the first few alerts would take hours to get someone in the monitoring chain to wake an admin. Given his last day was in November, and he got back in January, the admins probably thought their 90 access credential rotation was “good enough,” but he got in on his 80th day or whatever.

    I know this because I have had to do triage when a former contractor did this to a company I worked for. But instead of wiping out instances, he opened a new set of cloud accounts from the master account, put them in an unmonitored region (in this case, Asia), and spun up thousands of instances to run bitcoin mining. Only because AWS notified us of “unusual traffic” were we made aware at all, and this guy knew his shit and covered his tracks very well. He did it at a speed that could have only been automated. Thankfully, AWS did not charge us the seven figure amount that this activity amassed in just three days.



  • I remember hearing that some Hollywood contracts require that if you sign up for some studio, you must make X amount of films. Big stars get to chose those films to some degree, but once in a while, they have to do “a stinker” to end the contract as “X amount of films done, okay?” or something. Contractual Obligation and all. This film feels like a dumping ground of a lot of those contractual obligation hires from the trailer alone.


  • In the late 1980s, I had a roommate who graduated with a business degree and got recruited for a government contractor right out of college. She packed up her life and moved to the DC area. A month into her new job, the contract was pulled. But because she had a clause in the recruitment contract, they couldn’t fire her. But they had no work for her, either. So she had to come to work every weekday, 9-5. She’d sit at her desk with nothing to do. They didn’t ask her to look busy, just present.

    She read about 3-5 novels a week. Over the next few months, we watched her get more and more depressed. She’d complain about her situation, but it fell on deaf ears. “Must be nice,” people said in jealousy. “Get paid to do nothing.” She became despondent in the lack of people’s sympathy. “Nobody understands how much this sucks!”

    Eventually, she got a new job. Her mood vastly improved.

    I’ll never forget that lesson. People need to feel useful, productive. Sitting at a desk with nothing to do, no purpose, no validation. It will destroy you.


  • I have not done this for Youtube, but I have done it for tech reviews as a ghost writer. Basically, a lot of those tech reviews done under a pseudonym in magazines. No, I won’t tell you which ones, I like getting paid. Anyway, I’d say about 40% I had to send back in a set amount of time, about 50% I am told to destroy or keep, and 10% they don’t tell me and won’t answer my queries. Reselling is almost always a huge no-no, and that also applies to giving stuff away.

    Sounds fun, but some of this stuff is utter, unworkable crap. So many SBCs that never see the light of day, or have the most impotent release announcements on the planet. Like, “this is set for release Jan 3rd, 2024.” Then it’s not ever mentioned on any main page on their website, is listed as a .gz image in their repo (which is on gdrive), but only one release candidate and it’s the same one you reviewed where the wireless chip just randomly stops responding until you reboot. Maybe has a byline on their products page under “this power adapter works with [list of models, including the one they don’t have for sale on the same site].”

    I have two HUD displays I got in 2022, which look amazing, but the screen never powered on (which is why I have 2, they sent me a replacement, which was broken the same way), and I am considering at this point making them some cosplay item or taking it to a rave, because it glows super sexy. But with no working LED screen, kinda useless.



  • They had a multimillion dollar transit project near where I loved, like $112 million to replace a train station, a subway stop, and a major bus terminal to combine them into a single entity near Washington DC. They projected 3 years from start to finish, but it took almost 7. They had to reroute the entire bus terminal to surrounding streets and parking garages, which was a traffic nightmare. People using the train station or subway had to reroute their walk sometimes up to a mile off their present walk. While doing demolition, they found that the previous bus terminal was on the site of an old gas station which had been improperly sealed off: they just filled the tanks with concrete. Underneath that, they found tons of the the natural mineral serpentine, which naturally contains asbestos. So now they had a biological hazard which they had spent the last few months blowing up with dynamite into the surrounding city. After that was cleaned up and sealed, The got underway.

    There were a ton of other mistakes, but when it was completed, they found defects. The superstructure is made of concrete and thus construction specifications were replete with engineering criteria for the composition of the concrete, and its pouring, curing and tensioning. The Inspector General systematically examined 22 project management and control points from the time concrete was mixed until the time it was ready for final inspection. 14 of 22 control points that should have minimized defects were weak or ineffective. Those defects may require recurring engineering inspections, higher maintenance costs, and they could shorten the planned 50-year useful life. In addition, the IG described the risk of concrete falling onto transit-center patrons.

    The entire thing was a huge boondoggle costing the downtown untold millions into the future.



  • I was burned afoul by a former admin who, instead of diagnosing why a mail service was failing, labeled a script as a /etc/cron.d file entry as “…” (three dots) which, unless you were careful, you’d never notice in an "ls " listing casually. The cron job ran a script with a similar name which he ran once every 5 minutes. It would launch the mail service, but simultaneous services were not allowed to run on the same box, so if it was running, nothing would happen, although this later explained hundreds of “[program] service is already running” errors in our logs. It was every 5 minutes because our solarwinds check would only notice if the service had been down for 5 minutes. The reason why the service was crashing was later fixed in a patch, but nobody knew about this little “helper” script for years.

    Until one day, we had a service failover from primary to backup. Normally, we had two mail servers servers behind a load balancer. It would serve only the IP that was reporting as up. Before, we manually disabled the other network port, but this time, that step was forgotten, so BOTH IPs were listening. We shut down the primary mail service, but after 5 minutes, it came back up. The mail software would sync all the mail from one server to the other (like primary to backup, or reversed, but one way only). With both up, the load balancer just sent traffic to a random one.

    So now, both IPs received and sent mail, along with web interface users could use. But now, with mail going to both, it created mass confusion, and the mailbox sync was copying from backup to primary. Mail would appear and disappear randomly, and if it disappeared, it was because backup was syncing to primary. It was slow, and the first people to notice were the scant IMAP customers over the next several days. Those customers were always complaining because they had old and cranky systems, and our weekend customer service just told them to wait until Monday. But then more and more POP3 customers started to notice, and after 5 days had passed, we figured out what had happened. And we only did Netbackups every week, so now thousands of legitimate emails were lost for good over 3000 customers. A lot of them were lawyers.

    Oof.


  • Not just LinkedIn profiles: there was a case out here near DC a while ago where a well known company leased out their function space for training meetings. Using a compromised company account, a set of scammers set up some fake recruitment profiles, leased out the meeting space for “software training,” and did some “mass hiring” where 30 individuals had their credentials scanned and duplicated. The effect was someone from the recruiting company was contacting you, you had a face-to-face where you got offered an in-person, you showed up to their offices, and got a “job offer pending a background check,” with a date of hire in official-looking emails. You sent in your SSN, copies of your passport and driver’s licence, and after a few weeks, they tell you to show up for orientation. Only, the day these people showed up, the company was confused and had never heard of you. The people you supposedly spoke to had never heard of you. And your identity was stolen, and huge loans and charges started showing up in your credit report.

    Yikes.


  • Having moderated forums back in the day, I can answer to some of that motivation.

    First, some people are just bullies. A sense of tribalism forms around bullies, who feel the need to act out and repeat the abuses they have endured. Hazing stems from this, too. Cruelty masked as “you should know better,” advice. Given too late.

    Some have a smug sense of superiority, and want to keep it that way. Less smart people means they stay king of the mountain. Others are scared their own lack of knowledge will cripple them if they don’t keep the potential competition down. Insecurities drown out any sense of empathy.

    Some people hate themselves so they punish others in retaliation. Like, trying to erase past cringe by making others hurt to even the score.

    A few are sick of “the same fucking newbie questions again and again and again,” but still hang out in newbie forums for some reason.



  • really just doesn’t do what I needed to do.

    This has been my experience, or sort of does what I want it to do, but I have to rethink what I need it to do instead of something really simple. Like a “new type of shared file system” that replaces NFS/Windows sharing. So instead of files in a standard file system one can manage with a file browser, it has “indexed” your files in such a way that the actual files are renamed into data chunks, and one “finds” files by their non-intuitive search engine that can’t do even basic search engine tricks like “AND/OR” searches, wildcards, and the results are hit and miss. “But it’s faster and more elegant!” So how do you restore from backup when the system fails? “When the system does whatnow?”

    Yeah, no thanks. I can recover files from a file system much easier than some proprietary encoded bullshit fronted with a bad search engine over a proprietary and buggy index.


  • Punkie@lemmy.worldtoLemmy Shitpost@lemmy.worldtext don't call
    link
    fedilink
    arrow-up
    173
    arrow-down
    1
    ·
    5 months ago

    When I was 19, I had friends from high school who were still younger, and one of them was my friend Julie who had helicopter parents (she would have been 17-18). I was doing security at an event where the radio headsets we had were super-shitty, and the guy running security was a dumpster fire on his own. Julie’s parents forbid her from going to the event, and grounded her to her room. Then her dad called the hotel where the event was being held, was told Julie had “run away” to this event, and that I was somehow responsible. Given she was a minor, the event runners were understandably concerned, although they were frustrated that Julie’s dad was unable to describe her in a way that was useful: “Asian, wearing black, or a tee-shirt, or something. Ask Punkie where she is.” So they contacted the head of security to find me on my rounds to see if I knew what this crazy man was talking about. The head of security said “okay” and did nothing.

    At some point, the head of security was fired for a variety of reasons, and this increased the level of miscommunication. Meanwhile, Julie’s dad was calling every few hours, demanding to know where his daughter was. And soon there was a concerted effort to find me, which was complicated because of the communication issues. By the time someone found me and the connection was made, my response of, “I have no idea, Julie said her dad forbid her coming here,” was not what they wanted to hear, and met with skepticism “You’re not hiding her, are you? Like she ran away with you in some tryst? She’s 17 and you’re 19, that could have legal ramifications!” No. We’re platonic friends, I don’t know where she is. if I tried to bonk the poor woman, she’d clobber me.

    Meanwhile, Julie’s dad finds Julie in her bedroom, right where he left her. Julie later told me that she was ignoring her dad calling for her, and didn’t “come downstairs” like he demanded because she assumed it was a trap to get her punished for leaving her bedroom while she was grounded. So naturally, her dad assumed she wasn’t in the house. Because he called for her and she didn’t answer.

    Poor Julie. Her parents were crazy-nuts.


  • No mention of external dimensions, so I am going to assume that it exists in the abstract since you mention teleportation. Like you just think about it and teleport there, not carry it upon your person like a portable hole in D&D.

    Like others mentioned, a living space of some kind. I’d worry at first where I teleport inside, like hopefully not inside my mattress. Also, when I teleport back out, where is that? Where I teleported in? What if that gets replaced, like say I popped out while in an empty parking garage, but popped back in and a car is now parked where I left off? Might be nice if I pop back out anywhere I choose. Pop in while in New York, pop out in London.

    Man, I’d save so much on rent. Or at least storage.




  • I hate to be honest, but I used Amazon Prime a lot because:

    1. I cannot drive. Thus, getting to the store is difficult.
    2. I must bring in 3-4 items a week, so yeah, I save on shipping.
    3. Auto-subscriptions save a little.
    4. I have priced a lot of stuff over the years, and while Amazon is not always the best, the convenience is impressive.
    5. They have, multiple times, been incredibly helpful with customer service. Like above and beyond.
    6. COVID and nobody masks around here. I have an autoimmune condition, so it’s important that I not leave unless it’s a medical appointment or similar need.
    7. They just have stuff I can’t find anywhere. Yes, as some have said, caveat emptor, but that’s true for all the stores.

    I also save a shit ton of money. When I used to browse Walmart or Target, I used to buy a lot of shit I didn’t need. I don’t get as distracted with focused buying. I also order from Aliexpress if I can wait 30 days, and I have only been ripped off three times in several years, for a total of maybe $35.

    I’m not saying my way is better, and certainly not if it’s better for you, but it’s been a godsend to the house-bound.


  • I had an issue with a UK supplier shipping to me in the US because UK mail is owned by DHL. Two shipments made it to the US, made it to New York, made it through customs and then… “Attempted Delivery, Kein Standort ausgewiesen, US.” Never seen again.

    DHL kept trying to convince me and the seller that “Your German address is refusing shipment.”

    “Last delivery hop was Flushing, NY.”

    “No, last delivery hop was in Kein Standort ausgewiesen. That company refused shipment, it went back to the UK.”

    “‘Kein Standort ausgewiesen’ is German for ‘No location reported,’ dumbass. Where is my package?”

    “… We don’t know. Germany somewhere. Call them.”

    Thankfully my vendor has refunded my money. Sadly, he no longer will ship to the US because this keeps happening to his customers. :(