Skip to main content


A recent chat lead to the idea of the Standard Reference Olympian

Someone who is *not* good at the sport. Just to remind everyone how intense everyone there is.

"Oh this person got 20th place! Unremarkable"

make people compare them to the SRO

in reply to silverwizard

@silverwizard At least the SRO wouldn’t have defended “her creative vision” in the numerous interviews she’s given since.

silverwizard reshared this.


The assassin awaits the order, watching my mouse hover over the terms of service agreement checkbox as I login to watch The Mandalorian.

reshared this


skategoat 🐐 🇵🇸 reshared this.


Hey #Bhyve/#FreeBSD people!

I'm trying to manage USB passthrough into a guest, I can't find anything in the manpages. Is there something I'm missing?

reshared this

in reply to silverwizard

Not currently supported, as far as I’m aware. The closest you can get is to pass through a whole USB host adapter PCI device to the guest, then all devices connected to its ports will end up in the (same) VM.
Proper USB passthrough isn’t ridiculously difficult to implement by any stretch, but I guess nobody’s got around to it yet.
in reply to Phil Dennis-Jordan 😷

@Phil Dennis-Jordan 😷 "Not missing something" is a good answer! Thanks!

I gotta figure out if I have a host I can give my homeassistant server. But thanks!

in reply to silverwizard

You can pass entire USB controller (PCI passthru) into Bhyve VM but not a USB port or USB device.

Here instructions how to do it:

vermaden.wordpress.com/2023/08…



Alone for lunch (yes it's 4pm) for the first time since the kids were born.

writing a complex regex to manage emails, since, ya know, I know how to have fun.



I get all my music as FLACs because I'm not unwise.

My car will only play mp3s (and oggs?!).

This 2012 MacBook Air is not made for this find command.



InfoSec: If you use the wrong crypto, and have SSL broken, you could, maybe, get the email of the user. 10/10 CVE, Information Disclosure

Also Infosec: This Is Good And Normal


This battle was lost a long time ago. There is no going back to sane defaults. Data collection is now the primary goal of paid and free products. You don’t own anything, and you will be happy. Of course, you can still use privacy-enabled products at home, but those options are limited, and not all your apps will be available. bsky.app/profile/ahhmandah.bsk…


knightly reshared this.


've seen so many hearing aids on kids this week, often low profile, some very large, all taking wild abuse, like a child spraying his repeatedly with a water jet in a splash park

and - I feel so good about this - this is the core of accessibility - you didn't see a lot of deaf kids before because they were isolated! and now they're not!

in reply to silverwizard

almost sounds like that one kid wants some quiet and is trying to break it ;)

Bee O'Problem reshared this.


Phillips Hue keeps threatening me they're going to shut down everything. I put their app on a side device that wont download things and I don't update it, and I put their bridge on a no-internet-access VLAN - but I'd like to just not deal with their shit.

Is there a bulb that doesn't deal with their shit?

Unknown parent

@Neil Brown UK is a tall order, but I'd love to get good Tasmota bulbs. I am dangerously close to building one.
Unknown parent

@Mischa 🐡😎 Wait - you can connect them directly through zigbee?!

Hmmmmm

Bhyve USB passthrough reseach commences.



silverwizard reshared this.


Where can I get COVID tests in Waterloo region? @waterlooregion

reshared this



Security is Threat Modelling

Security Advice or guidance without a threat model is not correct. Full stop.



the Humble Bundle copy of Gratuitous Space Battles I bought years ago is causing OpenAL issues every time it makes a sound and seems to have no mute option.

I need to figure out dummying the linker...



Last night I had a dream that I was (kinda accidentally) elected UK Prime Minister, and I was confused as hell because I was a tourist and didn't know any of the ritual.

And I think that it's telling about the UK that my brain can find no holes in the theory that this is plausible



Security vendor demanding I install servers in my network running out of date FreeBSD which can't be updated and RCEs in SSH

I really wish there was a compliance framework these types needed to follow

Unknown parent

@The Psychotic Network Ferret I think it's so they don't need to tell me it's FreeBSD.

They also tell me to use the IP address on eth1 and the server *is FreeBSD*.

It's 11.4 so it's not dire - but it looks like they haven't updated it ever. I tried a poke at pkg and they don't have their own repo so the repo is just gone. And yes, the SSH is 8.4 from 2022.



Talking to coworkers "Remember, your laptop is 4-10x as powerful as one of the servers, your laptop has to run Slack and none of the servers take that kind of abuse"


The company I work for is really great, but the CEO is toxic as hell

Just completely and impossibly.

We had an outage and he joined the technical call, and started throwing out ideas and forced the response team to *stop* discussing the issue and *instead* explain why he was wrong.


silverwizard reshared this.


OH: this meeting couldn't have been an email, because the email client would warn you about the empty body

silverwizard reshared this.


eleven of the Bitcoin 2024 speakers are named Matt

(screenshot is a portion of a longer list, not the entire list of speakers)

#crypto #Bitcoin2024

reshared this


in reply to silverwizard

yes, provided you add enough sugar, but I doubt it'll taste fantastic.
in reply to þēodrīċ

@þēodrīċ I mean, probably do a very strong tea, as strong as I can get it, and then add a sugar, the problem is finding a good sugar for the yeasts to not sour, while also leaving the flavour dry


The problem with my current employer isn't the lack of technical sophistication, it's that everyone outside of the dev org thinks my skillset is fungible with every other person inside the dev org.

Despite me being hired explicitly outside the dev org's purview because it *isn't*

in reply to Alex P. 👹

@Alex P. 👹 I was hired by someone who knew what they were doing and given Infrastructure and Security as purview, and now everyone says "this person does DevOps" which... hurts every time
in reply to silverwizard

@Alex P. 👹 the real problem is when people
1) tell the dev lead about like, DNS changes or whatever, and then they don't tell me "but it's all engineering"
2) asking me to deal with frontend JS or python code that just... I don't know

silverwizard reshared this.


Resist the urge to be the smartest guy in the room; JD Vance fucked a couch and we just need *one* reporter to ask him about it on camera, one time - bonus points if he actually tries to respond.

We can do this.

silverwizard reshared this.

in reply to AnarchoNinaWrites

ooh, ooh. someone from, like, the BBC or some fancy shmancy European news agency. that way they won't get blocked or pre-screened cuz they're not american media.
in reply to your auntifa liza 🇵🇷 🦛 🦦

Like they don't even have to ask him "did you fuck a couch" they just need to ask him if he's aware of the RUMORS he fucked a couch.

This basically ended Ted Cruz, you don't hear about that guy nowhere except Fox News anymore...

Unknown parent

vruz

@sillyCoelophysis @inquiline @blogdiva

I don't have the time right now, but an ingenious mind could conceivably design and distribute among the Democratic base a new poster with JD Vance's likeness rendered in the famous style of Shepard Fairey's "HOPE" but with the word "SOFA" underneath.

Do it, internets! 😂


silverwizard reshared this.


uspol, i can't believe i need to say this

Don't normalize "make america X again," no matter what X is.

Don't normalize "lock him up," no matter how many felonies the SCOTUS is erasing for him.

Don't normalize "stand back and stand by," no matter how funny you think your meme is.

This shit is all deeply fascistic, and repeating it isn't actually subverting it.

reshared this

in reply to Irenes (many)

uspol, i can't believe i need to say this
@ireneista Like what is actually entirely wrong with people? Good fucking grief.
in reply to Cassandra Granade 🏳️‍⚧️

uspol, i can't believe i need to say this
we try to be charitable in our assumptions - maybe people just aren't in the habit of thinking about that - but anyway yeah, this one really ought to be obvious
in reply to Irenes (many)

uspol, i can't believe i need to say this
@ireneista I try to be charitable as well, but "stand back and stand by?" Seriously? That can't be rehabilitated, it just cannot.
in reply to Irenes (many)

uspol, i can't believe i need to say this

Some of them I just don't get because I never heard of, such as that "stand back" one.

"X again", I don't know, "native again" would be an interesting one. Land back thing.

As for "lock him up", I do have to wonder /why/ USA presidents seem to always get away with absurd atrocities without any consequences. There are a lot of other countries where they /wouldn't/ be an exception to the law.

If they didn't want those laws to remain an issue, maybe they should've endeavored removed them while they could?

in reply to LisPi

uspol, i can't believe i need to say this
there's this thing where many USians treat politics as a spectator sport, or perhaps a Hollywood movie, rather than as something that has real consequences for people's lives. the hyper-real simulacrum of governance rather than the real thing.
in reply to Irenes (many)

uspol, i can't believe i need to say this
That is a very strange thing.
in reply to LisPi

uspol, i can't believe i need to say this
@lispi314 @ireneista It's definitely egged on by horse-race style reporting, where the polls are the news and not candidates' policies or character. I mean, folks are still talking about Biden's disastrous debate performance, but I haven't heard a single word from the mainstream about how Trump spent the entire debate spouting heinous slurs about immigrants.
in reply to LisPi

uspol, i can't believe i need to say this

@lispi314 @ireneista in one of the 2020 debates Trump was asked to denounce white supremacists and specifically the Proud Boys, and he said “Proud Boys, stand back and stand by” then changed the subject to antifa

youtu.be/JZk6VzSLe4Y?si=3dLVkt…

in reply to ShadSterling

uspol, i can't believe i need to say this
there were reports, which we have not personally confirmed, that that group immediately responded by printing up tee-shirts for themselves with the quote on it. in its practical effect, the remark was an endorsement of political violence such as Jan 6.
in reply to Irenes (many)

uspol, i can't believe i need to say this
@ireneista @lispi314 yeah, I’d forgotten about that - I saw reports that included pictures. Publicly telling them to wait for instructions certainly isn’t denouncing them, and IIRC was near-universally seen as an endorsement
in reply to ShadSterling

uspol, i can't believe i need to say this
@ShadSterling @ireneista @lispi314 I can confirm that at least some shops still sell a shirt with that phrase and the initials PB, but I have no evidence that the design traces back to the Proud Boys directly.
in reply to Cassandra Granade 🏳️‍⚧️

uspol, i can't believe i need to say this either

Making fun of Vance for having had four names is not a great look. Changing names isn't a problem, let him have a dozen or so.

Him being a simulacrum formed out of the rarified id of Moldbug, Thiel, and MRA Reddit is a problem.



Google breaking NewPipe forcing me to properly setup my flows for watching video on Nebula


After the giant DDoS on DynDNS I started multi-hosting my domains and almost everything else. But no one will pay for multi-cloud. And I don't get why we never learned this lesson?

Field Replaceable Unit reshared this.


Honestly, the amount of time I spend flummoxing security vendors by saying things like "Oh, we're not using office 365" is very upsetting

It's not that I don't understand that 99% of their clients are using O365, it's how many products and support team fall apart



the booze is on strike

what a fuckin' weekend for the booze to be on strike



silverwizard reshared this.


So, I teach info security and IT governance certification courses.

And I have endured many years, it feels like many lifetimes, of “certifications don’t matter. Just make a home lab!” And “compliance doesn’t equal security!” From people who get paid a shit ton more than I do.

And I just want to say, accountability for this in every organization that is affected lies with the board of directors. Period. You cannot outsource accountability. There will be lawsuits. And downstream impacts.

So, you’re right. Certifications and compliance don’t equal security. But today it sure as hell seems like having a management team and BoD that can’t just say, “I had no idea automation was so risky and we needed security staff to evaluate releases” is a better option than “Fire the security staff, automate the hell out of everything, and don’t bother me until I’m back from my golf vacation.” Followed by the exhausted techs shrugging their shoulders, saluting the boss, screaming “YOLO” and hitting enter.

reshared this

in reply to Vickie Gray

@silverwizard yes exactly this. I remember the risk assessment doc I wrote in 2018. But no, KPIs not well set… so….


Tezrak, Impslayer of Worlds reshared this.


Remember
This is the fault of Crowdstike's C level execs

This is not the fault of the scapegoats they will blame this on

This is a failure of time, budget, expertise, and process.

They cut costs by cutting quality

in reply to silverwizard

reuters.com/technology/crowdst…

Honestly, looks like CrowdStrike said some shit would go down because they were contracting. Which uh - good call.

in reply to silverwizard

Every hacker in the world is posting this right now

I am assume it was Ed Zitron's post



in reply to K. Reid Wightman 🌻

still wondering where this strip is from 🤔 Is it „Red Rackham's Treasure“?
in reply to Anaximander

@anaximandro adventures of tintin. see: amp.knowyourmeme.com/memes/wha…

silverwizard reshared this.


More critical infrastructure should depend on a rootkit built by some private company with no accountability imo. It seems good.
This entry was edited (4 months ago)

reshared this


серафими многоꙮчитїи reshared this.


Banks are screwing my wife around. Her mom put some money in an account years ago for her, and she's pulling it out to put it somewhere more reliable, but the cheque was listed in both names, and so banks are refusing to deposit it because it's in the name of two people. So she tried to go into the bank with both of them and endorse the cheque in front of bank employees, which even then they are being a pain in the ass about. This is stupid.

But she went in this morning.

CROWDSTRUCK

in reply to silverwizard

@silverwizard *sick electric guitar riff*

I was caught in the middle of an OS update (Windows)
I looked 'round and I knew there was no turning back (Windows)
My mind raced and I thought, what could I do? (Windows)
And I knew there was no help, no help from you (Windows)
Sound of the drums beating in my heart
The thunder of BSOD tore me apart

You've been - crowdstruck

silverwizard reshared this.

in reply to Hypolite Petovan

@Hypolite Petovan crowdstruck is the verb form of "ruined by a vendor"

"CrowdStrike was worse, but SolarWinds was another vendor that crowdstruck everyone"


Sir Rochard 'Dock' Bunson reshared this.


Ug, I should have paid @404 Media long ago, they are the best reporting I've seen.

But at least I paid them Wednesday and I assume that my subscription will be spent on the spirits needed to get through their next few calls to CrowdStrike.

aacur8 reshared this.


silverwizard reshared this.


There is something to be said about security through diversity that I am just not caffeinated enough to express right now, but really, consider maybe not making all computing infrastructure look the same if you're interested in resilience and dependability.

reshared this

Unknown parent

Peak Twinner
@winterschon Pretty sure you're late for caping for an AI-assisted shrapnel bombing of a children's hospital somewhere. Better get to it
in reply to DJ Sundog - from the toot-lab

That is sort of supposed to be the Crowdstrike model, the mass pooling of leads and heuristic tuning. It works fairly well. Until it doesn't.

silverwizard reshared this.


Let's cut the bullshit and spell out a few things. The IT security industry is about as trustworthy as the food supplement and vitamin industry, but somehow they escaped the same reputation. Their products are overwhelmingly based on flawed ideas, and the quality of their software is exceptionally bad. And while not everyone will agree with the harshness of my words, I'll say this: Essentially everyone in IT security who knows anything in principle knows this.
in reply to hanno

@bagder Companies don’t buy Crowdstrike because they want security, they buy it because they need compliance. It's never about actual security, it's checking a box.
in reply to hanno

An open source threat and mitigations management tool would be nice. With version control and what not you need for traceability towards regulators. Instead I'm writing this shit in Confluence now ...


The best part of owning a VR headset is that I can put on the headset, use it for an hour, remember why it sucks, and then move on


using the Serverless Framework to update some lambdas

And all I can think of "Didn't I use a framework so I didn't have to type the same thing a billion times?"