• 2 Posts
  • 682 Comments
Joined 3 years ago
cake
Cake day: June 7th, 2023

help-circle





  • I deal with this sort of thing pretty regularly for the company I work for. We get threat intelligence from several vendors when they see our users show up in “dumps”. Basically, threat actors will package up stolen credentials in a large zip file and make that available (usually via bittorrent) for anyone to download. Security vendors (e.g. Mandiant, which Google bought) download those dumps and search for accounts associated with their customers and send out these warnings when they find one. On the customer side, if the breach was recent we’ll force a password reset and warn the user about the breached password, with a recommendation to change their password on the affected site and also change any passwords which might be similar elsewhere.

    Why do we force the password reset, even when it wasn’t the account for our business which was breached?
    There’s a couple reasons for this. First off, people still reuse passwords all the fucking time. Maybe this victim didn’t, but we have no good way validate that. Second, even without direct reuse, folks like to have one main password that they apply slight variations to. They might use “Hunter 42!” at one site and then “Hunter 69*” at another. This isn’t smart, attackers know you do this and they have scripts to check for this. Lastly, if an organization is following the latest NIST guidance, you’re not changing your password on a regular cadence anymore. With that is the expectation that passwords will be rotated when there is a reason to suspect the credentials are compromised. Ya it’s annoying, but that’s part of the trade-off for not having to rotate passwords every six months, we pull the trigger faster on forced rotations now.

    If you get one of these, consider it a good time to think about how you come up with and store passwords. If you are re-using passwords, please turn off your computer/device and don’t come back to the internet until you have thought about what you have done. If you aren’t already using one, please consider a password vault (BitWarden or KeePassXC make great, free choices). These will both help you create strong passwords and also alleviate the need to memorize them. Just create a strong master passphrase for the vault, let it generate the rest of your passwords as unique, long (12+ character) random junk, and stop trying to memorize them (with the exception of your primary email account, that gets a memorized passphrase).





  • This sort of thing is just awesome. I really wish there was more information on repairing these sorts of electronics out there and accessible to non-electricians. I do get that sometimes it really does take someone with a lot of specialized knowledge and training to troubleshoot and fix things like this. But, even basic, “look for X and try Y” type stuff for us plebes to make the attempt. Sure, we’ll fail as often as we succeed, but even that would save a lot of electronics from the scrapheap.







  • While that is possible, I’d seriously doubt it happening. Wagner’s run at Moscow seemed like the best opportunity for that to happen, but it just stalled out. I’m still surprised Prighozin, stopped his push short of Moscow. I was not surprised afterwards when an airplane he was on suffered “technical difficulties”. But, between the failure of Wagner to remove Putin and them now being rolled into the Russian military, I think Putin has done a lot to consolidate his control over the armed forces, exactly to prevent that outcome.

    Ya, it could happen, I don’t believe it’s likely.


  • The big ones for me were a frequent, sudden, urgent need to pee and getting up multiple times a night to pee. I also drank a copious amount of water. Like, the whole “eight glasses a day” thing which used to be popular was confusing to me, as I’d drink that much in the first couple hours of the day. I finally went in to the doctor and got a blood test and my A1Cs were well over the “welcome to Diabetes Land” number. With diet, exercise and drugs I’m well controlled now and caught it early enough that I still have good feeling in my feet. Given my family history, and all the shit I ate in my younger days, it’s not really a surprise. I just have to be more careful now, but I have discovered an enjoyment of climbing because of it.

    Really, if you have any family history of diabetes, start visiting your doctor on an annual basis and getting a blood test. It’s simple, and catching it earlier is good for preventing problems with neuropathy in your feet.


  • While I like the sentiment, unless the EU is interested in a WWII style total war and invasion of Russia, Putin is never going to be held to account for the invasion of Ukraine.

    The Russian government (Read: Putin and his cronies) are not going to agree to hand Putin over to The Hague. Even if the current war ends on favorable terms for Ukraine, that is never going to look anything like the German or Japanese surrenders. At best, this war ends with Russian military exhaustion and withdrawal. More like the end of Soviet involvement in Afghanistan. There will be no push to Moscow, no mass bombing of Russian factories or cities. Just Russian soldiers packing up and going home, leaving death and devastation behind for the survivors of their invasion to deal with.

    Any negotiated peace is going to look pretty similar. It will stop the death sooner at the cost of giving Russia something it’s willing to accept. That’s the way negotiations work. If you want to force the other side to accept your terms, without any compromise, that’s what war is for. Since it seems neither the EU nor the US are willing to engage in a direct confrontation with Russia, then the only choice to end this war early is compromise. And Putin facing accountability is almost certainly not going to be on the table.



  • It’s a simple test really. Have you ever considered thinking about having a inclination to plug the drive in? Well it’s probably broke now.

    In all seriousness, I used Zip and Jazz drives professionally back in the early '00s. And gods above and below we lost so many hours of work to them just crapping out. We used them for system imaging. We were building out bespoke servers and workstations for physical access control systems. We stored golden images on zip discs and would image completed systems to send to the customers along with their systems. We created those images on other zip discs before taking them to the one system with a cd/dvd burner. We chewed through so many zip discs it was crazy.

    I finally setup the dvd burning station on a cart so it could be wheeled over to customer systems. It provided a PXE server to boot from and images to both load the golden image over a network switch and image the competed systems. The savings in time and dead zip discs was huge.

    I get playing with those things for nostalgia. But the only thing they could be relied upon to do was die.


  • The Felon in Chief can bluster all he likes. When people don’t have the money to spend, they ain’t gonna spend it.

    This is also why the Trump administration is considering helicopter money checks. These types of hand-outs can give people a sense of having money. The problem is that it ultimately drives inflation. We saw this with the stimulus checks during the pandemic. Arguably, something was needed then to support people during an actual emergency. But part of the inflation problems we have now can be traced back to those checks.

    “Tariff” checks may give a short boost to holiday buying. But the long term damage is not going to be worth it to anyone but Trump. And that assumes the short term benefits last through the 2026 midterms.