• 2 Posts
  • 131 Comments
Joined 3 years ago
cake
Cake day: June 7th, 2023

help-circle
  • When you get to doing division and multiplication, it can make sense to look at what is being done to what and see if operations cancel out or simplify. E.g. if you are multiplying by 6 and dividing by 2 and bother operations are going to affect the same number/group/etc. there is no need to do both operations, you just multiply by 3 since that’s ultimately what you are doing. Really, any place you can simplify operations, do that. Same goes for addition/subtraction. The Commutative Property is really handy for making hard math easier.


  • Do any of you, living in the US, vote?

    Yup, everyone does. If someone chooses not to vote, they have cast a voted for “I don’t care”. And have decided to let everyone else choose for them. They may not like any of the choices, but politics has always been “the art of the possible”. If they want perfect solutions, they need to start their own dictatorship. If they won’t or can’t do that, voting is the only bit of control they’re going to get. And that means some type of compromise with everyone else in society. It’s a terrible system, but history hasn’t provided a lot of better examples to follow. Don’t like the system, change it. And unless you have the force of arms to do it the violent way (and it’s really unlikely you do), you’re only real option is to do it via the soap box and ballot box.

    Would you ever consider voting DSA/Socially democratic[?]

    Sure, though not any time soon. One of the things I’d like to change about our system is the First Past the Post nature of elections. But, until that happens, the math just doesn’t work in most elections. I vote in primaries and vote for the options who most closely match my views in those. But, come the general elections (especially at the federal level), third parties are basically DOA. I’d rather vote “not Nazi” than sit on my thumbs and watch “Nazi” coast to victory because I’m stuck letting “perfect” be the enemy of “not a fucking Nazi”. Should the DSA reach a point that they aren’t an “also ran” in an election I’m voting on, sure I’d probably vote for them.

    Would you ever vote for someone like Trump just to make things intentionally worse in the hopes of sparking off a revolution?

    Well, it hasn’t happened with Trump. And looking at history, I really don’t think revolutions are such the clean and wonderful things people in online forums like to make them out to be. History provides lots of example of revolutions ending up with groups like the Taliban in charge and basically none ending up as egalitarian utopias.

    Not sure if I will ever vote again at this point

    That’s your choice, but you’ve made the choice to let other people decide your government. You can sit on the sidelines and stew in your own smugness. But, no one cares. And no one will ever care about your opinions if you’re not willing to enter the political milieu and fight for them.


  • LinkedIn is basically a public resume. Using it for anything more demonstrates that you do not have a basic grasp of privacy or security. As such, there shouldn’t be anything up there which is all that bad to have leaked. Sure, if the password database gets dumped, rotate your LinkedIn password (it should already be unique, so no worries about it being reused elsewhere). And having an email address get added to every spam list everywhere kinda sucks. But, what else is the attacker going to get, my name and work history, which are already public on the site?

    I mean, yes LinkedIn should be raked over the coals for shit security practices. And we really need something like the GDPR here in the US to actually do that. But, I’m also not going to get terribly worked up about my public CV being leaked. The leak is kinda redundant.



  • Microsoft’s partner portal website mysteriously said his account had been deactivated, without specifying why.

    My money is on Microsoft’s AI based detections causing false positives again. I spend way too much time chasing ghosts from Defender. Their machine learning based signatures are especially egregious. You get an alert with a name like “Win32/Wacatac.b!ml”. That last “ml” bit denotes that it’s machine learning based. And then you get fuck all to help you determine why the alert fired. Sure, it might actually be a trojan. More likely, it’s a false positive. But who knows, because Microsoft won’t provide enough information to perform a reasonable analysis of the binary.

    And MS has been pushing CoPilot hard. It’s in everything and it’s happy to slop up answers for you. The accuracy of those answers though can be a bit spotty. I’d certainly never turn it loose on tools which can have business impact. But, I doubt Microsoft has any such reservations about letting CoPilot slop all over third party devs.




  • This one is a mixed bag. KYC regulations are very useful in detecting and prosecuting money laundering and crimes like human trafficking. But ya, if this data needs to be kept, the regulations around secure storage need to be just as tight. This sort of thing should be required to be kept to cybersecurity standards like CMMC Level 3, audited by outside auditors and violations treated as company and executive disqualifying events (you ran a company so poorly you failed to secure data, you’re not allowed to run such a company for the next 10 years). The sort of negligence of leaving a database exposed to the web should already result in business crippling fines (think GDPR style fines listed in percentages of global annual revenue). A database which is exposed to the web and has default credentials or no access control at all should result in c-level exec seeing the inside of a jail cell. There is zero excuse for that happening in a company tasked with protecting data. And I refuse to believe it’s the result of whatever scape-goat techs they try to pin this on. This sort of failure always comes from the top. It’s caused by executives who want everything done fast and cheap and don’t care about it being done right.



  • I have two:

    1. Waves glowing with bioluminescence during a red tide. We didn’t know it would be going on and were just camping by the beach. Walking on it at night, we all saw the waves glowing and weren’t sure it was real. As we got closer, our footsteps in the area where the waves were rolling in and out were glowing as well. Just surreal.
    2. A house blowing up. Guy opened a natural gas valve in the house and touched it off. Insulation shot way up in the air and the house itself bowed outwards in basically every direction, stayed standing though. At least until it burned down.


  • I mean, no shit? Part of the Snowden leaks was information that the NSA had intercepted Cisco routers and backdoored them before they were shipped on to international customers. So, even without willing actions by US vendors, there is that to worry about. And the idea that a private company would install a backdoor for US Spy agencies in their infrastructure isn’t new. The fact that any Chinese company is using US hardware/software just seems incredibly stupid. And no one should be using CheckPoint.

    It’s the same reason Huiwei was thrown out of US infrastructure. You cannot build trusted architecture with hardware/software from a nation which you know wants to hack you. I work for a US based company in cybersecurity, we treat WeChat as Chinese State spyware, because it is. We wouldn’t consider a router or firewall from a Chinese based company and we treat any software from China with outright suspicion. Sure that all sucks and we may be missing out on some great stuff which isn’t malicious. But, the risks far outweigh the costs. I’d expect my Chinese counterparts to be making the exact same risk calculation for US based tech.








  • sylver_dragon@lemmy.worldtoAsklemmy@lemmy.mlDoes this really work?
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    1
    ·
    7 months ago

    For the ones they own or have a contract with, probably. However, there are two problems with that.

    1. It will do fuck all for the AI models which are just scraping the internet and which have no contractual agreements with the blog (e.g. all the big ones).
    2. It’s a fixing a problem the blog hosting platform created. They likely have a data sharing agreement with some organizations to make the scraping easy for those organizations (e.g. direct content database access). So, they are like the mob, offering you “protection” so long as you pay them not to break your shit.

  • Location: ~87% of respondents are from Canada

    As others mentioned, this would be an interesting data point to validate. I’m not familiar with the server side of Lemmy, but does the server provide any logs which could be used with GeoIP to get a sense of the relative number of connections from different countries? While there is likely to be some misreporting due to VPN usage and the like, it’s likely to be a low enough number of connections to be ignored as “noise” in the data. Depending on the VPNs in question, it may also be possible to run down many of the IP addresses which are VPNs in the connections logs and report “VPN user” as a distinct category. This would also be interesting to see broken out by instance (e.g. what countries are hitting lemmy.world versus lemmy.ml versus lemmy.ca etc.).

    All that said, thank you for sharing. These sorts of exercises can be interesting to understand what a population looks like.