Notices by mkb (mkb@mastodon.social)
-
mkb (mkb@mastodon.social)'s status on Saturday, 14-Dec-2019 22:19:44 UTC mkb -
mkb (mkb@mastodon.social)'s status on Tuesday, 19-Nov-2019 18:20:40 UTC mkb @freemo I figure it’s impolite to interact with the human unless the dog introduces us first. 😜
-
mkb (mkb@mastodon.social)'s status on Sunday, 17-Nov-2019 20:11:19 UTC mkb Shit.
Hong Kong police move on university campus, begin mass arrests, threaten live fire - The Washington Post https://www.washingtonpost.com/world/hong-kong-police-pummel-university-with-water-cannon-as-officer-hit-by-arrow/2019/11/17/f004c978-091f-11ea-8054-289aef6e38a3_story.html
-
mkb (mkb@mastodon.social)'s status on Thursday, 05-Sep-2019 20:36:26 UTC mkb The folks at @protonmail are bringing their app to @fdroidorg:
-
mkb (mkb@mastodon.social)'s status on Monday, 15-Jul-2019 19:45:22 UTC mkb @jartigag A friend of mine used to say "You know you're about to have a bad day when someone comes up to your desk and asks, 'How much do you know about Sendmail?'"
-
mkb (mkb@mastodon.social)'s status on Wednesday, 19-Dec-2018 22:28:57 UTC mkb This is great:
Zakk Wylde playing Sabbath on a Hello Kitty mini-guitar:
-
mkb (mkb@mastodon.social)'s status on Sunday, 09-Dec-2018 18:11:36 UTC mkb @jartigag Yep, mac filtering is a fine illustration of a key security concept: “Secure” is not boolean.
Any mitigation we can come up with can still be circumvented. The goal is not to make attacks impossible but to shave risk by making attacks incrementally more difficult.
-
mkb (mkb@mastodon.social)'s status on Friday, 07-Dec-2018 22:04:45 UTC mkb The next (and better) mitigation is to use other layers: Use a VPN and use encrypted protocols wherever possible. You want both because VPNs can leak and encrypted protocols aren't always an option.
Actually, I highly recommend everybody use a VPN when using any sort of public wifi. Your university might provide one. If not, commercial options aren't terribly expensive compared to tuition and textbooks. :)
-
mkb (mkb@mastodon.social)'s status on Friday, 07-Dec-2018 22:00:32 UTC mkb There are mitigations but I'm not aware of an ironclad fix.
When thinking about these risks it helps to do a little thread modeling: What specifically do I want to protect? Who might threaten it? What specifically might they do?
A corporate network can help prevent wifi MITM from an outsider by using MAC filtering and the Enterprise variants of WPA/WPA2. That's too onerous for public networks or most smaller orgs.
-
mkb (mkb@mastodon.social)'s status on Wednesday, 31-Oct-2018 19:42:03 UTC mkb `git push` or it didn’t happen.
-
mkb (mkb@mastodon.social)'s status on Wednesday, 29-Aug-2018 19:36:25 UTC mkb Mixed feelings.
Mr. Robot’s fourth season will be its last https://www.theverge.com/2018/8/29/17796672/mr-robot-ending-fourth-season-series-finale
-
mkb (mkb@mastodon.social)'s status on Sunday, 26-Aug-2018 17:34:05 UTC mkb Today is the 100th birthday of technical badass Katherine Johnson. Ms Johnson calculated trajectories for Apollo space missions by hand.
-
mkb (mkb@mastodon.social)'s status on Friday, 17-Aug-2018 23:17:12 UTC mkb “Although VPNs pose special challenges for SIGINT (signals intelligence) collection and processing, we’ve recently had notable success in exploiting these communications,” said an article from the internal NSA newsletter SIDtoday.
https://theintercept.com/2018/08/15/nsa-vpn-hack-al-jazeera-sidtoday/
-
mkb (mkb@mastodon.social)'s status on Friday, 03-Aug-2018 06:04:52 UTC mkb #Elixir is the language I'm most excited about but I've only scratched the surface.
I'm most facile in #Ruby so that's what I've done the most in.
These days circumstances dictate that I do an awful lot in shell scripts. They're grody but still the right tool for certain jobs.
-
mkb (mkb@mastodon.social)'s status on Saturday, 23-Jun-2018 21:34:16 UTC mkb @rysiek @Gargron @charlag @wakest
The consensus among cryptographers is the Signal protocol is top of the heap for secure messaging right now.
Wire's protocol might be fine but it hasn't received the same level of scrutiny. Wire's privacy practices also aren't as robust. Among other things the server keeps a list of everyone you have communicated with.
Ultimately, the right choice depends on your particular application and threat model.