Post Ak60rsGN9UWrLC0DMO by w@11n.org
(DIR) More posts by w@11n.org
(DIR) Post #Ak5s3cmbdKXXDYbjXs by lanodan@queer.hacktivis.me
2024-07-19T16:13:27.831663Z
4 likes, 1 repeats
> Wakes up> Gradually discover the Crowdstrike thingFun way to wake up (as least as a self-hoster).
(DIR) Post #Ak5xpwqepk8h7VMfDM by drewdevault@fosstodon.org
2024-07-19T17:17:04Z
1 likes, 0 repeats
@lanodan I know it's mean but I low-key enjoy watching horrible vulnerabilities or IT failures unfolding when they don't affect me
(DIR) Post #Ak5y38sjP9q6Cocs0u by lanodan@queer.hacktivis.me
2024-07-19T17:25:11.899357Z
0 likes, 0 repeats
@drewdevault It's mean but at the same time, identifying SPOFs is something all somewhat critical infras ought to be doing.And then actual software audits but that's step 2 at least. :/
(DIR) Post #Ak5zy3uQfJ6ZFB7pmy by drewdevault@fosstodon.org
2024-07-19T17:41:02Z
2 likes, 0 repeats
@lanodan I feel like proper data management and principle of least privilege should be employed before you install a proprietary auto-updating rootkit on all of your machines
(DIR) Post #Ak60rsGN9UWrLC0DMO by w@11n.org
2024-07-19T17:49:54Z
0 likes, 0 repeats
identifying single points of failure is (sometimes) easy, convincing someone who can effect change to care is the real trickCC: @drewdevault@fosstodon.org
(DIR) Post #Ak60rteVzDR1eMJ0d6 by lanodan@queer.hacktivis.me
2024-07-19T17:56:47.024436Z
0 likes, 0 repeats
@w @drewdevault Which is seriously worrying when it's things like 911 and hospitals which I guess don't have the proper social ways to address those.It's quite like if during a fire drill you'd realize you can't escape the building when the electricity is out (yeah that happens) but then actually nothing gets done about it.
(DIR) Post #Ak6AbEVMChh6wOiOFU by w@11n.org
2024-07-19T19:43:51Z
0 likes, 0 repeats
@lanodan@queer.hacktivis.me @drewdevault@fosstodon.org a lot of it comes down to cost. It's hard to convince someone to proactively replace eol'd equipment when it's still working 'perfectly well'
(DIR) Post #Ak6AbFRqhETxro56Q4 by lanodan@queer.hacktivis.me
2024-07-19T19:45:51.120472Z
0 likes, 0 repeats
@w @drewdevault I don't think any of the CrowdStrike incident was due to EOL equipment though? More like the opposite I'd say.
(DIR) Post #Ak6EgFdZouD5iaCxSi by w@11n.org
2024-07-19T20:29:51Z
1 likes, 0 repeats
@lanodan@queer.hacktivis.me @drewdevault@fosstodon.org you're right, I was speaking more generally. It's been a long day 🙂