Forgot your password?
typodupeerror

Comment Re: Only the "flagships"? What a ripoff (Score 1) 69

I'd hate to even justify this with a response, but almost all smartphones lack a physical keyboard so a hardware keylogger wouldn't even be possible. Beyond that there's no information to suggest some type of global smartphone backdoor exists, if it did it would put vendors like Cellebrite out of business instead of the FBI paying them for their hacks.

Comment Re: "Trade issue" my ass (Score 1) 225

Unfortunately while I see you for trying to "own the libs," your Breitbart-world fantasy where abortion is for Democrat women is a complete fabrication. Rates are similar across party lines with Independent women having slightly more abortions. Democrat women are significantly less likely to report ever being pregnant in the first place, probably because they are smart and educated about birth control. https://www.kff.org/womens-hea...

Comment Re: Help Me Understand (Score 1) 39

Indeed, but on normal corporate networks (if IPv6 is even enabled) devices are still behind a firewall or ZTNA/web proxy like Zscaler, and the external interface for those addresses are filtered to disallow direct ingress.

If your cloud environment is binding an instance e.g. EC2 to a routable public IP and you have any ports exposed, it's going to fail every check in the books. Some careless folks or noobs might do this, but in that case, you've probably also got other security problems. Longstanding best practice is using a load balancer/CloudFormation/CloudFlare/CDN etc for any public ingress. This also wouldn't be the case for endpoints, which my example was around.

Comment Re: Only the "flagships"? What a ripoff (Score 1) 69

In the case of GrapheneOS the "someone" often means law enforcement, as the current famous case regarding the duress code exemplifies (https://www.androidauthority.com/grapheneos-duress-pin-us-prosecution-3691271/). It could also mean an "evil maid" scenario, or an "evil lover" or someone with time-limited physical access to the device. Most of the point of using GrapheneOS relates to these physical exploits, remote exploitation of an iPhone or Android device is possible but rather difficult in comparison to the physical ones. The physical exploits just require using a device like a GreyKey or Cellebrite, which any law enforcement organization can simply buy without having to deploy zero-day exploits; which are mostly the realm of intelligence agencies rather than local police and CBP.

Comment Re: Only the "flagships"? What a ripoff (Score 2) 69

Only the "flagships" have the necessary hardware security to support GrapheneOS. If you want to cheap out on a phone, you get phones without hardware-backed keystores, secure enclave or equivalent, verified boot, processor HAL blobs and sandboxing etc etc. That leaves them open to numerous physical attacks that can make installing GrapheneOS not improve the device security.

Comment Re: Help Me Understand (Score 1) 39

You would need another computer on the LAN, a compromised firewall/router, or the presence of port forwarding internet-accessible ports routed to the affected machine to deliver the magic packet. It would also work if you sent a link that causes the machine to visit a plaintext HTTP website or run a plaintext dns query that returns the magic packet. Then it must have unfettered access to hit it's C&C server over the internet without being detected by local antivirus or network based intrusion detection. If a corporate endpoint satisfies any of these conditions something is very wrong with their security model in the first place.

Comment Re: Help Me Understand (Score 1) 39

That's going to limit the attack surface area to very little. It's not the 90s where all machines have a public IP, like in PPP dialup. Everything is behind NAT and an external firewall device (or cloud equivalent like a load balancer and a security group). If you've got Windows devices such as endpoints with unfiltered direct Internet access, you're going to have a lot more security problems that are easier for attackers than sophisticated malware. For most endpoints, this would mean tricking the infected endpoint user to go to a web site or run a dns query that returns the magic packet and then hoping the reverse tcp shell it launches isn't network blocked as well.

Comment Re: Get rid of homework (Score 1) 58

You're absolutely right, I am not sure dependent variable however was exactly what I was trying to say. I meant more "necessarily overlapping," as "smart/capable" and "hard-working academically" need not always overlap, frequently they may not. Also, academic achievement may be correlated to eventual economic and career achievement, but it isn't the sole predictor. A student like myself who absolutely hated high school and did the minimum might, like I did, be driven to work hard in a technology job or entrepreneurship. Very early in my career I sat next to a new colleague who had the exact same job at a software company. He recently graduated from Harvard. A month later I was still there and he was fired for poor performance. The boss especially didn't like him playing chess and going on Facebook at work when he was supposed to be working, his unwillingness to start picking up tickets without someone over his shoulder telling him to etc; it was like he was scared to exit training and start working. His whole life had essentially been academic training up until that point. I ended up leaving for a much higher paying job a few months later. I ran into him at a bar around then and he was doing nothing, living comfortably off handouts from his parents. He did a lot better than me in his academic career, and probably worked a lot harder... but that didn't translate to working hard in his working career.

Slashdot Top Deals

A slow pup is a lazy dog. -- Willard Espy, "An Almanac of Words at Play"

Working...