Forgot your password?
typodupeerror

Comment Re: If sucking dick is your job.... (Score 1, Insightful) 92

Harvard is an educational institution with a massive endowment that makes them independent and have to answer to no one. Apple is a publicly traded company whose one objective is to make money. The board is compelled to fire a CEO who fails at this and replace them with someone who can deliver more money to shareholders. They did this to Steve Jobs in 1985. If they fail to do this corporate raiders can sue and even conduct a hostile takeover. Harvard's board is concerned with their brand reputation, so graduates of their schools can proudly weave "I went to Harvard" into every professional conversation they have for the rest of their lives. Harvard has incentive to weather short-term monetary losses to preserve their pretentious brand image. There is no risk of a shareholder revolt or hostile takeover. No matter what happens, there will always be more students willing to pay to go to Harvard. Problems in higher ed will affect and lead to the closure of lower ranked schools first. A school like Harvard that counts founding fathers like John Adams as graduates works like the Catholic church, in decades and centuries, not in presidential terms or daily stock value changes.

Comment Re: Only the "flagships"? What a ripoff (Score 1) 69

I'd hate to even justify this with a response, but almost all smartphones lack a physical keyboard so a hardware keylogger wouldn't even be possible. Beyond that there's no information to suggest some type of global smartphone backdoor exists, if it did it would put vendors like Cellebrite out of business instead of the FBI paying them for their hacks.

Comment Re: "Trade issue" my ass (Score 1) 229

Unfortunately while I see you for trying to "own the libs," your Breitbart-world fantasy where abortion is for Democrat women is a complete fabrication. Rates are similar across party lines with Independent women having slightly more abortions. Democrat women are significantly less likely to report ever being pregnant in the first place, probably because they are smart and educated about birth control. https://www.kff.org/womens-hea...

Comment Re: Help Me Understand (Score 1) 39

Indeed, but on normal corporate networks (if IPv6 is even enabled) devices are still behind a firewall or ZTNA/web proxy like Zscaler, and the external interface for those addresses are filtered to disallow direct ingress.

If your cloud environment is binding an instance e.g. EC2 to a routable public IP and you have any ports exposed, it's going to fail every check in the books. Some careless folks or noobs might do this, but in that case, you've probably also got other security problems. Longstanding best practice is using a load balancer/CloudFormation/CloudFlare/CDN etc for any public ingress. This also wouldn't be the case for endpoints, which my example was around.

Comment Re: Only the "flagships"? What a ripoff (Score 1) 69

In the case of GrapheneOS the "someone" often means law enforcement, as the current famous case regarding the duress code exemplifies (https://www.androidauthority.com/grapheneos-duress-pin-us-prosecution-3691271/). It could also mean an "evil maid" scenario, or an "evil lover" or someone with time-limited physical access to the device. Most of the point of using GrapheneOS relates to these physical exploits, remote exploitation of an iPhone or Android device is possible but rather difficult in comparison to the physical ones. The physical exploits just require using a device like a GreyKey or Cellebrite, which any law enforcement organization can simply buy without having to deploy zero-day exploits; which are mostly the realm of intelligence agencies rather than local police and CBP.

Comment Re: Only the "flagships"? What a ripoff (Score 2) 69

Only the "flagships" have the necessary hardware security to support GrapheneOS. If you want to cheap out on a phone, you get phones without hardware-backed keystores, secure enclave or equivalent, verified boot, processor HAL blobs and sandboxing etc etc. That leaves them open to numerous physical attacks that can make installing GrapheneOS not improve the device security.

Comment Re: Help Me Understand (Score 1) 39

You would need another computer on the LAN, a compromised firewall/router, or the presence of port forwarding internet-accessible ports routed to the affected machine to deliver the magic packet. It would also work if you sent a link that causes the machine to visit a plaintext HTTP website or run a plaintext dns query that returns the magic packet. Then it must have unfettered access to hit it's C&C server over the internet without being detected by local antivirus or network based intrusion detection. If a corporate endpoint satisfies any of these conditions something is very wrong with their security model in the first place.

Slashdot Top Deals

Parts that positively cannot be assembled in improper order will be.

Working...