Linux nerd and consultant. Sci-fi, comedy, and podcast author. Former Katsucon president, former roller derby bouncer. http://punkwalrus.net

  • 0 Posts
  • 40 Comments
Joined 1 year ago
cake
Cake day: June 22nd, 2023

help-circle
  • One revolution I have realized in baking is the recent trend to start talking about weight and not volume in recipes for certain dry ingredients like flour. Three cups of fluffy sifted flour is a lot less flour than three cups of densely packed flour. Same with brown sugar, or wondering if you need a “flat teaspoon” vs. a “heaping teaspoon” of something.


  • Someone did a study at MIT about tin foil hats, and found that not only do they not screen radio interference, in some cases, can actually magnify them.

    Conclusion: The helmets amplify frequency bands that coincide with those allocated to the US government between 1.2 Ghz and 1.4 Ghz. According to the FCC, These bands are supposedly reserved for ‘‘radio location’’ (ie, GPS), and other communications with satellites (see, for example, [3]). The 2.6 Ghz band coincides with mobile phone technology. Though not affiliated by government, these bands are at the hands of multinational corporations. It requires no stretch of the imagination to conclude that the current helmet craze is likely to have been propagated by the Government, possibly with the involvement of the FCC. We hope this report will encourage the paranoid community to develop improved helmet designs to avoid falling prey to these shortcomings.


  • Probably HR (or the NCS equivalent) never told the right people. I am not saying this is actually what happened, but a lot of IT bemoan the fact they are never told some rando employee was fired because HR neglects to inform them. Sometimes it takes months to discover, and even with a 90 day password/login lockout, some halfway decent admin could get around this by secretly building a back door, and using the messed up communication and politics between departments to hide this. Even in the 1990s, I saw people put in “time bombs” in their code that “if such and such is not updated in 6 months, run destructo-script A.”

    But imagine someone like Kandula Nagaraju here. Worked in QA, probably did a great jobs with some skills, but had the personality of swallowing broken glass. He was terminated in October 2022 due to “poor work performance,” which could mean anything. “Not a team player.” Or maybe he really was an idiot: I mean, a smart person would have a conniption, but get employed elsewhere and then slam his former company at parties. “Those NCS folks didn’t know what they had with me!” But this guy was probably someone with some anger management issues, probably a jerk, and possibly stupid. He might have had revenge fantasies, and set up a small virtual server posing as a backup code mirror. But outside the audits, it allowed ssh from the outside, and hid it through a knockd daemon. Or maybe only launched ssh at certain hours before shutting it down again. Silently working away in a sea of virtual servers with little to no updated documentation. He gets in, has internal access, and runs a script with admin credentials because they don’t rotate their AWS keys/secrets quickly enough. Or didn’t even know he was let go.

    After Kandula’s contract was terminated and he arrived back in India, he used his laptop to gain unauthorised access to the system using the administrator login credentials. He did so on six occasions between Jan 6 and Jan 17, 2023.

    That’s embarrassing to the company. Not only did he get in, but SIX TIMES after he was let go. he probably knew what order to run the delete commands (like, say, an aws “terminate-instances” cli command from a primary node), and did so one by one, probably during hours with the least amount of supervision, where the first few alerts would take hours to get someone in the monitoring chain to wake an admin. Given his last day was in November, and he got back in January, the admins probably thought their 90 access credential rotation was “good enough,” but he got in on his 80th day or whatever.

    I know this because I have had to do triage when a former contractor did this to a company I worked for. But instead of wiping out instances, he opened a new set of cloud accounts from the master account, put them in an unmonitored region (in this case, Asia), and spun up thousands of instances to run bitcoin mining. Only because AWS notified us of “unusual traffic” were we made aware at all, and this guy knew his shit and covered his tracks very well. He did it at a speed that could have only been automated. Thankfully, AWS did not charge us the seven figure amount that this activity amassed in just three days.


  • Punkie@lemmy.worldtoNo Stupid Questions@lemmy.worldXXX
    link
    fedilink
    arrow-up
    2
    arrow-down
    2
    ·
    6 months ago

    I can see that being very possible. You see this when taxes are levied to “improve something” and then that money doesn’t go to that something in a directly helpful way. And then the budget that is the main staple of survivability of that something is kept static because of the “new influx.”

    For example, say that you have a toll road increase to help the infrastructure of your roads. Say your Annual Budget for Transportation is $50mil for 2021. In 2022, you requested $60mil. You decide to implement tolls in new ways and increase tolls in other ways (like fines, mileage taxes, and so on) to make up that shortfall. This brings in an additional $10mil, let’s say, in 2022. The revenue is forwarded to 2023. But in 2023, you actually need $80mil because of the two years of shortfalls where it stayed at $50mil, yet costs continued to increase. That $10mil from 2022 now puts you $10 mil behind in 2023. The fact that the previous budget needed steady increases were ignored because “well, we’ll just make things more expensive to make up 2022’s shortfalls of the $60mil request.”

    That’s IF that $10mil isn’t siphoned for other things. Fresh money brings fresh ways to spend it. Grifters via backroom contracts to “fix roads” that go over budget with nothing to show for it. So these new fees and increases actually made things worse due to no oversight.

    So yeah, I could totally see UBI being siphoned off by similar things.




  • Not just LinkedIn profiles: there was a case out here near DC a while ago where a well known company leased out their function space for training meetings. Using a compromised company account, a set of scammers set up some fake recruitment profiles, leased out the meeting space for “software training,” and did some “mass hiring” where 30 individuals had their credentials scanned and duplicated. The effect was someone from the recruiting company was contacting you, you had a face-to-face where you got offered an in-person, you showed up to their offices, and got a “job offer pending a background check,” with a date of hire in official-looking emails. You sent in your SSN, copies of your passport and driver’s licence, and after a few weeks, they tell you to show up for orientation. Only, the day these people showed up, the company was confused and had never heard of you. The people you supposedly spoke to had never heard of you. And your identity was stolen, and huge loans and charges started showing up in your credit report.

    Yikes.



  • Punkie@lemmy.worldtoLemmy Shitpost@lemmy.worldtext don't call
    link
    fedilink
    arrow-up
    173
    arrow-down
    1
    ·
    7 months ago

    When I was 19, I had friends from high school who were still younger, and one of them was my friend Julie who had helicopter parents (she would have been 17-18). I was doing security at an event where the radio headsets we had were super-shitty, and the guy running security was a dumpster fire on his own. Julie’s parents forbid her from going to the event, and grounded her to her room. Then her dad called the hotel where the event was being held, was told Julie had “run away” to this event, and that I was somehow responsible. Given she was a minor, the event runners were understandably concerned, although they were frustrated that Julie’s dad was unable to describe her in a way that was useful: “Asian, wearing black, or a tee-shirt, or something. Ask Punkie where she is.” So they contacted the head of security to find me on my rounds to see if I knew what this crazy man was talking about. The head of security said “okay” and did nothing.

    At some point, the head of security was fired for a variety of reasons, and this increased the level of miscommunication. Meanwhile, Julie’s dad was calling every few hours, demanding to know where his daughter was. And soon there was a concerted effort to find me, which was complicated because of the communication issues. By the time someone found me and the connection was made, my response of, “I have no idea, Julie said her dad forbid her coming here,” was not what they wanted to hear, and met with skepticism “You’re not hiding her, are you? Like she ran away with you in some tryst? She’s 17 and you’re 19, that could have legal ramifications!” No. We’re platonic friends, I don’t know where she is. if I tried to bonk the poor woman, she’d clobber me.

    Meanwhile, Julie’s dad finds Julie in her bedroom, right where he left her. Julie later told me that she was ignoring her dad calling for her, and didn’t “come downstairs” like he demanded because she assumed it was a trap to get her punished for leaving her bedroom while she was grounded. So naturally, her dad assumed she wasn’t in the house. Because he called for her and she didn’t answer.

    Poor Julie. Her parents were crazy-nuts.




  • In my rare cases, it’s been one of those issues where I didn’t know they were keeping it from someone BUT it’s something that should be obvious if you thought about it for a second, OR, they claim they told me it was a secret, but it was not obvious. And I have to say, “At no point did you tell me this was a secret.” Which, you know, makes them look WORSE because now it looks like it was not only a secret, but they were intentionally covering it up as well. And then somehow that’s my fault. It becomes a game of “he said, she said,” and I lost some friends over that over the decades. Was I right? Yeah, but that’s not the point.

    The problem is people lie all the time. I do my best, but sometimes I don’t get those clues. And sometimes? I have had people lie FOR ME when there was no need to begin with. Like someone tried to “cover up” where I was some evening from my wife, when my wife knew where I was (a goth club). But then he claimed I was with him, and I wasn’t. So that started a whole mess. I had to explain, “I was still at the goth club, he thinks I was with him, because he thought you weren’t supposed to know I was at the goth club, and ‘was doing me a solid’ for no reason.” It got to the point I told everyone, “Never lie for me. Either I can stand on my own actions, or I deserve to get caught for being stupid. I am not someone who can keep track of things that actually happened, much less lies.” Lies make me panicky because, well, like I said earlier, I have accidentally exposed people.

    I try not to. But I make mistakes.


  • I rarely get angry at anyone, which, sadly, means I didn’t gain the skills to deal with it very well. Thus, if someone DOES make me angry, it can linger for YEARS. The record so far is some 50 years with my parents’ abuse, followed by a few friends’ betrayal as a teen (separate incidents). I have about half a dozen incidents where I have been seriously fucked over by people I trusted, and hate my continued anger over it more than I hate the event itself.

    I found, however, patience has its own reward. If you’re the type of person who really fucks me over, and it’s definitely not my fault, eventually your behavior will fuck yourself in other ways. I don’t “get revenge” like some cartoon, but years later, I’ll find out, “Yeah, that asshole? After her did that thing to you that took you years to get over, his super-special kid went to jail, his wife left him, his business tanked, and last anyone heard, he’s living with him mom (whom he despised) in his 50s with zero prospects for his future.” If you fucked me over, but it’s partially or wholly my fault, then, well, I deserved it. Sometimes I make mistakes, like screw someone’s lie over by revealing a secret I didn’t know was a secret. I try super super super hard not to do that, even if I hate their guts, or the lie needs to be told for some esoteric moral bullshit (like cheating on his wife I didn’t know he had). But I try to keep my nose clean. I try not to gossip when I can help it. This also helps to know “I did my best, given what I knew.”