• 0 Posts
  • 19 Comments
Joined 3 years ago
cake
Cake day: June 22nd, 2023

help-circle





  • I remember Jerome Powell being asked is he worried he’d get fired and his response is “He can’t fire me.”

    This guy doesnt realize fascists dont give a fuck about what they are “allowed” to do. Trump and his cronies have been doing so much illegal shit including illegal firings!

    This is not business as usual and Powell’s ass can easily be kicked to the curb with this Trump administration - illegal or not.

    The judges are learning they lack the enforcement power of their rulings since those left in the government are loyal to Trump and his crusade.

    We are learning our government system only works when everyone is a good faith actor.





  • DNSSEC is a means of authenticating the data receives was not tampered with, such as MITM attacks, thus ensuring data integrity. It uses PKI but it’s not an alternative to DoH or DoT which encrypts the DNS traffic, either over HTTPS or TLS, providing confidentiality.

    DNSSEC can be used in conjunction with DoH or DoT to achieve the Security CIA triad - Confidentiality, Integrity, Authenticity.




  • Even if the FBI does catch this guy, the Feds are still gonna have a helluva time trying to cobble together an impartial jury, not to mention alternatives. One question will eliminate a large portion of the jury pool…

    “Do you currently, or previously had UHC as a health insurer?”

    I could see this case having a hung jury or even seeing jury nullification occur - though it’s highly unlikely for nullification to happen.

    The Feds will put ungodly amounts of pressure to accept a plea deal.

    Edit: added the missing ‘y’ to ‘currently’ and added a space between ‘previously’ and 'had






  • I hate to say it but company data is most definitely on personal computers.

    This is why stuff like adaptive MFA and DLP are a thing. What most people don’t know is if DLP is properly implemented the IT team/department have records of who, when, where, and what device were used to not just access/download data/files.

    The problem is a lot of companies don’t properly implement DLP because it’s not a turn key solution. You need to properly classify your data first and that requires essentially a company wide audit with buy-in from all levels of management. After the classifications you can then implement restrictions and compensating controls.

    Back in the day you could just block USB/network transfer, but if you have data accessible outside of a corporate network you then need to implement conditional access/adaptive MFA where only registered devices are permitted to access certain systems.