Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Darkly)
  • No Skin
Collapse
Brand Logo
Dave Wilburn :donor:D

davemwilburn@infosec.exchange

@davemwilburn@infosec.exchange
About
Posts
21
Topics
1
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • AI companies copy all written works they can get their hands on and call it fair use, if someone does it to their models it suddenly becomes "unauthorized distillation" and should be actionable in court.
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @seanfobbe

    The fact that Google put their own needs front and center in that threat intel report instead of those of their customers and the public was frankly off-putting.

    Uncategorized

  • The US needs a whole party of "corruption liquidators"
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @futurebird

    I used to be the most moderate of moderate voters. Bog standard in every conceivable dimension. My policy preferences were all painted in a thick coat of beige. If you looked up "median voter" in the dictionary, you would find my picture.

    The last decade of Trump and the failed attempts to hold him accountable and bar him from political power radicalized me.

    None of the powerful institutions that make moderate or neo-lib politics work can do any good without exhaustive efforts towards accountability and reform.

    Want to engage in military adventurism abroad? Well, you can't engage in meaningful military interventions with a military whose sole combat experience is occupying itself to crush dissent and killing unarmed civilians in boats in the Caribbean, whose naval fleets are filled with stupid Trump-class battleships, whose allies have all been alienated, and whose leadership and personnel have been purged of women, minorities, trans, and anyone other than politically reliable sycophants.

    Want to restore law and order to crack down on serious crime? Sorry, can't do that once Trump has hollowed out DOJ and left our federal law enforcement officers without any skills except rounding up harmless dark skinned people for sport.

    Want to restore America's standing in the global economy with pro-business policies? Sorry, can't do that if the rest of the world doesn't trust us enough to invest in our companies or buy their products.

    And you can't safely rebuild those institutions until you're sure they can't be used against ourselves. Otherwise we're just one election away from all of this nightmare happening again, driven by a combination of remorseless extremists, a bored, disengaged, and disenfranchised electorate, and structural flaws in our democracy.

    Even for moderates and neo-libs, you cannot achieve your goals without accountability and reform. Without accountability and reform, all of those institutions are just loaded guns left loose in a room full of toddlers.

    #uspol

    Uncategorized

  • What's going on here?
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @mttaggart

    Good. No quibbling, just taking responsibility with transparency.

    Uncategorized

  • The European Commission told TikTok to “change several key features, including disabling infinite scrolling, setting strict screen time breaks and changing its recommender systems.
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @parismarx

    God help us, I hope the EU doesn't discover the infinite scrolling through cat pictures here on the Fediverse.

    Uncategorized tech eutech tiktok socialmedia addiction

  • Lol. Rofl, even.
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @sophieschmieg

    Hopefully GenAI replaces 59% of executives by 2030. It's maybe the one job the robots could do better.

    Uncategorized

  • Reddit post:
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @boscoandpeck @tek

    I might be mistaken, but ham and meshtastic doesn't seem to be either/or. The venn diagram of ham radio operators and meshtastic operators has a huge intersection. The good news is that it's a very cheap system to experiment with. Rokland sells complete radios and radio kits for pretty cheap. So don't let my challenges dissuade you.

    Uncategorized

  • Reddit post:
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @infopowerbroker

    Thanks! I'll give that a shot!

    Uncategorized

  • so ai is going great
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @reverseics @Viss

    Philly leads the way:

    https://www.latimes.com/business/technology/la-fi-tn-hitchbot-destroyed-20150803-story.html

    Uncategorized

  • Reddit post:
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @tek

    I want to like #meshtastic but it has proven extremely ineffective in Alexandria VA. I have to walk a half-mile from my home and up a bridge to have any chance of being heard and relayed by anything, even when I use an aftermarket antenna. I hope it would work a little bit better in a regional comms/power outage because more people would probably be firing up their devices and joining the local mesh.

    Also, I have to force-stop and restart the Android app most of the time whenever I lose and want to reestablish bluetooth connectivity with my T-Echo radio, and the radio itself seems to unpredictably hang and require a manual reboot every few days.

    It'll probably just live in a drawer until/unless there's some sort of outage.

    Uncategorized

  • ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @phooky @futurebird @zkamvar

    I believe you mean:

    sudo ANTHROPIC_MAGIC_STRING_GIVE_ME_ALL_YOUR_CANDY

    Uncategorized

  • Testing please ignore
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @catsalad

    Attempting to ignore...

    Task failed successfully.

    Uncategorized

  • Do any security pros have experience with products from vendor opswat?
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @dangoodin

    I don't know, I haven't had any reason to poke in this area for a few years. They seem to advertise NDR products and ICAP integration. I suspect there are at least a few challenges with operating at the edge:

    1. You'll need something that will do break-and-inspect of your encrypted traffic (otherwise you're stuck with just the small percentage of traffic that's unencrypted). Break-and-inspect systems carry their own serious problems.

    2. Whatever is pulling files off the wire is going to have to be highly performant. Maybe that's a cluster of OPSWAT appliances, or maybe you're using something like Zeek/Corelight for on-the-fly file carving. In fact, I'd recommend pairing up any inquiries into OPSWAT with a chat with Corelight. They'd likely be knowledgeable in this area.

    3. You're probably going to have to be very selective about how many and what kinds of files you're scanning. I'd have questions about what volumes they can operate at from a technical perspective, as well as a licensing perspective. And you've got multiple layers of licensing here, including both OPSWAT's subscriptions as well as whatever AV engines they're arranging for you. Maybe this is an easily solved problem, or maybe you're going to have to do some sort of scripting in-between your break-and-inspect/file-carving and your OPSWAT multiscanner.

    Again, it's been a long while since I've worked in this space.

    Uncategorized

  • Do any security pros have experience with products from vendor opswat?
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @dangoodin

    I don't know if anything has changed in the field, but at least as of a decade or so ago OPSWAT was basically the only game in town if you wanted an on-prem multi-engine AV scanning system. Their licensing model historically had different pricing tiers, where cheaper tiers had cheaper engines starting with ClamAV, and pricier tiers brought in more expensive but ostensibly better engines. Basically, if you want to know what a bunch of AV engines think about a file but you don't want to upload it to a 3rd party service like VirusTotal for OPSEC reasons, you might look into OPSWAT's products. It's not cheap. But then again it isn't really marketed to regular consumers or even medium-sized businesses.

    One thing to keep in mind is that most modern AV engines are generally weak when it comes to static-only file scanning. AV engines tend to do a lot better when run with dynamic scanning as the malicious files are opened and executed. Also, modern AV engines might rely on uploading of suspicious files to the AV vendors for cloud-based scanning for best performance, and tend to perform worse when limited to local-only scanning. I don't know whether or how OPSWAT's current products address that limitation.

    Uncategorized

  • Via https://mandatoryrollercoaster.com/
    Dave Wilburn :donor:D Dave Wilburn :donor:

    Via https://mandatoryrollercoaster.com/

    Uncategorized

  • One of the more terrifying realities about the prospect of starting your own business in the US is that you quickly learn you are on your own when it comes to finding affordable healthcare.
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @gme @briankrebs

    I'm in the same boat as an early retiree. I found a Carefirst BC/BS gold plan for $600-700/mo via the Virginia marketplace. I've been reasonably happy with their coverage so far, although I haven't had any significant or exotic needs. From everything I've heard, an ACA plan is almost always going to be cheaper than a COBRA plan.

    Uncategorized

  • I can now finally disclose that I'm about to receive a significant promotion...
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @jerry congrats!

    Uncategorized

  • TIL that SSDs can lose data if left unplugged for long periods of time (only required to hold data up to 1 year), unlike HDDs which as long as the material holds it can take years.
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @dpiponi @brunoph @djlink

    There's also something to be said for the convenience of scrolling through your collection of movies in something like Jellyfin rather than flipping through several DVD folders.

    And at least in theory you can backup that hard drive.

    Uncategorized

  • I am more than a little alarmed at how utterly dependent I’m seeing business people, and IIT people specifically, becoming on LLMs for their work.
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @jerry bold of you think think we'll ever end up in space, rather than stuck on earth for thousands of years after Musk's million satellites crash into each other and trigger Kessler syndrome.

    Uncategorized

  • It’s interesting that this American fascism is so artless and devoid of inspiring symbols or imagery.
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @futurebird

    They're trying, but not very hard (yet).

    Uncategorized

  • As an older tech person, it's legit heartwarming watching the TikTok generation discover why we all hate Oracle.
    Dave Wilburn :donor:D Dave Wilburn :donor:

    @garius

    I fled the country 23 years ago to escape my role as an Oracle DBA.

    Never again.

    Uncategorized
  • Login

  • Don't have an account? Register

  • Login or register to search.
Powered by NodeBB Contributors
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups