Security/Integrity/Availability Leftovers

  • DDoS Mitigation Firm Founder Admits to DDoS

    A Georgia man who co-founded a service designed to protect companies from crippling distributed denial-of-service (DDoS) attacks has pleaded to paying a DDoS-for-hire service to launch attacks against others.

  • Siemens Warns of Security Risks Associated With Use of ActiveX

    Some of Siemens’ industrial products — the list includes SIMATIC WinCC, SIMATIC STEP 7, SIMATIC PCS 7, TIA Portal, and S7-PLCSIM Advanced — rely on ActiveX components and customers need to use Internet Explorer to execute these components.

    However, the German industrial giant has warned that using Internet Explorer to access untrusted websites can pose serious security risks. Siemens recommends using a web browser that does not support ActiveX if accessing web pages other than the ones associated with the company’s products.

  • Y2038: It's a Threat

    On Unix-derived systems, including Linux and MacOS, time is stored internally as the number of seconds since midnight GMT, January 1, 1970, a time known as "the Epoch." Back when Unix was created, timestamps were stored in a 32-bit number. Well, like any fixed-size value, only a limited range of numbers can be stored in 32 bits: numbers from -2,147,483,648 to 2,147,483,647. (Without going into technical details, the first of those 32 bits is used to denote a negative number. The asymmetry in range is to allow for zero.) I immediately got pushback: did I really think that 18 years hence, people would still be using 32-bit systems? Modern computers use 64-bit integers, which can allow for times up to 9,223,372,036,854,775,807 seconds since the Epoch. (What date is that? I didn't bother to calculate it, but it's about 292,271,023,045 years, a date that's well beyond when it is projected that the Sun will run out of fuel. I don't propose to worry about computer timestamps after that.) It turns out, though, that just as with Y2K, the problems don't start when the magic date hits; rather, they start when a computer first encounters dates after the rollover point, and that can be a lot earlier. In fact, I just had such an experience.

Entrapment by Microsoft GitHub or Censorship by Microsoft

  • Docker, Perl and GitHub

    There are many reasons to use Docker Images, from setting up a development environment to pushing your code to production. The primary/first reason which pushes me to start using some Docker Images is "Continuous Integration". When maintaining a Perl package used by multiple users/companies (or not), you absolutely want to know how your code behaves on different versions of Perl. Even if you could have multiple versions of Perl installed on your development environment, most of the time, the development is only performed using a single version of Perl. Continuous Integration system like Travis CI or GitHub Workflows allows you to run your test suite on every push, pull request... without the need of testing manually on all Perl Versions. When testing your code on a container (or Virtual Machine) you do not want to install or compile a fresh version of Perl each time... This is a slow operation, that ideally, should be done once. This is where Docker Images come to the rescue. They are "snapshots" of a pre-set linux environment.

  • Week notes - 2020 w03 - worklog - Murphy

    Also GitHub decided to revive our anonymous bugs, around 39,000 bugs are back. We haven't yet reactivated our anonymous reporting.

  • Regula adds another element of control to cloud infrastructure as code

    Regula is protected under the GNU Affero General Public License, and, even though it is heavily referenced in the documentation, supposed to work independently from other, commercial Fugue projects.

Here’s Why Windows 7 Users Should Switch to Linux

Linux has so many different distros Linux Mint and Zorin OS are just a few Linux distros that are thought to be very Windows-user friendly. This means within no time, you should be up and running. Other distros like Ubuntu, Suse Linux and offer so much functionality without feeling cluttered. Many Linux distros are regularly updated. Microsoft might have stopped updating your Windows but if you switch to Linux, you are assured of regular security and feature updates, regardless of which distribution you choose. Also, if you install your applications from a central repository, all your applications will get updated via system updates. This means your whole computer will always be up to date. This eliminates the need to update each application independently. Read more

Have You Tried Kaisen Linux? — A New System Rescue Linux Distro

Being a system administrator, lots of responsibilities and duties are to be taken care of, which are wide-ranging from covering backups, disaster recovery, hardware maintenance, automation, filesystem housekeeping, system security management, and many more to add to the list. To keep the system running smoothly and securely, a sysadmin has to rely upon several tools that sometimes become frustrating to install and configure regularly. Keeping that in mind, and to ease the life of sysadmins, 11 months back, Linux developer Kevin Chevreuil, along with his mate Eren Arslan, started the development of their own Linux distribution based on Debian 9, dubbed as Kaisen Linux. Read more