• 0 Posts
  • 794 Comments
Joined 3 years ago
cake
Cake day: July 11th, 2023

help-circle
  • or didn’t have a defense against a 0 day.

    firewalls are not for defending against 0 days. it is about access control, and reducing, sometimes even minimizing access to potentially vulnerable services. firewalls are not an infallible security tool, but there is no such thing either. the reason to use it is to restrict access such that fewer attackers can take advantage of a potential vulnerability.

    there are intrusion detection/prevention systems that could do more, but it’s unlikely they will protect against 0 days, because 0 days are undiscovered and unknown issues.

    So the vlan doesn’t do anything either way.

    it does. its useful to force traffic through a firewall. its for limiting what has access to what. if you wouldn’t use vlans, hosts on the network would not care about your firewall because they can just go straight to the destination.

    I’m not sure I understand your argument, but I think what you say is, firewalls are not infallible so they are useless


  • Then I was not sure what you meant by this:

    I don’t actually know if this is the right way to calculate it, but if for each disk you count the time separately, and add it together for a combined MTBF, then that is 20 out of the 136 MTBF years.

    5 years of drive runtime for one drive. 20 “years” for 4 drives, 40 “years” for 8 drives. I say “years” because the way I mean it is like this: running 4 drives for 10 minutes is 40 minutes of combined drive runtime. running 4 drives for 5 years is 20 years of drive runtime. I think calculating it like this can be compared to MTBF. but again, I’m not totally confident that it really works this way.

    All in all, I am at this point only trying to track down and relay what I’m seeing about SAS vs SATA.

    I think it might be because SATA drives you normally run across, especially in laptops, are not the enterprise kind, but consumer drives built from cheaper components and simpler designs. and those are lower quality. while SAS drives are always enterprise grade.

    but still, in my experience SATA drives can have a long life too. but it may be more unpredictable than enterprise SATA/SAS drives

    HP says that SAS is more reliable

    could be controller chips and cable quality. but also, SFF-8644 type SAS connector can be used to attach a drive to multiple HBA cards as I heard, maybe even multiple machines, for redundancy


  • if you allowed that to happen you either did not set firewall rules strict enough, or if the client doing the compromise absolutely had to have access to the vulnerable service then you did everything you could to limit the chance of it happening.

    usually the solution to that is to limit who can access what more strictly. dont allow user devices like smartphones on the iot vlan, as any app running on the phone could be doing nefarious things. only allow the iot devices and the home assistant service on the iot vlan, and user devices will only talk to home assistant, something supposedly more secure than whatever iot devices there are.
    similarly, don’t allow user devices to access the ip cameras. put the ip cameras on a network where only the NVR software can access them, and user devices will only access the NVR. if you can, don’t put the whole operating system of these services on the iot and ipcam vlans either. this is possible when the services run in containers, because you can pass in only vlan specific interfaces to the containers. if not using containers, you can still use the operating systems firewall to filter incoming traffic.

    if you set up proper network filtering, the “if” in “If your firewall couldn’t stop it” will become a pretty big “if”


  • I’m a repair depot I typically didn’t see drives that live much longer than 17k hours (just under 2 years).

    I have a bunch of working drives with 2+ years, and in my area almost everyone still has their system installed on old hard drives

    that it would be difficult to project an average lifetime of 20 years

    I did not mean an average timeline of 20 years

    that when Backblaze mentions consumer vs enterprise drives they are possibly discussing SATA vs SAS.

    there are plenty of enterprise SATA drives

    This comes from the realization that enterprise workstation drives are still just consumer drives with a part number label on them (seen in Dell and HP Enterprise equipment).

    that’s workstation drives. Obviously if your work buys 2 TB wd blue drives they won’t become enterprise drives. enterprise drives include like that of wd red pro, ultrastars, etc, which do use the SATA interface.


  • I know he comes from Orbans party, but I also know that Orban wasn’t thought to be corrupt in the beginning.
    So it seems to me to show character for Péter Magyar that he no longer could stand by Orbam destroying Hungary.

    that’s indeed what he says but it is not obvious whether it’s completely true.

    Péter Magyar did not part ways back when Orbán became corrupt. He did that just 2 years ago, when Orbán has been corrupt for a very long time and party members had plenty of time to be accustomed to that, and to being defensive when being accused of that (in case of other fidesz members).

    before I become a russian propagandist for saying this, I want to say this does not directly mean Péter will be corrupt too. but many people (including me) think that the chance of it cant be ignored. I’ll be voting for his party, but I’ll keep this in mind.

    So it seems to me it is Orban that changed

    Orbán definitely seems to have changed, in the very beginning. but maybe he was just a liar, with different motives than he was showing. I don’t know how could someone change that much, but it would be an interesting read if it was ever uncovered.

    You hadn’t yet stated “here” is Hungary, so your sarcasm is misplaced.

    ok, you’re right there, I was unclear.





  • thanks! as you say because tye 5 vs 136 years it does not really matter in our environment, but it probably starts mattering when you have lots of disks.

    I don’t actually know if this is the right way to calculate it, but if for each disk you count the time separately, and add it together for a combined MTBF, then that is 20 out of the 136 MTBF years.
    But with 30 drives that will be 150 and indicate that you will likely have at least one error of some kind because of using SATA











  • But lets assume that your microphone is recording everything you say to some llm, and everyone else too. imagine the shitshow it must be to sort all that data, considering how unreliable llm are. There is no way to know for sure what the original meaning and intention of words is without actual human confirming it. there would be so much constantly going on that even with decent automation it would be nightmare to manage, i think.

    filtering for interesting words in a transcription would go a long way. I’m not convinced they would need an LLM for this. keyword based targeted advertising was a thing for quite a fewyears before LLMs became widespread.

    I have occasionally tried to investigate if my phone is listening even though it doesnt indicate so, but i havent noticed anything that would point to that.

    I have friends of all ages who are not really technically adept, and not caring much about privacy either, but who tell me from time to time that it’s like facebook is listening, because of some ad they saw on there. I still don’t have any clue how are they pulling that off, and I hear it too much to accept it being a coincidence.

    but I don’t use facebook, I refuse to use their apps, my phone is clean from google too, while theirs is littered with every garbage in addition to the factory bloat, so I can’t do much to figure it out