azl

  • 0 Posts
  • 57 Comments
Joined 3 years ago
cake
Cake day: June 7th, 2023

help-circle
  • I would like to know more about how this bypassed server certificate validation. microsoft.com might resolve to a malicious IP address, but your web browser will break as soon as the server certificate check fails. One would need to ignore a fat warning page and click the “Accept risk and continue” button.

    Also, if the attackers have hijacked DNS, why do they have these fake domains (m365-owa., etc.)? They can be microsoft.com; they don’t need a copycat domain. This suggests a fair amount of victim participation:

    1. Victim visits https://microsoft.com/ and DNS resolves to a malicious IP address.
    2. Web browser contacts the malicious web server and receives a TLS certificate that cannot be verified because it was not signed by a global root authority (in this case, DigiCert).
    3. Victim sees “This connection isn’t secure.”
    4. Victim ignores warning and clicks “continue”
    5. Victim either provides their credentials at the fake microsoft.com site, ignoring the red flags all over the browser, or
    6. Victim is quickly redirected to another domain which has a valid certificate and provides their login credentials there

    If certificate validation didn’t stop this kind of attack, then a VPN is useless. The attacker can simply redirect your initial handshake with your VPN provider and impersonate your VPN gateway. But because you most likely have some kind of prearranged trust (shared keys or a stored certificate), you can authenticate the VPN provider and establish an encrypted tunnel through all of the untrusted networks between your laptop and the VPN host.

    So, while spoofing microsoft.com is the big trick here, there are other failures the operator must commit to allow the attack to succeed.

    In many cases, a VPN is redundant to any TLS-encrypted HTTP session. The benefits of a VPN in these cases are to obscure your origin (location, IP address, etc.) from the web sites you are visiting, and to prevent the hotel/coffee Wi-Fi/ISP from tracking or potentially intercepting which sites or services you are accessing. The only time a VPN is not redundant encryption is if you are visiting unencrypted web sites (i.e. a URL starting with http:// and not https://), which by and large have not existed in nearly a decade.



  • Just a couple thoughts (I have a mix of 2.5Gb and 10Gb):

    • Mikrotik switches are a nice alternative to Unifi. Much less lipstick on the UI but reliable and fairly priced.

    • If possible, you’ll probably want to use your own router rather than the all-in-one provided by the ISP. In my case, the router provided to me (Eero brand) did not even have a port fast enough for my service, and would have been an instant bottleneck.

    • Options for 10Gb-capable PCIe adapters (what you might put in your server or desktops) are more limited (at least they were when I transitioned a couple of years ago). Intel-based network adapters seem to require less effort to get working (driver-wise) vs. some of the other 10Gb / SFP+ capable adapters.

    Finally, you are correct: nobody needs an 8Gb internet connection. Aside from well-seeded torrent file transfers, you will never reach that limit (and probably still never). And, you’ll need an adequate storage backend to write that fast.


  • azltoTechnology@lemmy.world*Permanently Deleted*
    link
    fedilink
    English
    arrow-up
    15
    ·
    1 year ago

    I’ve had a folding Samsung for the past year and it’s really great. The hardware and software do need time to mature (in fact, the phone is nearly useless in “folded” mode without third-party apps), but at this point I don’t think I could go back.










  • azltoFuck Cars@lemmy.worldTell me again why you need a pickup truck.
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    2 years ago

    Having moved server racks, copiers and other equipment from site to site, I am thankful for my (light) truck. Cargo vans are more popular in IT since they protect from rain and sun but a flatbed is certainly better than trying to put heavy, sharp-cornered things on fabric or leather in the back of a passenger car nearly the same size as my (light) pickup.







  • azltoTechnology@lemmy.world*Permanently Deleted*
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    2
    ·
    2 years ago

    What’s the difference between one technology you don’t understand (AI engine-assisted ) and another you don’t understand (human-staffed radiology laboratory)?

    Regardless of whether you (as a patient hopelessly unskilled in diagnosis of any condition) trust the method, you probably have some level of faith in the provider who has selected it. And, while they most likely will choose what is most beneficial to them (cost of providing accurate diagnoses vs. cost of providing less accurate diagnoses), hopefully regulatory oversight and public influence will force them to use whichever is most effective, AI or not.


  • They could have gone with a “visor” frame design that would have been more fashionable, but I think this is pretty impressive for demonstrating the bare minimum amount of plastic needed to house holographic transparent displays, internal/external tracking sensors, and a sound system.

    What they claim these glasses can do is absolutely incredible (we won’t really know because they are only being used internally for further development).