• 4 Posts
  • 545 Comments
Joined 3 years ago
cake
Cake day: June 7th, 2023

help-circle

  • While I don’t know the specific post you are referring to, Malware exists for Linux. Here’s a great overview from last year. If someone wants to argue, “oh it’s from a security company trying to sell a product” then let me point you at the Malware Bazaar and specifically the malware tagged elf. Those are real samples of real malware in the Linux specific ELF executable binary format (warning: yes it’s real malware, don’t run anything from this site). On the upshot, most seem to be Linux variants of the Mirai botnet. Not something you want running, but not quite as bad as ransomware. But, dig a bit and there are other threats. Linux malware exists, it has for a long time and it’s getting more prevalent as more stuff (especially servers) run on Linux.

    While Linux is far more secure than Windows by design, it’s not malware proof. It is harder for malware to move from user space into root (usually), but that’s often not needed for the activities malware gets up to today. Ransomware, crypto miners and info stealers will all happily execute in user-land. And for most people, this is where their important stuff lives. Linux’s days of living in “security through obscurity” are over. Attackers are looking at Linux now and starting to go after it.

    All that said, is it worth having a bloated A/V engine doing full on-access scanning? That depends on how you view the risk. Many of the drive-by type attacks (e.g. ClickFix, fake tech-support scams) all heavily target Windows and would fail on a Linux system. The malware and backdoors that come bundled with pirated software are likely to fail on a Linux system, though I’ll admit to not having tested that sort of thing with Wine/Proton installed. For those use cases, I’d suggest not downloading pirated software. Or, if you absolutely are going to, run those file through ClamAV at minimum.

    Personally, I don’t feel the need to run anything as heavy as on-access file scanning or anything to keep trawling memory for signatures on my home systems. Keeping software up to date and limiting what I download, install and run is enough to manage my risk. I do have ClamAV installed to let me do a quick, manual scan of anything I do download. But, I wouldn’t go so far as to buy A/V product. Most of the engines out there for Linux are crap anyway.

    Professionally, I am one of the voices who pushed for A/V (really EDR) on the Linux systems in my work environment. My organization has a notable Linux footprint and we’ve seen attackers move to Linux based systems specifically because they are less likely to be well monitored. In a work environment, we have less control over how the systems get (ab)used and have a higher need for telemetry and investigation.


  • Let’s ignore the pedantic issues of “there is no surface”, “there is no sun to rise” or “you’d be dead so insanely fast you probably wouldn’t notice”. Assuming you were magically teleported and held protected just above the event horizon of a black hole, it would be so bright you’d go blind almost instantly. Not because of any star coming over the horizon, but because the accretion disk would just be that bright. If you look at NASA’s pictures of M87, you aren’t actually seeing the black hole. There’s nothing there to see. Instead, what you are seeing in the pictures is the accretion disk around the black hole. As matter gets closer to the event horizon, it accelerates and all that stuff starts bumping into each other. At the energies involved, this produces electromagnetic radiation of basically every energy. There is infrared right up through x-ray, included lots and lots of visible light. And this is happening on a scale which is so mind mindbogglingly big that words really just fail to capture it. Here is an artistic representation with our solar system for scale. Pluto’s orbit would be well inside the event horizon. There is an insane amount of light and energy in that accretion disk. And thanks to the blackhole warping light around itself, you would be getting bombarded by its energy from every angle, including the disk on the opposite side of the black hole. In short, it would be really bright.


  • One of the things to look at is the interest rate you would be paying for either loan and how that would effect the total cost of the loan. Also, there is the question of the utility of any money spent up front. For example, if using a loan on the existing house would result in no up front costs and a 5% interest rate over 30 years, and the standard mortgage would cost $20,000 and have an interest rate of 8%, you’re almost certainly better to use the existing house as backing and throw that same $20K in a long term interest bearing investment (e.g. government bonds). All this assuming you plan to hold onto the second property long term.

    Compounding interest is a fantastic tool and a fearful master. If you can make it work for you, then do it. If you are facing the possibility of paying it, you almost always want to lower it as much as possible.




  • When did Right Click -> Set as Wallpaper -> Desktop involve writing code?
    Yes, older versions of Linux may have had that setting buried in a config file somewhere, which required editing in a text editor. And that sort of UI was shit, is shit and will always be shit. But, if we’re going to bring up old versions of an OS, let’s talk about Windows Me.




  • A-fucking-men.
    I’m in a similar boat house. We bought in 2011, used a USDA loan and were able to pick our place up for a song ($160k). It now has a “value” of ~$360k. And all that extra “value” is doing for me is increasing taxes and insurance costs. I’m not planning on selling any time soon, so my home “price” going up is a net negative. Sure, we might sell in a decade or so, but today’s price won’t have a major impact on that.

    What I’m getting at is, this doesn’t benefit homeowners, it benefits housing investors, who are the group Trump really wants to prop up.

    What? You’re telling me the pedophile, racist, Nazi sympathizer, billionare son of a racist, Nazi sympathizer who made the family’s billions by wartime real estate profiteering is more interested in protecting real estate profiteering than helping people? Color me shocked, absolutely shocked, I say. Well, not that shocked.


  • I ditched cable TV over a decade ago for a simple antenna (and wrote a notable Reddit post on the antenna while I was at it). That was done because I was tired of my wallet being raped each month, because I had to buy a higher bundle to get the channels I wanted. I was stuck with cable internet for a number of years afterwards, as it was the only option in my area. Then T-Mobile offered up 5G based internet in my area at a low price. That was around 6 years ago and I haven’t looked back.

    The cable companies sat on their laurels while the world moved on. They are now shocked that their terrible offerings for terrible prices are falling to real competition. Sure, I fully expect the new carriers to do everything in their power to enshitify their service offerings. That’s the nature of business/ But, with the market open to competition, there is now a real opportunity for us customers to shop around and get a less shitty experience. Broadband internet is a commodity and is completely fungible. Prices should be falling and it was only rent seeking rules keeping the prices up.





  • It tends to be much more focused on bringing products to market, but of course they do. The transistor, the base unit of all of the microchips which make this conversation possible, came out of Bell Labs. And, as much as we might hate them for it, you have companies like Monsanto doing a lot of work on chemical engineering and genetics. Much of the work on AI (for good or slop) is being done in private sector labs now. Aeronautics research happens heavily in companies like Boeing and Airbus, though they are often working hand in hand with government labs (e.g. NASA, JPL, EASA).

    Where Universities and Government really shine are areas like basic research and research which doesn’t have obvious commercial applications. Which is why support for those organizations is so critical. Those areas of research often have long term effects and can result in entirely new areas of knowledge, research and products.

    It’s easy to think of large corporations as soulless organizations hell bent of accumulating wealth at the cost of anything else, because they are. But they are also surprisingly good at focusing wealth and effort to find new ways to do things cheaper, faster and more efficiently. Specifically because those things make money. Veritasium had a video on a good example of this recently.




  • This is it exactly. I made a hard cut with Reddit, but I’ll admit to missing the sysadmin subreddit. The place was full of very smart, helpful people and also cranky. The PowerShell subreddit was another great resource. I haven’t been willing to go back, but those sorts of communities only exist when you hit a certain mass of people on a platform.



  • I mean, no shit? Part of the Snowden leaks was information that the NSA had intercepted Cisco routers and backdoored them before they were shipped on to international customers. So, even without willing actions by US vendors, there is that to worry about. And the idea that a private company would install a backdoor for US Spy agencies in their infrastructure isn’t new. The fact that any Chinese company is using US hardware/software just seems incredibly stupid. And no one should be using CheckPoint.

    It’s the same reason Huiwei was thrown out of US infrastructure. You cannot build trusted architecture with hardware/software from a nation which you know wants to hack you. I work for a US based company in cybersecurity, we treat WeChat as Chinese State spyware, because it is. We wouldn’t consider a router or firewall from a Chinese based company and we treat any software from China with outright suspicion. Sure that all sucks and we may be missing out on some great stuff which isn’t malicious. But, the risks far outweigh the costs. I’d expect my Chinese counterparts to be making the exact same risk calculation for US based tech.