Readit News logoReadit News
StudentStuff commented on Huawei HKSP Introduces Trivially Exploitable Vulnerability in the Linux Kernel   grsecurity.net/huawei_hks... · Posted by u/phoe-krk
Tsarbomb · 5 years ago
Didn't the UK last year rip into Huawei after reviewing the networking software, finding something like 18 different versions of OpenSSL inside of it with various vulnerabilities. At some point, continuing a trend of stupidity should be considered malice.
StudentStuff · 5 years ago
Huawei promised to fix these horrible security issues after a code review in 2012 and the establishment of the HCSEC oversight board in 2014, yet HCSEC found Huawei had not fixed the issues found in 2012 in their 2018 report, at which point Huawei promised to spend $2 billion to improve code security.

IIRC the 2019 report from HCSEC outlined the same bugs had yet to be fixed. I think Huawei doesn't want to fix bugs in products they aren't currently selling (in part based on Nortel code that has been patched over the last decade with new features), thus the lies and lack of investment.

More reading: https://www.fiercewireless.com/wireless/uk-says-huawei-equip... and https://aragonresearch.com/cyber-war-flashback-remembering-t...

StudentStuff commented on Mac hardware options for indie devs, Spring 2020   aplus.rs/2020/mac-hardwar... · Posted by u/ingve
greendave · 5 years ago
"This article is aimed at small companies and serious indie developers who do this for living; not for home and hobby use."

"Mac mini is not an option, don’t even look at it."

Absent any discussion, I'd be inclined to ask why. The Mini certainly won't win any bang-for-the-buck awards, but compared to the $3500 27" iMac he eventually recommends, it gives up a discrete GPU, 2 CPU cores and virtually nothing else, while saving a good chunk of money, plus the ickiness of having to junk a perfectly good 5K display when the iMac eventually fails.

StudentStuff · 5 years ago
I just picked up a Mac Mini for recompiling a handful of apps. If I were developing daily on it, a better specced machine might be worth it, but 2 to 4 year old Mac Minis are cheap, have the latest MacOS and fulfill my needs.
StudentStuff commented on Why are Soviet math textbooks so hardcore in comparison to US textbooks? (2017)   quora.com/Why-are-Soviet-... · Posted by u/webdva
adwn · 5 years ago
> I don’t see why so much focus should be placed on these elites at the expense of everyone else.

Because the big breakthroughs and innovations in math and science are achieved by the elites and not by the mediocre masses.

This doesn't mean that we should neglect the mediocre masses (I'm one of them, by the way), they do good, important work. But they're are not sufficient.

StudentStuff · 5 years ago
Who is permitted the time and resources to develop breakthroughs and innovations?

Surely not the proletariat in modern America, where the vast majority are getting poorer year by year.

StudentStuff commented on Google bans Zoom from employees' computers   buzzfeednews.com/article/... · Posted by u/Lagogarda
gnicholas · 5 years ago
> because then you're forced to dial in, which just puts you at a disadvantage when everyone can see everyone's face except yours.

Can't they just participate in a call from the browser? I thought Google only banned the application/app, not usage of the service altogether.

StudentStuff · 5 years ago
The browser version of Zoom seems to require a free account be created, and it was audio only in Chromium, I could not get it to use my camera. Zoom refused to work in Firefox.

Jitsi and Google Meet seem to work in both browsers, without requiring me to log in.

StudentStuff commented on Google bans Zoom from employees' computers   buzzfeednews.com/article/... · Posted by u/Lagogarda
rad_gruchalski · 5 years ago
> worked reliably for me

Every second time I’m using it, I either don’t hear the other people, or people do not hear me. YMMV.

StudentStuff · 5 years ago
I couldn't get it to work in Firefox ESR on Debian 10, and audio was consistently choppy for me in Chromium 80 after I went through their forced account creation process. Zoom wouldn't use my camera either in Chromium :c

Jitsi and Google Meet worked by following a link and clicking one popup. Much easier UX

StudentStuff commented on Open letter from Italy to the international scientific community   left.it/2020/03/13/covid_... · Posted by u/magoghm
cknoxrun · 5 years ago
My co-founder and I are really struggling with the decisions ahead of us. We feel we should act quickly, and enforce our team to work from home, but the spread in our city is quite low for now. We also wonder how long this can go on, are we going to be isolated for months?

We are at a critical point where we have just closed our seed round this past week. We have both put so much energy and time into this moment and we were ready to work harder and focus on scaling and growth.

Of course, the more tragic situation around us makes our issues seem small. I think we will likely announce to our team to work from home starting Monday. How surreal.

StudentStuff · 5 years ago
The spread may appear low in your city, but how much of that is from lack of testing? If your employees can work from home, it is best for you to implement work from home ASAP.

Businesses in Washington State have shuttered or gone to work from home over the last 3 weeks, had most businesses made this change earlier(eg: at the beginning of those 3 weeks) we would see much less spread and quicker easing of restrictions.

Is Alberta doing widespread Covid-19 testing yet? We had cases of teens with no international travel getting Covid-19 in February according to the Seattle Flu Study, there are likely more cases in Edmonton that exhibit minimal symptoms currently.

Seattle Flu Study: https://www.nytimes.com/2020/03/10/us/coronavirus-testing-de...

StudentStuff commented on Bankers Go Home, Tellers Stay: Virus Exposes Office Inequalities   bloomberg.com/news/articl... · Posted by u/pseudolus
celim307 · 5 years ago
I'd agree except I have friends in sales and almost unilaterally they were told to keep coming into the office, despite their entire job being done from phones and computers. Theres a pretty toxic culture in sales where everything is war, and you have to show how committed you are everyday.
StudentStuff · 5 years ago
Many sales environments are just fucked, look at the shit happening at Toyota of Kirkland, the town that is the epicenter of the Pacific Northwest Coronavirus infections: https://www.reddit.com/r/SeattleWA/comments/feflyn/dealershi...
StudentStuff commented on Ask HN: Can the US insurance industry afford to pay for Covid-19?    · Posted by u/34679
StudentStuff · 5 years ago
The healthcare industry can't afford to exist if they don't get paid by someone (whether that is the insurers or Medicare/Medicaid). We've seen mass closures of rural hospitals and medical practices as more rural Americans have lost insurance or gotten insurance that has large penalties for using said insurance: https://www.youtube.com/watch?v=18kxPz4Z_g8

Insurers themselves are a mixed bag, many have gone broke as IIRC the gov't managed pool of money they were supposed to pull out of/put money into to ensure no insurer went under from too many unhealthy, newly insured people has been starved of funding under our current administration.

StudentStuff commented on T-Mobile reveals data breach, customer account info accessed   t-mobile.com/responsibili... · Posted by u/el_duderino
pianoben · 5 years ago
This is the most content-free disclosure I've seen in a long, long time. Things I'd love to have seen:

1. attack vector

2. time when attack was detected

3. time attack was mitigated

4. scope of impact

There isn't even a single date! This could apply to just about _any_ breach at any time.

/rant

StudentStuff · 5 years ago
1. A store location or locations was compromised

2. January 10th was when we notified T-Mobile of the attack

3. Likely sometime between January 17th (the last successful SIM swap attack we experienced) and January 24th.

4. Who knows? T-Mobile refuses to disclose any info to the police :P

StudentStuff commented on T-Mobile reveals data breach, customer account info accessed   t-mobile.com/responsibili... · Posted by u/el_duderino
StudentStuff · 5 years ago
I was affected by this, they SIM swapped a line on our account twice, both times on Friday at 5:23pm (followed by swapping the old SIM back at 5:42pm).

Just received the CPNI notice today from T-Mobile, we had a 6 digit PIN set prior to the first SIM swap on January 10th, and changed it before the following SIM swap on January 17th.

T-Mobile told me these swaps occurred at a store for both attacks. I did remove all authorized users from the account prior to the SIM swap on the 17th. T-Mobile has refused to provide Seattle Police Dept with any info about the fraudulent activity, and left me in the dark prior to the letter today.

u/StudentStuff

KarmaCake day2765May 19, 2017View Original