Readit News logoReadit News
arter4 commented on Show HN: Using eBPF to see through encryption without a proxy   github.com/qpoint-io/qtap... · Posted by u/tylerflint
jonfriesen · 4 months ago
This is a great point, and Qtap itself does need to be used with care. The company behind Qtap (Qpoint.io) provides full inventory and alerting for this sort of scenario.

That said, the eBPF verifier has robust security guarantees and runs on every load. So arbitrary mem access for example isn't possible. Qtap runs exclusively on your nodes, so you control what it captures and where that data goes. Our paid offering provides more functionality with a Control Plane solutions that provides dashboards, alerting, and live config updates. However, all sensitive information, like captured http bodies, are uploaded to a S3 compliant bucket that you control. This could be S3, Minio, or anything else that supports the S3 API. We never see this information.

It's intentionally designed for deployment within your infra and abides by the security policies you set within your org.

arter4 · 4 months ago
>The company behind Qtap (Qpoint.io) provides full inventory and alerting for this sort of scenario.

Could you expand on this? I haven't seen anything on your company website that suggests detection of this kind of stuff. Also, could you explain how this could be detected? Through another eBPF program?

arter4 commented on How to become a meteorologist without a degree?    · Posted by u/deepakask
arter4 · 8 months ago
I'm not a meteorologist, but modern meteorology is a lot of physics and math and supercomputers.
arter4 commented on Nvidia Slams Biden for Trying to 'Preempt' Trump with Policy   removepaywall.com/search?... · Posted by u/aquir
bdcrazy · 8 months ago
Having opportunities to change things after being voted out seems to be a bad oversight to me. The difference is time and effort. If the outgoing administration doesn't do anything else, you can already setup your agenda and timelines for things you want to accomplish, tossing stuff in can derail your agenda and/or timing. The outgoing president is still president until the incoming one is sworn in though, so that is what you deal with.
arter4 · 8 months ago
Yeah, that's a valid argument.
arter4 commented on Nvidia Slams Biden for Trying to 'Preempt' Trump with Policy   removepaywall.com/search?... · Posted by u/aquir
verdverm · 8 months ago
Would you say the same about Trump's last minute changes in Afghanistan before he left office for Biden to take over? In this case, Trump removed the vast majority of troops in the interim period, leaving Biden with a situation where the number of troops still left were insufficient for the tasks at hand
arter4 · 8 months ago
Sure I would.
arter4 commented on Nvidia Slams Biden for Trying to 'Preempt' Trump with Policy   removepaywall.com/search?... · Posted by u/aquir
arter4 · 8 months ago
Regardless of whether you prefer Trump or Biden, I don't get this trend of making last-minute US policy changes before Trump sits in. Can't he undo all that once he becomes President? If so, what difference does it make?
arter4 commented on People's 'intimate' location data stolen in major hack   news.sky.com/story/millio... · Posted by u/austinallegro
arter4 · 8 months ago
>Tinder, Spotify, Citymapper, Mumsnet and Sky News were among hundreds of companies named in a sample list of apps linked to the breach.

>Hackers appear to have targeted a US location tracking firm Gravy Analytics. It collects information through smartphones, including peoples' precise movements, and then provides it to other companies or governments.

So... those companies sold their customers' data to Gravy Analytics? You know, Cambridge Analytica style? And these hackers just siphooned data from this tracking company?

>He also told Sky News the apps named in the leak weren't necessarily working with Gravy Analytics.

>Instead, he said, software development kits used in the apps appeared to be sending off users' location data.

So... those companies used SDKs from Gravy Analytics which secretly phoned home users' data to this tracking company?

Not sure what's worse, but if this is really the case, it highlights deep flaws in the way major companies evaluate their "software supply chain".

Also, from a more technical standpoint, single API calls following an established specification (assuming that's what those SDK actually do) should be favored over SDKs. If you send a POST containing certain data, there's no way the destination gets other data from you, unless your HTTP client is vulnerable and can somehow be attacked by the company who owns those APIs.

arter4 commented on Predictions for 2025   taoofmac.com/space/blog/2... · Posted by u/rcarmo
arter4 · 8 months ago
>I expect a Taiwan incident of some sort to happen, although I hope it will be a minor one.

>Either that incident or the continuing hostilities in Ukraine (which are likely to last another year at least) will cause the economy to tank again, screwing up the markets to a fair degree.

I'm not an economist or a diplomat, but I would argue that a serious Taiwan incident may be worse than continuing hostilities in Ukraine from an economic standpoint.

First, because the surprise effect is probably relevant. We have been dealing with the situation in Ukraine for a while. We know trades with Russia are very limited, European countries know they can't get reliable gas supply from Ukraine, and so on. Yes, things may get worse, and Western countries might send more (or less) money and aid to Ukraine, but at least we have already covered our bases. When it comes to Taiwan, if something significant happens, it will probably affect the semiconductor business, which goes from CPUs and GPUs to photovoltaics, all things that are highly relevant to our economy.

Also, China itself is much richer than Russia, so a prolonged China-Taiwan conflict may last for a really long time.

arter4 commented on Ships must practice celestial navigation   usni.org/magazines/procee... · Posted by u/HR01
arter4 · 8 months ago
>As The American Practical Navigator (aka “Bowditch”) states, “No navigator should ever become completely dependent on electronic methods. The navigator who regularly navigates by blindly pushing buttons and reading the coordinates from ‘black boxes’ will not be prepared to use basic principles to improvise solutions in an emergency.”

I wonder if this mindset is also applied, for example, to the rest of the military. Does the Army regularly practice land navigation? I know they get at least one landnav class, but it is a perishable skill. If you don't practice, you'll soon forget about it.

I guess this could also be useful to civilians. Being able to do stuff without relying too much on electronics.

arter4 commented on Today I learned that bash has hashmaps (2024)   xeiaso.net/notes/2024/bas... · Posted by u/stefankuehnel
agnishom · 8 months ago
> Q: How do I declare a Hashmap?

> A: You use the command `declare -A HASHMAP_NAME`

This is why I think Bash is a horrible language

arter4 · 8 months ago
what do you mean?
arter4 commented on     · Posted by u/popcalc
popcalc · 8 months ago
I have friends who work at gentrified restaurants in Budapest and they tell me the owners pocket all the tips. Only American tourists tip haha.
arter4 · 8 months ago
I'm from another European country.

We do tip, but occasionally, only if we believe something about that meal was really great, and there's no set percentage.

Also, there are no tip jars. What happens is the server brings the check to you, and you can tip the server by giving money directly to them. Of course, this doesn't mean the owner cannot pocket the tips, but it does give a feeling that the tip is more likely to reach the servers only.

u/arter4

KarmaCake day248January 28, 2023View Original