Readit News logoReadit News
hashimotonomora commented on NSA Network Infrastructure Security Guidance [pdf]   media.defense.gov/2022/Ma... · Posted by u/slacka
jabl · 4 years ago
Slightly related, is there any analytical writing on the human side of security? How to build organizations that are resistant to intrusion in various forms?

From reading books and watching movies as well as applying a bit of common sense, organizations like spy agencies or terrorist networks with more or less independently operating cells work with a strict least-privilege type model such that a mole in one part of the organization doesn't compromise the organization as a whole. And, I'd guess, at least in more formalized organizations, strict logging on who does what etc.

All this obviously adds a lot of overhead and friction in communications, which, say, a business operating in a competitive environment can ill afford. I'm quite sure there's no "magic pill", but rather a bunch of choices with tradeoffs (like security vs. ease of cross-team communication I touched on above).

hashimotonomora · 4 years ago
- need to know basis.

- strict separation of concerns.

- only outbound hiring.

- no hiring of people who can be blackmailed.

- understand your threat model.

- if you were an enemy and had to break into your org, what would you do? Improve that.

hashimotonomora commented on Scientists watch a memory form in the brain of a living fish   quantamagazine.org/scient... · Posted by u/doetoe
rakkhi · 4 years ago
In fish...

"Contrary to expectation, the synaptic strengths in the pallium remained about the same regardless of whether the fish learned anything. Instead, in the fish that learned, the synapses were pruned from some areas of the pallium — producing an effect “like cutting a bonsai tree,” Fraser said — and replanted in others."

This is a very counter intuitive. So there are existing neural connections (formed somehow previously...) and new memories form by pruning these connections? Crazy

hashimotonomora · 4 years ago
That’s counter intuitive (at least for you) because in modern society it’s customary to think that people are born tabula rasa and then “it’s all a social construct”. Perhaps we are indeed born with innate preferences, biases, and default sexual orientations …
hashimotonomora commented on What's the risk from fake Yubikeys?   shkspr.mobi/blog/2022/03/... · Posted by u/edent
hashimotonomora · 4 years ago
Do these keys work well under FreeBSD?
hashimotonomora commented on Nuclear war probabilities are useless - counter to the nuclear gambler’s ruin   unfashionable.substack.co... · Posted by u/SvenSchnieders
LeonB · 4 years ago
The insurance industry does a pretty good job of “what is the probability that you will die in the next billable period” - but they would never reduce the bet to “what is the probability that you will die today?”

You say it’s “essentially impossible to model” something that hasn’t occurred before.

Nations have engaged in a lot of wars.

Nations have engaged in a lot of wars they could not possibly win.

People have committed suicide to harm other people. Many many times.

Nations have developed weapons and then used those weapons on other people.

Countries that have engaged in arms races and stock piled weapons have then gone to war. Many times.

In some decades we do more of these things and in others we do less.

To say it’s hard to model, or the models are imperfect (as all models are) - fine. To say it is impossible to model - that’s very naive.

hashimotonomora · 4 years ago
If you are lost in a city would you rather have the wrong map or no map at all?

The person that has the wrong map and thinks that it’s the right map is the one that’s naive.

Regarding insurance companies, you are conflating ensemble probabilities with time probabilities. Insurance companies can estimate the ensemble probability of an event in a group of agents which belong to a certain category and not the time probability of said event on a single agent.

hashimotonomora commented on Nuclear war probabilities are useless - counter to the nuclear gambler’s ruin   unfashionable.substack.co... · Posted by u/SvenSchnieders
hashimotonomora · 4 years ago
What is an ensemble probability of something that has never occurred and is essentially impossible to model? Have you seen all infinite alternate universes? Probability does not make sense.

Compare the following: What is the probability that you will die today?

What is the probability that you will die today given that you belong to the category of people with A_i characteristics and whose ensemble probability of dying on a given day has been measured?

hashimotonomora commented on Tell HN: SWIFT is not a payments transfer system    · Posted by u/atdrummond
0xcoffee · 4 years ago
So how does it work when there are multiple of these systems (CIPS). Is double spending possible?
hashimotonomora · 4 years ago
Essentially trust. If your bank does not have relations with a foreign bank in a faraway country, both can use an intermediary bank that both trust and do have relations with.
hashimotonomora commented on Namecheap: Russia Service Termination    · Posted by u/exizt88
hashimotonomora · 4 years ago
Is this allowed by ICANN?
hashimotonomora commented on Namecheap: Russia Service Termination    · Posted by u/exizt88
NamecheapCEO · 4 years ago
We haven't blocked the domains, we are asking people to move. There are plenty of other choices out there when it comes to infrastructure services so this isn't "deplatforming". I sympathize with people that are not pro regime but ultimately even those tax dollars they may generate go to the regime. We have people on the ground in Ukraine being bombarded now non stop. I cannot with good conscience continue to support the Russian regime in any way, shape or form. People that are getting angry need to point that at the cause, their own government. If more grace time is necessary for some to move, we will provide it. Free speech is one thing but this decision is more about a government that is committing war crimes against innocent people that we want nothing to do with.
hashimotonomora · 4 years ago
Are you following a law or just arbitrarily and unilaterally deciding to do this? I am not Russian myself but I expect a domain name provider to be extremely neutral, unopinionated, and stable. Namecheap is showing to be neither so it can’t be trusted for important domains.
hashimotonomora commented on Namecheap: Russia Service Termination    · Posted by u/exizt88
hashimotonomora · 4 years ago
Are they following a law or just arbitrarily and unilaterally deciding to do this? I am not Russian myself but I expect a domain name provider to be extremely neutral, unopinionated, and stable. Namecheap is showing to be neither so it can’t be trusted for important domains.

u/hashimotonomora

KarmaCake day173October 3, 2021View Original