• 0 Posts
  • 512 Comments
Joined 2 years ago
cake
Cake day: December 29th, 2023

help-circle


  • there are public STUN servers: just like DNS, STUN is a fairly critical part of modern infrastructure

    peer to peer real time video is a fairly solved problem. the fact that we have google/amazon/zoom/etc in the middle isn’t because it’s necessary

    that having been said, STUN servers are also incredibly cheap to run… i wouldn’t consider it exactly off the cards for a company that’s selling products to support a public STUN server indefinitely… it’s not quite as simple as them having to pay tens of thousands /mo in infrastructure costs to keep the lights on: it’s more like $100/mo, which at numbers that small you’d make back in just interest on the sales you made… but i reckon it could go something like “support for 10 years” and then they release an update that lets you set your own STUN server; perhaps defaulting to a public, free one



  • Working for an organization is not a protected class. It’s not LGBTQ+ people, it’s people who work for those organizations

    targeting support organisations is targeting that protected class

    medically transition children

    sounds a whole lot like the language that trump etc used here:

    child abuse, including the chemical and surgical castration or mutilation of children or the trafficking of children to so-called transgender sanctuary States for purposes of emancipation from their lawful parents, in violation of applicable law.

    which is absolute shit… surgical intervention is the last in a very long list of steps that is only really offered to adults

    first up is simply counselling and psychological support to rule out temporary issues that could be clouding their judgement

    then puberty blockers (which are entirely reversible: if you stop them, you go through puberty as normal)

    then gender-affirming hormones

    THEN surgery, in adulthood

    these things all add up very slowly from completely reversible options over many years




  • the actual budget is passed, they know exactly how much is meant for each agency. What’s been held up is actually putting that money in the account and authotizing the spending of it

    wow that’s actually wildly fucked

    failure to fully fund the government would be seen as a sign of weakness in the government

    in australia it’s not just a sign of weakness, it’s the end of your government. if you fail to pass a budget, basically the governor general (the crowns representative in australia) dismisses the government, appoints an interim government, and fresh elections are called as soon as possible

    there are a few more options than this, but they all kinda amount to the same thing






  • they’re not going to go after the robot vacuum when the thermostat, tablets, computers, TV, router, access point, etc are right there.

    … and all of those things should be equally protected

    they’re going to go for the easiest thing to extract information or escalate

    since they have root they can add a password themselves!

    the most absurd thing is assuming that an end-user is going do add a root password to a serial interface

    i’m not saying end users shouldn’t be able to gain root somehow, simply that it shouldn’t be wide open by default… there should be some process, perhaps involving a unique password per device






  • you’re on programming.dev so i assume you know that secrets is a generic term to cover things like your cloud account login (whatever form that may take - a password, token, api key, etc) for the robot vacuum service and you’re being intentionally obtuse

    it’s a realistic attack scenario for some people - think celebrities etc, who might be being targeted… if someone knows what type of vacuum you have, it’s not “carefully take apart” - it’d take 30s, and then you have local network access which is an escalation that can lead to significantly more surveillance like security cameras, and devices with unsecured local access

    just because it doesn’t apply to you doesn’t mean it doesn’t apply to anyone… unsecured or default password root access, even with physical access, is considered a security issue