• 0 Posts
  • 160 Comments
Joined 11 months ago
cake
Cake day: October 21st, 2023

help-circle


  • “I keep overcooking my steak, any advice?”

    “I haven’t had meat in 40 years, have you considered simply going vegetarian?”

    Edit: FYI the key to cooking a good steak is salt, butter, and to flip it every 30 secs, until you’ve reached your preferred level of doneness. If you’re really trying to impress, and don’t care about a heart attack, you can also baste with butter in between each flip.

    Now, learning how much time it takes for each different type of cut and the variations within, that mostly comes with experience.


  • If there are open wifi networks near your TV that you can’t lockdown, you’ll want to confirm it your make/model is known to automatically connect to those, and then take whatever mitigation steps are justified for your own use case.

    For example, if you have multiple TVs, maybe you can swap models around based on their capabilities and location, or look up the schematic for the TV and see if it’s easy to block it’s internal antennas.

    Or maybe that seems like too much of a hassle and you just say fuck it, and don’t worry about it. Which is always an option, because given how much data already gets sucked up by surveillance capitalism, my evening TV viewing habits have to be some of the lowest value data points, as I already block ads and avoid all ad supported services.


  • I pirated for a long time, and even though I had(have) large media libraries and the home server capacity to manage everything just fine, I stopped.

    Not sure when, or why, I’m guessing a service broke and I just said fuck it, I already have Prime+Netflix, and that was years ago at this point.

    Netflix’s password policy and Amazon showing adds had me spin them up again, and even migrate over to Jellyfin because Plex is just another enshitified privacy nightmare.

    Which was a pleasant surprise, because the last I tried Jellyfin years ago, it was not worth the hassle. Also, Plex wasn’t nearly as bad as it is now.

    To swing this back around to this article, I’m betting eventually they’ll force their TVs online by disabling features, capabilities, or even the device itself, if it’s not phoning home.


  • I think you’ve confused my previous comments as some sort of moral equivocation, which they really weren’t meant to be, but since you brought it up…

    You may believe that America’s intelligence agencies, on balance, are more moral than Russia, and you’re probably right, but that is damning by faint praise.

    Espionage is literally the act of committing crimes on behalf of a government. It’s not altruistic and it’s not used to fight the good fight of corruption, or the mafia. In fact, it’s often done in conjunction with those actions and organizations, because that is what the job often requires.

    Either way, Russia doesn’t need Kaspersky to run its domestic surveillance network or it’s myriad of police state apparatuses.

    FYI oftentimes terrorism is blowback from actions taken by intelligence agencies years, or decades, prior. That is, the groups and ideologies they fund, train, and use, for their own ends, don’t cease to exist just because they’re no longer useful, or needed, by those agencies.


  • Retail generates the most margin, while enterprise generally the most revenue.

    At least, that’s how it works at most vendors that operate both B2C and B2B sales and product channels.

    But no, Kaspersky is a major legacy player in the B2B security market with both mature and cutting edge products/solutions.

    A better question might be, which companies in America were still using Kaspersky up until this month, and why.

    My guess that is a mix between budgetary constraints, incompetence, and weighted risk analysis.

    Imagine you’re a Midwestern ice cream wholesaler, it’s been a bad few years, and your 200 Kaspersky licenses were renewed with deep discounts.

    You’re not likely to lose any contracts for using Kaspersky, nor be a target of state sanctioned espionage, but spending $10,000 between new licensing and man hours, to rip, replace, and configure a new solution, now that could cause real issues for you.

    So, between a rock and a hard place, you just wait it out as long as possible and hope that when the other shoe drops, it doesn’t wreck your budget.


  • No problem, happy it helped.

    Your summary is mostly accurate, but I think a better way to understand it would be like this:

    Low level security software, by nature, is the ultimate attack vector, if compromised.

    Assume that all countries that have both a domestic tech sector, and a well-resourced national security apparatus, have some version of on demand government initiated supply chain attack capabilities.

    So it’s not like I believe that all Kaspersky installs include a RAT piped directly to some GRU/FSB unit, just the ability for a malicious payload to be inserted - just as the NSA can do with American tech companies.

    Not every risk can be mitigated, but some risks just shouldn’t be taken.


  • That is so wrong that it’s actually impressive.

    Either you’ve never worked in this space, or because it wasn’t present in the few IT departments you’ve worked in, you extrapolated that to mean it wasn’t present in any large organization.

    By all means, I don’t disagree that American firms should not be using Kaspersky, just as Russian firms should not be using Sophos (UK based), but to pretend that they aren’t one of the oldest and most well-established brands in the space is misinformed at best.

    I think you confused the fact they have a retail product presence, to mean that they don’t have serious enterprise solutions, but they do: NDR, XDR, agentless for hypervisors, etc.


  • Yes… no… sorta…kinda… but no different than how most, if not all, large American security and tech vendors have either overt, or covert, links to the the American Security State.

    Kaspersky is a long established credible actor and leader in the threat research space, hands down one of the best track records over the long run, and you should take their reporting and disclosures seriously.

    I’m not saying that to dismiss the very valid concerns about installing Kaspersky on sensitive private sector and government systems, but to contextualize my answer.

    On a sort of related note, earlier I said that the American security state has both overt, or covert, links all across the American tech sector.

    What that means is that, even if a company holds their principles not compromising their customers or their product, the US government can either get a court order to force it, or they’ll be targeted by something like the Pentagons Signature Reduction program and have sheep dipped employees worked into their organization.

    Point is, Kaspersky is one of the few remaining Russian brands and entities still holds a lot of credibility in it’s field, but again, that doesn’t mean the concerns of Western government’s aren’t valid, just that they should be viewed in the proper context.



  • This is an accounting trick as well, a way to shed profit, and maximize deductions, by having different units within a parent company purchase services from each other.

    I realize that my sentence long explainer doesn’t shed any light on how it gets done, but funnily enough, you can ask an LLM for an explainer and I bet it’d give a mostly accurate response.

    Edit: Fuck it, I asked an LLM myself and just converted my first sentence into a prompt, by asking what that was called, and how it’s done. Here’s the reply:

    This practice is commonly referred to as “transfer pricing.” Transfer pricing involves the pricing of goods, services, and intangible assets that are transferred between related parties, such as a parent company and its subsidiaries.

    Transfer pricing can be used to shift profits from one subsidiary to another, often to minimize taxes or maximize deductions. This can be done by setting prices for goods and services that are not at arm’s length, meaning they are not the same prices that would be charged to unrelated parties.

    For example, a parent company might have a subsidiary in a low-tax country purchase goods from another subsidiary in a high-tax country at an artificially low price. This would reduce the profits of the high-tax subsidiary and increase the profits of the low-tax subsidiary, resulting in lower overall taxes.

    However, it’s worth noting that transfer pricing must be done in accordance with the arm’s length principle, which requires that the prices charged between related parties be the same as those that would be charged to unrelated parties. Many countries have laws and regulations in place to prevent abusive transfer pricing practices and ensure that companies pay their fair share of taxes.


  • I mean, sure it’s possible this was an attack, but coal mining is incredibly dangerous, and Occam’s razor would suggest that it was caused by the mining itself.

    That doesn’t mean that no one is ultimately responsible, whether through negligence, shoddy practices, etc., just the explanation is most likely related to the mining operation itself.

    Not that I think blood and misery for it’s own sake is above Israel, just that their are much more likely scenarios here.



  • I don’t know if you grew up during the color coded terror threat level days, but after updating everyone on the days terrorism threat color, the nightly news anchors would share how many terrorists were killed in Afghanistan and Iraq.

    Even as a kid, I thought to myself, “how is everyone killed by coalition forces a terrorist?”

    Or, “why are car bombs that kill coalition forces in theatre, called terror attacks?”

    News flash, governments and media label all sorts of organizations and actions terrorism, 90% of it is propaganda, or bullshit.

    Otherwise, I guess that would mean Ukrainian forces fighting Russians are also terrorists, which is how the Russian government and media refers to them.



  • Those are rooted in actions like bombardments of civilian areas e.g. Dresden, Gaza, etc.

    Just because an action has collateral damage, does not make it indiscriminate.

    Again, it’s not like Israel isn’t already committing war crimes every day, I’m just not clear if this is one of them.

    For example, when the Ukrainian’s assassinated the propagandist in St Petersburg at the cafe, there was collateral damage. Still doesn’t make it a war crime.

    I am not comparing the morality of Ukraine to israel, I’m just giving you relevant example from recent history


  • Not that Israel needs an excuse to commit a war crimes on any day that ends in Y, but I don’t believe this is a violation of the Geneva convention.

    It was a mass targeted assassination campaign against an opposition military force structure. I’m not saying it’s not a crime, just that I don’t believe it’s a war crime.

    But I’m open to the very real possibility that I am wrong about that. So if I am, can you point me to the article(s) it’s in violation of?

    I genuinely would like to fill that gap in my knowledge, if it exists.


  • That comes out during trial, unless by whistleblower, you meant that you hope someone inside the investigation leaks details to the press? I’m not judging, just looking for clarification.

    Whistleblowers come forward to trigger a response that they feel is lacking or inadequate, typically administrative, legal, or political in nature.

    As there are multiple active DOJ investigations, what you have now are cooperating witnesses, and subjects with plea agreements.

    Both of which include the “goods”, but neither are allowed to talk to the press.

    FWIW I’m also very much looking forward to reading the accounts of the hilariously dumb acts of corruption acts these morons got up to.