So they’re going to deliver sysmon.exe as a windows optional feature. There’s nothing native to it. No config management via GPO or CSP or similar. Nothing. Just replacing the scheduled task/powershell script downloading exe and config by one enabling the feature and downloading the config.
- 0 Posts
- 48 Comments
faebudotoHacker News@lemmy.bestiver.se•Microsoft: We see all the backlash and we know we have a lot to fix in WindowsEnglish
4·27 days agoThey want devs to choose Windows so they develop the next big AI app on Windows to draw the gullible users to Windows. Would be a shame if they choose macOS or even Linux instead.
faebudotoCybersecurity@fedia.io•Phishers have found a way to downgrade—not bypass—#FIDO #MFA
1·5 months agoThe downgrade was implemented by the operator of the application. The phishers only found a way to exploit the downgrade.
faebudotoHacker News@lemmy.bestiver.se•Marathon fusion claims to invent alchemy, making 5000 kgs gold per gigawattEnglish
1·5 months agoA GWy is 8760 GWh. Cost for nuclear is about 100 USD/MWh So about 876M USD for 5000kg Gold worth 536M USD. This is only for the energy, no raw materials and apparatus.
faebudotoHacker News@lemmy.bestiver.se•BYU study: Why some people choose not to use artificial intelligenceEnglish
2·6 months agoUnfortunately many people don’t like to think themselves (not that AI would do it).
You can set the minimum extrusion width to a small value (20-25%) for better fill. You could also use classic mode with gap fill. You can use ironing for both to improve the results.
Does your slicer have Arachne slicing mode? It will use variable extrusion width which will help to prevent most of those gaps.
faebudotoCybersecurity@fedia.io•Did you know that if a spammer uses your email address as the FROM: address, which is easy to do, all the bounce messages will go to your email address? If the spammer really hates you, they will send
1·8 months agoAh yes. But you can just reject NDR messages with “550 5.7.509: Access denied, sending domain example.net does not pass DMARC verification and has a DMARC policy of reject” now.
faebudotoCybersecurity@fedia.io•Did you know that if a spammer uses your email address as the FROM: address, which is easy to do, all the bounce messages will go to your email address? If the spammer really hates you, they will send
1·8 months agoYes, however RFC7208 says not to send NDR when sender authentication fails (=when SPF/DMARC is correctly set up it will fail) So you will get massively less backscatter. There will still be some providers sending NDRs however not the big ones, they will instead inform you via DMARC reporting which is easier to ignore.
Generating non-delivery notifications to forged identities that have failed the authorization check often constitutes backscatter, i.e., nuisance rejection notices that are not actionable. Operators are strongly advised to avoid such practices
faebudotoCybersecurity@fedia.io•Did you know that if a spammer uses your email address as the FROM: address, which is easy to do, all the bounce messages will go to your email address? If the spammer really hates you, they will send
5·8 months agoYou want DMARC to protect the header From. This will protect you from backscatter due to out of office replies etc. Bounces go to the envelope from and are due to rejected mails.
TL;DR Implement SPF to not get bounces and implement DMARC to not get backscatter.
faebudotoHacker News@lemmy.bestiver.se•IBM orders US sales to locate near customers, RTO for cloud staff, DEI purgeEnglish
31·8 months agoThis is great. I already have seen this with some bigger companies that are work from home. Vendors go to their office and use the meeting rooms so they can talk to the employees which work from home.
So now to have IBM as your supplier will cost you more than the competition because you have to provide office space (which you eliminated for your own employees) to them.
I always like it when big companies put stones in their own way with their bad policies.
faebudotoHacker News@lemmy.bestiver.se•Philip K. Dick: Stanisław Lem Is a Communist CommitteeEnglish
2·8 months agoProbably because it has almost nothing to do with hacking.
faebudotoCybersecurity@fedia.io•Scammers set up domains with instructions to ignore email security failures on their emails via a DMARC record and Google et al. deliver their obvious dangerous spam to you. I thought, "how stupid" to
1·8 months agoYes, when setting up their own domain they can as well set the dmarc policy to reject and add valid spf and dkim records. They also do this sometimes.
faebudotoHacker News@lemmy.bestiver.se•Hyundai to buy 'thousands' of Boston Dynamics robotsEnglish
1·8 months agoWhy? The US will soon pay you if you take anything from them if they continue like this.
faebudoto
Cybersecurity@sh.itjust.works•Questions about Argon2id and authentication handling overallEnglish
2·9 months agoUse the recommemded parameters: https://datatracker.ietf.org/doc/html/draft-irtf-cfrg-argon2-04#page-11
Also consider WebauthN/Passkeys. They are much less ressource intensive on the server but useless to an attacker when the database is leaked and as such don’t rely on slowing down the crypto operations.
faebudoto
Europe@feddit.org•Tesla sues EU over tariffs on electric vehicles from ChinaEnglish
542·10 months ago“The company currently exports Model 3 vehicles from Shanghai to the EU, while it produces the Model Y in Berlin.”
It’s right there in the article if anyone would care to read it.
Your first step will be learning to dry it and keep it dry. I can recommend a scale that can resolve to at least 0.1g so you can measure the weight loss while drying. This will help in seeing when it’s sufficiently dry (put it in dryer and weigh it every hour) and if it took moisture again.
faebudoto
Cybersecurity@sh.itjust.works•CISA Releases Best Practice Guidance for Mobile CommunicationsEnglish
1·1 year agoThere are so many VPN providers selling your data, being operated by the feds, operated by cybercriminals etc. it really doesn’t matter just as said in 8.


I do. There are now projects giving you all the required tools in a single easy package. I use stalwart mail server as it includes all the relevant functions that I would have to host separately with other solutions. (CalDAV, CardDAV, DMARC Reporting, DANE, MTA-STS, Rate Limiting, Authentication, Spam Filtering etc.). Also facilitated by having a ISP which gives me fixed IPv6 addresses for free and a fixed IPv4 for a reasonable price. I additionally host simplelogin myself for managing aliases I use for logins.
I now get a lot less spam, I think the unsolicited senders mostly concentrate on the big mailhosters.