I am a Meat-Popsicle

  • 0 Posts
  • 1.3K Comments
Joined 1 year ago
cake
Cake day: June 10th, 2023

help-circle




  • Minimum open services is indeed best practice but be careful about making statements that the attack surface is relegated to open inbound ports.

    Even Enterprise gear gets hit every now and then with a vulnerability that’s able to bypass closed port blocking from the outside. Cisco had some nasty ones where you could DDOS a firewall to the point the rules engine would let things through. It’s rare but things like that do happen.

    You can also have vulnerabilities with clients/services inside your network. Somebody gets someone in your family to click on something or someone slips a mickey inside one of your container updates, all of a sudden you have a rat on the inside. Hell even baby monitors are a liability these days.

    I wish all the home hardware was better at zero trust. Keeping crap in isolation networks and setting up firewalls between your garden and your clients can either be prudent or overkill depending on your situation. Personally I think it’s best for stuff that touches the web to only be allowed a minimum amount of network access to internal devices. Keep that Plex server isolated from your document store if you can.








  • China certainly could be lying.

    Half of the US states are purposely bankrupting their education systems to make sure that the 1 percenters are the only ones with any advantage. Even in the States that aren’t actively trying to stamp out education the poor and middle class can’t afford a respectable education.

    China is sitting on a pile of natural resources and doesn’t have any problems with underpaying and working people to death.

    They’re set up to do a lot with very little, they have a lot of people and resources and they’re not afraid to educate enough people to get the job done.

    It’s not just space, they’re getting places with electric cars that we can’t touch.

    It’ll be interesting to see where all this ends up.