Hacker Newsnew | past | comments | ask | show | jobs | submit | dlgeek's commentslogin

Or maybe the sonde continued transmitting and they have data on where the guy took it which would help ID him.


FedRAMP actually has a bunch of workarounds for the problems of FIPS.

In the "FedRAMP Policy for Cryptographic Module Selection and Use" (https://www.fedramp.gov/resources/documents/FedRAMP_Policy_f...), there are a ton of gems that make it clear that the FedRAMP folks are fed up with the CMVP process backlog. The most explicit is:

"FRR9: CSPs shall determine if updating to a newer version of the software, whether or not its cryptographic modules are FIPS validated, would eliminate the vulnerabilities; if it would, CSPs shall promptly update if that is feasible."


How is that “a problem with FIPS?”

In layman’s terms that basically says if there’s a 0-day, patch first and we’ll worry about validation later.

You could say that’s “an issue” with literally every software package that has a support contract on earth. I can’t count how many times in my career we had to apply a patch release that wasn’t “officially ga” because of a zero day. That’s common sense, not a FIPS issue.


If our need to update fips certified packages out paces the ability to certify packages, that is absolutely a problem with the design of FIPs certifications.


So your choice inevitably boils down to running some ancient vulnerability-riddled version that's FIPS certified or running a recent less vulnerability-riddled version that's not certified. Most orgs that I've worked with keep running the vulnerable version because they have to be able to check the box that says "FIPS certified".


+1, been all the way to fed ramp high and this is a huge part of the security theater that is fedramp.

The second best part is either getting really good at patching every single thing, or playing the POA&M game.


Some of AT&T's fiber acquisitions still use PPPoE including CenturyLink and Quantum's fiber offerings (acquired from Lumen).


Quantum Fiber doesn't use PPPoE, it uses IPoE w/ VLAN tagging using VLAN 201, which is a common approach for legacy GPON networks. CenturyLink Fiber does use PPPoE, but I believe only the authentication portion of PPPoE, but I have never had CenturyLink Fiber so I can't say for certain.


I don't know how 'only authentication' from PPPoE would work... If you do PPPoE auth, then you can DHCP? That would be a pretty weird config to setup.

I know some CenturyLink fiber defaults to PPPoE, but you can ask for IPoE instead.


You're right about Quantum. I just went and checked my router config. (I switched from CL to Q about 6 months ago).

CenturyLink did use a full PPPoE stack though.


I have Quantum and a UCG fiber. IIRC you only have to turn off vlan tagging on the ONT, and then set DHCP and the vlan tag on the UCG. If you try to keep the vlan tag on ONT you will get horrendous latency. The ISP still shows as CenturyLink.


To muddy the water further, AT&T just bought Quantum fiber.

FWIW, I have Quantum fiber (from post-CenturyLink but Pre-AT&T vintage) and it uses PPPoE.


Not OP, but agent forwarding is a significant concern.


Is it enabled by default though?

AFAIK: No


It's not, but there is likely a small number people who have something like this configured:

  Host *
  ForwardAgent yes


You nerd-snipped me into digging through court records.

The case was 655669/2021 in the New York County Supreme Court (the Supreme Court is the name for the first-tier courts in NY state).

Docket: https://iapps.courts.state.ny.us/nyscef/DocumentList?docketI...

The parties were in settlement talks and postponed the hearing on an injunction and then settled and dismissed.


Thanks, it's a bit frustrating when a piece of old news is reported without a followup. Happens all the time, and due to news agencies not bothering to report the not-so-interesting stuff, it's often difficult to find out what happened after.


Thanks!


No, Penny Lane is in my ears and in my eyes....


There beneath the blue suburban skies...


From the latest update (https://www.ospo.noaa.gov/operations/goes/status.html#datafi...), it looks like they're already restoring systems.

``` Update #3: DCS and SAR have returned to service as of 1630Z. Engineers will now work to restore ABI and expect imaging to resume by 1900Z. Image navigation may be slightly degraded for the first hour after imaging starts. The GOES-19 instruments will be restored in the following order:

    ABI
    GLM
    SUVI
    CCOR-1/EXIS/MAG/SEISS

The recovery process to return all GOES-19 instruments to normal operations is projected to take approximately 8 hours.

Update #2: The GOES-19 Safehold has been resolved and engineers are working to prepare for restart of the onboard instruments. More information on the recovery timeline will be provided when known. ```


Looks like its started to publish new imagery again! I'm sure those fellows are relieved to have it working... I can't imagine the stress of trying to debug something that far away and unreachable!

https://www.star.nesdis.noaa.gov/GOES/sector_band.php?sat=G1...


I heard incoming audio after I keyed once.


makes sense most browsers don't allow autoplaying sound without interaction first.


He's not just the CEO, he's a co-owner... Meaning that the profits from the business acrue to him... and therefore enable this party.

So, it's a question of "am I ok paying for this service, knowing that a portion of that money will flow to this political party and how do I feel about the results of that funding?"


How do you feel about providing value to Hacker News, a plattform made by Y Combinator funding several startups, many of them destroying our society and benefiting from mass surveillance? You can do this argument with every company.


I'm not paying to use HN. I'm jaded and opposed to techno-optimism, so if anything by just expressing my honest opinions here I'm wearing away at those startups' power by challenging their most critical base of supporters.


I'm not opposed to techno-optimisim and I absolutely love hearing opposing views here!


Made by Chrysler. They had plenty of failures with the Juno I and Juno II launchers.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: