

Its Deja vu all over again: https://en.wikipedia.org/wiki/COINTELPRO


Its Deja vu all over again: https://en.wikipedia.org/wiki/COINTELPRO


We need comprehensive privacy legislation with teeth.
When you use biometrics with passkey, they are stored on-device. In that sense they respect privacy.
What size model? I can run 8 billion parameter models on my Geforce 3070 with 8gb of vram. Bigger models need more memory. For $1-2k you can upgrade to a 16 or 32 gb video card. For $3k you can get a Framework Desktop with 128 gb unified memory. For $6k you can get a DGX Spark with a blackwell chip and 128 gb unified memory. Mac mini or Mac studio are also good choices in this price range.


I just use KVM under linux.
This guide is pretty good -> https://ssd.eff.org/playlist/journalist-move
Avoid the internet altogether with Meshtastic or Recticulum if your goal is coordination amongst a closed group.
Good luck stay safe.


Take a look at Shai Hulud. All the attacker had was the key.


I would feel more comfortable running curl bash from a trusted provider than doing apt get from an unknown software repo. What you are trying to do is establish trust in your supply chain, the delivery vehicle is less important.


What you said is the key infra needs to get compromise. I do not need to own the PKI that issued the certs, I just need the private key of the signer. And again, this is something that happens. A lot. A software publisher gets owned, then their account is used to distribute malware.


Not sure how else to explain this. Look at the CISA bulletin on Shai-Hulud the attacker published valid and signed binaries that were installed by hundreds of users.
"CISA is releasing this Alert to provide guidance in response to a widespread software supply chain compromise involving the world’s largest JavaScript registry, npmjs.com. A self-replicating worm—publicly known as “Shai-Hulud”—has compromised over 500 packages.[i]
After gaining initial access, the malicious cyber actor deployed malware that scanned the environment for sensitive credentials. The cyber actor then targeted GitHub Personal Access Tokens (PATs) and application programming interface (API) keys for cloud services, including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.[ii]
The malware then:
Shai-Hulud via the GitHub/user/repos API.

If I can control your infra I can alter what is a valid signature. It has happened. It will happen again. Digital signatures are not sufficient by themselves to prevent supply chain risks. Depending on your threat model, you need to assume advanced adversaries will seek to gain a foothold in your environment by attacking your software supplier. in these types of attacks threat actors can and will take control over the distribution mechanisms deploying trojaned backdoors as part of legitimately signed updates. It is a complex problem and I highly encourage you to read the NIST guidance to understand just how deep the rabbit hole goes.
Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations


Signatures do not help if your distribution infra gets compromised. See Solarwinds and the more recent node.js incidents.


Yes this has risks. At the same time anytime you run any piece of software you are facing the same risks, especially if that software is updated from the internet. Take a look at the NIST docs in software supply chain risks.
According to ChatGPT the Mint car is a Chevy Spark. And now I am thinking I should be driving a Chevy Spark if it is anywhere near as reliable and easy to use as Linux Mint.
I like GUIs but I also like automation. Give me a nice simple GUI but also give me a way to run from a bash shell so I can automate functions based on complex conditions and/or a schedule.
I love NOAA’s hourly graphs. It is a quick visual way to understand the expected forecast. I wish I could find a good iPhone app that does something similar. Carrot is pretty good, but has annoying popups asking you to subscribe to premium.


Is that more than the kernel? How much more?


So its like Ntop for Kubernetes? Is it better than Ntop?
Yeah but you do backups right? Right?