And here's both the #dragon and #phoenix together.
#fantasyminiatures #miniature #minipainting #miniaturepainting
PSA
If you're a #trans person in #England who wants gender-affirming care via the #NHS, please be advised:
1. You have a choice of which Gender Identity Clinic (#GIC) you are referred to.
2. Since the pandemic, all GICs have offered virtual appointments via video conferencing in addition to in-person ones.
If you're okay with a virtual appointment, you can ignore distance & choose the one with the lowest waiting time.
Posted! More theism / atheism / apologetics stuff, with edgy philosophy
A Nice Tri-Omni God https://ceoln.wordpress.com/2023/08/06/a-nice-tri-omni-god/
AI / Superconductors / Satire / lol
Note (inter alia) the list of signatories.
I am quite happy and grateful to report that Transmissions from the Chaos Buddha is now a part of the Library of Eris. Thanks to @tuesday for the offer of inclusion.
The CEO of Tenable just ripped Microsoft a new one. It's bad enough that cloud vulnerabilities rarely get CVEs or any kind of external documentation.
"Microsoft’s lack of transparency applies to breaches, irresponsible security practices and to vulnerabilities, all of which expose their customers to risks they are deliberately kept in the dark about.
In March 2023, a member of Tenable’s Research team was investigating Microsoft’s Azure platform and related services. The researcher discovered an issue (detailed here) which would enable an unauthenticated attacker to access cross-tenant applications and sensitive data, such as authentication secrets. To give you an idea of how bad this is, our team very quickly discovered authentication secrets to a bank. They were so concerned about the seriousness and the ethics of the issue that we immediately notified Microsoft.
Did Microsoft quickly fix the issue that could effectively lead to the breach of multiple customers' networks and services? Of course not. They took more than 90 days to implement a partial fix – and only for new applications loaded in the service.
That means that as of today, the bank I referenced above is still vulnerable, more than 120 days since we reported the issue, as are all of the other organizations that had launched the service prior to the fix. And, to the best of our knowledge, they still have no idea they are at risk and therefore can’t make an informed decision about compensating controls and other risk mitigating actions. Microsoft claims that they will fix the issue by the end of September, four months after we notified them. That’s grossly irresponsible, if not blatantly negligent. We know about the issue, Microsoft knows about the issue, and hopefully threat actors don’t. "
Lucid, clear explanation (as is usual from @xriskology) of the grave risk posed by utopians with power & money:
1. #Utopian visions are inherently self-rationalizing. Their revolutions can never fail, they can only *be* failed.
2. #Utopianism is more or less always exclusionary. "If the Christian heaven were to include atheists, for instance, it wouldn't be heaven."
A bunch of right-wingers knew there was a trans woman in the Barbie movie, but couldn't figure out which Barbie they were supposed to be angry about. On the dangerous future of paranoia and transphobia: https://www.readtpa.com/p/transphobia-and-right-wing-paranoia
While not blogging about licenses, here's some thoughts about why the OSI is so ineffective at guiding those discussions - because they failed connecting to their champions.
👀 Via Kyle Griffin:
Justice Elena Kagan has voiced her support for a new Supreme Court ethics code — taking a sharply different stance than Samuel Alito.
"It just can't be that the court is the only institution that somehow is not subject to checks and balances ... We're not imperial." #SCOTUS
@tillshadeisgone one option for white people here who want to reply to posts about Black or Indigenous experiences is to 1. like (shows you read it) and 2. boost (shows it’s an idea that made you think). Still need to reply? “Thanks for posting this, it’s making me think” Still concerned the person of color is not quite right in describing their own experience? Consider workshopping your concerns with another white person you know likes to think about these ideas. We have options!
How to secure a Content Distribution Network (CDN):
1. If you don't have servers, no one can steal them. This approach is upsetting to executives; do not recommend.
2. If you don't connect servers to the internets, the servers are safe from most anything other than physical theft. The "Network" part of CDN is missing.
3. If you don't store data, your CDN is safe from data theft. The "Content" part of CDN is missing. The CDN may still be a vector for pivoting into other systems in your infrastructure, or could be used as a botnet or for griftocurrency miners, or as a cost center for other departments to use as an example. Hopefully a good example.
4. The less sensitive your data, the less risk you take on. But public data doesn't mean zero risk: What could an attacker do if they put malicious content on your CDN? Anything from CSAM to ransomware JavaScript that clients download and run.
5. You're gonna want to log things. Network flow logs, audit logs, system logs, error logs, access logs, logs logs logs, everyone wants a log. Depending on your business, logging which IP address requested what resource may be important data to collect. That non-sensitive data from #4? Connecting any ID to that in a log now makes that sensitive data. Don't play games with "well it's not THAT sensitive" nor "but we hashed it so it's anonymized". Bring that stinky diaper straight to Legal, Privacy, then Cryptography — in exactly that order, do not pass Go, do not collect $200.
6. Don't keep logs or data or packages or services or features you don't need, don't provide access you don't need, don't trust anything you don't have to. The fewer features you support, the less data you keep, the less data that touches a drive (or swap, or memory) in the first place, the better you can design your CDN from the ground up to be more resilient and more secure.
7. Do not under any circumstances assume that #6 will never change. Know what's coming down the road. Don't fall for the classic software blunders by over-engineering against all possible futures.
8. Do not under any circumstances assume that any one layer of controls is sufficient. You may accept the risk, with awareness and intent—but never assume. You will thank me when #7 bites you and you have an extra layer of winter clothing. You're welcome.
"I thought you said that your dog doesn't bite"
"He doesn't! That is not my dog!"
- The Pink Panther Strikes Again
A consciousness somehow associated with matter.
Posting about culture, philosophy, politics, AI Art Tools, NaNoWriMo, Software Development occasionally, the relationship of consciousness to matter.
Degrees in Philosophy and Computer Science, once had a US TS/SCI(redacted) clearance, radical-for-the-US politics, ex-Libertarian, zen-buddhist-pantheist-atheist.
Google employee, but I do not speak for Google in any way.
If your profile tells me nothing about you, it's less likely I'll follow you (back).
Header: abstract smoky patterns
pfp: Adorable weird piglet / delirium cultist... thing. In a hoodie.