Jump to content

seawolf

Members
  • Posts

    975
  • Joined

  • Last visited

Reputation

4,945 Excellent

About seawolf

  1. No, you made the error in assuming that I was preaching for closed source. All I asked was if you preferred Apple to document how to hack the iPhone. As in document all of the back doors and intentional vulnerabilities in iOS so that anyone and their brother could use them. That's what I said. Check it. Then see who jumped to the conclusion here. My later comment about obscurity combined with great security frameworks being the ideal means that if you could take the community review of open source and combine it with the obscurity (and money for developers and testers) of closed source you'd have the ideal security. Disagree? It's impossible yes, but it would be the ideal. Anyway, I'm done with it. Edugeek is a minefield of bias. Bye.
  2. Bugs are discovered and fixed all of the time in closed source software. Like Windows for example. You know, that closed source, proprietary system you use all of the time? So, the bug may have been found and fixed much faster. On the other hand, it may have not. You accuse me of championing security through obscurity (I am not) while apparently claiming that open source is always more secure. It is not. It's much more complicated than that. Systems and code that are more used are generally improved more rapidly and have more people working on them - whether open or closed source. And there about as many in open source. Let me improve my argument with a bit of empirical evidence showing that both closed and open source are pretty much equally vulnerable. http://www.icsi.berkeley.edu/pubs/networking/securityof09.pdf The worst thing though is to have good documentation and an open code base and having no one reviewing and updating that code regularly. That is a recipe for disaster as the documentation is just a gift to hackers (like Heartbleed) and there are quite a few open source projects that suffer from this sort of neglect (no one reviewing or updating code regularly or properly).
  3. So, anyway how did this strategy work out for OpenSSL? Biggest known security flaw in the history of the internet sitting right there out in the open for years. Awesome stuff. Give me more of that!
  4. Why of course not, I'm an Aussie after all. Right? A real fair dinkum bloke you are there mate. Good on ya.
  5. So, how did that out in the open thing work out for OpenSSL? Heartbleed anyone? Obscurity plus good security frameworks are the ideal. How things actually are is that you're dreaming if you think there is privacy on the internet. There hasn't been for a LONG time.
  6. You would prefer that Apple document how to hack the iPhone? Interesting perspective. In any case, I'm simply stating how it is. I don't even own an iPhone anymore and have no plans to buy one in the future, or any other smartphone for that matter (I have a Nokia 106 a basic as u can get). So, I couldn't really give a rip how secure or insecure the iPhone is. My view is that anyone who expects complete privacy in anything that is connected to the internet is delusional. That wasn't even true in 1988.
  7. LOL. Well, I'm going to speculate about beer now. Much more entertaining.
  8. It would only be speculation if I had no knowledge of these sort of things. But, I do. Yes, it is possible, but the war has only been going on since the spring and the SAM systems have only entered the arena recently, which makes it less likely. A more plausible answer might be that there are ex-Russian military soldiers fighting for the separatists or covert Russian soldiers fighting for them. Many countries have done this in the past, it certainly wouldn't be the first time. Exactly. Or, because they are going to allow Russia to save face as long as the Russian government hangs the separatists out to dry. The fact is that governments make all kinds of decisions like that which are perhaps morally questionable, but done for political or economic reasons in order to prevent wars and keep the status quo, etc.. It's happened many times in the past.
  9. So, from what can be gleaned from the article, the iPhone is pretty secure, particularly more recent ones. Except for those back doors that they have to provide to law enforcement or risk being shut down. Anyone have memory of Lavabit? They were being forced to handover encryption keys to the govt. and decided to shut the doors instead. The big IT companies chose to handover data via court orders when required rather than shut the doors like Lavabit did. So, yeah not ideal, but Google, Microsoft, Apple, etc. haven't really been given much choice have they? Apple even outlines the process pretty clearly in public domain: https://www.apple.com/legal/more-resources/law-enforcement/ Unless any of the big IT companies are willing to take a huge risk that's the way it is. Apple, Google, Microsoft unite against NSA spying program - CNET
  10. Sure, I could fire it with a little remedial training because of my previous training and knowledge. I could not set it up in the first place though without much more extensive training on this particular weapons system. That would normally require months of intensive training for the average air defence operator candidate, who would be a brighter bulb than the average soldier in the first place. Here is the thing though. Firstly, setting up the system to begin with takes a lot of specific knowledge and training. Not just anyone can do it. You could train someone on how to turn on the radars, engage a target and fire a missile in at least a week of training if the person is of at least average intelligence (for the general population, not the average grunt). The person doing the training would have to be highly knowledgeable on the system though to have a chance to train an operator reasonably. Additionally, an unskilled operator would be far more likely to launch a salvo of missiles at the target particularly if they believed it to be a military target. That didn't happen and only one well-placed missile was launched bringing down the plane. Since there were also Russian aircraft in the vicinity (being near the border), for the Russians to allow just indiscriminate firing that could bring down their aircraft seems to be highly unlikely and beyond stupid even for them. So, the system was setup by someone with a lot of knowledge and training. The system could have been fired by someone with short very intensive training, but the trainer would have to be highly knowledgeable. The system appears to have been used quite expertly in targeting the aircraft, other than the (hopefully) mis-identification of it (rather than intentional targeting). The Russians would not want their own aircraft downed because of completely incompetent operators shooting in the blind with no knowledge of what they are shooting at, which puts barely trained operator as a suspect proposition. These things point in the direction of trained Russian personnel. Could it have been an ex-Ukraine military air defence soldier? It's possible. Not as likely though and the next issue that I point out below makes it even more likely Russia was directly involved. Secondly, there is a great difference between how a skilled and experienced operator would use the system vs. a quickly trained grunt. A skilled operator would know that when the SA-11 radar is turned on to track and target aircraft, it lights up the electromagnetic spectrum like a flood light in pitch black. Every second the radar is on, the operator and his SAM site is a sitting duck for an anti-radar missile or a bomber. Leaving the system turned on for more than a couple of minutes is broadcasting to the enemy "Come bomb me! Come bomb me!". That being the case, the way SAM systems are almost always used is that they receive information from a central command station on targets based on collated radar data from various (non-SAM) sites. In some cases, a remote radar feed is relayed directly to the SAM site operator if their equipment is sophisticated enough (the Chinese and Russians both have such systems as do most western militaries). The central command station would inform the SAM operator that a target is nearing their position and the SAM operator would then fire up the radar to begin directly tracking and targeting the target(s). The target is engaged and fired on. The radar is then immediately turned off, and if it is a mobile SAM site the operators will then pack up and move to another location so they aren't targeted for a retaliatory attack. My particular expertise in this area is in targeting and destroying SAM systems, and a HARM or ALARM missile makes pretty short work of them. An experienced SAM operator knows they are a sitting duck leaving that radar on. So, leaving the SA-11 radar on just waiting for a target to come your way would most likely result in the SAM site being destroyed particularly since the SAM system in question was an enemy site in Ukraine territory. No, the most likely scenario is the SAM operator received information that there was a target or targets in the area and they then fired up the radar and fired on the target. Where would this radar information likely come from? You connect the dots. Unless its really the Ukraine military that shot down the plane, which appears highly unlikely based on what's been revealed about the incident so far, Russia is most likely far more involved in this shoot down than they want anyone to know. Notice that I used language such as likely, highly likely, and probable throughout this analysis. I don't have the intel in my hand to review, so I could be off the mark. But, some of the theories I've heard bandied about are extremely unlikely and espoused by individuals with no idea of what they are talking about.
  11. If only that is what they were actually doing. No, they are too often using technology to communicate with people that are in the same room as they are. And, what good is it to artificially socialise with people on the other side of the world at the cost of learning how to socialise with someone face to face. Then there are things like Snapchat, Wickr, Yik Yak, Streetchat, Ask.fm and piles of other apps and services that seem to have an almost singular purpose of providing teens ways to get themselves into some serious trouble and enabling bullying and sexting in a big way. Technology has a lot of pros as well, but I've seen a great too many negative impacts on kids and society as a whole the last couple of years to think what is happening is a good thing.
  12. In that case, here is what I would suggest. Write up a proposal explaining the importance of the backups and what the impact of not having proper backups could mean for the school, then make your recommendations for a minimally adequate backup solution including costings. Write it with enough detail, but keep it reasonably short and in a language they will understand (difficult I know), then email it to Pointy Haired Boss and any others involved in the decision. If they say no, file the email with its nice date-time stamp and your document away in a safe place prepared to bring it out if the need ever arises, which it very possibly will at some point in the future. You should also be very careful to document your backup system and strategies including backup jobs and disk rotations, so that if anything does go wrong (possible) you can show that you were implementing the inadequate system as well as was humanly possible. So, it will be clear the fault lay in the resources provided, not in you. Even better, ask Pointy Haired Boss to formally sign off on the backup strategy you develop using your inadequate resources. That way, they can't fault you for the backup strategy either.
  13. Finally, something plausible and reasonable said. Although, the actions by both the separatists and Russia following the shooting down of a plane with 298 people on board make it pretty clear they don't really care either.
  14. A drunken separatist wouldn't have a snowballs chance in hades of hitting an aircraft flying at 33,000 feet with an SA-11 missile system without extensive, specialised training in the use of that equipment. Which means it is highly unlikely it was a separatist that targeted the plane. Maybe they let the drunk separatist hit the button right at the pointy end. That's entirely possible. No, my secret squirrel clearance is no longer current. I do have several years worth of experience with SAM systems and associated radar technologies, including those used by Russia and other former Soviet states though. You said "murder" when describing the actions by Israel. Did you mean to say something else?
×
×
  • Create New...