Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Comment Re: Trump did not win 2020 (Score 1) 146

âoe Do you really think Trump was so bad that Republicans rigged the election to keep him out of office?â

Yes thatâ(TM)s what theyâ(TM)re saying. What too many experts misunderstood was Trump ran against the GOP in the primary: he positioned himself as the (ironically) anti-elite candidate and positioned (successfully) the other GOP candidates as elites (and the DNC as the party of the elites). He ran as a populist, an anti-elite populist, while the experts kept assuming he was a loyal member of the GOP.

Itâ(TM)s why so many experts got the Hillary v Trump election so wrong, they kept thinking it was a classic GOP v DNC match up, when it was really a different axis altogether he messaged around. So yeah, when some of his supporters say the election was stolen, theyâ(TM)re not limiting their ire to Democrats, theyâ(TM)re including Republicans as well, because they donâ(TM)t trust the GOP either. Populism v Elitism is the actual axis theyâ(TM)re on, not GOP v DNC.

Comment Re:Maybe they did, maybe they didn't. Commission s (Score 1) 110

The independent analysis by a law firm hired by thr court says they didn't knowingly do anything wrong. It sounds like the cops are trying to cover their ass, however.

The contract says they are allowed to pick locks.
The contract says they can work "in the day and in the evening", etc.

The county is a subdivision of the state, created by the state. States tell counties what they can and cannot do. Counties don't tell the state what the state can do.

I haven't spent a hundred hours looking into every be little detail, but it sounds like the pentesters did roughly what they were hired to do, and the cops got embarrassed.

I think youre right. If the Sherrifs department was also responsible for the security of the building, then this is a conflict of interest: theyre aggrieved and possibly embarrassed.

Comment Re:The World's Most Dangerous Job (Score 1) 110

Am I the only one here who wouldn't do this "penetration testing" job for any amount of money - in the USA, at least. There seem to be enough Americans who think nothing of using 'lethal force' if someone puts a single foot on their property, and cops who will shoot an unarmed kid for running away that I'd be scared of my life every minute. All it needs is one trigger-happy idiot to assume you ARE a terrorist/intruder/criminal/black and bang, you're dead. These guys must have big balls, and for that alone they should be exempt from prosecution...

In general we dont recommend customers do this kind of testing unless they had a solid program. If you think your physical security is lacking, then a daytime site assessment with the cooperation of the site is both a lot more effective and its safe. You can just tour the site, and look at anything you want preferably with someone from the site thats an SME on their measures along to show you what they have, how they use it, and to prove it works to you.

It can also be an excellent opportunity to build repor with the site and to get people to tell you what their problems are. Most people who care about security will gladly tell you whats lacking and what they would like to improve. That kind of candor is impossible to get if you've made the site look stupid. Active penetration testing is a little too kungfu hollywood bad assery for nearly everyone. Its only useful if your program is solid, and you want to test the entire program. For example, an actual force on force excercis: you're testing the site response basically. And to your point - hell yes you might get shot which is why this kind of "Sneakers" like pentesting is really a bad idea and almost always asked for by amateurs. Some standard says they have to have it, so they slap it into an SOW.

Personally, I dont do these kind of assessment anymore, theyre a waste. If the customer asked me to assess their physical security controls, I'd ask for a daytime tour and have someone come along thats authorized to touch and modify things, and ask them to show me how the control works. And leave it up to them to prove it to me, and I would never tell them how to do it, you dont want to be accussed of telling them to break something, or trigger an alarm like if you told them to pop open an iStar IDS control panel.

So yeah, no I wouldnt recommend doing this kind of work, its like testing someone to see if they have high blood pressure by telling them to run a marathon. These easier ways to test for that wont get you killed, and are far more pleasant.

Comment This what people do when their security sucks (Score 1) 110

I'm sorry, but this is how organizations behave when they know they have security issues and want to hide that fact. A pentesters job is to test security controls in the wild, under realistic scenarios. The Sheriff is changing the subject, they got in. So theres problems with the security of those buildings, fix it, end of discussion. And apparently the state is conducting these assessments because they suspect some counties have security problems, which in this case they do.

The fact that this time the people that broke in were friendly should be seen as a plus, you Mr. Sherrif are getting a get of jail free card. You get to correct these problems before real harm occurs. If these had been actual burglars or as they histronically implied terrorists, well the outcome would have pretty bad for the county.

Comment Why would you use company resources to do this? (Score 3, Insightful) 55

It seems kind of naive to assume you can use any companies systems and rooms without them knowing what youre doing, or at least wanting to know. And if youre doing this to schedule meetings to plan protests of the company itself? Seems pretty obvious any company would want to know about that. Whether or not you should be able to do this, its just wishful thinking to think any company isnt going to notice when more than 100 employees decide to hold a meeting that doesnt involve management, or otherwise isnt clearly work related. And if its to protest the company? Come on. Theyll know.

So, for Google employees: of course theyre "spying" on you, you work for them. They literally want to know what youre doing all day. If you dont want Google to know what youre doing, do it outside of work. Use some common sense.

Comment Re: Gun control however... (Score 3, Insightful) 856

The net effect is already known. We have jurisdictions with strict gun control in the US, and there's no causative decrease in armed crime. Gun control, at best, hopes to effect the supply, the supply is already massive so it can't do much there, at worst it's an attempt to control ownership which no law can accomplish: laws can only regulate legal commerce. Black markets just pop up and go around fhem when there is massive demand, and with the already massive supply prices stay relatively low. Example: the so called drug war. No impact on supply or demand. And with vigorous gun laws, you will create a black market.

So if you want to reduce supply, you have to get rid of guns: confiscation or buy back with significant incentives, and even then you can't eliminate supply. But thats what youd have to do. And to reduce demand you have to both reduce crime, and increase penalties on gun crimes to something so severe you both deter and slowly eliminate law breakers.

If you're serious about reducing gun violence, look at the root cause of most of it: drug control laws. Get rid of drug prohibition and a large percentage of all violent crime goes away. Anything else, including gun control laws, is only going to make a minor difference, at best, and is likely to just make things worse. You have to eliminate the root cause of violence, the gun is not the cause, it's just one means, and don't kid yourself if a lot of money is available to a criminal element, they will get all the guns they want no matter what laws you pass.

Slashdot Top Deals

C++ is the best example of second-system effect since OS/360.

Working...