Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror

Comment the cloud makes security so goddamn tedious (Score 2) 82

My list of blocked User-Agents grows daily, from obvious bots to ancient browser versions. Can't just block the IPs because lots of useful services are using the cloud too, like getting certs from Let's Encrypt. Scientology is now hiding behind the Amazon veil, when they send mail they use somerandombullshit@aws or whatever as the envelope sender so I have to scan the DATA headers in order to block their intergalactic propaganda at the server level.
Years ago I started watching the internet static, the random port connection attempts. I started out just wanting to find and block nmap-style port scanning, but I saw all this other weird stuff and started collecting data. For a couple years there was a guy using Digital Ocean droplets to do weird port scanning. He used a different droplet for each port he would scan and he set the hostname to "a 6 letter word from a standard dictionary list"."the port number but backwards and repeated by position, like 1234 = 4332221111"."three random letters", and the source port was always 61953. He'd hit my server 4-500 times a day, but only 3 days a week, Sunday thru Tuesday. I reported him consistently until after some months they finally said "Oh, we know."
Digital Ocean at least tries to give you a programmatic way of reporting abuse, the other guys make it so onerous with long web forms with so many required fields that rarely have anything to do with your particular issue. I wish they would just hire Lily Tomlin to say "We don't have to care, we're goozurewebsandwiches.usercontent or whatever the fuck."

Comment Re:And that's why we have standards (Score 1) 117

Same problem. I have a "WrongNumber" folder where I store them as evidence in case some site eventually tries to make me comply with a contract signed by "other me". >95% of the bogus emails I get have no verification link, and >99% don't have a "this isn't me" link. If you try to mail them back it takes 3-4 exchanges before they understand the dot rule, "But your mail has a dot, we didn't send to a dot." Could save so many headaches if they just implement double opt-in.

Comment Never trust a telco (Score 1) 582

"significant resources are spent to maintain 'legacy' POTS service" and when we kill POTS we can fire everyone and then keep our rates as high as they are and steal more money. An obvious win-win. For the telcos. Lose-lose-lose-lose-lose for us.

Also, the zoning board of my old town is so full of nimbys that they'd rather fall off the comms grid than erect a cell tower where it might be *gasp* VISIBLE! (ie. the only place a point-to-point signal is reliable.) Pretty sure they're not alone.

Fukt on many levels.

Slashdot Top Deals

Murphy's Law, that brash proletarian restatement of Godel's Theorem. -- Thomas Pynchon, "Gravity's Rainbow"

Working...