Content filtering should be highly context dependent. If the WAF is detached from what it's supposed to filter, this happens. If the WAF doesn't have the ability to discern between command and content contexts, then the filtering shouldn't be done via WAF. This is like spam filtering. I'm an anti-spam advocate, so the idea that most people can't discuss spam because even the discussion will set off filters is quite o…
SPF and DKIM are now more commonly implemented correctly by spammers than by major email providers. https://news.ycombinator.com/item?id=43468995
Writing "/etc/hosts" breaks the Substack editor
261–270 of 370 posts
Re: Writing "/etc/hosts" breaks the Substack editor
#262Earlier quoted context omitted.
I think I like this idea that the rotation interval could be made proportional to length, for example doubling the interval with each additional character. Security standards already now acknowledge that forced yearly rotation is a net decrease in security, so this would incentivize users to pick the longest password for which they would tolerate the rotation interval. Is yearly rotation too annoying for you? For mer…
Can confirm when I found out I'd be required to regularly change my password the security of it went down significantly. At my current job when I was a new employee I generated a secure random password and spent a week memorizing it. 6 months later when I found out I was required to change it, I reverted to a variation of the password I used to use for everything years ago with some extra characters at the end that I…
Re: Writing "/etc/hosts" breaks the Substack editor
#263Earlier quoted context omitted.
It's a standard practice. And at $CURENT_JOB it's driven by semi-literate security folks, definitely not insurance.
Insurance and liability concerns drive the security folks. Just wait when more countries keep adopting cybersecurity laws for companies liabilities when software doesn't behave, like in any other engineering industry.
Re: Writing "/etc/hosts" breaks the Substack editor
#264Earlier quoted context omitted.
Can confirm when I found out I'd be required to regularly change my password the security of it went down significantly. At my current job when I was a new employee I generated a secure random password and spent a week memorizing it. 6 months later when I found out I was required to change it, I reverted to a variation of the password I used to use for everything years ago with some extra characters at the end that I…
Why not make use of a password manager?
Re: Writing "/etc/hosts" breaks the Substack editor
#265Earlier quoted context omitted.
> I disagree with other posts here, it is partially a balance between security and usability. And economics. Many people here are blaming incompetent security teams and app developers, but a lot of seemingly dumb security policies are due to insurers. If an insurer says "we're going to jack up premiums by 20% unless you force employees to change their password once every 90 days", you can argue till you're blue in th…
> If an insurer says "we're going to jack up premiums by 20% unless you force employees to change their password once every 90 days", you can argue till you're blue in the face that it's bad practice, NIST changed its policy to recommend not regularly rotating passwords over a decade ago, etc., and be totally correct... but they're still going to jack up premiums if you don't do it. I would argue that password polici…
When you don’t require them to change it, you can just assign them a random 16 character string and tell them it’s their job to memorize it.
Re: Writing "/etc/hosts" breaks the Substack editor
#266it was a cf managed waf rule for a vulnerability that doesn't apply to us. we've disabled it.
Re: Writing "/etc/hosts" breaks the Substack editor
#267Earlier quoted context omitted.
> I disagree with other posts here, it is partially a balance between security and usability. And economics. Many people here are blaming incompetent security teams and app developers, but a lot of seemingly dumb security policies are due to insurers. If an insurer says "we're going to jack up premiums by 20% unless you force employees to change their password once every 90 days", you can argue till you're blue in th…
Why wouldn't the IT people just tell the grumbling employees that exact explanation?
Re: Writing "/etc/hosts" breaks the Substack editor
#268Everything old is new again :) We used to call this the Scunthorpe problem. https://en.m.wikipedia.org/wiki/Scunthorpe_problem
See also: Recent scrubbing US government web sites for words like "diversity", "equity", and "inclusion". Writing about biology, finance, or geology? Shrug. Dumb filtering is bad enough when used by smart people with good intent.
For bonus, the reverse proxy will run on a system infiltrated by Russian (why not Chinese as well) hackers.
Re: Writing "/etc/hosts" breaks the Substack editor
#269Earlier quoted context omitted.
I don’t think locking down slashes support calls because you will now receive support requests anytime someone wants to install something and actually have a good business reason to do so.
Consider the ones you don't get: ones where PCs have to be wiped from customization gone wrong, politics and productivity police calls - "Why is Bob gaming?", "Why is Alice on Discord?". It's about the transition from artisanal hand-configuration to mass-produced fleet standards, and diverting exceptional behavior and customizations somewhere else.
Alice is on Discord because half of the products the company uses now give more or less direct access to their devs through Discord
Re: Writing "/etc/hosts" breaks the Substack editor
#270Earlier quoted context omitted.
Why wouldn't the IT people just tell the grumbling employees that exact explanation?
If you've read this thread, it would appear that most people here on HN aren't actually involved with policy compliance work dictated from above. Have you ever seen a Show HN dealing with boring business decisions? No. We do, however, get https://daale.club/