▲ 459 ▼ Microsoft starts testing ads in the Windows 11 Start menu (www.theverge.com) submitted 2 years ago by dvdnet62@feddit.nl to c/technology@lemmy.ml 163 comments fedilink hide all child comments
[–] Zuberi@lemmy.dbzer0.com 42 points 2 years ago (3 children) Exactly why the Brazilian and German governments are switching to linux machines permalink fedilink source hideshow 6 child comments replies: [–] Contend6248@feddit.de 14 points 2 years ago* And my houshold 😁 Ther is for sure a 2.5k line powershell script from someone totally trustworthy which fixes this issue though permalink fedilink source parent [–] ahriboy@lemmy.dbzer0.com 7 points 2 years ago* (1 child) The French National Police also use Linux machines with its modified Ubuntu distro Gendbuntu. Plus, Russia uses Astra, based on vanilla Debian. permalink fedilink source parent hideshow 2 child comments replies: [–] Appoxo@lemmy.dbzer0.com 1 point 2 years ago Not like Russia can legally nor want to be dependant on MS/american software. permalink fedilink source parent [–] online@lemmy.ml 2 points 2 years ago (2 children) Which distro are the Germans switching to? permalink fedilink source parent hideshow 4 child comments replies: [–] Zuberi@lemmy.dbzer0.com 3 points 2 years ago (1 child) Can't find out the flavor on any websites. It might be a custom one and I imagine sharing the info would be more of a security risk. permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 2 points 2 years ago (1 child) It won't be a security risk once it's in use, IT across Germany will know within days of deployment. It will almost definitely be a modified version of some probably well known Linux. permalink fedilink source parent hideshow 2 child comments replies: [–] Zuberi@lemmy.dbzer0.com 1 point 2 years ago (1 child) No sense in giving an adversary info on the distro before it's fully implemented though I imagine. (I would consider that a head-start even if they heavily modify a popular distro) Giving the See👁️Aye advanced notice wouldn't be smart, no matter how they wanted to play it. It won’t be a security risk once it’s in use I agree permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 0 points 2 years ago (1 child) I don't think it really matters whether a potential adversary has a 'head start' all that much, security through obscurity doesn't work super well when it's going to be deployed to thousands of easily accessible devices anyway. It'd only just be a defense in depth, but even then meh. But it's neither here nor there, they'll do it whatever way they feel is best. permalink fedilink source parent hideshow 2 child comments replies: [–] Zuberi@lemmy.dbzer0.com 1 point 2 years ago (1 child) Basically all of social engineering is to get exactly what you're talking about, a "head start" Go to their LinkedIn: does the head engineer have MySQL version X on his skills, resume, job description, etc? Maybe somebody even endorsed them for it? "Wow they are THE best database administrator" Now you know who you need to hack for their database access AND what zero days to research. ANY info will be an attack vector permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 0 points 2 years ago* Social engineering is to gain access circumventing downcode, not really "get a head start"... Most attacks are entirely social engineering. You're not breaking into secure databases by pulling ridiculous zero day backdoors when it's much easier to convince an intern to download a file or give you access directly. These super involved attacks are state actors, and no amount of trying to hide what Linux version is being modified will do anything for you there. State actors of course also use social engineering Ultimately the point is hacking really doesn't involve the kind of subterfuge you're describing here in a way where " what Linux is it " matters at all. I mean, windows is used for secure systems across the world, it's hardly secretive. permalink fedilink source parent [+] dogzilla@lemmy.ml 1 point 2 years ago [deleted] permalink fedilink source parent
[–] Contend6248@feddit.de 14 points 2 years ago* And my houshold 😁 Ther is for sure a 2.5k line powershell script from someone totally trustworthy which fixes this issue though permalink fedilink source parent
[–] ahriboy@lemmy.dbzer0.com 7 points 2 years ago* (1 child) The French National Police also use Linux machines with its modified Ubuntu distro Gendbuntu. Plus, Russia uses Astra, based on vanilla Debian. permalink fedilink source parent hideshow 2 child comments replies: [–] Appoxo@lemmy.dbzer0.com 1 point 2 years ago Not like Russia can legally nor want to be dependant on MS/american software. permalink fedilink source parent
[–] Appoxo@lemmy.dbzer0.com 1 point 2 years ago Not like Russia can legally nor want to be dependant on MS/american software. permalink fedilink source parent
[–] online@lemmy.ml 2 points 2 years ago (2 children) Which distro are the Germans switching to? permalink fedilink source parent hideshow 4 child comments replies: [–] Zuberi@lemmy.dbzer0.com 3 points 2 years ago (1 child) Can't find out the flavor on any websites. It might be a custom one and I imagine sharing the info would be more of a security risk. permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 2 points 2 years ago (1 child) It won't be a security risk once it's in use, IT across Germany will know within days of deployment. It will almost definitely be a modified version of some probably well known Linux. permalink fedilink source parent hideshow 2 child comments replies: [–] Zuberi@lemmy.dbzer0.com 1 point 2 years ago (1 child) No sense in giving an adversary info on the distro before it's fully implemented though I imagine. (I would consider that a head-start even if they heavily modify a popular distro) Giving the See👁️Aye advanced notice wouldn't be smart, no matter how they wanted to play it. It won’t be a security risk once it’s in use I agree permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 0 points 2 years ago (1 child) I don't think it really matters whether a potential adversary has a 'head start' all that much, security through obscurity doesn't work super well when it's going to be deployed to thousands of easily accessible devices anyway. It'd only just be a defense in depth, but even then meh. But it's neither here nor there, they'll do it whatever way they feel is best. permalink fedilink source parent hideshow 2 child comments replies: [–] Zuberi@lemmy.dbzer0.com 1 point 2 years ago (1 child) Basically all of social engineering is to get exactly what you're talking about, a "head start" Go to their LinkedIn: does the head engineer have MySQL version X on his skills, resume, job description, etc? Maybe somebody even endorsed them for it? "Wow they are THE best database administrator" Now you know who you need to hack for their database access AND what zero days to research. ANY info will be an attack vector permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 0 points 2 years ago* Social engineering is to gain access circumventing downcode, not really "get a head start"... Most attacks are entirely social engineering. You're not breaking into secure databases by pulling ridiculous zero day backdoors when it's much easier to convince an intern to download a file or give you access directly. These super involved attacks are state actors, and no amount of trying to hide what Linux version is being modified will do anything for you there. State actors of course also use social engineering Ultimately the point is hacking really doesn't involve the kind of subterfuge you're describing here in a way where " what Linux is it " matters at all. I mean, windows is used for secure systems across the world, it's hardly secretive. permalink fedilink source parent [+] dogzilla@lemmy.ml 1 point 2 years ago [deleted] permalink fedilink source parent
[–] Zuberi@lemmy.dbzer0.com 3 points 2 years ago (1 child) Can't find out the flavor on any websites. It might be a custom one and I imagine sharing the info would be more of a security risk. permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 2 points 2 years ago (1 child) It won't be a security risk once it's in use, IT across Germany will know within days of deployment. It will almost definitely be a modified version of some probably well known Linux. permalink fedilink source parent hideshow 2 child comments replies: [–] Zuberi@lemmy.dbzer0.com 1 point 2 years ago (1 child) No sense in giving an adversary info on the distro before it's fully implemented though I imagine. (I would consider that a head-start even if they heavily modify a popular distro) Giving the See👁️Aye advanced notice wouldn't be smart, no matter how they wanted to play it. It won’t be a security risk once it’s in use I agree permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 0 points 2 years ago (1 child) I don't think it really matters whether a potential adversary has a 'head start' all that much, security through obscurity doesn't work super well when it's going to be deployed to thousands of easily accessible devices anyway. It'd only just be a defense in depth, but even then meh. But it's neither here nor there, they'll do it whatever way they feel is best. permalink fedilink source parent hideshow 2 child comments replies: [–] Zuberi@lemmy.dbzer0.com 1 point 2 years ago (1 child) Basically all of social engineering is to get exactly what you're talking about, a "head start" Go to their LinkedIn: does the head engineer have MySQL version X on his skills, resume, job description, etc? Maybe somebody even endorsed them for it? "Wow they are THE best database administrator" Now you know who you need to hack for their database access AND what zero days to research. ANY info will be an attack vector permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 0 points 2 years ago* Social engineering is to gain access circumventing downcode, not really "get a head start"... Most attacks are entirely social engineering. You're not breaking into secure databases by pulling ridiculous zero day backdoors when it's much easier to convince an intern to download a file or give you access directly. These super involved attacks are state actors, and no amount of trying to hide what Linux version is being modified will do anything for you there. State actors of course also use social engineering Ultimately the point is hacking really doesn't involve the kind of subterfuge you're describing here in a way where " what Linux is it " matters at all. I mean, windows is used for secure systems across the world, it's hardly secretive. permalink fedilink source parent
[–] Umbrias@beehaw.org 2 points 2 years ago (1 child) It won't be a security risk once it's in use, IT across Germany will know within days of deployment. It will almost definitely be a modified version of some probably well known Linux. permalink fedilink source parent hideshow 2 child comments replies: [–] Zuberi@lemmy.dbzer0.com 1 point 2 years ago (1 child) No sense in giving an adversary info on the distro before it's fully implemented though I imagine. (I would consider that a head-start even if they heavily modify a popular distro) Giving the See👁️Aye advanced notice wouldn't be smart, no matter how they wanted to play it. It won’t be a security risk once it’s in use I agree permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 0 points 2 years ago (1 child) I don't think it really matters whether a potential adversary has a 'head start' all that much, security through obscurity doesn't work super well when it's going to be deployed to thousands of easily accessible devices anyway. It'd only just be a defense in depth, but even then meh. But it's neither here nor there, they'll do it whatever way they feel is best. permalink fedilink source parent hideshow 2 child comments replies: [–] Zuberi@lemmy.dbzer0.com 1 point 2 years ago (1 child) Basically all of social engineering is to get exactly what you're talking about, a "head start" Go to their LinkedIn: does the head engineer have MySQL version X on his skills, resume, job description, etc? Maybe somebody even endorsed them for it? "Wow they are THE best database administrator" Now you know who you need to hack for their database access AND what zero days to research. ANY info will be an attack vector permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 0 points 2 years ago* Social engineering is to gain access circumventing downcode, not really "get a head start"... Most attacks are entirely social engineering. You're not breaking into secure databases by pulling ridiculous zero day backdoors when it's much easier to convince an intern to download a file or give you access directly. These super involved attacks are state actors, and no amount of trying to hide what Linux version is being modified will do anything for you there. State actors of course also use social engineering Ultimately the point is hacking really doesn't involve the kind of subterfuge you're describing here in a way where " what Linux is it " matters at all. I mean, windows is used for secure systems across the world, it's hardly secretive. permalink fedilink source parent
[–] Zuberi@lemmy.dbzer0.com 1 point 2 years ago (1 child) No sense in giving an adversary info on the distro before it's fully implemented though I imagine. (I would consider that a head-start even if they heavily modify a popular distro) Giving the See👁️Aye advanced notice wouldn't be smart, no matter how they wanted to play it. It won’t be a security risk once it’s in use I agree permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 0 points 2 years ago (1 child) I don't think it really matters whether a potential adversary has a 'head start' all that much, security through obscurity doesn't work super well when it's going to be deployed to thousands of easily accessible devices anyway. It'd only just be a defense in depth, but even then meh. But it's neither here nor there, they'll do it whatever way they feel is best. permalink fedilink source parent hideshow 2 child comments replies: [–] Zuberi@lemmy.dbzer0.com 1 point 2 years ago (1 child) Basically all of social engineering is to get exactly what you're talking about, a "head start" Go to their LinkedIn: does the head engineer have MySQL version X on his skills, resume, job description, etc? Maybe somebody even endorsed them for it? "Wow they are THE best database administrator" Now you know who you need to hack for their database access AND what zero days to research. ANY info will be an attack vector permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 0 points 2 years ago* Social engineering is to gain access circumventing downcode, not really "get a head start"... Most attacks are entirely social engineering. You're not breaking into secure databases by pulling ridiculous zero day backdoors when it's much easier to convince an intern to download a file or give you access directly. These super involved attacks are state actors, and no amount of trying to hide what Linux version is being modified will do anything for you there. State actors of course also use social engineering Ultimately the point is hacking really doesn't involve the kind of subterfuge you're describing here in a way where " what Linux is it " matters at all. I mean, windows is used for secure systems across the world, it's hardly secretive. permalink fedilink source parent
[–] Umbrias@beehaw.org 0 points 2 years ago (1 child) I don't think it really matters whether a potential adversary has a 'head start' all that much, security through obscurity doesn't work super well when it's going to be deployed to thousands of easily accessible devices anyway. It'd only just be a defense in depth, but even then meh. But it's neither here nor there, they'll do it whatever way they feel is best. permalink fedilink source parent hideshow 2 child comments replies: [–] Zuberi@lemmy.dbzer0.com 1 point 2 years ago (1 child) Basically all of social engineering is to get exactly what you're talking about, a "head start" Go to their LinkedIn: does the head engineer have MySQL version X on his skills, resume, job description, etc? Maybe somebody even endorsed them for it? "Wow they are THE best database administrator" Now you know who you need to hack for their database access AND what zero days to research. ANY info will be an attack vector permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 0 points 2 years ago* Social engineering is to gain access circumventing downcode, not really "get a head start"... Most attacks are entirely social engineering. You're not breaking into secure databases by pulling ridiculous zero day backdoors when it's much easier to convince an intern to download a file or give you access directly. These super involved attacks are state actors, and no amount of trying to hide what Linux version is being modified will do anything for you there. State actors of course also use social engineering Ultimately the point is hacking really doesn't involve the kind of subterfuge you're describing here in a way where " what Linux is it " matters at all. I mean, windows is used for secure systems across the world, it's hardly secretive. permalink fedilink source parent
[–] Zuberi@lemmy.dbzer0.com 1 point 2 years ago (1 child) Basically all of social engineering is to get exactly what you're talking about, a "head start" Go to their LinkedIn: does the head engineer have MySQL version X on his skills, resume, job description, etc? Maybe somebody even endorsed them for it? "Wow they are THE best database administrator" Now you know who you need to hack for their database access AND what zero days to research. ANY info will be an attack vector permalink fedilink source parent hideshow 2 child comments replies: [–] Umbrias@beehaw.org 0 points 2 years ago* Social engineering is to gain access circumventing downcode, not really "get a head start"... Most attacks are entirely social engineering. You're not breaking into secure databases by pulling ridiculous zero day backdoors when it's much easier to convince an intern to download a file or give you access directly. These super involved attacks are state actors, and no amount of trying to hide what Linux version is being modified will do anything for you there. State actors of course also use social engineering Ultimately the point is hacking really doesn't involve the kind of subterfuge you're describing here in a way where " what Linux is it " matters at all. I mean, windows is used for secure systems across the world, it's hardly secretive. permalink fedilink source parent
[–] Umbrias@beehaw.org 0 points 2 years ago* Social engineering is to gain access circumventing downcode, not really "get a head start"... Most attacks are entirely social engineering. You're not breaking into secure databases by pulling ridiculous zero day backdoors when it's much easier to convince an intern to download a file or give you access directly. These super involved attacks are state actors, and no amount of trying to hide what Linux version is being modified will do anything for you there. State actors of course also use social engineering Ultimately the point is hacking really doesn't involve the kind of subterfuge you're describing here in a way where " what Linux is it " matters at all. I mean, windows is used for secure systems across the world, it's hardly secretive. permalink fedilink source parent