2.5 Admins 171: RSA PSA

Why a small island nation’s top level domain ended up with such a terrible reputation, an ssh vulnerability that’s not as scary as it sounds, whether software can be “finished”, and using powerline or WiFi for security cameras.

 

 

Plugs

Support us on patreon and get an ad-free RSS feed with early episodes sometimes

 

News

How a tiny Pacific Island became the global capital of cybercrime

Passive SSH server private key compromise is real … for some vulnerable gear

 

Feedback

The beauty of finished software

 

 

 

Free Consulting

We were asked about using powerline or WiFi for security cameras.

 

 

 

 

 

 

Kolide

Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today to see how it works at kolide.com/25a

 

The Traceroute Podcast

Check out the new season of the Traceroute Podcast on Apple, Spotify, or wherever you get your podcasts.  Visit the website.

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

2.5 Admins 170: Uninterruptible WiFi

Why and how Allan installed a set of new Power over Ethernet wireless access points, and our hardware recommendations for a media server and NAS in one.

 

Allan’s new WiFi setup

Access points

Controller

 

 

Free Consulting

We were asked for hardware recommendations for a media server and NAS in one.

 

 

 

 

 

 

HelloFresh

With HelloFresh, you get farm-fresh, pre-portioned ingredients and seasonal recipes delivered right to your doorstep. Get free breakfast for life at hellofresh.com/25adminsfree with code 25adminsfree. (One breakfast item per box while subscription is active).

 

Kolide

Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today to see how it works at kolide.com/25a

 

 

 

 

 

See our contact page for ways to get in touch.

 

2.5 Admins 169: SDCoF

A Cloudflare outage shines a light on sloppy data center practices, and why you shouldn’t run a mail server at home. Plus followup on the Android multi-user bug, package managers on Windows, and Toshiba hard drives.

 

Plugs

Support us on patreon and get an ad-free RSS feed with early episodes sometimes

 

News/discussion

Cloudflare claims Flexential data center outage was behind service disruption – DCD

Post Mortem on Cloudflare Control Plane and Analytics Outage

Android 14’s storage disaster gets patched, but your data might be gone

 

Feedback

winget

Toshiba Consumer Internal Hard Disk Drives

 

Free Consulting

We were asked about running a mail server at home.

“Run Your Own Mail Server” chapter 0

 

 

 

 

 

 

HelloFresh

With HelloFresh, you get farm-fresh, pre-portioned ingredients and seasonal recipes delivered right to your doorstep. Get free breakfast for life at hellofresh.com/25adminsfree with code 25adminsfree. (One breakfast item per box while subscription is active).

 

Kolide

Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today to see how it works at kolide.com/25a

 

 

 

 

 

See our contact page for ways to get in touch.

 

2.5 Admins 168: Do The Right Thing

Okta seems to not be taking its security seriously enough, crashing iPhones is far easier than it should be, Jim’s report from the Ubuntu Summit, and what to do when you find a company’s sensitive data on the Internet.

 

Plugs

Support us on patreon and get an ad-free RSS feed with early episodes sometimes

 

News

No, Okta, senior management, not an errant employee, caused you to get hacked

Okta October breach affected 134 orgs, biz admits

Okta hit by another breach, this one stealing employee data from 3rd-party vendor

This tiny device is sending updated iPhones into a never-ending DoS loop

Jim went to the Ubuntu Summit

 

Free Consulting

We were asked about what to do when you find a company’s sensitive data on the Internet.

 

 

 

 

The Traceroute Podcast

Check out the new season of the Traceroute Podcast on Apple, Spotify, or wherever you get your podcasts.  Visit the website.

 

Automox

Save time, eliminate risk, and automate the patching, configuration, and control of all your Windows, macOS, and Linux endpoints with Automox.

 

 

 

 

 

See our contact page for ways to get in touch.

 

2.5 Admins 167: Delayed Flush

The large water consumption of AI and data centers in general, China’s big push towards IPv6, why we don’t talk about Toshiba hard drives very often, and the implications of poor Bluetooth security on an e-bike.

 

Plugs

Support us on patreon

Unlocking Infrastructure Sovereignty: Harnessing the Power of Open Source Solutions for Business Flexibility and Cost-Effectiveness

 

News/discussion

The Secret Water Footprint of AI Technology

China requires all new Wi-Fi kit to run IPv6

 

Free Consulting

We were asked about the implications of poor Bluetooth security on an e-bike.

Monitor Traffic With Wireless Travel Time Sensors

DeepBlue Sensor

Bluetooth Pedestrian and Vehicle Tracking

 

 

 

 

The Traceroute Podcast

Check out the new season of the Traceroute Podcast on Apple, Spotify, or wherever you get your podcasts.  Visit the website.

 

Kolide

Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today to see how it works at kolide.com/25a

 

 

 

 

See our contact page for ways to get in touch.

 

2.5 Admins 166: 20 Second Cheque

What Google should do to prevent malware sites in their ads, why you might want to avoid using multiple profiles on Android devices, a speculative execution vulnerability in Apple Silicon, and the pros and cons of TP-Link Omada and Ubiquiti Unifi.

 

Plugs

Support us on patreon

 

News

Clever malvertising attack uses Punycode to look like KeePass’s official website

pixel 6 can’t access storage with multiple profiles after updating to android 14

Hackers can force iOS and macOS browsers to divulge passwords and much more

 

Free Consulting

We were asked about the pros and cons of TP-Link Omada and Ubiquiti Unifi.

 

 

 

 

 

See our contact page for ways to get in touch.

 

2.5 Admins 165: Big AI

The nuances of copyrighting AI-generated art, getting the best speeds with Samba, and building an SSD-only NAS.

 

News/discussion

Opinion: The Copyright Office is making a mistake on AI-generated art

 

Free Consulting

We were asked about building an SSD-only NAS.

 

 

 

 

Kolide

Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today to see how it works at kolide.com/25a

 

 

 

 

See our contact page for ways to get in touch.

 

2.5 Admins 164: Filthy Internet

Why enabling password autofill isn’t a great idea, Jim’s adventures in network repair, and setting up a home router/WiFi hotspot.

 

Feedback

Don’t use autofill on your password manager

 

Story Time

Adventures in network repair

 

Free Consulting

We were asked about hardware for a home router/Wi-Fi hotspot.

 

 

 

 

HelloFresh

With HelloFresh, you get farm-fresh, pre-portioned ingredients and seasonal recipes delivered right to your doorstep. Get 50% off plus free shipping at hellofresh.com/5025admins using code 5025admins.

 

 

 

 

See our contact page for ways to get in touch.

 

2.5 Admins 163: Two Factors One SPOF

A network breach teaches us all a valuable lesson about threat models, Allan and Jim’s TV setups, and picking the right external storage solution.

 

Plugs

Support us on patreon

 

News/discussion

How Google Authenticator made one company’s network breach much, much worse

Amolith’s wiki page about passwords

 

Feedback

Allan’s TV remote control

 

Free Consulting

We were asked about picking the right external storage solution.

 

 

 

 

Kolide

Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today to see how it works at kolide.com/25a

 

 

 

 

See our contact page for ways to get in touch.

 

2.5 Admins 162: Irresponsible Disclosure

Google and Apple do a bad job of disclosing a pretty serious vulnerability, why hard drives aren’t physically bigger, and setting up a distributed backup system with a group of friends.

 

Plugs

Support us on patreon

 

News

Submit your ideas or articles – OpenSource.net

Incomplete disclosures by Apple and Google create “huge blindspot” for 0-day hunters

Google quietly corrects previously submitted disclosure for critical webp 0-day

 

Free Consulting

We were asked about setting up a distributed backup system with a group of friends.

 

 

 

 

Kolide

Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today to see how it works at kolide.com/25a

 

 

 

 

See our contact page for ways to get in touch.