Hacker Newsnew | past | comments | ask | show | jobs | submit | fname's commentslogin

Allegedly owned by someone that attended the DEFCON Shoot event where gun powder was transferred to the package, tipping a dog doing a random search in the Forums.


That would be wild. Bomb dogs usually are not trained to hit on ammunition since every officer on a scene is carrying some. Gunpowder is also a low explosive (meaning it burns at subsonic speed) which sucks for making things go boom.


> Gunpowder is also a low explosive

Yes, but a lot of modern formulations are based around RDX chemistry or nitroguanidine, etc. So, a big portion of the "smell" is high explosive even if the overall formulation burns subsonic.


Got a source? I was there and never heard that rumor.


Who alleged that?


This might help: https://www.securityweek.com/whats-threat-group-name-inside-...

For Microsoft specifically, we leverage the periodic table of elements when naming nation states.


Maybe that can get Verizon another $1B discount.


I'm hoping Verizon kills the deal. It would send a powerful message (unintentional on Verizon's part, but irrelevant) that a major data breach + installing NSA's rootkit on your servers could one day cost you billions of dollars, as well as give you a forever tainted reputation.

https://motherboard.vice.com/read/yahoo-government-email-sca...


Tabs across all windows, all apps.


BeOS lives.


> Personally, I'd never put a MS project between me and the cloud, or my data and the cloud

Why?


[deleted]


Realistically I think that the last field, Vulnerabilities / Product, is the one of more interest here. Rates are much more informative than absolutes. I'd be more concerned using a Canonical product based on the data you've shared than a Microsoft product.


+ the pencil @ $99 and the smart keyboard at $169. > $1k for the entry level model to be comparable with the Surface Pro 3 at ~$930 (which starts at 64GB, btw).


It seems more comparable to the Surface 3 ($499) than Surface Pro 3. The "Pro" moniker doesn't buy you a laptop replacement with Apple like it does with Microsoft.


I don't disagree. Unfortunately, this all falls on DoD-DISA. The NSA works with DISA to write the policy for how to secure systems (called STIGs) and also has 'Red Teams', but they aren't the arm that certifies these systems before coming online, nor are they the ones the ensure the systems stay secured as new vulnerabilities are found and patched -- that's DISA again.


I could see the CIA NSA taking their vetteing back in house every CIA and NAS employee must be incandesant with rage over this cock up.


That makes sense from an org-chart level. But if that's actually the thinking inside, it represents a total lack of ownership on their part to get to the overall goal of security.


You obviously know what you're talking about, but DISA can't enforce STIGs across the entire government can they? Some say that's DHS's job, or some Office within DHS (or within an Agency under DHS).


> but DISA can't enforce STIGs across the entire government can they?

No, with a small caveat: If that civilian agency (say DHS) is connected to the GIG[1], then DISA has a say-so and can threaten to disconnect them for failing security audits.

Something to keep in mind is that the STIGs are merely implementation guides to secure a system. Therefore, different agencies have different interpretations. In some cases specific secure implementations break systems and applications (mostly legacy ones), so they avoid securing those particular settings all together.

1: https://en.wikipedia.org/wiki/Global_Information_Grid


I'm guessing they mean they had a break-glass list of passwords for accounts to access those systems.


> Also on whether WinXP users are going to qualify for the free upgrade?

Nope. There is no upgrade path from XP -> Windows 10. You will have to go from Win7/8 to qualify for the free upgrade to 10.


Yes, both can be disabled. However, I'm not sure if it's dependent upon which 'edition' though. For example, you can turn it off in Enterprise, but not Professional.


So, the answer is "no" then. As in, "no, I won't upgrade my grandma to Windows 10".


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: