6 ms·
Cloudguy says we should log out of Amazon
- fafqg 3y ago[flagged]
- Etrnl_President 3y ago[dead]
- dgrin91 3y agoI've never heard of this guy at all. Does he have any credibility at all?
- amelius 3y agoIt's some guy who has his head in the clouds.
- christkv 3y ago[flagged]
- danielbln 3y agoNot that I follow the original reasoning, but the slippery slope of Eugenics starts _way_ before we end up at "breeding houses", no?
- raesene9 3y agoGot any links there? My googling didn't turn up anything like that (albeit I didn't get too many pages in).
- nobody9999 3y ago>I searched him seems on a personal quest to get Musk. Tons of articles all going after Musk. Seems like another partisan hack. Out of morbid curiosity, where did you find those "[t]ons of articles all going after Musk"? Perhaps my DDG-fu is inferior, but searches for both "Dick Morrell" and "Cloudguy" showed a bunch of IT/infosec blogs/articles and articles flogging his technology bona fides. What am I missing here?
- raesene9 3y agoLooks like it's this person https://diveintotheclouds.wordpress.com/about/ https://diveintotheclouds.wordpress.com/about/ If so, founder of smoothwall, history in the UK security scene. Not to say that means that what's happening here is as serious as what's being alluded to, but has some background in the area.
- boynamedsue 3y agoThe person who touts himself as a security expert should have SSL implemented on his personal website? http://dickmorrell.com http://dickmorrell.com
- rideontime 3y agoWhy?
- nathanaldensr 3y agoHow many times must this question be answered? TLS is a requirement because otherwise nodes between your device and the server can easily modify the HTTP requests and responses to inject malicious code. Your traffic is also trivially tracked.
- zamnos 3y agoBecause it's a security liability not to have it enabled, so if he's going to complain about others security problems, the least he could do is put his metaphorical pants on first. He could be forgiven for not having it locked down to an few specialist cyphers he personally believes are resilient to attack, but to not even have it enabled is on the level of not putting your pants on before leaving the house.
- ukuina 3y agoI have not understood the need to force SSL on content that needs no verification.
- 1letterunixname 3y agoYes and no. It's more like flossing than wearing a seatbelt. The html tags won't fall out if you use http:// http:// over port 80. It's not nice to end users in that it permits eavesdropping and content modification of website traffic in the clear by anyone in the network path. The assumption of http:// http:// is that "pamphlets for the public" don't require privacy, confidentiality, and nonrepudiation for other users such as downloading software sources &| binaries or exchanging secret PII. The post-Snowden/-PRISM world opted to deploy https:// https:// ubiquitously as both a virtue signal and technical defense to various problems inherent to using port 80.
- srslack 3y agohttps://web.archive.org/web/20230426082627/https://sackheads.social/@Cloudguy/110256209708866473 https://web.archive.org/web/20230426082627/https://sackheads... Reminds me of this: https://github.com/yadayada/acd_cli/issues/549 https://github.com/yadayada/acd_cli/issues/549
- raesene9 3y ago<meta> hmm one of the downsides of distributed social media here. Many mastodon instances are not up to handling a big influx of traffic from a popular post.
- TonyTrapp 3y agoWould you say the same if this was a blogpost? If the blog software cannot handle the HN hug of death, the person should use Blogspot / WordPress / whatever instead? Centralized solutions cannot be the answer to every server going to its knees.
- moffkalast 3y agoCan't Mastodon get itself a Cloudflare setup or something? They'll literally serve terabytes of cached data for free.
- TonyTrapp 3y agoThere is no "can Mastodon...", only "can this specific Mastodon instance...". Not everyone wants to run their traffic through a third party, especially if they usually do not expect such an influx of requests.
- marginalia_nu 3y agoTo be fair, you could probably run a local cache. There's no point in re-rendering a page that is expected to change at most once every minute at every single request during a hug of death type scenario.
- moffkalast 3y agoWell from what I understand there's some kind of interoperable network that everything works through though? There ought to be some general caching there at least. Right now every time there's something hosted on Mastodon posted anywhere it's not accessible because apparently the architecture is so bad that the average instance can't even handle a few hundred visitors without completely freezing.
- andrewstuart 3y agoSome random person telling me to do something does not result in me doing said thing.
- mikelovenotwar 3y agohttps://web.archive.org/web/20230426082627/https://sackheads.social/@Cloudguy https://web.archive.org/web/20230426082627/https://sackheads... Ex RedHat, co-founder SmoothWall, Ex director Cloud Security Alliance, Ex CTO Gartner Group
- KomoD 3y agoStill won't make me do it
- unethical_ban 3y agoYou are not being persecuted, no one is making you do anything.
- wolkmo 3y agoNow he is telling us to not update Twitter and Fire Tablets, and he is deleting "dubious followers". He doesn't seem to have a problem with Microsoft Defender scanning his network though. Clearly an absolute sane security expert.
- 1letterunixname 3y agoYou must be new here, chief.
- sydney6 3y agoSo many people following, apparently blindly, advice on the interwebs.. i can't even figure out what this supposedly is about. Are Amazon devices scanning local wifi networks or what is going on?
- nibbleshifter 3y agoWho or what is a cloud guy and why should I care about what he says?
- fpanzer 3y agoThis
- frouge 3y agoPut all your amazon devices into the garbage, trust me...one day you'll thank me :)
- mikelovenotwar 3y agoOr just put them in your parts bin, for harvesting at a later date.
- smcleod 3y agoHonestly this is pretty good advice for their consumer products.
- suddenclarity 3y agoReading his other tweets the issue seems to be that old devices continue to get notifications even after you change the password since Amazon doesn't automatically remove old devices. I don't know how that's abused beyond being an issue for Amazon. Maybe if you lose your devices and don't force logout. His message seems a bit over the top but maybe there's more to it than I'm seeing.
- 1letterunixname 3y agoSeems like the only vulnerability is if you've ever stopped using an Amazon-connected device without a logout everywhere and password change. Seems like the only precaution necessary is to do that after disconnecting but before giving away an Amazon-connected device.
- trabant00 3y agoLooks like and old tactic to gain popularity: recommend something that could never hurt to do, presenting a minor or no problem as pretty important. Do this enough times to enough people and by chance some will benefit from it, raising your profile.
- jms703 3y agoIs this for everyone with an Amazon account? Or is this for people that have Amazon Echo devices?
- 1letterunixname 3y agoHey, someone technical in the Amazon consumer products division: Can you sus-out for fellow MAANGers if this is righteous anger, prudent caution, or John McAfee-level flat-earther paranoia?
- zamnos 3y ago(not at Amazon) It depends on how worried you are about stalkers. If your address leaking is a big deal to you (which, it validly is for some), then yeah, do the thing. Everyone else need not panic though.
- 1letterunixname 3y agoAbsolutely. If you were in such a position, you would weigh cutting down your online footprint, adjusting your privacy settings, and securing your accounts by rolling passwords. For Google users, there is the APP that works with smartphone embedded keys and FIDO2 keys like Yubikeys and Titankeys. https://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/