• 0 Posts
  • 160 Comments
Joined 2 years ago
cake
Cake day: June 16th, 2023

help-circle
  • Yup. Regulatory and audit requirements are a motherfucker.

    Also, I don’t mean to speak down to devs, but as a rule of thumb you tend to think far higher of your skills just because you know the building blocks. Being able to build a boat doesn’t mean you know how to sail.

    I know multiple people who are prodigous developers but know jack shit about basic computer usage and security. People who had to be guided to the control panel in Windows. Yes, even after they added the search bar. People hired to work in an exclusively Windows enterprise environment.

    Now add that amount of potential that lack of basic operational skill carries for fucking things up to the least competent (or at minimum the least careful) co-worker on your dev team.

    You (any dev reading this) as an individual would probably never fuck up that badly. You (any dev reading this) would probably do everything right, correct, and wouldn’t cause problems with root. But the rules aren’t written to protect against the competent, or against people never making mistakes.



  • Your user base must be better than mine.

    Some chucklefuck over a decade ago caved to the “need” for a public shared drive. I can see the argument for things like HR policy documents and such. But they didn’t just give all users read access. Oh no, everyone got full read write. No fucking governance model, no process to check that PII wasn’t being stored there by people too lazy to follow proper procedure.

    Thankfully that horror has been thoroughly killed, and MS Teams makes it so easy for people to spin up collab spaces and file storage that there’s no use case anymore.


  • Xbox has all of microsoft behind it, and they linked xbox accounts with microsoft accounts many years ago, allowing them to leverage all the security tools they’re making for themselves and corporate customers of Azure/Entra. They also effectively have infinite money.

    Banks, surprisingly, do not. They also are often using third party systems under the hood for things like online access to your account. Those third parties tend to have less money than a bank.

    Laws can’t keep up with tech developments in security, and getting all your ducks in a row to be legally covered in the finance industry is a fucking nightmare.

    Lastly, banks (and companies) don’t stay afloat by spending money on things that aren’t necessary. Until it shows a significant impact through a breach or in customers leaving specifically for the reason of lackluster MFA options, and until that impact is easily communicated to the executives, trying to fight for some budget to improve shit is an uphill battle.


    I am so so glad that the closest my work gets to customers, legal, or anything regulatory is data rentention policies.







  • I’ve literally seen no one say that it’s forbidden. Maybe one of the comment chains from someone I already have blocked does, but there’s only four two of those.

    I see plenty of people saying this is a stupid post. A post that is uselessly vague. A post that is almost entirely purposeless.

    I understand wanting to avoid brigading, but as it stands this post amounts to “You all should know that I reported someone (I won’t say who, tee hee) for posting something that I think is misinformation about Wikipedia (I won’t say what, tee hee). It’s really bad, but you’ll just have to take my word for it. This person I won’t name is just the worst. You need to know they’re the worst. But you don’t need to know who they are or what they said, that’s not important! Also I have vague consipiratorial feelings about anyone who would speak ill of Wikipedia after Musk said bad things about it, because no one could possibly have grievances or concerns with Wikipedia that are still valid despite Musk’s derangement.”


    If you wanted to spread awareness, you should have named the problem user. If you wanted to force the admins into action you should have named the problem user.

    If you are willing to give the admins time to handle things properly, especially during the fucking holidays where they likely have other things to do, instead of needlessly raising an alarm on something pitifully small… then you should have waited a few days for them to do something before running off to play vigilante with this post.

    If you want to make people waste time trying to evaluate if you’re a nutter, thin skinned, or otherwise blowing smoke… you make a post like this one.

    Either you had enough evidence to make this warning/call out post legitimately, and then you make it with names, screenshots, and fucking receipts… or you give admins time to respond and sit until they show they won’t do something.

    This weak, vague post just says that you’re too impatient to let the admins work, you don’t trust them to do what you think is the right thing, but you’re also chickenshit that they might ban you for talking about it. Rather than post this from a throwaway made on another instance you make this useless thing.


    TL;DR- People are telling you that this attempt to “warn” people is worthless without actionable info.



  • Then why are you trying to be cute and not call out the username (or usernames if they are using alts)? This doesn’t identify jack, just says that someone exists doing something nonspecifically bad towards wikipedia.

    As important as Wikipedia is, there are a ton of legitimate problems with the site and community moderators. Some of the drama that comes out of there is downright otherworldly. Without examples it’s hard to take what you’re saying seriously.

    Edit: Either there’s enough direct screenshotted evidence that this needs to be a specific call for admins to ban this person, or this just comes across as absurd escalation of some stupid internet debate.

    Second edit: it’s wikipediasuckscoop

    Do we really need a warning for someone so obviously biased? Next you’ll be warning us that madthumbs might have some reservations about the usefulness of linux.









  • If you do, I can’t reccomend the Viva New Vegas modpack enough. It’s a wonderful “vanilla-plus” pack that keeps the feeling of the base game while fixing bugs, improving the balance and leveling curve, reintroducing appropriate cut content, and giving it all a consistently good new coat of paint. And it’s not crash prone, which even the base game has trouble with at times.

    I can’t help myself from tinkering further, but it’s the best baseline setup I’ve found since the game released over a decade ago.

    There are also sister packs done by the same team for 3, and Tale of Two Wastelands (another mod that puts 3 into New Vegas’s slightly improved engine, which a lot of people prefer to playing 3 on it’s own). I haven’t used them myself, but they look to be up to the same gold standard.