ai6yr, (edited ) to random
tallship, to browsers

After several years of warning after warning after advisory after advisory and calls to repeatedly update or remove and NOT USE CHROME by the Department of Homeland Security, it should be inconceivable that anyone does - but they do.

Sometimes these are patched with automatic updates before horrific and catastrophic results occur, sometimes not. To be frank, part of the problem stems from the fact that Chrome is the largest attack surface out there where browsers are concerned, but notwithstanding it being the fav target are also serious privacy concerns that aren't shared by other chromium based browsers.

To be fair, many exploits are indeed shared by other chromium based browsers, but not most, while some are related to other browser capabilities, like WebRTC, but it's still best to just ditch Chrome and never look back.

Here's more coverage on vulnerabilities issued less than a month ago. It took 3 seconds to bring this up, and no, not using Google, which didn't reveal this when I tried that search engine in a subsequent search, lolz. Why would they return SERPs that poo poo their own product?

This one did come up in a google search

There's truly only one way to ensure safety - unplug. But there's a lot of simple things you can do to exact a reasonable level of security, so why not observe some of those best practices? It's not like it will cramp your style.

Anyway, that's my two cents. h/t to @darnell for raising awareness of this latest brokewell. Make sure you take the time to visit the link he's provided for you too.

There are plenty of that run on (to name a few, alphabetized):

  • Brave Browser
  • Chromium
  • DuckDuckGo
  • Firefox
  • Kiwi
  • Vivaldi

IMO, No one should be running Chrome - Desktop or otherwise. It's a privacy nightmare even when there aren't CERT warnings circulating.

.

RE: https://one.darnell.one/users/darnell/statuses/112371221294882180

@darnell

ai6yr, (edited ) to random

My son's T-shirt today. Used to think "vacations and sun", but nowadays it's a sober reminder of disaster. 🙏

MsMerope,
@MsMerope@sfba.social avatar
mstankiewicz, to random Polish
@mstankiewicz@pol.social avatar

Czy posiada jakiś adres, na który można przesyłać złośliwe maile (tak jak mają numer 8080, na który można przesłać złośliwe SMSy)? Gdzie jeszcze mogę wysłać takiego złośliwego maila?
Można powiedzieć, że zostałem dzisiaj zaatakowany. Jednak dobrze, że nie podałem w ogłoszeniu o poszukiwaniach asystenta mojego prywatnego maila.

ai6yr, to random

La Canada Flintridge, California:

Do you want to be a part of our future Community Emergency Response Team (CERT)?

Interested individuals must attend all in-person CERT training days at City Hall.

📍These trainings will take place from 6 to 9 p.m. every Wednesday from March 27-May 15.

MsMerope,
@MsMerope@sfba.social avatar

@ai6yr
highly recommend training.

As far as I know all Sac County programs have completed Spring Basic so sign up for Fall!

Find a program near you!
https://community.fema.gov/PreparednessCommunity/s/cert-find-a-program?language=en_US

peterdrake, to pdx
@peterdrake@qoto.org avatar

From SW Hills NETs:

Whether it is weathering an ice storm, heat dome, wind event, or urban wildland fire, preparedness is essential. No one is coming to save us except us. Please do check out this amazing series of check lists provided by our SW Hills NETs.

https://collinsview.org/NET/BePrepared.html

Sources of Emergency Power - Basic
https://collinsview.org/NET/Sources-of-Emergency-Power-Basic.pdf

Surviving An Ice Storm
https://collinsview.org/NET/SurvivingAnIceStorm.pdf

#pdx #portland #disaster #preparedness #net #cert #pdxtst

amuse, to random

w00t!

Starting in ten minutes, I'm teaching my favorite community safety class to my local community #CERT members (and anyone else who wanted to come)

MsMerope, to random
@MsMerope@sfba.social avatar

our volunteers put in over 150 hours over the weekend just on the storm.

geravitywave, to random
@geravitywave@sfba.social avatar

There's been a lot of buzz about California's next storm system, and while I'll occasionally share my thoughts based on operational and research experience, remember to rely on your local Weather Service and Emergency Management offices for local updates.

MsMerope,
@MsMerope@sfba.social avatar

@geravitywave
.....and... do a search, find your local and sign up for Spring Basic!!
All kinds of disaster preparedness, response and safety information!
Most programs are getting ready for Spring Basic now!

If you're in Sac County I can probably direct you to your local agency if not? ⬇️

https://community.fema.gov/PreparednessCommunity/s/cert-find-a-program?language=en_US

petergleick, to random
@petergleick@fediscience.org avatar

From my new LA Times op-ed.

"Atmospheric rivers and bone-dry droughts are like earthquakes and wildfires — challenges Californians have to face. We know they’re coming; we just don’t know exactly when or where. An earthquake-resilient house or a more flood-resilient community won’t stop the ground from shaking or the rain from falling, but it can mean the difference between weathering the storm or cleaning up after a disaster."

https://www.latimes.com/opinion/story/2024-01-31/california-atmospheric-river-flood-rain-snow

gopal,
@gopal@mamot.fr avatar

@petergleick CERT (Community Emergency Response Team) started in LA. It is a group of volunteers that the program became a model for the rest country that deals with lots of kinds of problems like the ones you mention for responding to events like those. https://community.fema.gov/PreparednessCommunity/s/welcome-to-cert?language=en_US

As far as updating the building codes to meet the increasing number of event that is a good thought and this is call here for others for ideas.

#preparedness for #emergency #cert #IncidentResponce #weatherevent

ai6yr, (edited ) to random

Noticed this at the temporary housing the other day. Daylight through a door... leaking heat out, cold in. Easy fix to this. Really helpful during something like this Polar Vortex to minimize heat loss.

MsMerope,
@MsMerope@sfba.social avatar

@ai6yr
from our cold weather training a cheap weather stripping option are dollar store pool noodles. Slit them lengthwise and put them on doors. Also can be used to insulate outside water pipes.

MsMerope, to random
@MsMerope@sfba.social avatar

Wow, some programs charge money to take Basic?
That's cuckoo for Cocoa Puffs!

I'm seeing prices from $100-$25

lol we've thought of charging like a refundable $30 fee. We usually sign up 30-50 - only half of that show up.

MsMerope, to MultipleSclerosis
@MsMerope@sfba.social avatar

not sure how to tag this
#preparedness
#MultipleSclerosis
#mobility
#CERT

We were contacted by a local agency that would like a presentation on educating their clients on how to prepare and stay safe during an emergency

"Many of the patients are in wheelchairs or use some sort of mobility assistance and a significant amount of them are seniors."

We are considering focusing on three topics:

  1. "72 hour kits" with attention to things like backup generators/inverters, extra medications and/or equipment, and portability.

  2. sheltering in place

  3. planning for evacuation

We are waiting to hear if these folks are in licensed care homes of any sort (in California licensed facilities would be required to have emergency plans in place)

Would there be anything else that we should cover?

We'll be taking some info from the Red Cross and FEMA.
Such as what's found here:
https://www.ready.gov/disability

boosts appreciated

DontSwitch, to random German
@DontSwitch@chaos.social avatar

Das @c3cert hat auch wichtige Hinweise.

image/jpeg

peterdrake, to portland
@peterdrake@qoto.org avatar

Live in Portland, OR? Want some FREE training in disaster preparedness to improve your (and your neighbors') chance when the Big One (or next year's wildfire, ice storm, etc.) hits? Want to avoid the most common deathbed regret of never having discharged a fire extinguisher?

Portland is training Neighborhood Emergency Team members (equivalent to CERT in other cities). Sign up here:

https://www.portland.gov/pbem/neighborhood-emergency-teams/volunteer

#portland #pdx #net #cert #disaster #preparedness

justyourluck, to earthquake
@justyourluck@masto.ai avatar

I think I figured it out.

The mass delusion of this mass infection event.

I've told the story of how I got into ... Local govt held a community meeting about preparing for a 9.0+ zone hitting the . Power co, water co, etc all gave useful advice.

Then the fire chief stood up there and said

"We're not coming to help you"

Shock from the audience...

Then the yelling ... 1/

mizblueprint,
@mizblueprint@mastodon.online avatar

@justyourluck
Good for you. is not anywhere near ready for the . Infrastructure will be destroyed - as well as roads, bridges, power grid, a lot of underground utilities, un-reinforced masonry buildings in piles of rubble, concrete buildings from earlier 20th century pancaked, all the chimneys broken, and many wood frame buildings off their foundations.

training can help. Be prepared to be on your own for several weeks, and be prepared to help some neighbors.

MsMerope, to random
@MsMerope@sfba.social avatar

So what's in a Basic class?
There are 9 units each covering a different topic.

1 community preparedness, 72 hour kits, ways to get local disaster updates, and what the most likely local natural disasters are.

2 ICS - how do the pros organize a disaster situation? how can those principles be applied to a neighborhood incident?

Units 3 and 4 are disaster medical - how to access injuries (we teach START triage) how to treat injuries and how to set up medical treatment areas.

  1. disaster psychology

  2. utilities and fire suppression [where are your gas, water, electrical shutoffs? how do they work? when do you turn them back on?]

7 light search and rescue including search techniques and cribbing

Unit 8 is recognizing and responding to terrorism

Unit 9 is the final and a disaster simulation

Our Basic class typically runs 27 hours depending on class size and how many questions people ask.

ai6yr, to climate
MsMerope,
@MsMerope@sfba.social avatar

@ai6yr
You know me... gotta pile on here. Spring CERT Basic classes will be here before you know it. Find your local and get on the interest list:

https://community.fema.gov/PreparednessCommunity/s/cert-find-a-program?language=en_US

zakalwe, to random
@zakalwe@plasmatrap.com avatar

https://www.theregister.com/2023/11/24/opencart_vulnerability_dispute/

"You have a ," says security researcher to author, "here's the details and a fix"
"Not a problem, not a vulnerability, stop wasting my time, says OpenCart author
Oh look, CVSS severity 8.8 (on a scale of 10), says

tl,dr on the article: This is not a one-off. Kerr (author of OpenCart) has a well established history of cavalier attitudes towards reported security vulnerabilities. "Shut up, I meant to do it this way."

Capsule summary: ... maybe don't use OpenCart?

irfan, (edited ) to Kubernetes

UPDATE: The service is accessible by its domain () as soon as I set the DNS server of my client machine to my PiHole. For other systems not using my local DNS (so outside my network), the domain remains unreachable. My suspicion is an issue with the Port Forwards, but idk what's wrong w em as it is.


Note: this may not be in the exact order. If the order to any of this is important, feel free to point that out.

  1. I've added to , to my zone (domain), the hostname foo pointing to my network's public IP.

  2. I've deployed everything you'd need including (which determines the dedicated Ingress private IP), -ingress (type set to LoadBalancer instead of NodePort), and -manager (with both HTTP/DNS clusterissuers). If you want to take a peek at how I've deployed/configured them, more details are on here: https://github.com/irfanhakim-as/orked.

  3. I've added foo.domain to the closest thing resembling to a DNS server that I have, , pointing to the dedicated Ingress private IP.

  4. I've set my router's only DNS server to the PiHole's IP.

  5. I've set all my Kubernetes nodes' (Masters and Workers) DNS1 to the Router's IP (DNS2 set to Cloudflare's, 1.1.1.1).

  6. I've created a port forwarding rule for HTTP on my router with 1) WAN Start/End ports set to 80, 2) Virtual Host port set to its nodePort (acquired from kubectl get svc -n ingress-nginx ingress-nginx-controller -o=jsonpath='{.spec.ports[0].nodePort}' i.e. 3XXXX), 3) Protocol set to TCP, and 4) LAN Host address set to the dedicated Ingress private IP.

  7. I've created a port forwarding rule for HTTPS on my router with 1) WAN Start/End ports set to 443, 2) Virtual Host port set to its nodePort (acquired from kubectl get svc -n ingress-nginx ingress-nginx-controller -o=jsonpath='{.spec.ports[1].nodePort}' i.e. 3XXXX), 3) Protocol set to TCP, and 4) LAN Host address set to the dedicated Ingress private IP.

  8. I've deployed a container service, and an Ingress for it, using 's DNS validation clusterissuer.

Current result:

  • Cert-manager creates a certificate automatically and is in a Ready: True state as expected.

  • The subdomain (foo.domain) however remains unreachable, no 404 errors, no nothing. Just "The connection has timed out" error.

  • Describing the container service's ingress (foo.domain), shows that it's stuck at "Scheduled for sync".

and experts - please tell me what I've done in any of this that were either wrong or unnecessary, or what I'm currently missing here for me to reach my goal of being able to get my container accessible via foo.domain through that Ingress. I suspect that I might be doing something wrong with this whole DNS mess I literally cannot fathom. I feel like I'm insanely close to getting this thing to work, but I fear I'm also insanely close of blowing up my brain.

cc: @telnetlocalhost (thanks for bearing w me and getting me this far)

m0bi13, (edited ) to security Polish
@m0bi13@pol.social avatar

Od niedawna CERT Polska ma nowy, bezpłatny, łatwy numer do powiadamiania o scam/próbach oszustwa/wyłudzeniach:

8080

Co robimy, jak zidentyfikujemy sms ze scammem?

Kopiujemy treść i wysyłamy sms na 8080.

Efekt na obrazku 1.

Co to daje?

Na obrazku 2 wynik działania przeglądarki z włączonym .

Na obrazku 3 wynik działania przeglądarki z wyłączonym SafeBrowsing (bo to nadal Google), ale z włączonym od dostawcy europejskiego dns0.eu, współpracującego z CERT krajów członkowskich Unii Europejskiej. Nazwa nie jest rozwijana, strona się nie załaduje.

Polecam: https://dns0.eu

Domena unieszkodliwiona, nikogo już nie nabiorą.

Osoby świadome, potrafiące rozróżnić scam, proszę, zgłaszajcie do próby oszustw ❤️

P.S. Nie byłem pierwszy, gdy zgłosiłem, strona już była zablokowana. Nie szkodzi. Mogła nie być i byłbym pierwszym zgłaszającym.

Można podbić, niech się niesie 🚀 😉

Strona CERT Polska: https://cert.pl

comrad, to openSUSE German
@comrad@mastodon.social avatar

Wegen eines Buchungsfehlers musste ich innerhalb von zwei Wochen meinen für SLES 15 durchziehen. Dadurch, dass ich die zuvor schon gemacht habe, war das tatsächlich auch machbar.

Nun darf ich mich offiziell SUSE Certified Administrator for Linux Enterprise 15 (sca_sles15) nennen!

Ich habe vor über 20 Jahren mit SUSE Linux angefangen und bin heute in der -Community aktiv. Daher freut mich das besonders.

ErikJonker, to security
@ErikJonker@mastodon.social avatar

This looks bad, critical Google Chrome vulnerability, update your browser. CVE-2023-4863
https://www.cert.europa.eu/static/SecurityAdvisories/2023/CERT-EU-SA2023-063.pdf

ai6yr, to Terminator
Kurious1,

@ai6yr Responding to your number one, basic first aid skills are essential. I am encouraged that more high schools are offering a Community Emergency Response Team (CERT) course.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • GTA5RPClips
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • osvaldo12
  • Youngstown
  • ngwrru68w68
  • slotface
  • everett
  • rosin
  • thenastyranch
  • kavyap
  • tacticalgear
  • megavids
  • modclub
  • normalnudes
  • cubers
  • ethstaker
  • mdbf
  • Durango
  • khanakhh
  • tester
  • provamag3
  • cisconetworking
  • Leos
  • anitta
  • lostlight
  • All magazines