Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Rufus Ping posted:

google aws azure and cloudflare should club together and "take the L" pending widespread adoption of quic which will hide sni hostnames inside the encrypted payload anyway. gently caress to russia

russian blocks don't make use of SNI in the slightest. they're entirely IP-based. connections to an unblocked IP sending a banned hostname in SNI aren't blocked, at least on providers i've tested. that said, it's reasonable to assume that most providers simply use IP blocks, since RKN provides IPs and they're simpler to implement.

randomizing DNS responses and routing based on SNI would defeat single-IP blocks, but Roskomnadzor has already demonstrated that they don't really mind taking a scorched-earth/ignore collateral damage approach to blocking entire subnets with the Telegram block.

Adbot
ADBOT LOVES YOU

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

jit bull transpile posted:

Probably some God dammed swede

*checks url in screenshot*



yep, :sweden:

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Lain Iwakura posted:

you can move goal posts around as much as you want but vpn services are terrible

they're very needs suiting for dealing with region blocks vov

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Jowj posted:

mega yes.

also, like, poo poo loads of tech companies have older people managing even security teams or overseeing managers of security teams who still swear by epo/sophos/garbage.

bringin up fond memories of AV rollout for PCI compliance. chosen AV vendor (iirc Sophos, but gently caress cares) provided a Linux binary that segfaulted immediately on newer kernels. compliance team was happy to tick the "AV installed" box insofar as some files from AV vendor were indeed resident on disk. good enough!

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

haveblue posted:

a large chunk of the subway still runs on early 20th century tech which is why countdown clocks are so hard. there is no data stream that the clock could use to figure out when the train is coming because sensors that could be used for that purpose were never installed. the system only barely works well enough to stop the trains from crashing into each other

switch to the moscow system where the clocks track how long since the last train left the station. works great when you have headways of approximately 70 seconds.

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

evil_bunnY posted:

Unless it specifies a cypher throughput means precisely fuckall

the best rfc posted:

2.4. Performance

The NULL encryption algorithm is significantly faster than other
commonly used symmetric encryption algorithms and implementations of
the base algorithm are available for all commonly used hardware and
OS platforms.

it's valid IPSec and beats out all the competition on performance

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
just install openresty and then you can have the speed of nginx and the power of plang-based modules. direct access to nginx internals with all the type safety and error handling that lua can offer!

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

BIGFOOT EROTICA posted:

the bgp stuff is good and it happens on a monthly basis, I honestly don't know why russian/chinese IPs aren't blacklisted from advertising routes

how do you think anyone gets informed about routes those ISPs should be announcing legitimately

Adbot
ADBOT LOVES YOU

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Oneiros posted:

i've had to tell our cs reps to tell our customers not to send us full CC numbers, CCV, and addresses unsolicited in our tickets. god help us all if/when Zendesk gets breached.

it wont help. the class of user that wantonly tosses their passwords, private keys, and cc into support tickets on the assumption that it will help agents solve their issue faster will never be purged from this world.

it's okay tho, as those users' info was leaked long long ago in that big dump of definitely anonymized aol search queries or whatever. storing it in yet another location will do no harm.

  • Locked thread