Linux nerd and consultant. Sci-fi, comedy, and podcast author. Former Katsucon president, former roller derby bouncer. http://punkwalrus.net

  • 0 Posts
  • 102 Comments
Joined 1 year ago
cake
Cake day: June 22nd, 2023

help-circle



  • I had an assistant who didn’t really need the job, but her parents forced her to have one. She was the youngest, and only girl, of a family of 5 siblings. All her older brothers worked at the race track that their family owned, and she was dating someone they didn’t approve of. I liked her boyfriend, he seemed friendly and soft-spoken, but her folks were like “if you’re going to date whom you want, you better have a job and live on your own.” Well, one day, she got mad because I asked her to work a shift she didn’t want to. So she simply didn’t show up, which really fucked me over. So I called her up, pretty pissed. No answer.

    She didn’t show up for 3 days. So I fired her for job abandonment. She didn’t really need the job, right? Her parents owned a racetrack.

    A week later, her folks called me, and asked if I’d seen her. No, she didn’t show up for work ever again. They panicked. “OMFG WE DON’T KNOW WHERE SHE IS!” They immediately assumed her BF kidnapped and/or murdered her. The police were called, an investigation was opened up. Her BF’s address showed he’d moved away. I had to sit with the police and go through an interrogation about her last whereabouts. She became a missing person, and once a week for two months, her parents called and asked if I had heard anything. The detective called with more questions. Then her car was found in an impound lot: it had been abandoned and looted in a New Jersey parking garage. Then the calls petered off and stopped.

    A year went by, and I assumed the worst.

    One day, one of the employees in another store in the mall told me he saw her with her BF. I didn’t believe them, but then other people said that they’d seen her, and corroborated some stories she told them. Apparently, she had been planning to run away for some time, and just ran away with her BF and went NC with her family. That didn’t work out so well, because both had trouble finding jobs and then their car got carjacked. Both of them were forced to return home, and her parents were forced to reconcile that she was never going to leave her BF.

    I was pretty pissed, though, that I thought she was dead.


  • Cats can pant, I have seen it happen in times of extreme stress, and is often a bad sign. Like dogs, cats may pant if they are anxious or overheated. Strenuous exercise may be another reason, especially after a huge fight. Once your cat has had a chance to rest, calm down and cool down, this sort of painting should subside. However, even this type of panting is much more rarely seen in cats than in dogs. So, if you’re not 100% positive about why your cat is panting, it’s best to bring her to the vet.

    A side note, however, I misread this as “since cat’s don’t like pants like dogs,” and wanted to point out that dogs also do not like to wear pants, before my anti-dyslexia medicine kicked in.


  • One revolution I have realized in baking is the recent trend to start talking about weight and not volume in recipes for certain dry ingredients like flour. Three cups of fluffy sifted flour is a lot less flour than three cups of densely packed flour. Same with brown sugar, or wondering if you need a “flat teaspoon” vs. a “heaping teaspoon” of something.


  • When eventually washed off, the aerogel is handily broken down by soil microbes.

    I am not going to claim to be an expert on any of this BUT that wording sounds suspiciously like bullshit. Maybe it’s not, but it’s one of those phrases that sounds like when vitamin companies claim that more B12 has shown to fix whatever ails you. Or “our plastic is environmentally friendly: 100% recyclable, and breaks down into teeny micro-particles over time, and gets absorbed by the sea life like ordinary sand…”



  • I have had two tech jobs like that, even before COVID, starting in 2016. The first time, it was a company that outgrew their workspace. They put us in ‘rent-an-office’ spaces for a bit, and then my boss started working from home a few days a week. Then he allowed me to. We moved to a new office, but it was always empty in my section. That was fine, too, but the commute was terrible, so I started doing 2 days a week, then once a week, then a few times a month. I rarely saw my other coworkers in person, and nobody said anything aloud.

    The next job started because of COVID, and when they started doing RTO, they also wanted to do “hot desking” (no assigned seating) and open office plans, and I was not having that. I was not going to work in a “cafeteria” like setting. So I got contracted work and have worked from home 100% for several years now. Nobody has office space, and we work all over the world to collaborate. I get paid very well.

    I hope i never had to go back to an office. I reach retirement age in about 15 years, and I am hoping to make it.



  • Someone did a study at MIT about tin foil hats, and found that not only do they not screen radio interference, in some cases, can actually magnify them.

    Conclusion: The helmets amplify frequency bands that coincide with those allocated to the US government between 1.2 Ghz and 1.4 Ghz. According to the FCC, These bands are supposedly reserved for ‘‘radio location’’ (ie, GPS), and other communications with satellites (see, for example, [3]). The 2.6 Ghz band coincides with mobile phone technology. Though not affiliated by government, these bands are at the hands of multinational corporations. It requires no stretch of the imagination to conclude that the current helmet craze is likely to have been propagated by the Government, possibly with the involvement of the FCC. We hope this report will encourage the paranoid community to develop improved helmet designs to avoid falling prey to these shortcomings.


  • Probably HR (or the NCS equivalent) never told the right people. I am not saying this is actually what happened, but a lot of IT bemoan the fact they are never told some rando employee was fired because HR neglects to inform them. Sometimes it takes months to discover, and even with a 90 day password/login lockout, some halfway decent admin could get around this by secretly building a back door, and using the messed up communication and politics between departments to hide this. Even in the 1990s, I saw people put in “time bombs” in their code that “if such and such is not updated in 6 months, run destructo-script A.”

    But imagine someone like Kandula Nagaraju here. Worked in QA, probably did a great jobs with some skills, but had the personality of swallowing broken glass. He was terminated in October 2022 due to “poor work performance,” which could mean anything. “Not a team player.” Or maybe he really was an idiot: I mean, a smart person would have a conniption, but get employed elsewhere and then slam his former company at parties. “Those NCS folks didn’t know what they had with me!” But this guy was probably someone with some anger management issues, probably a jerk, and possibly stupid. He might have had revenge fantasies, and set up a small virtual server posing as a backup code mirror. But outside the audits, it allowed ssh from the outside, and hid it through a knockd daemon. Or maybe only launched ssh at certain hours before shutting it down again. Silently working away in a sea of virtual servers with little to no updated documentation. He gets in, has internal access, and runs a script with admin credentials because they don’t rotate their AWS keys/secrets quickly enough. Or didn’t even know he was let go.

    After Kandula’s contract was terminated and he arrived back in India, he used his laptop to gain unauthorised access to the system using the administrator login credentials. He did so on six occasions between Jan 6 and Jan 17, 2023.

    That’s embarrassing to the company. Not only did he get in, but SIX TIMES after he was let go. he probably knew what order to run the delete commands (like, say, an aws “terminate-instances” cli command from a primary node), and did so one by one, probably during hours with the least amount of supervision, where the first few alerts would take hours to get someone in the monitoring chain to wake an admin. Given his last day was in November, and he got back in January, the admins probably thought their 90 access credential rotation was “good enough,” but he got in on his 80th day or whatever.

    I know this because I have had to do triage when a former contractor did this to a company I worked for. But instead of wiping out instances, he opened a new set of cloud accounts from the master account, put them in an unmonitored region (in this case, Asia), and spun up thousands of instances to run bitcoin mining. Only because AWS notified us of “unusual traffic” were we made aware at all, and this guy knew his shit and covered his tracks very well. He did it at a speed that could have only been automated. Thankfully, AWS did not charge us the seven figure amount that this activity amassed in just three days.


  • I remember hearing that some Hollywood contracts require that if you sign up for some studio, you must make X amount of films. Big stars get to chose those films to some degree, but once in a while, they have to do “a stinker” to end the contract as “X amount of films done, okay?” or something. Contractual Obligation and all. This film feels like a dumping ground of a lot of those contractual obligation hires from the trailer alone.


    1. Things like CNC machines and proprietary interfaces to TOL equipment, like bus fare systems, message boards, etc.
    2. Don’t connect them to the Internet (most can’t, anyway, but some systems use a run-of-the-mill PC, so…)
    3. Don’t install anything on them that wasn’t supposed to be installed, even wallpaper as this could fuck up the resolution of a small 240 x 180 screen


  • Punkie@lemmy.worldtoNo Stupid Questions@lemmy.worldXXX
    link
    fedilink
    arrow-up
    2
    arrow-down
    2
    ·
    8 months ago

    I can see that being very possible. You see this when taxes are levied to “improve something” and then that money doesn’t go to that something in a directly helpful way. And then the budget that is the main staple of survivability of that something is kept static because of the “new influx.”

    For example, say that you have a toll road increase to help the infrastructure of your roads. Say your Annual Budget for Transportation is $50mil for 2021. In 2022, you requested $60mil. You decide to implement tolls in new ways and increase tolls in other ways (like fines, mileage taxes, and so on) to make up that shortfall. This brings in an additional $10mil, let’s say, in 2022. The revenue is forwarded to 2023. But in 2023, you actually need $80mil because of the two years of shortfalls where it stayed at $50mil, yet costs continued to increase. That $10mil from 2022 now puts you $10 mil behind in 2023. The fact that the previous budget needed steady increases were ignored because “well, we’ll just make things more expensive to make up 2022’s shortfalls of the $60mil request.”

    That’s IF that $10mil isn’t siphoned for other things. Fresh money brings fresh ways to spend it. Grifters via backroom contracts to “fix roads” that go over budget with nothing to show for it. So these new fees and increases actually made things worse due to no oversight.

    So yeah, I could totally see UBI being siphoned off by similar things.



  • I was burned afoul by a former admin who, instead of diagnosing why a mail service was failing, labeled a script as a /etc/cron.d file entry as “…” (three dots) which, unless you were careful, you’d never notice in an "ls " listing casually. The cron job ran a script with a similar name which he ran once every 5 minutes. It would launch the mail service, but simultaneous services were not allowed to run on the same box, so if it was running, nothing would happen, although this later explained hundreds of “[program] service is already running” errors in our logs. It was every 5 minutes because our solarwinds check would only notice if the service had been down for 5 minutes. The reason why the service was crashing was later fixed in a patch, but nobody knew about this little “helper” script for years.

    Until one day, we had a service failover from primary to backup. Normally, we had two mail servers servers behind a load balancer. It would serve only the IP that was reporting as up. Before, we manually disabled the other network port, but this time, that step was forgotten, so BOTH IPs were listening. We shut down the primary mail service, but after 5 minutes, it came back up. The mail software would sync all the mail from one server to the other (like primary to backup, or reversed, but one way only). With both up, the load balancer just sent traffic to a random one.

    So now, both IPs received and sent mail, along with web interface users could use. But now, with mail going to both, it created mass confusion, and the mailbox sync was copying from backup to primary. Mail would appear and disappear randomly, and if it disappeared, it was because backup was syncing to primary. It was slow, and the first people to notice were the scant IMAP customers over the next several days. Those customers were always complaining because they had old and cranky systems, and our weekend customer service just told them to wait until Monday. But then more and more POP3 customers started to notice, and after 5 days had passed, we figured out what had happened. And we only did Netbackups every week, so now thousands of legitimate emails were lost for good over 3000 customers. A lot of them were lawyers.

    Oof.


  • Not just LinkedIn profiles: there was a case out here near DC a while ago where a well known company leased out their function space for training meetings. Using a compromised company account, a set of scammers set up some fake recruitment profiles, leased out the meeting space for “software training,” and did some “mass hiring” where 30 individuals had their credentials scanned and duplicated. The effect was someone from the recruiting company was contacting you, you had a face-to-face where you got offered an in-person, you showed up to their offices, and got a “job offer pending a background check,” with a date of hire in official-looking emails. You sent in your SSN, copies of your passport and driver’s licence, and after a few weeks, they tell you to show up for orientation. Only, the day these people showed up, the company was confused and had never heard of you. The people you supposedly spoke to had never heard of you. And your identity was stolen, and huge loans and charges started showing up in your credit report.

    Yikes.