Spyke

Posts

indiana·IndianabyRedFox

We might be in trouble: IN HB1343:

HB 1343 has a section that slips in a possibly dangerous ability for the governor to use a military police entity within the national guard as he wishes, without much checks and balances. See below, it's now in section/chapter 23.

This seems like a bad idea.

Note, the governor can already call members of the National Guard to state active duty orders, and there's already a military police unit under 81st Troop Command, but it's more limited and they generally are still not police for a civilian population like most people think of. LLM explained it well for those who don't know:

  1. The "Emergency" Loophole

Current Law: Generally, for the Guard to be used in a law enforcement capacity, the Governor declares a State of Emergency. This declaration is usually tied to a specific event (tornado, pandemic, civil unrest) and has time limits and legislative oversight.

Under HB 1343: The bill allows deployment "at any other time the governor considers necessary."

Implication - This effectively removes the requirement for a formal "Emergency" or "Disaster" declaration to use military police. The Governor could theoretically deploy this force to patrol a city for "crime suppression" without ever declaring an emergency or citing a specific disaster.

This is also a good way to think about it:

"Martial Law Lite": HB 1343 allows the Governor to use military personnel to police civilians without the political and legal fallout of declaring Martial Law. The courts remain open, and civil law remains in effect, but the enforcers are soldiers answering directly to the Governor, not local police chiefs or sheriffs answering to voters.


Here's the full text of the section, buried within the rest of the bill.

https://iga.in.gov/pdf-documents/124/2026/house/bills/HB1343/HB1343.04.ENGH.pdf

Chapter 23. Military Police Force of the Indiana National 29 Guard 30 Sec. 1. The adjutant general may establish a military police 31 force of the Indiana National Guard. 32 Sec. 2. (a) Before granting police powers to an individual 33 appointed as a member of the military police force of the Indiana 34 National Guard, the adjutant general shall validate that the 35 individual has a current security clearance and has not been 36 convicted of a felony. 37 (b) An individual appointed to serve in the military police force 38 of the Indiana National Guard may not exercise police powers until 39 the individual successfully completes either army or air military 40 police occupational training and receives qualifying instruction on 41 Indiana law enforcement prescribed by the adjutant general. 42 (c) An individual appointed to the military police force of the HB 1343—LS 6518/DI 116 33 1 Indiana National Guard shall take an appropriate oath of office in 2 the form and manner prescribed by the governor. 3 Sec. 3. The governor may authorize the military police force of 4 the Indiana National Guard to exercise police powers throughout 5 Indiana, or in any part of Indiana prescribed by the governor, if 6 the governor orders the military police force of the Indiana 7 National Guard to state active duty under IC 10-16-7-7. The 8 governor shall provide reasonable notice to local law enforcement 9 agencies affected by the deployment of the military police force of 10 the Indiana National Guard and coordinate with local law 11 enforcement agencies as circumstances permit. 12 Sec. 4. An individual serving in the military police force of the 13 Indiana National Guard who is authorized to exercise police 14 powers under section 3 of this chapter may: 15 (1) make an arrest; 16 (2) conduct a search or seizure of a person or property; 17 (3) carry a firearm; and 18 (4) exercise other police powers with respect to the 19 enforcement of Indiana laws.


In case you care:

Here's the voting results of the house:

https://legiscan.com/IN/rollcall/HB1343/id/1618347

https://iga.in.gov/pdf-documents/124/2026/house/bills/HB1343/HB1343.04.ENGH.pdfOpen linkView original on infosec.pub
9
indiana·IndianabyRedFox

No more hybrid schedules for state workers as remote work slashed

Article covers Braun's intentions to reduce state employees by revoking remote work - my opinion.

Anyone have really good support for removing remote or hybrid work?

All I hear is rhetoric about productivity in person and collaboration, but too many studies say that's unnecessary.

Is this a veiled attempt to reduce headcount or is there actual legitimacy to removing remote work?

https://www.therepublic.com/2025/07/02/no-more-hybrid-schedules-for-state-workers-as-remote-work-slashed/Open linkView original on infosec.pub
1
indiana·IndianabyRedFox

Gov. Mike Braun says tolling needs to be an option for Indiana's road funding future

Could anyone explain this in a way that doesn't make me hate it?

The usual arguments I relate to are things like: we are taxed multiple times for vehicle ownership. Purchase, plates, mandatory insurance, gas tax, parking. Did I miss any?

Now I know there's plenty of people who would rather have robust public transportation, which would be nice, but I don't see that happening as a result of all this money I'm already paying.

People who make just enough or barely enough to afford to drive to work could now have to pay for the right to trade their precious time for money.

Insert tirade here about that.

I've heard view points regarding tolls:

recover costs to maintain interstate infrastructure used by commercial trucking to move the rolling warehouse of America around so Jeff Bitchboy can have a Venice wedding and I can have my materialistic lifestyle delivered to my door possibly the same day...sorry slipped into rant.

Should I be looking at this a different way before I exercise the almost non-existent power I have as a resident and voter, which is sending emails to my elected corrupt aristocrats and beg them to consider regular people, darn did it again.

Gov. Mike Braun says tolling needs to be an option for Indiana's road funding futurehttps://www.wfyi.org/news/articles/gov-mike-braun-says-tolling-needs-to-be-an-option-for-indianas-road-funding-futureOpen linkView original on infosec.pub
3
selfhosted·SelfhostedbyRedFox

Sophos XG Firewall Home Use

Public Service Announcement:

Have you checked out Sophos XG Firewall for home use lately?

It's basically an enterprise firewall fully licensed for personal use.

  • All the firewall stuff
  • Normal IPS
  • Built-In easy transparent SSL/TLS proxy
  • Web Application Firewall

I like it better than PF/Open Sense right now.

https://youtu.be/Ui8UC8-MeJU

Sophos XG Firewall Home Usehttps://www.sophos.com/en-us/free-tools/sophos-xg-firewall-home-editionOpen linkView original on infosec.pub
-36
indiana·IndianabyRedFox

State settles with anti-abortion group; will release terminated pregnancy reports • Indiana Capital Chronicle

I consider myself slightly in a conservative, Christian viewpoint camp. I say slightly because as I get past middle age, all those views or opinions have shifted.

I'm not a huge fan of abortion, but my opinion is slightly more nuanced and that's not a topic I think will be fruitfully discussed online.

Button line, seeing things like this however make me slightly lose my fucking mind.

Insert huge rant here about hypocrisy and unreasonable people, laced with outrage and much profanity.

I know others in my circle who also feel similarly. My hope is that people might know even church going conservative people think this is fucking bullshit and that piece of shit attorney general need to go. Fuck him.

State settles with anti-abortion group; will release terminated pregnancy reports • Indiana Capital Chroniclehttps://indianacapitalchronicle.com/briefs/state-settles-with-anti-abortion-group-will-release-terminated-pregnancy-reports/Open linkView original on infosec.pub
3
technology·TechnologybyRedFox

Keep Tier-One Applications Out of Virtual Environments

After reading this article, I had a few dissenting thoughts, maybe someone will provide their perspective?

The article suggests not running critical workloads virtually based on a failure scenario of the hosting environment (such as ransomware on hypervisor).

That does allow using the 'all your eggs in one basket' phrase, so I agree that running at least one instance of a service physically could be justified, but threat actors will be trying to time execution of attacks against both if possible. Adding complexity works both ways here.

I don't really agree with the comments about not patching however. The premise that the physical workload or instance would be patched or updated more than the virtual one seems unrelated. A hesitance to patch systems is more about up time vs downtime vs breaking vs risk in my opinion.

Is your organization running critical workloads virtual like anything else, combination physical and virtual, or combination of all previous plus cloud solutions (off prem)?

Keep Tier-One Applications Out of Virtual Environmentshttps://www.darkreading.com/application-security/keep-tier-one-applications-out-of-virtual-environmentsOpen linkView original on infosec.pub
22
education·EducationbyRedFox

What We Never Say Out Loud In Higher Education

The author of this article asserts some of the recent complaints I've either personally heard from others or some of my own opinions regarding the costs of higher education.

Scott Galloway has recently become well known for additional criticism of higher education creating artificial constraints on admissions or acceptance of potential students.

Do you believe any of these points have merit?

Do you believe the current costs of higher education either in the US or other first world countries provides appropriate return on investment?

Do you believe the assertion that senior lecturers don't have the same teaching skill requirements as primary education in addition to their subspecialty or focus?

How could higher education be improved or is the current model working well enough?

What We Never Say Out Loud In Higher Educationhttps://www.forbes.com/sites/nicholasladany/2024/08/05/what-we-never-say-out-loud-in-higher-education/Open linkView original on infosec.pub
3

Firewall Schemes at Different Layers

This is a network defense design scheme question.

In a scenario where your organization is designing multi-layered firewall deployment and management, how granular  do you create rules at each of these three layers?

Example site is a main/HQ site that also houses your data center (basic 3 tier model).

  1. Site has your main internet gateway and VPN termination point. As am example, it's a Cisco or other ZBF. It has four zones: (1) Internet, (2) VPNs from other sites/clients, (3) your corporate LAN including data center, (4) Guest/untrusted/Iot.

  2. Between your gateway and the rest of your corporate network/datacenter, you have transparent proxy firewall/IPS/monitor. It's bridging traffic between gateway and data center.

  3. Within data center, hosts have software host based firewalls, all centrally managed by management product.

Questions:

  • How granular do you make ZBF policies at gateway? Limit it to broad zones, subnets, etc? Get granular by source/destination? Further granular by source/destination/port?

  • How granular do you make rules for transparent proxies between segments? Src/dst? Src/dst/port?

  • How granular do you make rules for host based firewalls? Src/dst? Src/dst/port? Src/dst/port/application/executable?

  • How have organizations you've worked for implemented these strategies?

  • Were they manageable vs effective?

  • Did the organization detect/prevent lateral movement if any unauthorized access happened?

  • What would you change about your organization's firewall related designs?

View original on infosec.pub
2

Technical Controls

What sources of technical controls does your organization use?

Do you base device/operating system configurations on:

  • CIS workbench?
  • NIST/STIG?
  • Microsoft best practice?
  • Google searches and 'that looks good'?

How closely rigorously does your organization enforce change management for policies or settings?

  • Can you change GPOs/Linux/Network device settings as needed?
  • During maintenance window?
  • After a group meeting with code/change review and some sort of approval authority?
View original on infosec.pub
2