Spyke

Replies

gaming

Comment on

Warlock: Dungeons & Dragons - Official Gameplay Reveal

Color me underwhelmed. It looks like a pretty run of the mill, third person action game with the "Dungeons and Dragons" name tacked on to try and drum up purchases. The dark magic wielding swords-woman is a great starting point, but I wasn't sure where the combat ended and quick time events started. The entire "fight" with the gazer looked like a scripted QTE sequence. The fight with the undead ogre and associated attackers (ghouls, maybe?) looked better. Though the end of that fight seemed to go back to QTE for the "finish him" sequence. Hopefully, I'm wrong and this turns out to be another great D&D game. But, it's mostly just making me think about breaking out Baldur's Gate 3 again.

linux

Comment on

Has anyone in a windows dominated workspace actually tried using Linux on their device?

I've been on several sides of this. As a sysadmin supporting a Windows dominated environment integrating Linux, as a user who wants to use Linux in a Windows dominated environment and in security trying to secure an environment with both Windows and Linux. In short, it depends on the use case, environment and the users' tolerance for problems.

The first question which will come up is, "why?". If you don't have a good business use case, you should expect to be basically told to go get fucked. I realize that this seems like IT sticking their head in the sand, and it kinda is. But, also realize that you are asking them to take on extra work for nothing more than your own self edification. I have yet to meet an IT department which is so overflowing with time and resources that they want to take on new work which isn't required. Even with the most basic use cases for Linux, IT is going to need to have resources dedicated to support, maintenance and oversight. Things like asset management, patching and license management don't go away on Linux systems. Sure, the OS may not have a license to worry about (unless it's RHEL or Ubuntu Pro), but there may be other software installed which is licenses and that license may be a different SKU on Linux. Then there are issues with ensuring IdM works on that flavor of Linux and supporting it when it breaks.

Along side that "why" question, be ready to answer the "why not" questions. Why not a Windows based alternative? Why not Cygwin/WSL? Why not a Linux based server that you SSH into from your main Windows desktop? Especially with a lot of workloads moving to the cloud, I've seen the mainframe model start to return, just with Linux instead of Unix/AIX this time. This sort of thing centralizes a lot of the IT headaches into a single host (or handful) which can much more easily be centrally managed. And that's a theme to keep in mind, IT departments love centralized management. This is one of those places where Linux kinda lags Windows. Centralized management does work on Linux. It's one of the reasons RHEL is all over the place, Satellite is like crack for IT departments dealing with Linux. But, a lot of centralized management looks like a folder full of Ansible scripts. With proper code management, it can work quite well. Keep in mind that many folks in IT are not coders and for a handful of Linux systems, dedicated resources which can handle that may not be in the budget (in the end, everything is about money).

Ok, so you have your "why" and are ready for "why not". Let's talk about the security stack. No, just because it's Linux doesn't mean you can ignore security. I've personally worked cases where Linux boxes got popped. And from the user side, things like ClickFix attacks are starting to crop up targeting Linux desktops. So, does your company's software stack support Linux? This has, thankfully, started to be more common. Go back a decade and the answer was almost certainly, "no". Partly because Linux wasn't that common and partly because idiots believed Linux was fully secure by design. Anyone who believes that today shouldn't be allowed to work on anything more advanced than an Etch-a-Sketch. With the dominance of Linux in the cloud, attackers are targeting Linux and your system will need to be ready for it. If your company's security stack doesn't support Linux, and/or your security department doesn't have the expertise to monitor and respond to issues on Linux systems, you might find them resistant. Thankfully, that whole "Linux dominating the cloud" thing has started pushing security teams towards supporting Linux. And more advanced security teams often utilize Linux themselves in some capacity. So, that could ease your path a bit.

The final bit might be your tolerance for pain. If you're out there on the bleeding edge, trying to be the first Linux system in an all Windows environment, expect things to break. No matter how well planned the rollout, the fact that the IT department hasn't done this before means that they are going to miss stuff. It happens. If your system becomes a common source of trouble tickets, IT leadership may try to pull the plug. If you turn out to be a high maintenance user, you might find IT slow to respond and unwilling or unable to help with things aren't working quite right. Some level of self-help and patience with a help desk which doesn't have Linux expertise are going to be necessary. You really don't want to become the phone number which pops up on the Help Desk queue and all the analysts scramble to avoid taking the call.

To conclude this long ramble. Linux systems in a Windows dominated environment is getting easier. That "the cloud" basically runs on Linux has gone a long way into getting Linux integrated into Windows environments. Microsoft has been forced to make their tools actually work with Linux, rather than the abomination which was setting up POSIX uids in a Windows 2000/2003 Active Directory domain. But, a lot of IT departments will still want to treat Linux as a server OS and not a desktop OS. MS Office, Teams and the rest of their communications and collaboration software still treats Linux as a pariah. Integrating and supporting Linux alternatives means budget and resources which aren't dedicated to the core business. And that's really what IT is going to care about.

linux

Comment on

After Europe ditched Windows, China follows suit with its own home-grown Linux distros

Reply in thread

Along side what you mention, I work for a company with a lot of engineers from multiple disciplines. Linux is everywhere in our environment and has been growing. Most of our engineers either have a Linux laptop, use Linux virtual machines or submit jobs through Linux backed software stacks. Our products have tools built on Linux to the point that we used to maintain our own Linux distribution to make having all those tools on a system easy, though we've just moved to having scripts to install and setup everything. Almost all of those engineers also have a Windows laptop as their daily driver. The few who don't have Macs.

I don't doubt that organizations can move to all non-Windows, but the Windows Ecosystem of Exchange, Office and Active Directory/Entra is very hard to replace. Yes, you can absolutely cobble together alternatives. But, you then have a special snowflake of an IT infrastructure. Maintenance may be eased by the use of tools like Ansible, but even that will likely result in organization specific playbooks and scripts. But centralized management of a Linux environment isn't quite as standardized yet and so requires more planning and effort. And then there is the challenge of security.

Folks like to tout the inherent better security of Linux. As someone who works in Cybersecurity daily, I fully agree with that assessment. However, "better" isn't "perfect". You still need vulnerability management, monitoring and response tools. And this is an area where Linux lags behind Windows, mostly because of the effort put into it. Something as basic as Endpoint Detection and Response (EDR) on Linux is still a foreign concept to a lot of folks. And yes, it's absolutely necessary. I've personally worked cases involving compromise of Linux systems and Linux specific malware. And more than just XMRig clone #5374. It may be harder to move from user to root on Linux than moving to local admin on Windows (unless some jack-off decided that Linux doesn't need updates and DirtyCow still worked); but, there is still a lot of damage which can be done without root.

Overall, I'd say that the Linux ecosystem is evolving. It's already embedded in a lot of environments of all sizes, but it's usually a smaller part of a much larger Windows network. Hopefully, if enough large organizations start pushing away from Windows and towards Linux, there will be more investment and standardization. And, we've already seen some of that. Red Hat is a common distro of choice for large organizations because of that higher level of centralized control and standardization. Of course, a lot of the tools engineers want to use aren't on Red Hat, specifically because of that centralization (read: everything AI). So, it will be interesting to see where we land.

world

Comment on

US Senate Democrats block Republican bid to aid Israel, not Ukraine

Good. Tying aid to cuts in IRS funding was absolutely asinine. Failing to fund Ukraine, which is actually fighting for it's continued existence as a political entity is also asinine.

Yes, Hamas is a horrible organization; but, the Israeli Government isn't facing an existential threat and has not been an innocent actor in the situation in Gaza. Aid and support should come with strings attached to ensure the protection of civilians and property rights of the people being displaced.

world

Comment on

Russia has lost 87% of troops it had prior to start of Ukraine war, according to US intelligence assessment

If we could harness the energy of Regan spinning in his grave, we'd have a limitless supply of energy.
Imagine telling any conservative, during the Cold War era, that we could completely fuck Russia's military power and readiness, for years to come, by sending weapons to a relatively small country. They would be rushing to arm anyone and everyone they could, unintended consequences be damned. And yet, here we are with the GOP blocking exactly that sort of activity. And even better, there is a very real possibility that we aren't arming future terrorists this time around. Maybe that's the GOP's problem, Russia losing in Ukraine won't create an excuse in 20 years to kill more brown people.

news

Comment on

Ford Executive Chair Bill Ford calls on autoworkers to end strike, says company's future is at stake

Ford Motor Co.'s second-quarter profit more than tripled to $1.92 billion versus a year ago (source)
Revenue rose 12% to $44.95 billion

Kinda hard to drum up sympathy for the company when it's raking in almost $2 billion in profit per quarter. Yes, Ford is burning about $1billon per quarter on EVs right now. That's not something the workers should be financing. That's money the company is investing to be viable in the future. That sucks for the shareholders; but, they are the ones who will reap any benefits of that investment and they should be the ones eating the cost.

Comment on

"Nobody's making games for the retired people" – The growing yet underserved market for grey gamers

I think it's pretty telling that so many of the people they talk to and a lot of the focus of the article isn't really about older gamers, it's about their money.

The opportunity is substantial. The 40+ segment in the US is on track to grow from $19 billion in 2022 to $43 billion by 2030, a 132% expansion at a moment when the rest of the industry is shrinking. These are players with the most disposable income, the longest gaming literacy, and the highest brand loyalty.

I'm in that "40+ segment" and I suspect part of the "problem" these companies face is that older gamers have seen the enshitification of so many of the brands we love. Our tolerance for bullshit is basically gone at this point. Micro transactions, season passes, fucking ads in games, all of that bullshit is a quick way to not get our money.

I also suspect "brand loyalty" is basically gone for the same reason. As a kid, I looked for the Electronic Arts logo. If I saw this logo on a game package, I knew I was looking at a good game. I haven't bought an EA game in years. I don't expect to buy an EA game any time soon and I basically ignore everything they do. Sure, if a trailer for Starflight 3 dropped, I'd sit up and take notice. I'd also expect it to be an enshitified mess wearing the skin of a beloved series to sucker me in, before pouncing on my wallet.

So ya, maybe just make good games and older gamers will inevitably buy them. I mean, Larian can pretty much say, "hi we're making..." and I'll have my wallet out and be pulling bills before they get any further. And maybe that's your "brand loyalty". Game companies who make good games and aren't private equity firms wearing the dead skin suits of brands we used to love.

news

Comment on

Baltimore bridge collapses into river after being hit by cargo ship

The investigation report is going to be interesting. While bridges can only take so much punishment, they are usually designed to survive some collisions with their pylons. I wonder what the state of the bridge was, prior to the collapse. If it's anything like the rest of the infrastructure in the US, it was probably not good. Though, this may also be a case that the designers in the 70's planned for a collision with a cargo vessel of the times, which were tiny bath tub boats compared to the super container ships we have now. The Dali was built in 2015 she is a 300m ship capable of carrying 116851 tons. That's a lot of mass for the pylon and it's barriers to stop.

Comment on

Can I refuse MS Authenticator?

I work in cybersecurity for a large company, which also uses the MS Authenticator app on personal phones (I have it on mine). I do get the whole "Microsoft bad" knee-jerk reaction. I'm typing this from my personal system, running Arch Linux after accepting the difficulties of gaming on Linux because I sure as fuck don't want to deal with Microsoft's crap in Windows 11. That said, I think you're picking the wrong hill to die on here.

In this day and age, Two Factor Authentication (2FA) is part of Security 101. So, you're going to be asked to do something to have 2FA working on your account. And oddly enough, one of the reasons that the company is asking you to install it on your own phone is that many people really hate fiddling with multiple phones (that's the real alternative). There was a time, not all that long ago, where people were screaming for more BYOD. Now that it can be done reasonably securely, companies have gone "all in" on it. It's much cheaper and easier than a lot of the alternatives. I'd love to convince my company to switch over to Yubikeys or the like. As good as push authentication is, it is still vulnerable to social engineering and notification exhaustion attacks. But, like everything in security, it's a trade off between convenience, cost and security. So, that higher level of security is only used for accessing secure enclaves where highly sensitive data is kept.

As for the "why do they pick only this app", it's likely some combination of picking a perceived more secure option and "picking the easiest path". For all the shit Microsoft gets (and they deserve a lot of it), the authenticator app is actually one of the better things they have done. SMS and apps like Duo or other Time based One Time Password (TOTP) solutions, can be ok for 2FA. But, they have a well known weakness around social engineering. And while Microsoft's "type this number" system is only marginally better, it creates one more hurdle for the attacker to get over with the user. As a network defender, the biggest vulnerability we deal with is the interface between the chair and the keyboard. The network would be so much more secure if I could just get rid of all the damned users. But, management insists on letting people actually use their computers, so we need to find a balance where users have as many chances as is practical to remember us saying "IT will never ask you to do this!" And that extra step of typing in the number from the screen is putting one more roadblock in the way of people just blinding giving up their credentials. It's a more active thing for the user to do and may mean they turn their critical thinking skills on just long enough to stop the attack. I will agree that this is a dubious justification, but network defenders really are in a state of throwing anything they can at this problem.

Along with that extra security step, there's probably a bit of laziness involved in picking the Microsoft option. Your company picked O365 for productivity software. While yes, "Microsoft bad" the fact is they won the productivity suite war long, long ago. Management won't give a shit about some sort of ideological rejection of Microsoft. As much as some groups may dislike it, the world runs on Microsoft Office. And Microsoft is the king of making IT's job a lot easier if IT just picks "the Microsoft way". This is at the heart of Extend, Embrace, Extinguish. Once a company picks Microsoft for anything, it becomes much easier to just pick Microsoft for everything. While I haven't personally set up O365 authentication, I'm willing to bet that this is also the case here. Microsoft wants IT teams to pick Microsoft and will make their UIs even worse for IT teams trying to pick "not Microsoft". From the perspective of IT, you wanting to do something else creates extra work for them. If your justification is "Microsoft bad", they are going to tell you to go get fucked. Sure, some of them might agree with you. I spent more than a decade as a Windows sysadmin and even I hate Microsoft. But being asked to stand up and support a whole bunch because of shit for one user's unwillingness to use a Microsoft app, that's gonna be a "no". You're going to need a real business justification to go with that.

That takes us to the privacy question. And I'll admit I don't have solid answers here. On Android, the app asks for permissions to "Camera", "Files and Media" and "Location". I personally have all three of these set to "Do Not Allow". I've not had any issues with the authentication working; so, I suspect none of these permissions are actually required. I have no idea what the iOS version of the app requires. So, YMMV. With no other permissions, the ability of the app to spy on me is pretty limited. Sure, it might have some sooper sekret squirrel stuff buried in it. But, if that is your threat model, and you are not an activist in an authoritarian country or a journalist, you really need to get some perspective. No one, not even Microsoft is trying that hard to figure out the porn you are watching on your phone. Microsoft tracking where you log in to your work from is not all that important of information. And it's really darned useful for cyber security teams trying to keep attackers out of the network.

So ya, this is really not a battle worth picking. It may be that they have picked this app simply because "no one ever got fired for picking Microsoft". But, you are also trying to fight IT simplifying their processes for no real reason. The impetus isn't really on IT to demonstrate why they picked this app. It is a secure way to do 2FA and they likely have a lot of time, effort and money wrapped up in supporting this solution. But, you want to be a special snowflake because "Microsoft bad". Ya, fuck right off with that shit. Unless you are going to take the time to reverse engineer the app and show why the company shouldn't pick it, you're just being a whiny pain in the arse. Install the app, remove it's permissions and move on with life. Or, throw a fit and have the joys of dealing with two phones. Trust me, after a year or so of that, the MS Authenticator app on your personal phone will feel like a hell of a lot better idea.

Comment on

Spanish Flu 1918

Viruses had only been discovered a few decades before this picture was taken. It's very likely that the family (and most of society) had no understanding that the virus was unlikely to jump species and so took the same precaution to keep the cat from spreading the disease that they themselves took. I'd rather people made this sort of mistake than the willful idiots we had this time around refusing to believe in viruses at all.

news

Comment on

Pennies Are Trash Now | The government has no plan for America’s 300 billion pennies.

They are still legal tender, the Mint just isn't producing them anymore. If things stay that way, eventually they will just become rarer and rarer until no one really sees them anymore (we stopped caring about them decades ago). Why bother with some convoluted, expensive plan to do anything about them? It's really a problem that will solve itself for the cost of someone a bank occasionally delivering a bag of them to the Mint as they do with any currency which is old and should be taken out of circulation.