Hacker Newsnew | past | comments | ask | show | jobs | submit | kevincloudsec's commentslogin

I think everyone's glossing over that this extends to anyone who knows the password. Your sysadmin, your business partner, your spouse. Hong Kong just turned your company's entire key management chain into a legal liability.

Forget the Iran attribution for a second. The FBI director's personal email was already in leaked credential databases from prior breaches.

Every now and then something happens that makes me wonder how the fuck America is number one, this being one of them.

Loads of natural resources, no local military threats, and historically a government that stayed out of the way and allowed individuals to reap the rewards of their efforts.

The first is almost impossible to screw up, though we're really trying on the last front.


We're ranked number one based on the summation of all the angsty teen America bad comments on social media. At least that is the stat the press goes off of I believe

One of the largest populations, and by extension, GDPs.

Bretton Woods, Petro dollar and Lindy effect?

Also the only major economy which didn't fight World War 2 on its own territory.

Boy are there some angry Pearl Harbour comments incoming...

Don't worry, it's on its way out.

America had the advantage of getting through WW2 relatively unscathed with lots of resources and intact infrastructure that it used to leverage against the reconstruction of Europe, Japan and the USSR and entrench its cultural and economic hegemony. Also the US essentially colonized the West with nuclear weapons under the guise of "Pax Americana" and making the dollar the reserve currency.

That's really it. Not moral superiority, not technical ingenuity, not the indomitable American spirit. Just imperialist opportunism.


Plus huge amounts of braindrain from all over the world after WW2 (originally from Europe, but nowadays mainly from India and China).

Number one based on what metric other than they constantly say they're number one?

Because America is a lot more than a podcaster put into a position that he has no qualifications for.

FBI director was asked point blank if he'd commit to not buying Americans' location data. he said no.

two verdicts in two days, $375m in new mexico and $6m in LA. meta's insurance company already got cleared of covering these claims. if even ten more states follow, meta is paying out of pocket at a scale that actually shows up on the balance sheet.

the fine is 0.6% of last year's profit. the lobbying budget probably costs more.

cloud providers design for software failures and network partitions. they do not design for drone strikes. the redundancy model assumes your availability zones won't get hit by the same military operation.

Thats what regions are for... AZ downtime is one thing, if you loose the region, you should be able to bring up your services in another region.

the ban covers all foreign-made consumer routers but practically every router is manufactured abroad, even the ones sold by American companies. the only domestic exception is Starlink, iirc

hack back assumes you know who hit you. attribution in cyber is hard enough for the NSA

second breach in a month from the same initial credential compromise. the first rotation didn't fully revoke access. the attacker walked right back in. no persistence needed.

telling users on a cybersecurity website to click past certificate warnings is training them to do the exact thing every security awareness program says never to do. DISA runs the security standards that every defense contractor has to comply with...

The requirements for vendors are based on NIST standards and frameworks. They do not have to apply DISA STIGs to their own systems. And the mandatory annual cybersecurity awareness training for anyone with a CAC does include teaching users not to click through these warnings. DoD users wouldn't typically see this page at all.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: