Alex1Powell's Categories
Alex1Powell's Authors
Latest Saves
I kinda disagree with this.
Not disagree as in "He's wrong, this is complete bollocks" but as in "He's right about some things, wrong bout others, missing yet others and the things are much more nuanced and discretion must be applied".
I was asked to elaborate, so here it is.
The whole article is based on the premise "ransomware contains data that's private for you, once you upload it, everyone can get it from VirusTotal". This is wrong and incomplete in several ways.
To begin with, by far not all ransomware is hand-crafted for the victim and even when it is, by far not all of it contains personal information.
Furthermore, the author is confusing the ransomware executable (which is what you normally upload to VirusTotal, so that the scanners there can tell you what it is) with the ransom note. The note contains victim-specific data much more often than the executable.
Next, VirusTotal, while hugely popular, is not the only such service. I very much like id-ransomware for ransomware identification - and you never upload the executable there anyway; only encrypted files (and ransom note, if available; often it's not).
Not disagree as in "He's wrong, this is complete bollocks" but as in "He's right about some things, wrong bout others, missing yet others and the things are much more nuanced and discretion must be applied".
Never upload #ransomware samples to the Internet. Let me explain what information such a sample contains, why you shouldn't upload them, and what happens if you upload them after all. #SysAdmin #DFIR #malwarehttps://t.co/M4S3ET5Eqc
— Thomas Barabosch (@tbarabosch) December 28, 2020
I was asked to elaborate, so here it is.
The whole article is based on the premise "ransomware contains data that's private for you, once you upload it, everyone can get it from VirusTotal". This is wrong and incomplete in several ways.
To begin with, by far not all ransomware is hand-crafted for the victim and even when it is, by far not all of it contains personal information.
Furthermore, the author is confusing the ransomware executable (which is what you normally upload to VirusTotal, so that the scanners there can tell you what it is) with the ransom note. The note contains victim-specific data much more often than the executable.
Next, VirusTotal, while hugely popular, is not the only such service. I very much like id-ransomware for ransomware identification - and you never upload the executable there anyway; only encrypted files (and ransom note, if available; often it's not).
The proposal for $2000 stimulus checks is divisive, and not along simple left-right lines. Lots of disagreement among progressives, with people like Bernie Sanders very pro but many others not on board. Both sides have a point 1/
My take: the economics aren't very good, but the political economy may make such checks necessary 2/ https://t.co/XY7d9E8SDY
The key economic argument, which @crampell picks up on, is that given a slump that has affected people very unevenly, aid should concentrate on those actually suffering 3/
So if you have a fixed amount to spend, unemployment benefits and maybe small-business aid should be priorities, not checks that will in many cases go to people who are doing OK 4/
But is there a fixed amount to spend? No binding budget constraint for the feds, so this is all about politics. And my sense is that broad issuance of checks is actually kind of a loss leader, helping to sell a package that includes UI 5/
My take: the economics aren't very good, but the political economy may make such checks necessary 2/ https://t.co/XY7d9E8SDY
The key economic argument, which @crampell picks up on, is that given a slump that has affected people very unevenly, aid should concentrate on those actually suffering 3/
So if you have a fixed amount to spend, unemployment benefits and maybe small-business aid should be priorities, not checks that will in many cases go to people who are doing OK 4/
But is there a fixed amount to spend? No binding budget constraint for the feds, so this is all about politics. And my sense is that broad issuance of checks is actually kind of a loss leader, helping to sell a package that includes UI 5/
One thing I really notice in friends who haven't done any therapy is a lack of conflict resolution skills. So I figure hey, let's do a mini lesson on conflict resolution right here in this thread.
One philosophy for conflict resolution within psychology is that there are three main priorities you can have in a conflict: respecting yourself, maintaining a good relationship with the other person, or getting a task done. (Reference: these DBT skills https://t.co/C7CAlDaE5A )
Most people want to do all three, and you can, but the idea is it can be unrealistic to get all three goals accomplished perfectly-- maybe it's worth thinking about which goals matter most to you right now, in this scenario and relationship, and which you're willing to sacrifice.
To respect yourself, these are good guidelines to prioritize:
1 Keep fairness strongly in mind.
2 Be wary of apologizing. Think hard before offering any apology-- do you really need to say sorry here?
3 Keep in mind what you value.
4 Stick to being truthful, even if you're angry.
To maintain a relationship, keep these in mind:
1 Be gentle, not aggressive.
2 Ask questions, be actively interested in their opinions.
3 Actively validate the way they feel.
4 Have an easy manner. Watch your tone of voice & body language. It's not all about what you're saying.
One philosophy for conflict resolution within psychology is that there are three main priorities you can have in a conflict: respecting yourself, maintaining a good relationship with the other person, or getting a task done. (Reference: these DBT skills https://t.co/C7CAlDaE5A )
Most people want to do all three, and you can, but the idea is it can be unrealistic to get all three goals accomplished perfectly-- maybe it's worth thinking about which goals matter most to you right now, in this scenario and relationship, and which you're willing to sacrifice.
To respect yourself, these are good guidelines to prioritize:
1 Keep fairness strongly in mind.
2 Be wary of apologizing. Think hard before offering any apology-- do you really need to say sorry here?
3 Keep in mind what you value.
4 Stick to being truthful, even if you're angry.
To maintain a relationship, keep these in mind:
1 Be gentle, not aggressive.
2 Ask questions, be actively interested in their opinions.
3 Actively validate the way they feel.
4 Have an easy manner. Watch your tone of voice & body language. It's not all about what you're saying.
Better late than never. Here we go. What does this deal mean for borders, border formalities, customs & trade facilitation?
Long one. TL:DR very little at the moment but has potential
/1
Borders
When compared to no deal the deal changes very little in terms of border procedures. All formalities and checks will still be required.
Reminder - we're not starting from 0 here – both our container ports and our ro-ro ports are already congested
/2
On top of that, all the issues related to border readiness: lack of capacity and space, IT systems not ready, shortages of customs agents, treader readiness – have not been solved.
The deal doesn’t help with that.
/3
Here is where we are:
☑️The UK will phase-in border formalities over 6 months (customs and SPS)
☑️The EU will introduce full formalities in 3 days (customs + SPS)
☑️Irish Sea border also fully operational in 3 days with some short-term SPS easements
/4
Pre-notifications (safety & security declarations) not initially required on the UK side, needed for imports into the EU.
So what's in the deal?
/5
Long one. TL:DR very little at the moment but has potential
/1
Lots of stuff on technical barriers and customs cooperation. See @AnnaJerzewska for more on the latter. pic.twitter.com/3sC5xHD3Z8
— Steve Peers (@StevePeers) December 26, 2020
Borders
When compared to no deal the deal changes very little in terms of border procedures. All formalities and checks will still be required.
Reminder - we're not starting from 0 here – both our container ports and our ro-ro ports are already congested
/2
On top of that, all the issues related to border readiness: lack of capacity and space, IT systems not ready, shortages of customs agents, treader readiness – have not been solved.
The deal doesn’t help with that.
/3
Here is where we are:
☑️The UK will phase-in border formalities over 6 months (customs and SPS)
☑️The EU will introduce full formalities in 3 days (customs + SPS)
☑️Irish Sea border also fully operational in 3 days with some short-term SPS easements
/4
Pre-notifications (safety & security declarations) not initially required on the UK side, needed for imports into the EU.
So what's in the deal?
/5