techhub.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A hub primarily for passionate technologists, but everyone is welcome

Administered by:

Server stats:

4.6K
active users

#securityvulnerabilities

0 posts0 participants0 posts today

Went on @trtworld over the weekend to provide live commentary on the Crowdstrike global IT outage on the Newshour programme and explain why it isn't an easy fix, as well as why we really should be looking at Microsoft to make changes in order to avoid this happening again. Thanks for the chat Maria Ramos!

Here's a clip from the segment, you can watch the full video here 📹:
youtube.com/watch?v=NNDg52RPhM

It looks like it might be time to replace the network gear. I hate #unifi and the #uniquity platform (named for the ubiquitous #securityvulnerabilities) but I couldn't exactly afford to rip it all out and replace it. That is, until they EOLd the fancy "enterprise-class" gateway I bought 3 years ago. In proper #unifi style it was never actually capable of the enterprise-class features they promoted, but that doesn't mean I'm not using it anyway.

Some quick examples from my 'prosumer' home use. If you turn on traffic inspection, the total throughput drops to about 30%. If you want to add (or disable, or rename) a firewall rule you can expect 5 minutes of reloading where connectivity sometimes just goes spinning beachball.. And I'm not getting into the terrible no good web interface, the increasing push towards monthly subscriptions, or what a mess the guest network setup is.
The only 'enterprise' feature that actually functions is the WAN failover. It doesn't support custom routes or anything, just a choice of 50/50 or failover, but it works.

The question is, do I buy the replacement gateway? It isn't the cost, the thing is cheap, but I just don't want to keep encouraging them. Supposedly the new one can do everything the enterprise one originally claimed, except for the only feature that actually worked..
:rick: (It doesn't do failover, but I only had failover for like a month anyway before elmo went nuts and we cancelled.)

#networking #wifi #selfhosting

Have clients that are still on Ruby versions well beyond #EOL (end-of-life)? For some of them, it may be a lack of budget, staff, or skills to perform system-wide upgrades. Performing #majorVersionUpgrades can be hard, but opening yourself up to known #securityvulnerabilities is more costly in the long run.

If you're still on an old Ruby version, it's past time to upgrade. It's well worth the effort from both a security and a performance perspective!

ruby.social/@todd_a_jacobs/111

Ruby.socialTodd A. Jacobs (@todd_a_jacobs@ruby.social)Just over two weeks until the annual release of a new #RubyLang version. This year it will be Ruby 3.3.0. Ruby 2.7.8 is #EOL; 3.0.8 is on its way out. If you aren't at least on Ruby >=3.1.4, your #cybersecurity team and #technologyleadership ought to be asking you some very tough questions right about now.