• 0 Posts
  • 20 Comments
Joined 1 year ago
cake
Cake day: August 28th, 2023

help-circle
  • It provides a safety net by pooling the resources of the community to support the less fortunate. This prevents people from having to sacrifice their long term goals because their short term needs may not be otherwise met.

    Also in contrast to capitalism that treats society as a zero sum game (“I can’t get ahead unless I take something from someone else”) socialism is a benefit multiplier (“I’m part of the community. By making the life of everyone in the community better I’m also improving my own life”).












  • The CIS benchmarks for Linux are a good start. There are some off the shelf tools that let you run those, notably linux-bench. Another tool in a similar fashion is lynis. You can also use eBPF tools like callander to examine your workload behaviour and help tighten your seccomp policies.

    Once you’ve established a baseline for your system, you’ll next want to harden your environment. This means network scans, OWASP, etc. As far as off the shelf tools go, OpenVAS is quite popular even in Enterprise environments.

    Finally there’s the continuous security tasks. Continuous package updates, runtime security, log analysis, etc. There are some free tools that cover part of this like Security Onion, but if the price is right a SaaS tool can save you a lot of time.








  • You can’t run vmalert without flags

    Running grep without parameters is also pretty fucking useless.

    500 words in to the over 3,000 word dump, I gave up.

    Claims to have a Unix background, doesn’t RTFM.

    Nobody really uses Kubernetes for day-to-day work, and it shows. Where UNIX concepts like files and pipes exist from OS internals up to interaction by actual people, cloud-native tooling feels like it’s meant for bureaucrats in well-paid jobs.

    Translation: Author does not understand APIs.

    Want an asynchronous, hierarchical, recursive, key-value database? With metadata like modified times and access control built-in? Sounds pretty fancy! Files and directories.

    Ok. Now give me high availability, atomic writes to sets of keys, caching, access control…

    I’m ashamed enough that I can’t really apply to these jobs

    This reads as “I applied to the jobs and got rejected. There’s nothing wrong with me, so the jobs must be broken”.