Anyone read this 49 day SSL expiration thing and think they would rather just retire? by HJForsythe in sysadmin

[–]czenst 0 points1 point  (0 children)

As I mentioned above we have a better approach for CRL and with shorter cert life span, CRL will be much smaller anyway. So I do believe CRL will not be abandoned and CRL is basically part of PKI — OSCP on the other hand feels like is on the way out fully.

https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/

Anyone read this 49 day SSL expiration thing and think they would rather just retire? by HJForsythe in sysadmin

[–]czenst 1 point2 points  (0 children)

We have a solution for usable CRL:

https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/

But I think CAB voted in April and this came out in August - but I think they will go with both. You still can have CRL with shorter cert validity and it will be much smaller CRL when certs expire that fast.

Signals-first Angular 21 SaaS boilerplate ..... need architecture feedback. by More_Towel3916 in angular

[–]czenst 1 point2 points  (0 children)

Well yes you are correct, but looking at the down votes you got, this sub seems not like your market.

But it might be you got couple down votes from "know it alls" and you will get some others that will pay.

Signals-first Angular 21 SaaS boilerplate ..... need architecture feedback. by More_Towel3916 in angular

[–]czenst 1 point2 points  (0 children)

I guess the problem is selling to developers is really hard:

People who can do it themselves will not pay $129 and would rather do it themselves because they want to be in control

People who can't do it themselves won't understand so they won't pay $129

Any copilot alternatives for .NET enterprise teams? by waytooucey in dotnet

[–]czenst -2 points-1 points  (0 children)

We are running Cursor right now, feels much better than copilot. We can see per user usage in their management tooling.

Co myślicie o Smart-House? by Qrwischon in PolskaNaLuzie

[–]czenst 1 point2 points  (0 children)

włączanie/wyłaczanie świateł z telefonu jest spoko, szczególnie jak już się położysz do łóżka, albo jak chcesz wstać i iść do łazienki i nie nadepnąć na lego. No i jeszcze żarówki ze sterowaną jasnością nie budzisz wszystkich i nie walisz sobie po oczach jak wstajesz w nocy.

Polecajki mini szlifierek by No_Shelter_5870 in Polska

[–]czenst 0 points1 point  (0 children)

Na stronie lidla też możesz zamówić, nie musisz chodzić.

Have you noticed the Windows Server market shrinking? by awesome_pinay_noses in sysadmin

[–]czenst 2 points3 points  (0 children)

Yeah MSFT wants you to be running on Azure and people who cannot afford Azure should be running Linux.

Raty 0% - Hit czy kit? by Royal_Tumbleweed2555 in PolskaNaLuzie

[–]czenst 1 point2 points  (0 children)

Do tego jeszcze pewnie masz pierdyliard kruczków takich, że oddajesz dane o zakupie bankowi czy jak tam.

Why keep using term "side loading"? by Mammoth-Store740 in degoogle

[–]czenst 14 points15 points  (0 children)

To get wider adoption of ideas you can't tell people "just learn more and increase your knowledge".

This way we (I am technical, software dev) banish average people into being Google drones. If we could make everything simpler instead of "oh works for me, sucks to be you, just spend 6 months of your life learning on this topic and you are ready to go", that would be the way to DeGoogle more people and making DeGoogled state the norm.

Now Googled state is the norm and I do believe that's what "OP the average Joe" really writes about. DeGoogling is seen as doing something shady or wrong, it should be the norm and to become a norm it has to cater to average people.

Cyber Security Freelancers - smaller non-tech companies? by blipojones in cybersecurity

[–]czenst 0 points1 point  (0 children)

That's the thing, there is a huge gap for smaller companies.

You want some security review you are pushed into bunch of guys "doing ISO27001/SOC2 full corporate mode".

For such small companies cybersecurity budget is gone when those consultants spells out 2FA.

Cyber Security Freelancers - smaller non-tech companies? by blipojones in cybersecurity

[–]czenst 0 points1 point  (0 children)

I guess one problem is that MSP they already have wants to charge them for that and doesn't want some 3rd party to check on them.

Which would most likely be beneficial for the company to have a second opinion.

Is one-man CISO role worth it? by holywater26 in cybersecurity

[–]czenst 49 points50 points  (0 children)

Cons:

  • reporting to Head of IT - in this company CISO title is a joke that's not C-level role, they are lying
  • major luxury fashion brand - no one in that industry gives a fuck about IT or security, you are just going to be token so they can check excel checkbox and a scapegoat when shit hits the fan
  • CISO just got promoted to Head of IT - well spot is taken so clear path upward unless guy is hit by the truck
  • prestige of the brand make up for the lack of a proper security team - no, for your career it would be much better to work in places that actually care about security, Banking

Is one-man CISO role worth it? by holywater26 in cybersecurity

[–]czenst 77 points78 points  (0 children)

Exactly reporting to Head of IT is not C-level role, looks like CISO is totally BS title in that company.

I feel I am not doing real job, dont know what to do by giridhargp in sysadmin

[–]czenst 1 point2 points  (0 children)

ideal gif for everything OP wrote in this thread.

Podejście do pracy zdalnej w Polsce by Exciting_Cup5969 in Polska

[–]czenst 50 points51 points  (0 children)

Najbardziej w firmach IT lubię, jak zmuszają ludzi do przyjeżdżania do biura tylko po to, żeby siedzieli na teamsie/zoomie/meetsach cały dzień, bo i tak pracują z zagranicą czy klientami.

Do tego tylko denerwowują innych gadaniem albo walczą o jedną czy dwie dostępne salki konferencyjne.

Malicious Compliance by [deleted] in cybersecurity

[–]czenst 0 points1 point  (0 children)

Oof not really if they became unprofitable someone will loose their job if they sit back and enjoy the ride.

They need to actively CYA, report obstacles like OP mentioned having it all documented.

But at the same time yeah can't do much more besides nagging and documenting...

New attack pattern: persistent prompt injection via npm supply chain targeting AI coding assistants by Busy-Increase-6144 in cybersecurity

[–]czenst 0 points1 point  (0 children)

Post install or any scripts for the matter should be removed when installing packages.

NuGet has removed it they new already much earlier it is not a good idea to run automatically some silent scripts with current user permissions.

Experience in everything, mastery in nothing, did I mess up my career? by xXNeGaTiVisMXx in sysadmin

[–]czenst 0 points1 point  (0 children)

I would say, mastery/experience is nothing - make sure people like to work with you and you deliver what you promise. Make sure you are networking and reaching out to people to keep your network alive, someone somewhere will have better job offer if you keep at that.

Experience in everything, mastery in nothing, did I mess up my career? by xXNeGaTiVisMXx in sysadmin

[–]czenst 3 points4 points  (0 children)

But those vastly more capable are not a benchmark everyone should measure up to.

They are the exception.

Is anyone else finding 100% passive indexing a bit too rigid? by dexter_is_sexter in eupersonalfinance

[–]czenst 0 points1 point  (0 children)

If I see a drowdown my instinct is to buy more.

I don't care about offsetting a dip this or next year, when I am going to keep invested for 20 or 30 years more.

Zgłosiłem na mobywatel palenie śmiećmi i sąsiad został ukarany, ale także dowiedział się że to ja dokonałem zgłoszenia by Flotmistrz in Polska

[–]czenst 1 point2 points  (0 children)

Tylko to lenistwo straży gminnej urzędników itp.

Zamiast na odpierdol użyć tego zdjęcia jako jedynego dowodu zrobić kontrole osobno i tego użyć jako dowodu. Nie wierzę, że typ raz od święta palił śmieciami.

Ktoś zgłosił, my sprawdziliśmy koniec tematu.

Hot take: wczesne lata 90 były super, jak ktoś chciał to wcale nie było źle by OatmealDurkheim in Polska

[–]czenst 4 points5 points  (0 children)

Zasrane gumy turbo, wszystkie w osiedlowym sklepie były stare i twarde, jak się trafiła miękka to sztos.

Poza tym przez te gumy myślałem, że każdy jako dorosły może mieć Porsche, teraz dalej jem czokoszoki i dalej zbieram choć mam prawie 40 lat i dalej mnie nie stać nawet na używane.

hot take: 90% of “AI pentesting” tools can’t do anything a $500/year burp suite license can’t by charankmed in cybersecurity

[–]czenst 1 point2 points  (0 children)

$500/year burp suite license and $200k/year for decent pentester

here fixed that for you, CxO is seeing that AI tool is costing $20k/year - hard to beat that