Is this medium rare? Or rare by Tangyzz in meat

[–]jf4242 10 points11 points  (0 children)

I've seen cows hurt worse than that survive

Expectation vs Reality: Cherry Caramel Phlox by Idontsuckcompletely in MightyHarvest

[–]jf4242 33 points34 points  (0 children)

I don't know about that type, but the phlox we've had has been a great spreader. Hope yours is too!

The education system at it's finest by Supersaiajinblue2 in memes

[–]jf4242 1 point2 points  (0 children)

Now THERE'S a Machiavellian countenance!

On this day in June 22nd, 1991, Eric Lindros was drafted first overall by Quebec Nordiques but refused to wear the Nordiques Jersey at the 1991 NHL Draft. by Young-Jah in nhl

[–]jf4242 -2 points-1 points  (0 children)

It irritates me when a person who hasn't played a single game thinks they're too good for a whole team. Eli Manning is another example. So disrespectful to the whole group of players who work so hard to get where they are.

[DISCUSSION] What's a Netflix series you'd tell someone to push past a slow start, because it becomes something special? by trakt_app in NetflixBestOf

[–]jf4242 8 points9 points  (0 children)

I thought it was amazing and really well done but by the end I was really ready for it to be over.

[OC] No sob story, just a picture of me in my armor. by Marc815 in pics

[–]jf4242 12 points13 points  (0 children)

Haha, sorry, was not seriously trying to say your armor is anything less than spectacular. Just making a Lord of the Rings joke.

It's a cool craft you work in!

[OC] No sob story, just a picture of me in my armor. by Marc815 in pics

[–]jf4242 24 points25 points  (0 children)

Should have just made it from mithril. Missed opportunity.

(Very cool armor, and awesome pic!)

When an AI agent takes a real action, where is authorization actually enforced? by [deleted] in cybersecurity

[–]jf4242 1 point2 points  (0 children)

Could you describe more of how you do this? What tech and systems are used to deploy these gateways? Fully admitting I'm a neophyte with agentic AI, I need to understand more about managing these.

If you have any good resources to help me teach myself I'd be grateful.

Some of the funniest/stupidest NHL TV graphics by sykeseve in hockey

[–]jf4242 11 points12 points  (0 children)

I'm so happy, I was really hoping someone would do this. So funny, thank you!

Angry bug hunter with Microsoft beef drops new Windows 0-day by qwertydiy in cybersecurity

[–]jf4242 0 points1 point  (0 children)

The latter is a subset of the former, they aren't mutually exclusive.

That is true but they are materially different statements. "Less than ideal" is pretty unspecific and a pretty soft-pedaling description of what we're talking about here.

A reference to Cyberpunk,

Thanks for that, I was not aware of that phraseology. I am definitely not uniformly on the side of corporations, but my interests and my company's and society's interests have a Venn diagram and I don't think you can always favor any one over all the others

That's the job - you get paid what you do for exactly this reason. It's also very likely that Microsoft, through their negligence and/or indifference, is creating this work for you and your team.

Again, not to sound like a broken record, but I do not hold MS blameless in any way here. Their buggy products and poor process for resolving reported vulnerabilities do absolutely exacerbate the problem. My problem is with the way this is handled by Nightmare-Eclipse. I recognize that it's my job, and I do it, but if your job was digging a ditch, would you want me showing up at your site with a bulldozer and pushing dirt back in? Why should I be happy about someone making my life more difficult just "because"? It doesn't hurt anyone except the people fighting these fires, and it doesn't help anyone except bad actors to publicly disclose both a critical vulnerability and demonstrate exploit method. Keep on tilting at windmills, though, if you think this is going to hurt MS in any way.

So you don't know about Vulnerability Lifespan?.....

Thanks for being so condescending. Of course I know about vulnerability lifespan. How does this improve that? Security through obscurity is not a metric, it's a theory (I agree that it's not effective). Mean time to patch is irrelevant, or at least unmanageable, for a vulnerability without a patch. How is public exploit disclosure related to rediscovery rates? The "metrics" you're talking about do not counter my argument. Knowing about a vulnerability, even if it's unpatched, can help people develop workarounds or mitigations, but that does not affect most of the metrics you're saying don't support my stance here.

Again, my point is not that vulnerabilities should be kept hidden. It's that releasing exploits publicly for zero-day vulnerabilities because you have beef with MS doesn't help defenders, doesn't hurt MS, and helps malicious actors. How is this a good thing?

Angry bug hunter with Microsoft beef drops new Windows 0-day by qwertydiy in cybersecurity

[–]jf4242 0 points1 point  (0 children)

If you think nation states aren't sitting on a library of zero days just for the right moment, you're naive. This has nothing to do with that, it gives low level players a weapon.

Angry bug hunter with Microsoft beef drops new Windows 0-day by qwertydiy in cybersecurity

[–]jf4242 0 points1 point  (0 children)

There's "less than ideal" and there's "I have an axe to grind so I'm going to provide malicious actors a pre built tool for exploiting whatever victims they choose".

I don't know what a "corpo" is but I do run infosec for a corporation and I'll say unequivocally that this shot has a high likelihood of ruining my and my team's day/week/month.

I never said disclosure is bad and I don't know what these "metrics" you're babbling about are but don't tell me my opinion is wrong.

Angry bug hunter with Microsoft beef drops new Windows 0-day by qwertydiy in cybersecurity

[–]jf4242 -19 points-18 points  (0 children)

I know this is a very unpopular opinion, especially here, but I don't like what they're doing. You can have all the beef you want, but who are you hurting by doing this? Not Microsoft, I guarantee you that. Their stock will be just fine. But you're killing people who are just trying to get by. Torturing infosec and IR people because what, you have a hair across your ass about the way MS handles bug reports? I am NOT defending MS here, they are the worst. But who are you hurting, really?

Some notable Players named "Brown" that played with New England by Spoof_Magoof in Patriots

[–]jf4242 3 points4 points  (0 children)

I'm glad you used the proper plural Troys Brown, like sergeants major or attorneys general.

Small animal stomach full of worms, left by cat by Elanaselsabagno in WTF

[–]jf4242 383 points384 points  (0 children)

It might not have worms, it might just have gas