boroboro's comments

boroboro | 10 years ago | on: Cyber attack on German parliament still active, could cost millions

Not sure about your agenda and why you spill inaccuracies and distort what articles say with a tendency to promote Russian SWR goals.

1. The problem arose because the parliamentarians did not use experts from the BSI but have no clue but do it on their own with their own people. The BSI protected government network is not affected.

2. The German interior intelligence agency is not "involved" as you put it - what agenda do you have? - the article says parliamentarians need to decide if they want to ask the counterespionage department of the German interior intelligence agency, what some don't want.

boroboro | 10 years ago | on: Cyber attack on German parliament still active, could cost millions

The German BSI is not part of the "intelligence community" and is not an intelligence agency, no matter how often you repeat your conspiracy theory. To spare everyone the trip to Wikipedia:

"The Federal Office for Information Security (German: Bundesamt für Sicherheit in der Informationstechnik, abbreviated as BSI) is the German Upper-level Federal agency in charge of managing computer and communication security for the German government. Its areas of expertise and responsibility include the security of computer applications, critical infrastructure protection, Internet security, cryptography, counter eavesdropping, certification of security products and the accreditation of security test laboratories."

boroboro | 10 years ago | on: Cyber attack on German parliament still active, could cost millions

1. People want to work, and I assume the 'productivity' of politicians (meaning "we don't want security") brought this in the first place. 2. If sophisticated, the outflow of information might be with a mobile device plugged in, or other means to jump the air gap when ethernet is disconnected.

boroboro | 10 years ago | on: Cyber attack on German parliament still active, could cost millions

Some years ago there was some press about how many German politicians were complaining about the state phones and would bring in and use their own shiny phones, probably this goes for laptops too. I assume this was against the wishes of IT security. Then boom, and the politicians are complaining again.

boroboro | 10 years ago | on: Apple Boss Tim Cook Hits Out at Facebook and Google

Everyone is collecting user data for targeting and segmentation in marketing. Not sure Tim Cook knows everything that is going on at Apple. I've worked directly with several CEOs of larger companies and none new everything that was going on.

boroboro | 10 years ago | on: Is ReactJS really fast?

How is something 310% slower. My physics professor would have slapped me for such sloppiness in wording.

boroboro | 10 years ago | on: Over 30% of Official Images in Docker Hub Contain Security Vulnerabilities

I'm confused.

Looking at the top vulnerability CVE-2014-9462 in mercurial.

It affects mercurial clients that access crafted repositories as far as I understand.

https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-94...

Even if I use mercurial in my Docker image to get my app and not prepackage it (what I do), and I know this is about public images, how is this "high" vulnerability? I don't deny it's one I would just like to learn why it is classified high if e.g. I use Docker for my HAProxy.

page 1