• 0 Posts
Joined 1 year ago
Cake day: June 14th, 2023


  • Could a hypothetical attacker not just get you to visit a webpage, or an image embedded in another, or even a speculatively loaded URL by your browser. Then from the v6 address of the connection, directly attack that address hoping for a misconfiguration of your router (which is probable, as most of them are in the dumbest ways)

    Vs v4, where the attacker just sees either your routers IP address (and then has to hope the router has a vulnerability or a port forward) or increasingly gets the IP address of the CGNAT block which might have another 1000 routers behind it.

    Unless you’re aggressively rotating through your v6 address space, you’ve now given advertisers and data brokers a pretty accurate unique identifier of you. A much more prevalent “attack” vector.

  • If you still do the sizing (it’s not entirely wasted as it’s a reasonably effective tool to gauge understanding across the team), This can still be done without the artificial time boxing.

    “How much work have we done in the last two weeks?” Just look at all the stories closed in the last two weeks. Easy.

    “When will X be delivered?” Look at X and all its dependencies, add up all the points, and guesstimate the time equivalence.

    Kanban isn’t a free for all, you still need structure and some planning. But you take most of that away from the do-ers and let them do what they do best… do.

  • It’ll most likely mean the people running stuff in the background. payroll, asset management and purchasing, IT staff, etc.

    These people will have an impact on ‘crime fighting’, but marginally. Eg. If there’s a problem with payroll it might mean the police officers are paid a day or two late. Or maybe office supplies aren’t kept well stocked in station.

    But it might also be anyone who’s not an “officer”. So police station support/maintenance, mechanics, analysts (people who help the police analyse gathered intelligence), 111 operators, etc.

    This would probably have significant impacts on ‘crime fighting’. 500 extra police isn’t going to be as effective if police cars are broken, intelligence isn’t accurate, or there’s a wait time on 111.

  • Ok. Did a quick read. And I think I mixed my words a little.

    Yes, Active Directory supports TOTP fine.

    But my understanding is rollouts can disable TOTP, and instead force the use of the proprietary scheme requiring the MS Authenticator app (which also supports TOTP) that uses push notifications to the device.

    As is the case with my employer. They didn’t enable TOTP, and I am unable to use the provided MFA QR code with 1Password.